Effective: 2 September 2026
Subprocessors
This list sets out the service providers that receive information from 4word so the service can work: who the provider is, what it does, what information it receives and in which product. The list is derived from the internal register we maintain, and it is updated whenever a material provider is added or its role changes.
The short version
Each provider receives only the information its role requires, and not every provider is used for every feature or every user. Some providers process information outside Israel. We do not ask our AI providers to train models on call content, and every provider listed here is live in the code today.
How we choose a provider
Before a provider is enabled we check what information it needs to receive, where it processes that information, what its transfer terms are and what contractual commitments it gives. A provider receives only the minimum its role requires. Other providers exist in the code as technical alternatives and are not active, so they are not listed here.
The provider list
The table lists every provider that receives information today. A role marked as depending on a choice runs only when the business or the user enables it.
| Provider | Role | Information it receives | Where it applies |
|---|---|---|---|
| Twilio Inc. | Telephony: phone numbers, call routing, audio streaming and phone-number verification by SMS | Phone numbers, call times and status, communications metadata and the call audio stream. Calls are not recorded to a file. | Personal and business products |
| Soniox Inc. | Speech recognition and live transcription for calls, in a project hosted in the United States. The standalone transcription feature in the app uses a separate project in the European Union. Speech generation is an option that is not enabled by default. | Call audio, transcript text, language hints and technical metadata. No name, number or user identifier. | Calls in both products, and standalone transcription in the app |
| Google LLC (Gemini API) | The conversation model that runs the call in real time | System instructions, conversation context, transcript turns, the business knowledge base, tool results and the model output | Personal and business products |
| Google Cloud Text-to-Speech | Text to speech - the voice the assistant speaks in | Only the text the assistant says. Caller audio is never sent. | Personal and business products |
| Anthropic PBC | Summaries, titles, translation, reply suggestions, business knowledge-base processing and replies on the WhatsApp channel | The transcript text and the business texts the task needs, plus images a business uploads explicitly. Audio is never sent. | Personal and business products |
| Railway Corporation | Hosting of the backend, the voice engine, the database and the cache | Everything the product stores or caches, plus operational request logs | The whole service apart from the public website |
| MongoDB Inc. (Atlas) | Storage of the public website form data and consent records | Name, email, phone, message text, consent metadata and a one-way hash of the IP address | The public website only |
| Google Firebase Cloud Messaging | Push notification delivery to the app | The device identifier and the notification payload: the caller's name and number, so a deaf user can see who is calling, plus a short question or summary line. A full transcript is never sent in a notification. | Personal product |
| Brevo | Verification and service emails sent from the app backend | Email address, name and message content. A business summary email carries the summary and the lead's name and number. | Personal and business products |
| Resend | The emails sent from the public website: form confirmations and team notifications | Email address, name and the contents of the form | The public website only |
| Vercel Inc. | Hosting the public website and running its API routes | Network requests, technical information and form data in transit | The public website only |
| Google OAuth, Google Calendar, Google Drive | Business product sign-in, and when the business connects them, calendar availability and Drive files as a knowledge source | Name, email address and Google account id; calendar events and free or busy times; and the files the business selected | Business product, at the business's choice |
| Google Places | Identifying a caller you have not saved | The caller's phone number as a search query, and the business identity that comes back. The result is cached for a limited period. | Personal and business products |
| Meta Platforms, Inc. (WhatsApp Cloud API) | The business WhatsApp channel, only when the business enables it | The customer's phone number, name, messages and delivery metadata | Business product, at the business's choice |
The details are derived from the internal provider register, which also holds the contractual evidence for each provider. A provider that is not enabled in production does not appear in the table.
AI providers
Speech and model providers receive audio or text only to the extent needed to run the feature. We do not ask them to use call content to train models. A provider may retain information for a limited period for security, abuse prevention, service operation or legal compliance, according to its agreement and the account settings; we choose plans and settings that reduce retention and training where those are available and suited to the feature. The limits of AI output are set out in the annex to the privacy policy.
Transfers outside Israel
Some providers process information outside Israel, mainly in the United States and the European Union. Before enabling a provider we review its processing region, its transfer terms and its contractual commitments. We do not present any environment as automatically compliant, and we do not undertake that any provider processes information in Israel only.
Change log
2026-09-02 - first publication of the list, derived from the internal provider register.
Questions about providers
4word operates the service. For questions about a particular provider, about the processing region or about your personal information, write to support@4word.io or use the contact form on the site.