Sub-processors
Harry The Marketer · Last updated 6 August 2026
The short version: the list below is every third party that can touch your data, and what
each one is for. Which ones apply depends on how your deployment is configured — a self-hosted instance with no AI
key set uses none of the AI providers.
We give notice before adding a sub-processor. To be told when this page changes, email privacy@harrythemarketer.com.
| Sub-processor | Purpose | Data it can see | Applies when |
|---|---|---|---|
| Auth0 (Okta) | Authentication and identity | Email address, name, profile picture | Auth0 sign-in is configured |
| Google LLC | Gmail send and read for connected mailboxes | Your mailbox contents accessed under the granted scopes | You connect a Gmail mailbox |
| Anthropic PBC | Email composition, reply classification, research, goal planning | Prompt content: business context, lead fields, thread text | An Anthropic key is configured for the deployment |
| OpenAI | Same AI functions, when selected as the provider | Prompt content: business context, lead fields, thread text | An OpenAI key is configured for the deployment |
| Hosting provider | Running the application and its database | All workspace data at rest | Hosted deployments; self-hosted operators are their own provider |
Not used
No advertising networks, no third-party analytics or session-recording scripts, and no data brokers. The platform ships with no tracking scripts of any kind on its marketing pages.
AI provider terms
The AI providers above act as processors and, under their standard API terms, do not train their general models on API inputs or outputs. Where a deployment has no AI key configured, the agent falls back to deterministic templates and a keyword classifier and no content leaves the deployment.