Sub-processors

Last updated: 2026-05-22

SourceWeaver uses the third-party services below to operate. The sub-processors process personal data on our behalf under GDPR Art. 28; the technology & model suppliers are software, model weights, or static assets we run or fetch ourselves and receive no customer personal data. All of our sub-processors are US-based providers engaged under appropriate data-processing terms.

Sub-processors

Provider Purpose Personal data processed Region
Render Application hosting, PostgreSQL database, Redis queue, and encrypted file storage. All account data, job metadata, and transcript files (at rest and in transit). United States
Modal On-demand GPU transcription (WhisperX speech-to-text and speaker diarization). Audio extracted from the sources you submit. United States
Anthropic AI text processing via Claude Haiku — speaker-name resolution, semantic chunking, and Anki card generation. Excerpts of transcript text. United States
Cloudflare R2 Encrypted off-site backups. Backups of transcript files and the database. United States / Global
Webshare Residential proxy used to fetch the public sources you submit. The source URLs you submit and the content fetched from them. United States
Resend Transactional email delivery (address verification, password reset). Your email address and the message content. United States
Google “Sign in with Google” authentication (optional — only if you choose it). Your Google account email address and identifier. United States / Global
Sentry Error monitoring and crash reporting. Diagnostic error data. Personal data is minimised — IP/email/cookie capture is disabled. United States
Stripe Payment processing and subscription billing. Your email and billing details. Stripe handles card data directly — we never store card numbers. United States

Technology & model suppliers

Disclosed for transparency. These receive no customer personal data.

Supplier Role Data handling
Hugging Face Source of the pyannote diarization and Whisper speech-recognition model weights. Model weights are downloaded into our Modal containers. No customer audio or personal data is sent to Hugging Face.
WhisperX & pyannote.audio Open-source transcription and speaker-diarization libraries. Executed inside our Modal compute environment — they are software we run, not a third party we send data to.
Front-end asset CDNs (Tailwind, unpkg) Serve static JavaScript and CSS to your browser. Your browser fetches these assets directly, so the CDN sees your IP address. They receive no account data from us.
Termly Authoring tool for our legal policy text. Used offline only. Production serves policy text committed to our own codebase and never contacts Termly at runtime.

Changes

We update this page when we add or remove a sub-processor. For questions about our data processing, contact privacy@usesourceweaver.com.