Subprocessors

Last updated: September 24, 2026

These are the third parties that host, store or process personal data for AutoTalent. We update this page when we add or replace one.

Used for every account

ProviderWhat forPersonal data involved
VercelHosts the web app and its server functions; runs scheduled jobs (daily follow-ups)All data handled by the web app in transit; request and function logs
SupabasePrimary databaseAccount, organization, requisition, candidate, outreach and billing records
RailwayHosts the MCP server used by the CLI and customer agentsRequests from MCP clients and the data those tools return; logs
ClerkSign-in, sessions and organization membershipCustomer users’ names, email addresses and organization membership
StripePayments and subscriptionsBilling contact and organization name; payment details are collected by Stripe directly
OpenAILanguage models for candidate scoring, drafting outreach and follow-ups, and classifying repliesCandidate profile data, requisition details, email drafts and candidate replies
TypeSafeModels that pre-screen and rank search results before full profiles are retrievedCandidate name, headline or summary, current title, company, tenure and location; requisition details
ApifyRetrieves public LinkedIn profile data for candidate searchesSearch queries and the public profile data returned
SendGrid (Twilio)Sends outreach and system email; receives candidate replies; reports delivery, bounce and spam eventsRecipient email addresses, message content, replies

Used only in some cases

ProviderWhat forPersonal data involvedWhen
Apollo.ioFinds a candidate’s work email addressCandidate name, current company and LinkedIn URLWhen an email address is needed and none is on file
Hunter.ioFallback email finderCandidate first and last name and a company domainWhen Apollo.io finds no address
OpenRouterRoutes talent assistant chat to a language model (DeepSeek)Chat messages and the candidate and requisition data the assistant’s tools returnWhen the talent assistant is enabled for an account
Google (Gmail API)Sends outreach from a customer’s own Gmail account (send-only permission)Outgoing messages and recipient addressesOnly if a customer connects Gmail

If a customer connects their own SMTP server, their mail provider sends that customer’s outreach. That provider is chosen by the customer, not by us.

Where candidate data comes from

These are sources, not processors: AutoTalent requests public or licensed data from them to find candidates.

  • Public LinkedIn profiles, retrieved through Apify
  • Public GitHub profiles and repositories, through the GitHub API
  • Work email addresses from Apollo.io and Hunter.io
  • Information that customers enter, and messages that candidates send back

Not in use today

Voice screening is in development and is not available to customers. Before it launches we’ll add its telephony and speech providers to this page.

Questions

Email support@autotalent.ai about any of these providers, or to ask for a data processing agreement.