legal

Subprocessors

Producing a video requires sending parts of your project to AI providers and running the service on managed infrastructure. Every third party that touches customer data is listed here, along with what it receives.

Last updated

Current subprocessors

Generated from the service's own configuration, so it changes when the stack does.
ProcessorPurposeData receivedRegion
Dodo PaymentsMerchant of record: checkout, payment processing, tax, invoicing, refundsName, email, billing country, payment details (never received by supaintro)Global
SupabaseManaged databaseAccount and project dataConfigured cloud region
Amazon Web ServicesObject storage and render computeFiles you upload, and the media the service generatesConfigured AWS region
NetlifyHosting and delivery of the web applicationRequest metadata (IP address, user agent) in server logsGlobal edge
AnthropicAI text and image processingProject text, and a screenshot of your product pageUnited States
Google (Gemini API)AI video and text processingProject text, and video the service generatesUnited States
ElevenLabsAI audio generationProject text used to generate audioUnited States
Bright DataFetching a public product page when it is behind a bot wall. Only when the product or brand URL returns a bot challenge, and only if configuredThe product URL you suppliedGlobal
TavilyAlternative fetch path for a public product page behind a bot wall. Only when the product or brand URL returns a bot challenge, and only if configuredThe product URL you suppliedUnited States

What this means in practice

Three kinds of data leave the service. Text from your project, meaning your description, brand details, storyboard, and script, goes to AI providers to be read, written, and spoken. Images and video, meaning a screenshot of your product page and the cuts the service renders, go to AI providers to be looked at and assessed. Everything else stays with infrastructure. No provider receives more of your project than the step it runs requires, and none of them receives your payment details.

The infrastructure providers see whatever the service stores or serves: the database holds accounts, projects, and entitlements; object storage holds uploads and rendered video; the hosting provider sees ordinary request logs.

Payment details never reach us. Card data is entered on our merchant of record's checkout, and they are the seller of record on the transaction.

The two conditional entries only run when a product or brand URL you supplied returns a bot challenge, and only where that fallback is configured. Each receives one thing: the public URL you gave us.

Notice of changes

This page is the notice. If you have a data processing agreement with us that requires advance notice of new subprocessors, that notice is sent to the contact address on the agreement. To be told about changes without an agreement in place, write to support@vyanlabs.in and ask to be added to the list.