Legal

Sub-processors

Version
2.6
Effective
30 July 2026
Applies to
The ReadyAudit audit service, readyaudit.dev and the macOS app

In short: Seven parties can technically see something: Apple (purchases, and TestFlight where you use Device Verification), Cloudflare (website traffic and inbound mail routing), Google (the mailbox that inbound mail lands in), our host (the API, the queue and the build at rest), the model provider (screen content only), our email relay (notification mail), and our own audit machine. Your build binary reaches the audit machine, our host and — for Device Verification — Apple; it is never sent to the model provider. We give 30 days' notice before adding a sub-processor, and you can object.

1. What this page is

Where we process personal data on your behalf (see Privacy Policy, section 12), Article 28(4) GDPR requires us to tell you who else is involved. This is that list. It is exhaustive: if a company is not named here, it has no access to customer data in the ReadyAudit pipeline.

2. The boundary that matters most

Your build binary is never sent to the model provider. Three parties hold it, and no others: the simulator .app bundle travels from the macOS app to our API, where our host stores it at rest for as long as the job is queued, and it is then installed on a machine we own and control. Where you have enabled Device Verification, a second copy reaches a physical device we own by way of Apple's TestFlight — a distribution you initiate, from your own developer account, so Apple holds it under your agreement rather than ours. It is not uploaded to the model provider, not written to a cloud object store, and not shared with any other party in the table below.

What the model provider receives is screen content: the accessibility tree of the screen currently on display, control labels and roles, and — where a judgement must be made visually — an image of that screen. That is a narrower surface than the build, and it is the minimum an audit can work from. Whatever your app renders during the run can be part of it, which is exactly why the Terms require a disposable demo account and non-production data.

3. The list

4. Who is not on this list

We use no analytics provider, no advertising or attribution network, no customer data platform, no CRM holding customer records, no session-recording tool, no chat widget, no crash reporter that transmits off-device, and no cloud object store for evidence. Evidence is embedded_in_report, so no screenshot or recording is ever written to an object store — there is nothing for a storage provider to hold, and therefore none to name.

5. How we choose them

Before engaging a sub-processor we check that it offers a data processing agreement with terms at least as protective as ours, a lawful transfer mechanism where relevant, and a security posture appropriate to what it will hold. Each is bound by a written contract imposing the Article 28 obligations on it, and we remain liable to you for its performance.

6. Changes and your right to object

We give 30 days' notice on this page before a new sub-processor starts processing customer data, and we move the effective date at the top when we do. If you object on reasonable data protection grounds, write to info@readyaudit.dev within those 30 days. We will try to offer an alternative; if we cannot, you may stop using the service and we will return the value of any unspent credits through the process in the Refunds & purchases policy.

There is no email list to subscribe to for this — deliberately, since that would mean holding your address. Check this page, or ask us and we will tell you the current state.

An emergency replacement — a provider failing, or a security incident forcing a migration — may have to happen faster than 30 days. If that occurs we will say so here, explain why, and your objection right still applies after the fact.

Contact

Buğra Günay, Erzene Mahallesi, 113/28 Sokak No: 8/4, Bornova, İzmir, Türkiye.

One address handles everything — legal notices, privacy and data subject requests, support, security disclosure and accessibility feedback: info@readyaudit.dev. Put the subject in the first line and it reaches the right person.