Trust Center

Subprocessors

We use the following third-party vendors to deliver MyBookie. Each one processes only the data needed for their specific function. Subscribe to our changelog at /security to be notified when this list changes.

Last updated: May 17, 2026

SubprocessorPurposeData ProcessedLocation
MongoDB Atlas Primary database for all customer data (transactions, accounts, businesses)Email, hashed password, business data, transactions, encrypted Plaid tokensUnited States (us-east)
Plaid Bank account connection and transaction syncBank account metadata, transaction history (read-only)United States
Stripe Payment processing for subscription billingEmail, billing address, masked card number (PCI handled by Stripe)United States · global
Resend Transactional email delivery (security alerts, weekly briefs, invoices)Email address, email contentUnited States
OpenAI AI insights, KPI commentary, weekly Finance Brief generationAggregated financial summaries (no raw transaction data with PII)United States
Anthropic AI smart-categorization and chatbot responsesTransaction descriptions, user questionsUnited States
Vonage SMS delivery for 2FA codes (when SMS 2FA is enabled)Phone number, 6-digit one-time codeUnited States · global
Emergent (hosting) Application hosting and Kubernetes infrastructureAll data in transit and at restUnited States

How we add or remove subprocessors

  • Every new subprocessor is reviewed for data handling, security posture, and contract terms before integration.
  • This page is updated with every change. Material additions are announced via security@mybookie.ai to paid customers.
  • Customers on Business+ plans may object to new subprocessors in writing within 30 days of notice; we will work with you on a resolution.
  • For a signed DPA listing these subprocessors with EU Standard Contractual Clauses, email security@mybookie.ai.