TRANSPARENCY
Sub-Processors & Vendors
Last updated: April 2026
Last Updated: April 2026
Next Review Date: July 2026
If you have questions about any vendor on this list, email privacy@passthebot.dev
AI & Analysis Providers
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| Groq | United States | Primary AI optimization engine | Resume content, job descriptions, extracted text | groq.com/privacy |
| OpenRouter | United States | AI fallback routing (routes to OpenAI, Anthropic, Meta, others) | Resume content, job descriptions, extracted text | openrouter.ai/privacy |
| Google Gemini API | United States | AI analysis (tertiary fallback) | Resume content, job descriptions, extracted text | policies.google.com/privacy |
| Mistral AI | European Union / United States | AI analysis and fallback inference | Resume content, job descriptions, extracted text | legal.mistral.ai/terms/privacy-policy |
| Anthropic (Claude) | United States | AI model (via OpenRouter) | Resume content, job descriptions | anthropic.com/privacy |
| OpenAI (GPT-4) | United States | AI model (via OpenRouter) | Resume content, job descriptions | openai.com/privacy |
Payment Processing
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| Razorpay | India | Payment processing for Indian users (primary) | Email, billing address, payment method tokens (no card storage) | razorpay.com/privacy |
| Stripe | United States | Payment processing for international users (fallback) | Email, billing address, payment method tokens (no card storage) | stripe.com/privacy |
Email & Notifications
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| Resend | United States | Email delivery (TIER 1 - primary) | Email address, email content | resend.com/privacy |
| SendGrid | United States | Email delivery (TIER 2 - fallback) | Email address, email content | sendgrid.com/policies/privacy |
| Mailgun | United States | Email delivery (TIER 3 - final fallback) | Email address, email content | mailgun.com/privacy |
Analytics & Monitoring
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| Posthog | United States | Product analytics & user behavior | Anonymized usage events, feature interaction data (NO resume content) | posthog.com/privacy |
| Sentry | United States | Error tracking & performance monitoring | Error logs, performance data (NO resume content) | sentry.io/privacy |
| Datadog (optional) | United States | Infrastructure monitoring | Server logs, performance metrics (NO resume content) | datadoghq.com/privacy |
Infrastructure & Storage
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| PostgreSQL Database | India / US (configurable) | Primary data storage (encrypted at rest) | All user data: accounts, resumes, optimizations, job descriptions | Open source (postgresql.org) |
| Upstash Redis | United States | Caching & session storage | Session tokens, cache entries (temporary) | upstash.com/privacy |
| Cloudflare R2 | Global (distributed) | File storage for resume uploads (optional backup) | Resume files (encrypted) | cloudflare.com/privacy |
| AWS / GCP** (optional) | Global | Additional backup storage | Encrypted backups of user data | aws.amazon.com/privacy |
Job Search Aggregation
PassTheBot aggregates job listings from multiple sources. These vendors process your search queries but not your resume:
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| Jobspy | United States | Job aggregation (Indeed, LinkedIn) | Search query (role, location, keywords) | github.com/cullenwatson/jobspy |
| SerpAPI (Google Jobs) | United States | Google Jobs search results | Search query | serpapi.com/privacy |
| Adzuna | United Kingdom | Job search aggregation | Search query | adzuna.com/privacy |
| JSearch (RapidAPI) | United States | Job aggregation API | Search query | rapidapi.com/privacy |
| Remotive | Remote (distributed) | Remote job listings | Search query | remotive.com/privacy |
| WeWorkRemotely | Remote (distributed) | Remote job listings | Search query | weworkremotely.com/privacy |
Note: These vendors only see your job search queries, not your resume or any personal information.
Hosting & CDN
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| Vercel / Netlify (optional) | United States | Frontend hosting & CDN | HTTP request logs, IP addresses | vercel.com/privacy |
| Cloudflare (optional) | Global (distributed) | CDN & DDoS protection | HTTP request logs, IP addresses | cloudflare.com/privacy |
Security & Compliance
| Vendor | Location | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| 1Password / Vault | Canada | Secrets management | API keys, database credentials (NO user data) | 1password.com/privacy |
| Dependabot / Snyk | United States | Dependency vulnerability scanning | Source code repository access (NO user data) | snyk.io/privacy |
Data Retention by Vendors
Each vendor has different data retention policies:
- AI Providers: Retain conversation logs for 30 days, then delete (configurable per contract)
- Email Services: Store email delivery logs for 90 days
- Analytics: Retain anonymized usage data for 12 months
- Payment Processors: Retain transaction records for 7 years (tax/regulatory requirement)
- Database: Retained indefinitely until user deletes account + 30-day grace period
Your Rights Regarding Sub-Processors
- Right to Know: You can request a complete list of sub-processors at any time
- Right to Notice: We will notify you 30 days in advance of any changes to sub-processors
- Right to Object: You can object to the use of specific sub-processors; we will work with you to resolve concerns or you may delete your account
- Right to Details: We can provide detailed information about how any sub-processor handles your data
To exercise these rights, email privacy@passthebot.dev
Changes to This List
PassTheBot regularly reviews and updates vendor relationships. We will:
- Update this list at least monthly
- Notify users 30 days before adding new vendors that process personal data
- Provide a change log of vendor updates (available upon request)
Last reviewed: April 2026
Next review: July 2026
Questions?
If you have questions about any vendor on this list, or concerns about data processing, contact:
privacy@passthebot.dev
PassTheBot
Pune, Maharashtra, India