Legal
Sub-processors
Last updated July 29, 2026
Each company below is bound by an agreement compatible with our Terms and Privacy Policy, and with the processor obligations in Article 28 of the GDPR. We do not sell your data to any of them, and none of them may use it for their own purposes.
A company earns a place on this list by actually receiving data. We keep it short on purpose: a name appears here only if a live part of Torchable sends something to it, not because we once considered the service or because it is named somewhere in our configuration.
AI and language models
These providers generate the answers you see from Torchable AI, and turn your documents into a searchable form.
Anthropic, PBCanthropic.com
Region: United States
- Purpose
- Claude Opus + Haiku LLM (Torchable AI responses across Base, Connect, and Welcome Desk)
- Data scope
- Chat messages + AI responses (encrypted in transit; not used for training per Anthropic’s commercial API terms)
Google LLC (Vertex AI)
Region: United States
- Purpose
- gemini-embedding-2 for RAG embeddings
- Data scope
- Document chunks (text only in V1)
Infrastructure
These providers store and serve your data and run the application itself.
Supabase, Inc.supabase.com
Region: United States (primary), with optional EU region for EU customers
- Purpose
- Postgres database, Auth, Storage, Realtime, Edge Functions, Vault
- Data scope
- All Customer Data
Railway Corporationrailway.com
Region: United States (primary)
- Purpose
- Hosting for the Torchable web application (HTTP API + scheduled jobs) and the background worker (long-running jobs: sermon downloading, transcription, website scraping). Managed Redis for cache + rate-limit persistence.
- Data scope
- All Customer Data passing through the HTTP API or worker; sermon audio temporarily during transcription; transcripts; scraped HTML
Cloudflare, Inc.cloudflare.com
Region: Global edge
- Purpose
- Edge proxy + caching for torchable.com. CDN / Pages / R2 for cdn.torchable.com (the Welcome Desk widget bundle).
- Data scope
- Public widget assets + cached HTML; no Personal Data stored at rest
Data ingestion
This provider reads publicly available pages so Torchable can answer questions about them.
Firecrawl, Inc.firecrawl.dev
Region: United States
- Purpose
- Website scraping so your church’s public site can be used to answer questions. Receives your public root URL and per-page URLs during crawls; returns clean text.
- Data scope
- Public church-website content only (no Personal Data)
Billing
This provider handles subscription payments.
Stripe, Inc.stripe.com
Region: United States (primary), EU (via Standard Contractual Clauses) for EU Customers
- Purpose
- Payment processing, subscription management, metered billing
- Data scope
- Billing contact info, payment method (held in Stripe’s vault, so we never see card numbers), subscription metadata
This provider delivers the email Torchable sends on your behalf. That includes ordinary account email, and it also includes crisis escalations and Welcome Desk handoffs, which can carry pastoral content.
Resend, Inc.resend.com
Region: United States
- Purpose
- Transactional email: signup confirmation, password reset, staff invitations, crisis-escalation notifications, Welcome Desk handoffs to a person, and support contact
- Data scope
- Recipient email address and the content of the message. Escalation and handoff emails can carry pastoral content, so this scope is sensitive rather than routine.
Monitoring and error tracking
This provider helps us notice when something breaks. Every error report passes through a filter that strips personal information before it leaves Torchable.
Sentry, Inc.sentry.io
Region: United States (with EU residency option)
- Purpose
- Browser, server, and mobile app error tracking
- Data scope
- Error stack traces and event metadata. Every event passes through a filter that strips personal information before it is sent. From the mobile app, that includes the error type, a scrubbed error message, a scrubbed file path, the app version, which over-the-air update was running, and the user’s ID. It does not include message content, names, email addresses, breadcrumbs, or the device’s IP address.
Services you choose to connect
The list above covers the companies Torchable engages in order to run the Service. Your church’s information can also reach services that you connect to Torchable yourself. Those are described here so this page is a complete picture of where your data goes, whoever set the connection up.
Some of these connections only read information into Torchable. Others also write back out. Where Torchable can write, it is called out below, because the direction is the part worth knowing before you connect something.
- Planning Center Online. Connected by an administrator at your church, using your church’s own Planning Center account. Torchable reads people, groups, calendars, and services on a schedule and on request, and stores that information so it can be searched. Torchable can also write back, adding or removing a person’s group membership in your own Planning Center account. That write capability operates only for churches that have turned it on.
- Google Workspace and Microsoft 365. Connected by an individual staff member, using their own work account rather than a church-wide one. Torchable reads calendar events and the specific files that person selects, and it can create or update calendar events and send email as that person. The permissions we ask for are deliberately narrow: we cannot browse a mailbox or a whole drive. The access can be revoked at any time from Google’s or Microsoft’s own account settings, without involving us.
- Signing in with Google. If you sign in to Torchable with a Google account, Google passes us your name, email address, and profile image so we can create or match your Torchable account, and Google can see that you signed in to Torchable and when. Signing in with an email address and password does not involve Google.
- YouTube. A channel or playlist an administrator connects and attests your church owns. Torchable reads video information and captions so sermons can be searched. Read only.
- Calendar feeds and your church website. Public addresses you point us at. Read only. Your website is read through Firecrawl, which is on the list above in its own right.
You can disconnect any of these at any time, and for most of them you can also revoke Torchable’s access directly from that service, without asking us.
How we tell you about changes
When we engage a new sub-processor:
- We add it to this page, with its purpose, region, and data scope.
- We tell Customers, by email to the billing contacts on the account, and with a notification inside Torchable.
- You may object, in writing, on reasonable grounds. We will work with you in good faith to resolve it.
- If we cannot resolve your objection, you may terminate the affected portion of the Service under your Data Processing Agreement.
The timing of that notice and the length of the window you have to object are set by your Data Processing Agreement, and that agreement governs. If you are not sure what yours says, email us and we will confirm it in writing.
When we remove a sub-processor
If we replace, retire, or bring a service in-house, we update this page and let you know. Removing a sub-processor does not require your consent, but we still tell you, because you should be able to trust that this page reflects reality.
Questions
If anything here is unclear, or you want to object to a sub-processor, write to privacy@torchable.com and a person will answer you. You may also want to read our Privacy Policy and Terms & Conditions.