Sub-Processors
Last updated: August 21, 2026
Forbidden Finance engages a small number of third-party companies — sub-processors — to help us operate the Service. The lists below identify each company, what we use it for, and where it processes data. Detailed categories of personal information we collect, and the purposes for which we process them, are described in our Privacy Policy (see Section 9).
For users in the EEA and the United Kingdom. The Service is hosted in the United States, and several of the providers below process personal data there. Where personal data of EEA or UK users is transferred to a country without an adequacy decision, the transfer is protected by appropriate safeguards — the EU Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data protection law applies — incorporated into our data-processing agreement with the relevant provider, or by an adequacy decision where one applies. You may request a summary or copy of the relevant safeguards at privacy@403fin.io. See Section 16 of our Privacy Policy for how international transfers are handled.
Sub-processors that handle personal data on our behalf
| Vendor | Purpose | Location |
|---|---|---|
| Apple | In-app purchase and subscription billing for the iOS application | Global |
| Backblaze B2 | Encrypted off-site backup storage | US |
| Charla | Live-chat support widget on the marketing site (403fin.io), the help documentation site (help.403fin.io), and from the in-app Application Support chooser inside the application (app.403fin.io); all three surfaces route to the same support inbox | US |
| Cloudflare | DNS; CDN and edge caching; DDoS mitigation; Web Application Firewall; Bot Management (currently monitor-only, no enforcement); Page Shield script-integrity monitoring on the marketing site; Leaked Credentials Detection at authentication endpoints; Cloudflare Tunnel for public ingress to our application; Health Check probes of our public endpoints; Cloudflare Workers running at the network edge — including the data-export-edge Worker that serves your post-deletion data-export archive on a single-use signed URL, plus operational Workers for cache purging, cache-tag injection, and redirect routing; Workers AI, which performs the optional AI receipt reading described in the Privacy Policy — receipt images and forwarded receipt emails are processed for extraction only when you have turned that setting on, and under our agreement with Cloudflare this content is not used to train generative AI models; and Cloudflare R2 object storage for (i) the 30-day post-deletion data-export archive (encrypted at rest, 30-day lifecycle) and (ii) receipt images, which are encrypted under keys specific to your account before they are written to storage | Global |
| Consently | Consent management platform — cookie banner, consent record, GPC handling | Global |
| documentation.ai | Hosted help-documentation platform at help.403fin.io | US |
| emailit | Transactional and notification email delivery | US |
| Firebase (Google Cloud) | Mobile push notifications and app-integrity attestation | Global |
| Google Play | In-app purchase and subscription billing for the Android application | Global |
| Lunch Flow | Optional "bring your own connections" rail for bank accounts in the United Kingdom, Europe, Asia-Pacific, Brazil, and New Zealand. You subscribe to Lunch Flow directly, authorize your banks with them, and we read your account and transaction data from your Lunch Flow account; we provide your email address to Lunch Flow so it can identify your account when you sign in. Lunch Flow states that it acts as an independent controller of the personal information you provide to it, and connects to financial institutions through regional open-banking providers — GoCardless (UK/EU), Finverse (Asia-Pacific), Pluggy (Brazil), and Akahu (New Zealand) — which act for Lunch Flow under your direct agreement with Lunch Flow and are not sub-processors of ours. Lunch Flow maintains its own privacy policy and sub-processor disclosures | UK |
| Microsoft Azure | Primary application hosting — servers and databases (East US region, Virginia) | US |
| Neon | Managed PostgreSQL database hosting for our self-hosted in-app feedback and changelog portal — the feedback, comments, and votes you submit there, together with the account identifier, email address, and subscription tier used to sign you in (US East region, Virginia) | US |
| Plaid | Bank-account connection and transaction sync for U.S. users | US |
| Quiltt | Primary bank-account connection and transaction sync, together with Finicity (a Mastercard company) — the connected data aggregator Quiltt engages on our behalf. Quiltt maintains its own downstream sub-processor disclosures | US |
| Reoon | Email-address deliverability verification at signup and on email change | EU |
| Rybbit | Cookieless, consent-gated web analytics on the marketing site, help-documentation site, and feedback/changelog portal (direct browser visits only — the portal surface embedded inside the application carries no analytics) | EU |
| SnapTrade | Brokerage and investment-account connection — holdings, balances, transaction, and cost-basis (tax-lot) sync for U.S. users; read-only access authorized directly with your brokerage | US |
| Stripe | Subscription billing and payment processing | Global |
| Talsec | Mobile application integrity and device-security signals (runtime application self-protection SDK in the iOS and Android apps) | EU |
| Tally | Embedded forms (newsletter signup, waitlist) on the marketing site | EU |
| ZITADEL (self-hosted) | User authentication and session management — software we run on our own infrastructure | Self-hosted |
Vendors that do not receive personal data
The vendors below support Service operations but do not receive any personally identifying information about you. They receive public market data, currency identifiers, or anonymous monitoring signals only.
| Vendor | Purpose | Location |
|---|---|---|
| CoinGecko | Cryptocurrency price reference | Global |
| European Central Bank | Authoritative EUR reference rates | EU |
| ExchangeRate-API | Foreign-exchange rate provider (fallback) | US |
| Healthchecks.io | Cron-heartbeat monitoring (dead-man-switch) | US |
| Open Exchange Rates | Foreign-exchange rate provider (primary) | US |
Change management
We may add, remove, or replace sub-processors as the Service evolves. When we do, we update this page. If you would like to be notified by email when this page changes, contact us at privacy@403fin.io and we will add you to a notification list maintained for that purpose.
For questions about a specific sub-processor's privacy practices, please refer to that vendor's own privacy policy. Some of our sub-processors publish their own sub-processor lists for downstream transparency; we encourage you to consult those lists if you are interested in the full chain of processors.