Subprocessors and Service Providers
Effective date: August 7, 2026
Version: 6
Bornly uses the providers below to operate the Services. A "subprocessor" processes personal data for Bornly. Some listed platform or payment recipients can act as an independent controller for part of their processing; their own notice then applies.
Vendor access depends on the feature used. A provider's corporate group and published subprocessors may support its service under its agreement with Bornly. Restricted international transfers use the safeguards described in the Privacy Policy; details about the safeguard applicable to a request are available from privacy@bornly.com.
Processors
| Provider and main location | Service | Data that may be processed |
|---|---|---|
| Render Services, Inc., United States | Application and website hosting, managed database/cache infrastructure, logs, backups | Account, user content including health data, requests, IP/device data, operational logs |
| Cloudflare, Inc., United States/global network | DNS, security, content delivery, video streaming, and R2 object storage | IP/request metadata; requested static or video assets and app context; uploaded or generated assets including meal photos where used |
| OpenAI Ireland Ltd., Ireland, with OpenAI group subprocessors in the United States and other published locations | User-requested food, gut-health, nutrition, sleep, and Baby Names AI; permitted feedback/support AI; food-catalogue operations; surveys, research, translations, and internal product or marketing drafts | Relevant prompts, conversation history, health or lifestyle records, meal descriptions/photos, product and label images, food submissions/corrections, catalogue context, names and preferences, feedback, diagnostics, survey questions and responses, response context and identifiers, generated output, and usage metadata. The exact content depends on the feature and may include personal or sensitive data |
| Resend, Inc., United States | Transactional and support email | Recipient name/address, message content, templates, delivery and interaction metadata |
| RevenueCat, Inc., United States | Subscription and entitlement management | App/account identifier, store transaction, product, entitlement, subscription and attribution metadata |
| Slack Technologies, LLC, United States | Restricted internal support and operational notifications | Feedback and attachments, app/account/diagnostic context, food-operations reports, incident or service information, which can include personal or sensitive data |
| GitHub, Inc., United States | Software development and human-controlled issue tracking | Feedback and limited app/account/technical context placed in an issue by staff; source code and development records |
| Waastly content service, global internet delivery | Delivery and caching of articles, symptom definitions, symptom groups, app-specific product content, and fixed website or in-app marketing images | IP/request/device metadata, referrer information where sent, app and language, fixed asset paths, collection or document identifiers, and requested article category or feature identifiers. These requests do not intentionally contain account profiles, journal entries, HealthKit records, or health-log payloads, but identifiers and paths can reveal a visited page, app context, or health-related content interaction |
| Imgix, Inc., United States/global delivery network | Processing, caching, and delivery of a static Pregnancy/Gestatly image | IP, request and device/browser metadata and the static asset path, which identifies the Pregnancy app context. The URL does not include account data, pregnancy week, due date, journal entries, or other pregnancy records |
Payment and platform recipients
| Provider | Role and data |
|---|---|
| Apple Inc. | App distribution, in-app purchases, push delivery, Sign in with Apple, HealthKit, maps, widgets, and device services. Apple determines some platform processing independently. |
| Stripe Payments Europe, Limited / Stripe, Inc. | Direct payment, tax, fraud, dispute, and billing processing where offered. Stripe handles card and transaction data under its applicable roles. |
Public reference-data service
USDA FoodData Central supplies public food reference data and is not represented as a Bornly processor. When Bornly's server performs a user-requested barcode fallback, the service receives the product barcode and Bornly server request metadata. Bornly does not include the user's account identifier, IP address from the app request, journal entry, HealthKit record, or other health-log payload.
| Service | Role and data |
|---|---|
| USDA FoodData Central | Public-domain food and nutrient reference data; requested product barcode or food-reference ID and Bornly server request metadata |
Changes and questions
We update this page before or promptly after adding a provider that materially changes personal-data processing. Where a contract requires advance subprocessor notice, we give that notice through the agreed channel. Continued use after a public update does not replace consent where law requires a new consent.
Questions or transfer-safeguard requests: privacy@bornly.com.
Bornly apps
Use the policies. Then choose the app that fits.
Compare Bornly's focused apps, their purpose, and their availability.