Legal

Subprocessors

Last updated: July 13, 2026

Whisply is a Mac-only app. To deliver the service reliably we rely on trusted third-party providers, known as subprocessors, that may process certain data on our behalf. Each provider is engaged under a contract that requires appropriate confidentiality and security obligations, and we share data only to the extent needed for the specific purpose described below.

Current subprocessors

The following list reflects the subprocessors we use today, along with the purpose of the processing and the categories of data involved:

  • Cloudflare— Hosting, content delivery (CDN), and edge compute for whisply.net and related services. Data category: request data, including IP addresses, request metadata, and standard server logs.
  • Supabase— Authentication and database services that store account-scoped product records. Data category: account and authentication data, subscription and usage data, saved chats and transcripts, memories, task and receipt metadata, connector metadata, skills, settings, and deletion or export state.
  • Lemon Squeezy (Sold through Link, LLC, formerly known as Lemon Squeezy LLC)— Merchant of record. Lemon Squeezy handles payment processing, subscription management, tax collection, and remittance on our behalf. Mailing address: 354 Oyster Point Blvd, South San Francisco, CA 94080, USA. Privacy policy: lemonsqueezy.com/privacy. Data category: billing data, including payment method details and transaction history. Whisply does not store full card numbers on its own systems.
  • Composio— Authorization and credential brokering for managed connected accounts. Data category: pseudonymous Whisply account correlation, provider account identifiers, OAuth scopes, encrypted provider credentials, token lifecycle metadata, and transient provider API requests and responses for the services you choose to connect. Whisply configures provider-payload logging off and does not use Composio continuous sync or connector webhooks. GitHub is handled directly by Whisply's strictly read-only GitHub App and is not brokered through Composio.
  • AI and retrieval providers, including OpenAI, Anthropic, Google, and xAI— Inference and retrieval for the features that respond to your requests. Data category: the bounded prompt, conversation, transcript, screen, browser, connector, memory, attachment, or tool-result content routed to the selected provider for that request, plus minimized request metadata. Raw credentials are never included.

Services you connect

Google, GitHub, Microsoft, Notion, Slack, Zoom, Calendly, and any other service you deliberately connect are data sources and destinations you direct Whisply to use. They generally act under their own terms and privacy policies rather than solely as Whisply subprocessors. The connection flow identifies the provider, requested access, account, on-demand retrieval behavior, and how to disconnect or revoke access.

Changes to this list

We review and update this list from time to time as our infrastructure evolves or as we add, replace, or remove providers. When a material change occurs, we will revise the date at the top of this page. If you would like to be notified in advance of new subprocessors, email us at the address below and we will add you to our notification list so you can review changes before they take effect.

Contact

If you have questions about our subprocessors, the data they process, or how to receive change notifications, contact us at dynamicgpt@pm.me. We are happy to help and aim to respond promptly.