1. Overview
My Evening uses a small number of third-party service providers ("sub-processors") to deliver the App. Each sub-processor processes personal data only as instructed by us and only for the specific purpose listed below, under a written data processing agreement or equivalent contract terms. This page is the dated list: it is where each provider's identity, location, contracting entity, transfer mechanism and retention posture are recorded, and our other legal pages point here rather than repeating those details.
Contract status. Data-processing terms are in force with every provider listed below; for the two AI providers they are incorporated into the service agreements we accepted.
2. Current Sub-processors
Apple Inc. / Apple Distribution International Ltd.
- Role: App Store distribution and subscription billing as merchant of record (StoreKit 2); App Store Server API counterparty for entitlement verification; HealthKit on-device APIs. Apple is not an identity provider for My Evening: the App does not use Sign in with Apple and requests no Apple identity token.
- Data flows: Inbound: signed StoreKit 2 transactions and App Store Server Notifications V2 (including REFUND and REVOKE) are delivered to our backend. The signed transaction the App presents when you subscribe is also the credential our backend uses to establish your session: it verifies Apple's signature and derives your pseudonymous account identifier from the subscription's original transaction ID. Outbound: our backend calls the App Store Server API to read transaction, refund, and notification history by original transaction ID for entitlement verification and our operator admin portal. Our backend stores subscription, entitlement, and transaction data linked to your user account.
- Categories of personal data: Subscription entitlement and transaction records (product ID, original transaction ID, expiry, renewal and revocation status, environment, offer and ownership type, trial state). Your account identifier is a SHA-256 hash derived from the original transaction ID of your subscription; that transaction ID is itself part of the records above, so we hold both. We receive no name, email, or Apple ID; the App does not request them. Apple additionally processes your Apple ID account and billing data as an independent controller under its own privacy policy.
- Location: United States; Apple Distribution International Ltd. (Cork, Ireland) acts as the EEA/UK contracting party.
- Transfer mechanism: EU Standard Contractual Clauses + EU-US Data Privacy Framework (Apple Inc. is DPF-certified).
- Contract: Apple Developer Program License Agreement and Schedule 2 (Paid Applications Agreement).
- Privacy reference: apple.com/legal/privacy
Eleven Labs Inc. (ElevenLabs)
- Role: Real-time speech-to-text transcription. When you choose to speak, microphone audio streams over an authenticated connection from your device to our backend, which passes it to the provider. Our backend does not currently keep a copy of the audio.
- Categories of personal data: Voice audio. The names and non-relational aliases of people you thank are also sent as recognition keyterms to improve transcription accuracy (third-party personal data).
- Current handling: Audio is sent to the provider's endpoint in the United States. Our backend does not currently keep a copy. The provider's own retention terms under its data processing addendum apply.
- Location: United States.
- Transfer mechanism: Article 45 adequacy under the EU-US Data Privacy Framework is the primary basis. We checked the official Framework register on August 1, 2026: the entry under the register legal name Eleven Labs Inc. (New York, NY; participant id 9996) shows the EU-US DPF, the Swiss-US DPF and the UK Extension all Active, certified February 9, 2026, next certification due February 9, 2027, with JAMS as dispute-resolution provider and the FTC as statutory enforcement body. The EU Standard Contractual Clauses (Module 2: controller to processor, section 11.1 of the addendum) and the completed UK International Data Transfer Addendum (section 11.4) are the fallback, so this transfer would not be left without a Chapter V basis if the Framework fell.
- Contract: ElevenLabs Data Processing Addendum, last updated April 8, 2026, in force by incorporation into the ElevenLabs Terms of Use, which provide that it governs the processing of personal data contained in content input to the services.
- Privacy reference: elevenlabs.io/privacy
OpenAI (OpenAI Ireland Ltd. / OpenAI L.L.C.)
- Role: Cloud-assisted person detection on gratitude entries. This is a core part of how the App works: with AI features on, it runs whenever you save a gratitude entry, to suggest who you thanked. You agree to the AI features when you set the App up and can turn them off in Settings.
- Categories of personal data: The gratitude-entry text (first 1,000 characters) plus structured details about the people you have thanked: display name, preferred name, all aliases (including relational and kinship terms) and a count of how many times each has been thanked. This includes third-party personal data about people you mention.
- Retention / training: OpenAI does not train on API data by default. OpenAI retains each request and the response for at least 30 days (the provider's documented minimum; we do not control the maximum), and we may review them during that period to diagnose and improve person-detection quality.
- Location: United States. OpenAI Ireland Ltd. (Dublin) is our contracting party because we are established in the EEA; inference runs in the United States.
- Transfer mechanism: OpenAI holds no Data Privacy Framework certification: we checked the official Framework register on August 1, 2026 and it returns no entry for OpenAI under any status, and OpenAI's own European privacy policy relies on adequacy decisions, the Standard Contractual Clauses and the UK International Data Transfer Addendum rather than on the Framework. For EEA-origin data our own contract is with OpenAI Ireland Ltd., so our transfer is intra-EEA, and the onward transfer to the United States is made by OpenAI Ireland under section 4.1 of the addendum on the basis of agreements containing the Standard Contractual Clauses or an adequacy decision; we remain accountable for it as controller, and we assess it in our internal transfer-impact assessment. For UK-origin data, section 4.2 of the addendum has the Standard Contractual Clauses as amended by the UK Addendum deemed entered into (Module Two; Clause 17 governed by the law of England and Wales; the Information Commissioner's Office as competent authority), so no UK Extension certification is needed for this flow.
- Contract: OpenAI Data Processing Addendum, effective January 1, 2026, in force by incorporation into the OpenAI Services Agreement (its section 5.3) and accepted by using the services.
- Privacy reference: openai.com/policies/privacy-policy
Microsoft Corporation (Microsoft Azure)
- Role: Hosting and infrastructure: Azure Functions, App Service, Table Storage, Key Vault, Application Insights / Log Analytics, Front Door (global edge), Static Web Apps.
- Categories of personal data: The hashed subscription identifier that serves as your account identifier, and account timestamps (the user profile record); subscription, entitlement and transaction records linked to your account; per-user daily usage counters (call counts, token and cost totals, audio byte and session totals: counts only, not journal content); per-user and per-IP-hash rate-limit counters; live connection counters; first-party product analytics events (the onboarding funnel and counts-only ritual usage summaries), keyed to a random installation identifier generated on your device and to nothing else (not to your account, your name or email, and not to a device identifier assigned by Apple); because that installation identifier persists, we describe these events as pseudonymous; and Application Insights / Log Analytics telemetry (custom events keyed to the hashed account identifier, such as person-detection, speech-to-text and subscription events, plus exceptions, connection records and request telemetry, including IP-derived approximate city and country). Connection records can contain person names, aliases and phonetic variants sent as speech-recognition hints. Operational logs follow a rolling retention schedule, currently configured to 90 days. Deleting your account does not automatically remove these logs. Personal-data erasure requests require separate handling as described in the Privacy Policy. Front Door is a global edge; we configure no access logging on it, so we hold no edge access logs. Key Vault holds secrets only; no end-user personal data.
- Location: All backend resources that hold personal data (compute, Table Storage, Key Vault, Functions, App Service and Log Analytics) are in North Europe (Ireland). The marketing website static hosting is in West Europe (no personal data); Front Door is a global edge.
- Transfer mechanism: EU Data Boundary commitment (in-region processing for EEA customer data) + Microsoft Online Services DPA (which includes EU SCCs and the UK IDTA).
- Contract: Microsoft Customer Agreement + Microsoft Products and Services Data Protection Addendum (Online Services Terms).
- Privacy reference: Microsoft Trust Center
Microsoft Entra ID (Azure AD): operator portal identity provider
- Role: Identity provider that authenticates the sole operator's sign-in to our internal admin portal. No end-user personal data flows to Entra ID; it processes only the operator's own administrator login. Listed here for transparency.
- Categories of personal data: The operator's administrator account credentials and sign-in metadata. None of your data.
- Location: Microsoft cloud (operator tenant). Covered by the same Microsoft Online Services DPA as Azure above.
- Transfer mechanism: Microsoft Online Services DPA (EU SCCs and UK IDTA where applicable).
- Contract: Microsoft Customer Agreement + Microsoft Products and Services Data Protection Addendum.
- Privacy reference: Microsoft Trust Center
3. Notification of Changes
Material changes to this list (new sub-processors, removed sub-processors, or significant changes in role or location) are recorded on this page with the date of the change, and the "Last updated" line above is moved on every material change.
How we give notice. We do not hold your email address, so we cannot email you. Notice of a change to this list is given by updating this page and its version and date, and by updating the "Last updated" date on our Privacy Policy.