Sub-processors
Every provider that can see customer data, what it receives, and where it runs. Named individually, because “trusted partners” is not a list.
1The providers, and what each one sees
These are the third parties that can process customer data on our behalf. Each is bound by a written processing agreement, may act only on our instructions, and receives only what its job needs. A provider that is not on this list is not called.
| Provider | What it does | What it receives | Region |
|---|---|---|---|
| Fly.io | Hosting for the API and the job workers | Everything the service processes, in transit and in memory | EU and US regions |
| Cloudflare | Site and app delivery (Pages), file storage (R2) | Uploaded sources, rendered clips, request metadata, IP addresses | Global edge, bucket region as configured |
| Neon | The Postgres database | Account, workspace, source, moment, job and billing records | EU or US region as configured |
| Upstash | The Redis job queue | Job identifiers and the parameters a job runs with | EU or US region as configured |
| Google (Firebase Authentication) | Sign-in, email verification and password reset | Email address, user identifier, sign-in events, device metadata | US and global |
| Stripe | Subscriptions, payments and invoices | Billing email, customer and subscription identifiers, payment data | EU and US |
| Deepgram | Word-level transcription | The audio stream of the source being analysed | US |
| OpenAI | Moment selection, on-screen keywords and clip titles | Transcript text and the metadata of the source it came from | US |
| Google (Gemini API) | Choosing the output shape of a clip by looking at it | Ten thirty-second windows of the source, at 360p, and nothing else | Global |
| RunPod | Serverless GPU for rendering and speaker tracking | The seconds of video being rendered, and the transcript for that range | EU and US regions |
| Sentry | Error monitoring: recording failures so they can be fixed | Error messages and stack traces, account and job identifiers, IP address | EU and US |
| Replicateoptional feature | Hosted speaker tracking, when no local GPU is configured | Video frames of the range being rendered | US |
| Pexelsoptional feature | Stock b-roll lookup for cutaways | Search terms only — no customer footage or transcript | US |
| YouTube Data API (Google)optional feature | Title, duration and thumbnail for a pasted link | The video identifier in the URL you paste | Global |
| Google (Analytics)optional feature | Counting visits on the public site, with consent | Pages visited, referrer, IP address, coarse device information | Global |
2What that means for a single video
It is easier to judge the list by following one file through it. For a link you paste and one clip you approve:
- The file lands in Cloudflare R2, uploaded straight from your browser. Video bytes never pass through our API.
- An audio-only stream goes to Deepgram for word-level transcription. The video is not sent.
- The transcript text goes to OpenAI, which ranks the passages and writes the on-screen keywords. It does not receive the audio or the video.
- To decide what shape each clip should come out in — a square box, the whole frame, a bubble in the corner — ten thirty-second windows of the video are shown to Google’s Gemini API at 360p. It is the one provider on this list that sees pictures rather than words, and it sees five minutes of a two-hour recording.
- Only when you approve a moment do the seconds of that moment go to RunPod to be rendered. Nothing else in the video is fetched.
- The finished MP4 goes back to R2. Job records live in Neon, the queue in Upstash, the account in Firebase, and the subscription in Stripe. If any step throws, the error — not the footage — goes to Sentry.
3Transfers outside the EEA
Several providers process data in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the provider is certified under it. Where a provider offers a choice of region, the service is configured to the region named in the table.
4Notice of changes
This page is the notice. Before a new sub-processor starts handling customer data we update the list here and, for customers on a data processing agreement, send notice by email at least 30 days in advance so there is time to object.
To be told by email whenever this list changes, or to request the data processing agreement itself, write to intheclips.business@gmail.com. How the data is handled once it reaches these providers is described in the privacy policy.
The contract: accounts, plans, billing, your content, and where our liability ends.
What is processed, why, on which legal basis, for how long, and your rights over it.
The four things stored in your browser, and which of them need consent.
What you may not run through the pipeline, and what happens if you do.
What a score is and is not, and what the output does not promise.
For people we wrote to first: where the address came from, why it was yours, and how to make it stop.
Questions about any of this — including a request about your own data — go to intheclips.business@gmail.com.