Legal
Subprocessors
The third parties that process data on our behalf so Pharos can run. Some are core to the service; several are engaged only if you switch on the feature that uses them.
Last updated 25 August 2026
Draft. The facts here — where data is hosted, how long it is kept, what is deleted when — have been checked against the running system. What is still missing is the company's registered details, the governing law, and a lawyer's review; anything in square brackets is one of those. This is not legal advice, and counsel should review it before Pharos accepts customers.
Your email provider is not on this list
This is the important one. Pharos does not send your campaigns from an account we control — you connect your own Resend or Amazon SES account, and your subscribers' addresses go to your provider under your contract with them. They are your subprocessor, not ours, and you choose them.
The consequence worth understanding: your list, your domain reputation, and your suppression history live in an account that stays yours whether or not you keep using Pharos.
Core infrastructure
Always engaged
These run the service itself; using Pharos means using them.
| Provider | Purpose | Data |
|---|---|---|
| Neon | Managed Postgres — the primary database | All application data: accounts, contacts, campaigns, delivery history |
| Vercel | Application hosting and edge network | Requests to the app, including anything in transit |
| Cloudflare | R2 object storage for uploaded images, and a Worker that triggers scheduled jobs on time | Project logos and uploaded screenshots. The scheduling Worker only calls our own endpoints on a timer; no customer data passes through it. |
| Upstash | QStash job scheduling for campaign batches and automations | Recipient email addresses in scheduled batch payloads |
| Axiom | Operational logging | Diagnostics and error context; not contact records |
Account email
Pharos's own mail
Separate from your campaign sending. This is Pharos mailing you about your Pharos account — a password reset has to work before a sending credential could exist, so it cannot use yours.
| Provider | Purpose | Data |
|---|---|---|
| Resend or Amazon SES | Delivery of Pharos account email — address verification, password resets, workspace invitations | The recipient's email address and the message |
Optional integrations
Only if you connect them
None of these are engaged by default. Each is activated by an explicit action in project settings, and disconnecting stops the flow of data to it.
| Provider | Purpose | Data |
|---|---|---|
| Google (Gemini)Opt-in | AI drafting of campaign and social copy | Your prompt, brand voice and campaign brief. Not your contact list. |
| MailchimpOpt-in | Contact import, if you connect an existing audience | Contacts synced from the list you point at |
| Apple, Google Play, RevenueCatOpt-in | Revenue and app store review sync | Store reviews and aggregate revenue figures |
| Meta, BlueskyOpt-in | Social publishing and mention monitoring | Posts you publish and public mentions matched to your watches |
Changes
We will update this page before a new subprocessor starts handling customer data, and notify account owners by email where a change materially affects how data is processed. See the privacy policy for what we collect and why.