Sub-Processors — Me Journal
Last updated: 2026-07-07 Effective date: to be set when published Operator: Astronero Ltd (England & Wales)
This page lists every third-party processor that handles Me Journal user data on our behalf, what they process, where, the legal basis for the transfer, and how to reach their Data Processing Agreement.
We notify users by email at least 30 days before adding a new sub-processor that handles personal data. These notices go to every account holder at their registered email address — there is no separate list to join.
Currently active (in production)
| # | Sub-processor | Role | Personal data we share | Location | Certifications | DPA | |---|---|---|---|---|---|---| | 1 | Convex, Inc. (USA) | Application backend (database, functions, storage) | All app data — but journal, gratitude and mood-note content is encrypted in the user's browser before it is sent (end-to-end encryption), so Convex stores ciphertext we cannot read; Body Compass / PMS health data is additionally encrypted at the application layer; operational data (account identifiers, preferences, programme progress, AI usage ledger) is processed in the clear | United States | SOC 2 Type II | https://www.convex.dev/legal/dpa | | 2 | Clerk, Inc. (USA) | Authentication, session management, user records | Email, name (optional), password hash (we never see plaintext), Clerk session tokens | United States | SOC 2 Type II | Available on request from Clerk's legal page | | 3 | Stripe — Stripe, Inc. (USA) and its regional affiliates (e.g. Stripe Payments UK Ltd, Stripe Payments Europe Ltd) | Payment processing, subscription billing, fraud detection | Email, billing address, payment method (we never see full card numbers), subscription status, transaction history | UK + EU + USA | PCI DSS Level 1; SOC 1 + 2; EU-US Data Privacy Framework + UK Extension + Swiss-US DPF certified | https://stripe.com/legal/dpa | | 4 | Vercel, Inc. (USA) | Web hosting, edge runtime, analytics (when user has consented) | Request metadata inherent to hosting (visitor IP address, user agent, requested URLs) and application logs; pseudonymous page-view events when analytics consent is given; service-worker assets | United States | SOC 2 Type II | https://vercel.com/legal/dpa | | 5 | OpenAI, L.L.C. (USA) | LLM inference for the in-app AI chat assistant and AI mood recommendations | Chat messages a user types to the AI assistant; recent mood descriptions and streak counts for mood recommendations; connection metadata in transit. API content is not used to train OpenAI's models and is retained by OpenAI for up to 30 days for abuse monitoring, per OpenAI's API data-usage policy | United States | SOC 2 Type II | https://openai.com/policies/data-processing-addendum/ |
Planned (not yet in production — listed for transparency)
The following sub-processors are integrated in the codebase but inert until we enable them in production by configuring the relevant API keys. They will become active processors only after that happens, and we will update this page when they do.
| # | Sub-processor | Role | Personal data we will share | Location | Certifications | DPA | |---|---|---|---|---|---|---| | 6 | Anthropic, PBC (USA) | LLM inference for AI features when activated (gratitude insights, monthly synthesis) | Selected user content (e.g. journal excerpts, gratitude entries) only when AI features are explicitly enabled by the user. Zero retention will be configured before activation — Anthropic will not retain or train on Me Journal user content. | United States | SOC 2 Type II; ISO 27001 | https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa | | 7 | Beehiiv, Inc. (USA) | Newsletter and marketing email | Email address, name (optional), subscription tags (no journal content) | United States | SOC 2 (verify on Beehiiv trust page) | Available from Beehiiv's compliance team — request when configuring | | 8 | Resend, Inc. (USA) | Transactional email — account, programme and safety notices, synthesis reminders, support replies (password-reset and sign-in emails are sent by Clerk, not Resend) | Email address, message content (only the transactional message we send) | United States | SOC 2 Type II | https://resend.com/legal/dpa |
| 9 | Cloudflare, Inc. (USA + global) | R2 object storage for founder videos and cold system-log archives; Turnstile bot-detection on our public forms (waitlist, contact) | For R2: video files and redacted system logs (no journal content). For Turnstile: the visitor's IP address and browser signals are processed by Cloudflare when a form challenge runs | Global edge network; primary storage US | SOC 2 Type II; ISO 27001 | https://www.cloudflare.com/cloudflare-customer-dpa/ | | 10 | RevenueCat, Inc. (USA) | In-app-purchase subscription management for future native mobile apps (Apple App Store / Google Play would act as merchants of record) | App user ID, purchase receipts, subscription status (no journal content) | United States | SOC 2 — verify on RevenueCat trust page before enabling | Available from RevenueCat — verify before enabling |
Data flows — what goes where
Per-user typical data flow
USER BROWSER
│
│ HTTPS (TLS 1.2+)
▼
┌─────────────────────┐ ┌──────────────────────┐
│ Vercel (USA) │ ◀─────▶ │ Clerk (USA) │
│ — hosts Me │ auth │ — sessions, MFA │
│ Journal app │ │ — user records │
└─────────┬───────────┘ └──────────────────────┘
│
│ Convex API
▼
┌─────────────────────────────────────────────────────────┐
│ Convex (USA) │
│ — primary database (journal, mood, gratitude, ...) │
│ — server functions (queries, mutations, actions) │
│ — storage for audio (current) + cron schedules │
│ — encrypted at rest (AES-256) │
└────────────┬────────────────────────────────────────────┘
│
┌───────┼─────────────────┬──────────────────────┐
│ │ │ │
▼ ▼ ▼ ▼
┌────────┐ ┌────────┐ ┌──────────────┐ ┌──────────────────┐
│ Stripe │ │ OpenAI │ │ Cloudflare + │ │ Beehiiv + │
│ pay- │ │ mood + │ │ Anthropic │ │ Resend │
│ ments │ │ chat │ │ (when │ │ (when configured)│
│ │ │ AI │ │ configured) │ │ email surface │
│ │ │ │ │ │ │ │
└────────┘ └────────┘ └──────────────┘ └──────────────────┘
Key principles
-
Voice dictation never reaches our servers as audio. Dictation uses the browser's built-in Web Speech API; only the resulting text is sent to Convex. We do not use Whisper API or any server-side transcription service of our own. Note that some browsers (e.g. Chrome) process Web Speech audio on the browser vendor's servers rather than on-device; that processing happens under the browser's own privacy policy and the browser vendor is not our sub-processor.
-
AI providers must not train on user content. Content sent to OpenAI via its API is not used to train OpenAI's models and is retained by OpenAI for up to 30 days for abuse monitoring, per OpenAI's API data-usage policy. Before the dormant Anthropic-backed features are activated, we will configure Anthropic zero retention so it does not retain or train on Me Journal user content.
-
Payment data is minimised. We never see full card numbers — Stripe handles the entire card-on-file flow. We see only billing address, the masked card brand/last-4, and subscription state.
-
Authentication credentials are minimised. Clerk handles password storage (bcrypt hashing) and session token management. We never see user passwords in plaintext, hashed or otherwise.
-
No advertising or behavioural-tracking sub-processors. We do not use Google Analytics, Facebook Pixel, LinkedIn Insight Tag, or any other behavioural-advertising or cross-site-tracking sub-processor.
-
Web fonts load from Google Fonts. The app's fonts (Inter and Urbanist) are served from fonts.googleapis.com / fonts.gstatic.com, so Google LLC (USA) receives the visitor's IP address and browser metadata for those font requests. Google states that Google Fonts requests use no cookies and are not tied to Google accounts. We may self-host the fonts in future to remove this disclosure.
International data transfer mechanisms
Several sub-processors are based in the United States. Personal data transferred to them outside the EU/UK is subject to UK GDPR + EU GDPR's data-transfer rules. Our reliance:
- Stripe (Inc., USA), Vercel, Convex, OpenAI, Cloudflare, Anthropic, Resend, Beehiiv — primary basis is the EU Commission's Standard Contractual Clauses (SCCs) as included in their DPAs.
- Stripe specifically is also certified under the EU-US Data Privacy Framework, the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework.
- UK transfers rely on the UK Addendum to the SCCs where the processor offers it, or the UK International Data Transfer Agreement otherwise.
- Supplementary measures in addition to the contractual
mechanisms:
- Encryption in transit (TLS 1.2+) and at rest (AES-256) across all sub-processors
- No-training configuration on AI providers (API content is not used to train provider models), with zero retention configured where the provider offers it
- Minimisation of data sent to each sub-processor (only the fields strictly required for their function)
- We will evaluate EU-region storage for Convex data (via a Convex-offered EU region or an equivalent deployment) if the volume of EU users comes to justify it. Sign-ups from the EU/EEA are currently waitlisted rather than served, so EU-origin personal data is presently limited to waitlist contact details (email, first name, coarse region)
How we vet new sub-processors
Before any new sub-processor is added, we verify:
- DPA is in place (or can be signed) and incorporates the current SCCs as appropriate
- Security posture: SOC 2 Type II OR ISO 27001 certification preferred; documented security controls reviewed if not
- Data residency is acceptable for the data types involved
- Sub-processor's own sub-processor list is reviewed (chains matter — your processor's processor can be your weak link)
- Termination + data return / deletion clauses are reasonable
- Breach notification timeline is no slower than 72 hours
For each addition, we update this page and email all account holders at least 30 days in advance.
How we exit a sub-processor
When we end a sub-processor relationship:
- We export all relevant data within the 30-day notice window
- We confirm with the sub-processor that they have deleted (or anonymised) Me Journal user data per the DPA's data-return clause
- We update this page within 30 days of the termination
- We do NOT email users about termination per se — we only email for additions where their data goes to a NEW party
Article 28 GDPR compliance summary
UK GDPR + EU GDPR Article 28 requires controllers (us) to engage processors (the parties above) only under a written agreement that includes specific terms about subject matter, duration, nature, purpose, types of data, categories of data subject, obligations and rights, and procedures for breach + return / deletion + assistance with data subject rights.
Each DPA above contains those terms. Where a processor's standard DPA omits any element required by Article 28, we negotiate an addendum. Records of all signed DPAs are maintained internally as part of our Article 30 Records of Processing Activities (RoPA).
Contact
Questions about a specific sub-processor or data transfer:
- Email: privacy@me-journal.com
- Subject line: "Sub-processor query"
We respond within the 30-day window required by GDPR.
Sources
- Convex DPA
- Stripe DPA — DPA FAQ
- Vercel DPA
- Cloudflare DPA
- Anthropic DPA
- Resend DPA
- Beehiiv compliance — request DPA from compliance team
- EU Commission Standard Contractual Clauses
- UK Addendum to SCCs
- EU-US Data Privacy Framework