Subprocessors
Subprocessors
Effective Date: May 20, 2026 Last reviewed: August 6, 2026
This page lists every subprocessor that Vorda Holdings LLC, a Delaware limited liability company ("Vorda") engages to deliver the Services described in our Privacy Policy. Each subprocessor is contractually bound to:
- process personal data only for the purposes Vorda directs,
- maintain appropriate technical and organizational security measures, and
- comply with applicable data-protection laws (including, where relevant, the GDPR, UK GDPR, CCPA/CPRA, and the EU Standard Contractual Clauses).
For Vorda's direct individual users, this list is informative. For institutional customers under a Data Processing Agreement, this list is authoritative and material changes are notified with the lead time specified in that DPA.
Active subprocessors
| Subprocessor | Location | Data classes processed | Purpose | Transfer mechanism |
|---|---|---|---|---|
| --- | --- | --- | --- | --- |
| **Google Cloud Platform** (Cloud Run, Cloud SQL/Postgres, Cloud Tasks, Cloud Scheduler, Secret Manager, Cloud Logging, Cloud Storage, Cloud Armor) | United States | All Vorda data, at rest and in transit on Vorda infrastructure | Cloud infrastructure, encrypted-at-rest data store, queue processing, scheduled jobs, secret management, observability, edge geographic / abuse protection (Cloud Armor) | SCCs + GCP Data Processing Addendum |
| **Firebase** (Google): Authentication / Identity Platform | United States | Email, hashed credentials, MFA factors, sign-in events | Sign-in, identity verification, MFA (TOTP / SMS / recovery codes) | SCCs + Google Cloud DPA |
| **Anthropic**: Claude API | United States | Excerpts of Connector Data, training-plan inputs (the user's training goal and stated constraints, which may include injury information), and Vorda prompts at inference time only; **zero-retention** of inputs and outputs | AI inference for Vorda chat, briefings, and training-plan generation and revision | Anthropic Zero Data Retention enterprise agreement + DPA; no training on customer data |
| **OpenAI**: GPT API | United States | Excerpts of Connector Data, training-plan inputs (the user's training goal and stated constraints, which may include injury information), and Vorda prompts at inference time only; **zero-retention** of inputs and outputs | AI inference for Vorda chat, briefings, and training-plan generation and revision (when the user opts to use OpenAI as the model) | OpenAI Enterprise zero-retention agreement + DPA; no training on customer data |
| **Plaid**: Financial connectivity | United States | Item access tokens (held by Plaid, encrypted reference held by Vorda); account, transaction, balance, and liability data | Connecting bank and credit card accounts via Plaid Link; transaction and balance sync via `transactions/sync` | Plaid End User Privacy Policy + Plaid Data Processing Addendum |
| **Google APIs (Calendar)** | United States | Calendar event metadata + bodies for calendars the user has granted | Calendar-event sync (read-only) and push notifications via `events.watch` | Google API Services User Data Policy, Limited Use; data is the user's own Google account data |
| **Google APIs (Gmail)** | United States | Email threads, messages (headers + bodies), draft metadata for mailboxes the user has granted | Inbox sync via `users.history.list`; draft creation via `users.drafts.create`; push notifications via Pub/Sub. **Send is not used.** | Google API Services User Data Policy, Limited Use; restricted-scope verification required (`gmail.modify`) |
| **Oura Health Oy** (Health and recovery connectivity) | Finland (Oura Health Oy); United States (Oura Inc.). Data is cloud-stored; the exact processing region is to be confirmed by counsel before publish. | Oura Ring biometrics for the Health Skill: sleep sessions and stages, HRV, resting heart rate, readiness / sleep / activity scores, workouts, SpO2, wrist temperature. **Special-category health data.** | Recovery, sleep, and activity sync for the Health Skill via the Oura API | Oura Data Processing Addendum; for any transfer outside the EEA or UK, EU Standard Contractual Clauses and the UK Addendum as applicable. Entity, processing region, and transfer basis pending counsel confirmation. The data is the user's own Oura account data, retrieved at end-user direction under OAuth. |
| **Stripe** | United States | Billing contact identity, payment-method tokens (full PAN never held by Vorda), subscription metadata | Subscription billing for paid Vorda tiers | Stripe Data Processing Addendum |
| **Resend** | United States | Email-address recipient, message content for transactional emails (briefings, alerts, service notices) | Transactional email delivery | Resend DPA + SCCs |
| **Vercel** | United States | IP addresses, request metadata; rendered HTML/JSON for the marketing site and admin web app, with **no decrypted Connector Data and no Vorda conversation content traverse Vercel edge** | Hosting and edge serving of `usevorda.com` (marketing, waitlist, blog, legal) and the Vorda admin web app | Vercel DPA + SCCs |
| **Sanity** | United States | Editor-authored content (blog posts, legal pages, marketing copy) and editor identities. **No end-user personal data, no Connector Data, no Vorda content is sent to Sanity.** | Headless CMS that serves blog and legal content rendered on `usevorda.com` | Sanity DPA + SCCs |
| **Expo (Application Services)** | United States | Push tokens, push-message content | Push-notification delivery to the Vorda mobile app on iOS and Android | Expo Terms of Service + DPA |
| **Cloudflare** | United States | IP addresses, request metadata for `usevorda.com` and `api.usevorda.com` | DNS, CDN, DDoS protection, edge-level WAF | Cloudflare DPA + SCCs |
| **Sentry** | United States | Error events, stack traces, request URLs, and **never** decrypted token material, decrypted Connector Data, or message bodies | Application error tracking | Sentry DPA + SCCs |
Connector flows are end-user-directed
Plaid, Google APIs, and Oura are listed above as subprocessors because Vorda calls them on the user's behalf. The data they hand back, however, is the user's own data from the user's own accounts, accessed by the user's explicit consent through each provider's standard connect flow. Vorda stores that data on the user's behalf under the Privacy Policy; we do not purchase data from these providers.
Training data is not an end-user-directed connector flow and adds no subprocessor. The training goals and constraints a user writes in Vorda Health, and the plans, revisions, benchmarks, and adherence records Vorda generates from them, are created inside the platform, stored on Vorda infrastructure, and sent to the AI subprocessors above only at inference time under zero-retention terms. See Section 1.6 of the Privacy Policy.
Cross-Skill connections that Vorda draws in a briefing (Section 1.3 of the Privacy Policy) add no subprocessor. They are derived inside the platform from data the user already connected, stored on Vorda infrastructure, and sent to the AI subprocessors above only at inference time under the same zero-retention, no-training terms; they are not shared with any additional subprocessor.
Apple HealthKit is not a subprocessor. Health Skill data from HealthKit is read locally on the end user's device under the user's per-category HealthKit permission and synced to Vorda; Vorda transmits no health data to Apple. HealthKit is a data source for the Health Skill, governed by the Privacy Policy.
Notification of changes
We may add, remove, or replace subprocessors as the Services evolve.
- For direct individual users: material changes are published here and at <https://usevorda.com/legal/subprocessors> and, where required by applicable law, reflected in the next version of the Privacy Policy.
- For institutional customers under a DPA: Vorda gives at least thirty (30) days' written notice (or the period stated in the DPA, whichever is longer) before engaging a new subprocessor. Customers may object in writing within that notice period if they have a reasonable, lawful basis for doing so, in which case Section 6.3 of the DPA controls.
Subscribe to subprocessor updates
To be notified by email when this list changes, email legal@usevorda.com with the subject line "Subprocessor notice subscription." Institutional customers under a DPA receive notifications automatically per their agreement.
Contact
For questions about a subprocessor or this list:
Vorda Holdings LLC Legal: legal@usevorda.com Privacy: privacy@usevorda.com Website: usevorda.com