Subprocessors
Every third party that receives data from Brand Climb, what it receives, and why. This list lives in the same repository as the code, so a provider cannot enter the request path without appearing here in the same change.
In the request path today
HTTP requests, and operational logs for the pages and API routes you use.
Your account, projects, prompts, competitors, monitoring runs and stored answers. This is the system of record.
Job event payloads — project identifiers and run parameters, not the answer text.
Stack traces and technical diagnostics. Configured with sendDefaultPii disabled, so user identifiers are not attached.
Your billing identity and payment details, entered on their checkout. Card numbers never touch our systems; we store only which plan you are on and its status.
Your email address and the contents of the message being sent.
The text of the prompts you track. Not your account, credentials or contact details.
Prompt text, and for analysis the brand context you entered.
Prompt text. If you connect Search Console, an OAuth token scoped to the properties you authorise.
The text of the prompts you track.
Public page text fetched from the site being audited.
The text of the prompts you track, for projects on the Pro plan. Plans below Pro read three metrics engines and do not reach it.
Configured but switched off
Nothing on a customer plan. Every plan reads one citation engine and that engine is Perplexity, so a run does not reach this one. If a plan is ever given a second citation engine, it would receive prompt text plus the country and language you selected.
Nothing. The credentials are configured, but no plan reads enough metrics engines to reach it — it sits fifth and the highest cap is four.
Most of these providers are established in the United States. Brand Climb is not yet incorporated, so no transfer mechanism has been signed — see the data-processing page for what that means today. Questions: legal@brandclimbai.com.