# Subprocessor and external-recipient register > **Current launch policy — 2026-09-06:** KarmicCompass is for adults aged 18 and over in every launch country. This supersedes prior teen/parental-admission instructions. App-wide access requires adult eligibility; no parental approval exception is offered. Date of birth is self-declared and server-checked, not independently verified. Historical records remain subject to existing retention/withdrawal/erasure rules. Apple: truthful questionnaire plus minimum-age override to 18+ (regional/older-OS mapping may differ). Google Play: only **18 and over**, with **Restrict minor access** enabled. Store settings do not replace in-app/backend enforcement. Privacy v3.5 / Terms v2.8 are verified on the public website. Production app/backend rollout remains separate and pending. **Version:** v3.5 — 2026-09-07 (plain-language policy update; controls unchanged; aligned to Privacy Policy v3.5, 2026-09-07) **Aligned with:** Privacy Policy v3.5 **Controller:** Diksha Dutt, operating as KarmicCompass **Contact:** `app.karmiccompass@gmail.com` The Privacy Policy governs. This register records the actual runtime routes and the evidence required for Google Play's service-provider `Shared = No` convention. A vendor is treated as a processor/service provider only if its current contract and practice show it processes solely on KarmicCompass's instructions. If that cannot be proved, update Privacy, RoPA and affected Play rows to disclose sharing before launch. The product currently has **no advance-notice mechanism** for subprocessors; changes follow the Privacy Policy's update/fresh-consent process and must not be described as seven-day advance notice. ## Runtime processors / provisional service providers | Provider/entity | Service and purpose | Data | Route / location | Contract and launch evidence | |---|---|---|---|---| | Google LLC | Firebase Auth, Firestore, Cloud Storage, Cloud Functions/Run, App Check, logging | Account, profile, consent, journal/chat, media, AI-derived data, usage/security, deletion and subscription state | Primarily configured `us-central1`; verify every deployed resource | Verify and retain the agreement accepted by the production account, the applicable Google Cloud data-processing terms/SCCs and effective date, plus the live project/resource/IAM/retention inventory. Public terms alone are not execution evidence. | | Google LLC | Vertex AI — only inference route for eligible adults, including nightly letters; under-18/unknown DOB requests blocked | Feature-specific profile, journal, chat, audio/image and health-adjacent prompt and response context. One raw voice recording is sent for transcription; the local retry/recovered-transcript stores are not separately sent except when the user-requested processing is retried. Daily Horoscope sends zodiac sign/date, a bounded current-sky briefing and ten locally derived theme scores; no raw DOB, birth time, birthplace, search text, city/country, timezone, place ID or coordinates. | Configured Vertex project/region; verify final deployment. Google may apply temporary service-delivery caching and abuse-monitoring logging under the governing terms/settings; zero provider retention is not claimed without evidence. | Verify and retain the production account's accepted agreement, applicable Google Cloud data-processing terms/SCCs and effective date, customer-data terms, paid project, cache/request-log settings, abuse-monitoring exception status and health-adjacent processing eligibility. Under-18 AI access is disabled; no written teen permission is verified. | | Google LLC | Gemini Developer API — retired historical route, not current processing | No current data flow | No API-key secret is bound and source hard-disables the route for every user | Treat any proposed reintroduction as new processing requiring legal/product review, policy versioning and fresh consent before activation. | | RevenueCat, Inc. | Subscription entitlement, webhook/reconciliation and erasure | Firebase UID as App User ID, store receipt/product/status | RevenueCat infrastructure (verify region) | Verify and retain the production account's applicable DPA/SCCs and effective terms, plan/webhook support, retention and exact delete endpoint/key canary. | | Functional Software, Inc. d/b/a Sentry | Optional App crash/performance diagnostics and DSAR erasure; optional website browser error reports; failure-only kc-mobile Cloud Functions error reports (`SENTRY_DSN_FUNCTIONS`, inert when unset). Website server reporting remains source-disabled because server requests have no browser consent signal. | App: server-mapped pseudonymous IDs and scrubbed stack/diagnostic/performance data. Website: scrubbed browser error/stack/path data after browser opt-in only. Cloud Functions: operation name, redacted message and stack only — no UID or other account identifier, content, request body or IP (Privacy §7.5/§8.5). | Sentry project (verify region) | Verify and retain the production account's applicable DPA/SCCs and effective terms, configured retention, limited token, App/browser consent, website server-disable, ingestion/scrub/export/delete canaries. | | Expo, Inc. | Push-notification relay to APNs/FCM | Expo push token and generic notification title/body | Expo push infrastructure (verify region) | Current terms/DPA or service-provider terms; confirm no independent use and generic payloads | | Google email service — deployment identity to verify | Deletion/consent/security/support email delivery | Recipient email, OTP/link and message content | Current code uses Gmail SMTP credentials | Determine whether this is consumer Gmail or Google Workspace. Retain the applicable service-provider/DPA terms; if no processor basis exists, update Play `Shared` answers and policy. | | Vercel Inc. | Public website hosting for Privacy, Terms, support, deletion and cancellation pages | Website visitor IP/request/device metadata in platform logs. Deletion-form submissions go directly from the browser to Firebase, not through a Vercel application handler. New cancellation secrets use URL fragments, which are not sent in the HTTP request; the temporary query fallback for old emails creates a legacy log-review gate. | Vercel edge/infrastructure; verify region/log settings | Vercel DPA/terms, log/analytics settings and retention. Confirm no undisclosed analytics/cookies; inspect/purge legacy query-token logs and remove fallback after old links expire. | ## Independent controllers / platform recipients These entities are not described as KarmicCompass subprocessors for the processing they independently determine: | Provider | Role/data | |---|---| | Apple Inc. | App Store distribution, Apple sign-in and iOS subscription/payment/receipt data under Apple's terms; KarmicCompass does not receive card details | | Google LLC (Google Play / Google sign-in) | Android distribution, Google sign-in and Play subscription/payment/receipt data under Google's platform terms; KarmicCompass does not receive card details | ## Not runtime recipients - The separate `kc-admin` operator system is controlled by KarmicCompass, not a new external recipient. Its hosting/storage providers remain the applicable rows above. UID/userId/auth-subject-linked records must join DSAR/erasure; email-only legacy support requires verified operator review. - The OS App sandbox, raw-audio queue, recovered-transcript/outbox/quarantine stores, content-free replay receipts/chat epoch and encrypted cleanup-path ledger are storage or first-party controls, not subprocessors. Device backup behavior must still be reflected in platform disclosures and tested. - Google fonts are bundled in the binary; no font CDN request is made. - GitHub and EAS process source/build materials, not ordinary end-user journal/chat data. Keep production user fixtures and secrets out of both systems. - There are no advertising networks, data brokers or cross-app tracking recipients. ## Pending before any EU/EEA/UK launch - Qualified EU and UK representatives where Art. 27 or equivalent applies. - Market/transfer/legal review, updated notices and any required consumer withdrawal implementation. Appointment must precede reopening those storefronts. ## Release evidence checklist - [ ] Retain current agreement/DPA/service-provider terms for every processor row. - [ ] Verify the exact legal entity, project/account, region, retention, independent data use and deletion/export capability. - [ ] Make Play Data Safety `Shared` values agree with the evidence. No evidence means change the affected row to `Yes` or remove/disable the transfer. - [ ] Verify Google AI paid project and health-adjacent processing eligibility in writing; verify the deployed 18+ AI restriction. - [ ] Verify whether email delivery is consumer Gmail or Workspace; do not claim a Workspace DPA merely because a Gmail address is configured. - [ ] Verify the operator system's actual Google project/account, IAM, UID/userId/ subject DSAR/erasure queries and shared erasure barrier; this source register is not deployment evidence. - [ ] Review this register quarterly and before every provider/model/region change. ## Plain-language reference crosswalk The customer documents are now authored in `docs/legal/privacy.json` and `docs/legal/terms.json`. The implementation references above retain their pre-rewrite labels against `docs/legal-history/privacy-v3.4.html` and `terms-v2.7.html`. In the current Privacy Policy, sections 1–3 keep their major numbers, former 3a is section 4, and former sections 4–18 are now 5–19. In Terms, sections 1–16 keep their major numbers, former 16a is section 17, and former sections 17–26 are now 18–27. Current user-facing cross-references use these new section numbers.