Sub-processors
Last updated: 2026-05-22
SourceWeaver uses the third-party services below to operate. The sub-processors process personal data on our behalf under GDPR Art. 28; the technology & model suppliers are software, model weights, or static assets we run or fetch ourselves and receive no customer personal data. All of our sub-processors are US-based providers engaged under appropriate data-processing terms.
Sub-processors
| Provider | Purpose | Personal data processed | Region |
|---|---|---|---|
| Render | Application hosting, PostgreSQL database, Redis queue, and encrypted file storage. | All account data, job metadata, and transcript files (at rest and in transit). | United States |
| Modal | On-demand GPU transcription (WhisperX speech-to-text and speaker diarization). | Audio extracted from the sources you submit. | United States |
| Anthropic | AI text processing via Claude Haiku — speaker-name resolution, semantic chunking, and Anki card generation. | Excerpts of transcript text. | United States |
| Cloudflare R2 | Encrypted off-site backups. | Backups of transcript files and the database. | United States / Global |
| Webshare | Residential proxy used to fetch the public sources you submit. | The source URLs you submit and the content fetched from them. | United States |
| Resend | Transactional email delivery (address verification, password reset). | Your email address and the message content. | United States |
| “Sign in with Google” authentication (optional — only if you choose it). | Your Google account email address and identifier. | United States / Global | |
| Sentry | Error monitoring and crash reporting. | Diagnostic error data. Personal data is minimised — IP/email/cookie capture is disabled. | United States |
| Stripe | Payment processing and subscription billing. | Your email and billing details. Stripe handles card data directly — we never store card numbers. | United States |
Technology & model suppliers
Disclosed for transparency. These receive no customer personal data.
| Supplier | Role | Data handling |
|---|---|---|
| Hugging Face | Source of the pyannote diarization and Whisper speech-recognition model weights. | Model weights are downloaded into our Modal containers. No customer audio or personal data is sent to Hugging Face. |
| WhisperX & pyannote.audio | Open-source transcription and speaker-diarization libraries. | Executed inside our Modal compute environment — they are software we run, not a third party we send data to. |
| Front-end asset CDNs (Tailwind, unpkg) | Serve static JavaScript and CSS to your browser. | Your browser fetches these assets directly, so the CDN sees your IP address. They receive no account data from us. |
| Termly | Authoring tool for our legal policy text. | Used offline only. Production serves policy text committed to our own codebase and never contacts Termly at runtime. |
Changes
We update this page when we add or remove a sub-processor. For questions about our data processing, contact privacy@usesourceweaver.com.