Legal
Subprocessors
Last updated: September 15, 2026
The third-party providers that process personal data on our behalf when you use Contrics. This list reflects what the product actually uses.
Verification in progress. The providers listed here were confirmed against our own codebase and configuration. The specific contractual terms, transfer mechanisms and data-processing agreements with each provider are being reviewed and will be reflected here once confirmed.
1. Core infrastructure
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database, authentication and serverless backend — the primary data store | Account data, workspace content, credit ledger, connected-account tokens | EU region (project vzksxfufdbycwhwstyma) |
| Vercel | Application hosting, serverless functions and CDN for www.contrics.com | Request metadata, IP addresses, anything submitted through the app server | US company; deployment region iad1 (US East) |
| Stripe | Payment, subscription and credit-pack processing | Billing details, payment method, transaction and invoice data | US/IE |
| Anthropic | AI processing for content generation, analysis and insights | Prompts and content you submit for generation or analysis | US |
| Resend | Transactional email — refund updates, withdrawal acknowledgements, notifications | Email address and the content of the message | US |
2. Platform and content providers
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Meta (Instagram, Threads) | Platform APIs for accounts you choose to connect | OAuth tokens, profile and content metrics for the connected account | US/IE |
| Google (YouTube Data API) | Platform API for a YouTube channel you choose to connect | OAuth tokens, channel and video metrics | US/IE |
| Google Fonts | Previewing a Google font you choose for your brand kit inside the app (the website's own typefaces are self-hosted) | IP address and browser details, sent when a preview font is fetched | US/IE |
| Competitor-research worker | Fetching public competitor content for the Intelligence feature | Public profile/post data; no Contrics customer personal data is sent | ⚠️ To confirm — self-hosted worker, region not documented in the repo |
3. Feature-specific providers (used only when enabled)
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Photoroom | Background removal for photos in the creative editor, when configured | Images you submit for background removal | ⚠️ To confirm: used only if enabled; a self-hosted model is the alternative |
| OpenAI (Whisper speech-to-text) | Transcribing video audio for captions, when the hosted endpoint is configured | Audio from videos you submit for transcription | ⚠️ To confirm: used only if enabled; a self-hosted server is the alternative |
| Meta (WhatsApp Business Platform) | Notifying our team of a new Enterprise demo request, when configured | Name, work email and company entered in the demo request form | ⚠️ To confirm: used only if enabled |
4. International transfers
Several providers above are established in, or transfer data to, the United States. Where we transfer personal data outside the EU/EEA we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision. The specific mechanism applying to each provider is part of the review noted above.
5. Changes and notice
We will update this page when we add or replace a subprocessor. If you are a business customer and would like advance notice of changes, email support@contrics.com.
See also our Data Processing information and Privacy Policy.