Subprocessors
Producing a video requires sending parts of your project to AI providers and running the service on managed infrastructure. Every third party that touches customer data is listed here, along with what it receives.
Last updated
Current subprocessors
| Processor | Purpose | Data received | Region |
|---|---|---|---|
| Dodo Payments | Merchant of record: checkout, payment processing, tax, invoicing, refunds | Name, email, billing country, payment details (never received by supaintro) | Global |
| Supabase | Managed database | Account and project data | Configured cloud region |
| Amazon Web Services | Object storage and render compute | Files you upload, and the media the service generates | Configured AWS region |
| Netlify | Hosting and delivery of the web application | Request metadata (IP address, user agent) in server logs | Global edge |
| Anthropic | AI text and image processing | Project text, and a screenshot of your product page | United States |
| Google (Gemini API) | AI video and text processing | Project text, and video the service generates | United States |
| ElevenLabs | AI audio generation | Project text used to generate audio | United States |
| Bright Data | Fetching a public product page when it is behind a bot wall. Only when the product or brand URL returns a bot challenge, and only if configured | The product URL you supplied | Global |
| Tavily | Alternative fetch path for a public product page behind a bot wall. Only when the product or brand URL returns a bot challenge, and only if configured | The product URL you supplied | United States |
What this means in practice
Three kinds of data leave the service. Text from your project, meaning your description, brand details, storyboard, and script, goes to AI providers to be read, written, and spoken. Images and video, meaning a screenshot of your product page and the cuts the service renders, go to AI providers to be looked at and assessed. Everything else stays with infrastructure. No provider receives more of your project than the step it runs requires, and none of them receives your payment details.
The infrastructure providers see whatever the service stores or serves: the database holds accounts, projects, and entitlements; object storage holds uploads and rendered video; the hosting provider sees ordinary request logs.
Payment details never reach us. Card data is entered on our merchant of record's checkout, and they are the seller of record on the transaction.
The two conditional entries only run when a product or brand URL you supplied returns a bot challenge, and only where that fallback is configured. Each receives one thing: the public URL you gave us.
Notice of changes
This page is the notice. If you have a data processing agreement with us that requires advance notice of new subprocessors, that notice is sent to the contact address on the agreement. To be told about changes without an agreement in place, write to support@vyanlabs.in and ask to be added to the list.
Related
- Privacy Policy, for what we collect and why.
- Data Processing Addendum, for customers who need one.
- Terms of Service.