Subprocessors

Last updated: July 1, 2026

Probara uses the following third-party subprocessors to deliver the service. Each processor is bound by a Data Processing Agreement (DPA) or equivalent contractual mechanism under their standard terms. We update this list when subprocessors are added or removed.

Vendor Purpose Data Processed Location
Cloudflare, Inc. Frontend hosting and CDN (Cloudflare Pages) IP addresses, request metadata, static page delivery Global (Cloudflare edge network)
Railway Corp. API backend hosting API request payloads, response data, application logs United States
Clerk, Inc. User authentication and account management Email address, hashed passwords, session tokens United States
Stripe, Inc. Payment processing and subscription management Billing information, card data (PCI-DSS compliant vault), transaction history United States
Resend, Inc. Transactional email (key issuance, receipts, notices) Email address, name, email content United States
Anthropic, PBC AI-assisted evidence synthesis (evidence grading pipeline) Ingredient name, outcome, anonymised corpus excerpts. No personal data is sent to Anthropic. United States

Evidence Data Source

Evidence corpus data is sourced from PubMed, a public biomedical literature database operated by the National Library of Medicine (NLM), US National Institutes of Health. PubMed is a public data source, not a subprocessor, and is accessed via the publicly available Entrez API. No personal data is transmitted to PubMed.

Subprocessor Change Notification

We will notify registered API key holders via email at least 14 days before adding a new subprocessor that processes personal data. To receive these notifications and to request information about any subprocessor, contact hello@probara.dev.

Probara