Sub-processors

Every provider that can see customer data, what it receives, and where it runs. Named individually, because “trusted partners” is not a list.

Last updated
29 August 2026
In force from
29 August 2026
Provided by
Simone Panini
Governed by
The law of Italy

1The providers, and what each one sees

These are the third parties that can process customer data on our behalf. Each is bound by a written processing agreement, may act only on our instructions, and receives only what its job needs. A provider that is not on this list is not called.

ProviderWhat it doesWhat it receivesRegion
Fly.ioHosting for the API and the job workersEverything the service processes, in transit and in memoryEU and US regions
CloudflareSite and app delivery (Pages), file storage (R2)Uploaded sources, rendered clips, request metadata, IP addressesGlobal edge, bucket region as configured
NeonThe Postgres databaseAccount, workspace, source, moment, job and billing recordsEU or US region as configured
UpstashThe Redis job queueJob identifiers and the parameters a job runs withEU or US region as configured
Google (Firebase Authentication)Sign-in, email verification and password resetEmail address, user identifier, sign-in events, device metadataUS and global
StripeSubscriptions, payments and invoicesBilling email, customer and subscription identifiers, payment dataEU and US
DeepgramWord-level transcriptionThe audio stream of the source being analysedUS
OpenAIMoment selection, on-screen keywords and clip titlesTranscript text and the metadata of the source it came fromUS
Google (Gemini API)Choosing the output shape of a clip by looking at itTen thirty-second windows of the source, at 360p, and nothing elseGlobal
RunPodServerless GPU for rendering and speaker trackingThe seconds of video being rendered, and the transcript for that rangeEU and US regions
SentryError monitoring: recording failures so they can be fixedError messages and stack traces, account and job identifiers, IP addressEU and US
Replicateoptional featureHosted speaker tracking, when no local GPU is configuredVideo frames of the range being renderedUS
Pexelsoptional featureStock b-roll lookup for cutawaysSearch terms only — no customer footage or transcriptUS
YouTube Data API (Google)optional featureTitle, duration and thumbnail for a pasted linkThe video identifier in the URL you pasteGlobal
Google (Analytics)optional featureCounting visits on the public site, with consentPages visited, referrer, IP address, coarse device informationGlobal
The ones marked optional feature are only reached if that feature is switched on or configured. With the feature off, no request is made and the provider receives nothing.

2What that means for a single video

It is easier to judge the list by following one file through it. For a link you paste and one clip you approve:

  • The file lands in Cloudflare R2, uploaded straight from your browser. Video bytes never pass through our API.
  • An audio-only stream goes to Deepgram for word-level transcription. The video is not sent.
  • The transcript text goes to OpenAI, which ranks the passages and writes the on-screen keywords. It does not receive the audio or the video.
  • To decide what shape each clip should come out in — a square box, the whole frame, a bubble in the corner — ten thirty-second windows of the video are shown to Google’s Gemini API at 360p. It is the one provider on this list that sees pictures rather than words, and it sees five minutes of a two-hour recording.
  • Only when you approve a moment do the seconds of that moment go to RunPod to be rendered. Nothing else in the video is fetched.
  • The finished MP4 goes back to R2. Job records live in Neon, the queue in Upstash, the account in Firebase, and the subscription in Stripe. If any step throws, the error — not the footage — goes to Sentry.

3Transfers outside the EEA

Several providers process data in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the provider is certified under it. Where a provider offers a choice of region, the service is configured to the region named in the table.

4Notice of changes

This page is the notice. Before a new sub-processor starts handling customer data we update the list here and, for customers on a data processing agreement, send notice by email at least 30 days in advance so there is time to object.

To be told by email whenever this list changes, or to request the data processing agreement itself, write to intheclips.business@gmail.com. How the data is handled once it reaches these providers is described in the privacy policy.