Legal

Subprocessors

Last updated: September 15, 2026

The third-party providers that process personal data on our behalf when you use Contrics. This list reflects what the product actually uses.

Verification in progress. The providers listed here were confirmed against our own codebase and configuration. The specific contractual terms, transfer mechanisms and data-processing agreements with each provider are being reviewed and will be reflected here once confirmed.

1. Core infrastructure

ProviderPurposeDataLocation
SupabaseDatabase, authentication and serverless backend — the primary data storeAccount data, workspace content, credit ledger, connected-account tokensEU region (project vzksxfufdbycwhwstyma)
VercelApplication hosting, serverless functions and CDN for www.contrics.comRequest metadata, IP addresses, anything submitted through the app serverUS company; deployment region iad1 (US East)
StripePayment, subscription and credit-pack processingBilling details, payment method, transaction and invoice dataUS/IE
AnthropicAI processing for content generation, analysis and insightsPrompts and content you submit for generation or analysisUS
ResendTransactional email — refund updates, withdrawal acknowledgements, notificationsEmail address and the content of the messageUS

2. Platform and content providers

ProviderPurposeDataLocation
Meta (Instagram, Threads)Platform APIs for accounts you choose to connectOAuth tokens, profile and content metrics for the connected accountUS/IE
Google (YouTube Data API)Platform API for a YouTube channel you choose to connectOAuth tokens, channel and video metricsUS/IE
Google FontsPreviewing a Google font you choose for your brand kit inside the app (the website's own typefaces are self-hosted)IP address and browser details, sent when a preview font is fetchedUS/IE
Competitor-research workerFetching public competitor content for the Intelligence featurePublic profile/post data; no Contrics customer personal data is sent⚠️ To confirm — self-hosted worker, region not documented in the repo

3. Feature-specific providers (used only when enabled)

ProviderPurposeDataLocation
PhotoroomBackground removal for photos in the creative editor, when configuredImages you submit for background removal⚠️ To confirm: used only if enabled; a self-hosted model is the alternative
OpenAI (Whisper speech-to-text)Transcribing video audio for captions, when the hosted endpoint is configuredAudio from videos you submit for transcription⚠️ To confirm: used only if enabled; a self-hosted server is the alternative
Meta (WhatsApp Business Platform)Notifying our team of a new Enterprise demo request, when configuredName, work email and company entered in the demo request form⚠️ To confirm: used only if enabled

4. International transfers

Several providers above are established in, or transfer data to, the United States. Where we transfer personal data outside the EU/EEA we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision. The specific mechanism applying to each provider is part of the review noted above.

5. Changes and notice

We will update this page when we add or replace a subprocessor. If you are a business customer and would like advance notice of changes, email support@contrics.com.

See also our Data Processing information and Privacy Policy.