Subprocessors

Last updated 14 September 2026

Localizing a video, recutting one to another shape, redrawing a creative, generating a clip or a still from a prompt, or generating a track all mean sending something somewhere. This is everywhere it goes, what each service receives, and what it is for. There is nothing off this list, except the timestamping service that countersigns the images, video and audio we deliver: it receives a hash and never the file itself. A subtitle or text file carries no signature, and today neither does the cover art on a track nor a still you generate — our own code offers both for signing under the wrong file type, as the service terms set out — so nothing of any of them reaches it at all.
ServiceWhat forWhereMay train on itSince
Contabo GmbH
Everything you type passes through this machine — a prompt, a style note, lyrics, glossary terms, the copy you approve on a creative — on its way to the database. What you upload passes through it too, unless your browser was handed a one-file link that puts that file into storage directly: a font is never uploaded that way and always comes through here, an extra cut of a video and a static creative always are, and a video or an image attached to a generation can arrive either way. It also reads an image back out of storage when you ask us to rewrite a prompt, and it holds the application's own configuration. It keeps no copy of your files: they are written to storage and released, and the temporary copy is deleted as the request ends.
Hosting for cralio.app and api.cralio.appGermany (Munich)Runs no model
Infrastructure. Sees bytes in transit, runs no model.
Keeps it: No copy kept — the file is written to storage and released.
Announced 2026-08-23; in service since 2026-08-22. No advance period ran: the 30-day rule was adopted 2026-09-07.
Amazon Web Services
Everything you upload — a video, a static creative, the stills and reference images you attach to a generation, a font — the finished files, the wording you typed, which is written into the request manifest stored here and onto the job's own row in the database named below, and the transcripts and subtitle files created along the way. Audio extracted from your video for transcription is never stored: it exists only on the disk of the machine running the job, which is itself a task in this account, is sent to the transcription provider named below, and is deleted when the step ends. It is never written to the bucket and never appears in a backup.
Storage, processing and queueingeu-north-1 (Stockholm)Runs no model
Infrastructure. Storage and a queue, no model.
Keeps it: On your plan's retention window. The transcripts and subtitle files a job writes along the way are stored beside the delivered video and are deleted with it. The database itself is dumped here once a day, from a table list derived from the migrations rather than hand-picked — accounts, job records, the credit ledger, your glossary, your saved subtitle styles, your consent records and the waiting list; never your files. One table is not on that list, and it is named here rather than left out quietly: the prompts you save in Generate. A rollback line in that table's own migration reads to the scanner as a drop, so nothing you save there is in any copy — and on a day the check can see the table, the run refuses rather than store a copy without it. The last thirty copies are kept, counted rather than aged, so a deleted row survives about a month while the daily copy runs, and longer whenever it does not — never past ninety days, which is the rule the storage service applies to the copies themselves.
Announced 2026-08-17; in service since 2026-08-11. No advance period ran: the 30-day rule was adopted 2026-09-07.
Google
For a static creative: the image itself, the wording read off it, and the translations you approved — then the delivered image a second time, so its pixels can be transcribed and checked against the line you approved, and a third time if you buy the second opinion described below. Your glossary terms are sent with a static creative, inside the prompt that reads it, so a brand name is protected before the work as well as corrected after it — the glossary is applied to the returned lines either way; they are not sent for a video, where the correction happens only on our side, after the words come back. For a track: your prompt, your style note, and your own lyrics if you wrote them, and — where you asked for a cover — the cover Google itself drew, sent back once so its lettering can be read off the pixels the way a static creative's is. You upload nothing to Music, so no file of yours is in that trip. For a generation: your prompt, and the stills or reference images you attached to it — a still to open or close a clip, or up to five references depending on the model. Rewriting a prompt sends the prompt and those images once more. The picker's resolution choice goes with the repaint, and the model, the aspect ratio, the resolution, the size of a still or the length of a clip, and the Variation setting on the models that take one go with a generation; nothing else about your account does.
Reading and repainting static creatives, checking the delivered pixels, and reviewing them if you buy that; generating music, titles and cover art; and generating clips and stills from a promptUnited States / Google's own regionsNo
The paid Gemini API tier. Google's Additional Terms for Paid Services say submitted content is not used to improve their models, and processing is under Google's own data processing addendum. We never call the free tier, where that is not the case.
Keeps it: Prompts and outputs are logged for up to 55 days for abuse monitoring only. We upload nothing through the Files API: every image goes inline with the request, and no audio of any kind is sent to Google at all. A generated clip is different — Google holds it as an operation and a file inside our own project until Google expires it. We fetch the clip and delete nothing ourselves.
Announced 2026-08-20, the day it went into service. No advance period ran: the 30-day rule was adopted 2026-09-07. Receives nothing of yours until you have accepted this register with this row on it; the tick is on the screen you submit from, and it covers the register whole — there is no box of this company's own to decline.
Needs your permission. Nothing of yours reaches this company until you have accepted this page with this row on it; the tick is on the screen you submit from, and it names this page among the documents that have moved. If you would rather not, clause 6 of the addendum gives you 14 days from the posting to end the part of the service that needs it and have back what you prepaid for it.
HeyGen
The source video, fetched once over a link that expires. We send it only for the job you submitted. Every video mode except captions in the video's own language goes through them; nothing from Statics, Music, Generate or a recut reaches them at all.
Dubbing, lip-sync, and the translation behind translated subtitlesUnited StatesYes, by default
Under its Privacy Policy and its Terms, HeyGen may use content submitted by accounts such as ours to train and improve its models, and that is the default. An opt-out is available on request to HeyGen and we have not asked for one; if we do, this row will say so and give the date. HeyGen states that its own AI vendors are contractually barred from training on content it passes to them. This is the reason the site no longer says "we do not train models on your content": we do not, and the company that dubs your video may.
Keeps it: Per HeyGen's own policy. Data belonging to a deleted account persists in their backups for about 60 days.
Announced 2026-08-17; in service since 2026-08-11. No advance period ran: the 30-day rule was adopted 2026-09-07. Receives nothing of yours until you have accepted this register with this row on it; the tick is on the screen you submit from, and it covers the register whole — there is no box of this company's own to decline.
Needs your permission. Nothing of yours reaches this company until you have accepted this page with this row on it; the tick is on the screen you submit from, and it names this page among the documents that have moved. If you would rather not, clause 6 of the addendum gives you 14 days from the posting to end the part of the service that needs it and have back what you prepaid for it.
Luma
The video you asked to have recut, fetched once over a link of ours that expires, and the sentence describing the shot if you typed one — it is optional, and where you leave it empty an empty one is sent. The shape you asked for and the resolution you picked go with it either way. Nothing else about your account does, and nothing from Video, Statics, Music or any other Generate tool reaches them at all.
Recutting a finished video to another aspect ratioUnited StatesNo
Their API Terms of Use — last updated 28 April 2026, read 11 September 2026 — say Luma will not train, fine-tune or otherwise develop its models on Input a customer submits through API access, or on Output generated from it. That promise is scoped to API access, which is the only way we reach them: their consumer Terms of Service take the opposite licence over Input, and their privacy policy describes training on what it covers. So the answer in this column is true because of the door we come in through, and we would rather write that down than print a bare No.
Keeps it: Not stated for the API, and we will not invent a schedule they have not published. Their API Terms name no retention period at all. Their enterprise terms give thirty days after an agreement ends to export what was sent and say they are under no obligation to hold it after that; their data processing addendum returns or deletes it on request at the same point. The recut comes back over a link of theirs that expires. Our own copy runs on your plan's retention window, like every other delivery.
Announced 2026-09-11. Receives nothing of yours until you have accepted this register with this row on it; the tick is on the screen you submit from, and it covers the register whole — there is no box of this company's own to decline.
Needs your permission. Nothing of yours reaches this company until you have accepted this page with this row on it; the tick is on the screen you submit from, and it names this page among the documents that have moved. If you would rather not, clause 6 of the addendum gives you 14 days from the posting to end the part of the service that needs it and have back what you prepaid for it.
OpenAI
Audio extracted from the video. No picture is sent.
Speech-to-text (Whisper)United StatesNo
API traffic is not used for training by default. The transcription endpoint is eligible for zero data retention, which we have not yet asked for.
Keeps it: Up to 30 days of abuse-monitoring logs.
Announced 2026-08-17; in service since 2026-08-11. No advance period ran: the 30-day rule was adopted 2026-09-07. Receives nothing of yours until you have accepted this register with this row on it; the tick is on the screen you submit from, and it covers the register whole — there is no box of this company's own to decline.
Needs your permission. Nothing of yours reaches this company until you have accepted this page with this row on it; the tick is on the screen you submit from, and it names this page among the documents that have moved. If you would rather not, clause 6 of the addendum gives you 14 days from the posting to end the part of the service that needs it and have back what you prepaid for it.
Supabase
Your email, your balance, and your job history — which carries the wording you typed on a generation, your style note and any lyrics you wrote, on the job's own row. Your glossary terms, your saved prompts and your presets are held here too, as are your credit ledger, the record of which terms you accepted and when, and your entry on the waiting list if you joined one. No video and no audio.
Accounts, job records and the credit ledgereu-west-1 (Ireland) — inside the EEARuns no model
A database. No model.
Keeps it: For the life of the account. A waiting-list address is the one thing here that is not tied to an account: it is deleted 90 days after the single message it was left for goes out, and kept until then if that message has not gone.
Announced 2026-08-17; in service since 2026-08-11. No advance period ran: the 30-day rule was adopted 2026-09-07.
Stripe
What you pay, and the card details you give them directly — those never touch our servers.
PaymentsUnited States and IrelandRuns no model
A payment processor. No model.
Keeps it: As their own terms and financial law require.
Announced 2026-08-17; in service since 2026-08-12. No advance period ran: the 30-day rule was adopted 2026-09-07.
Google Workspace (Gmail)
Your email address and the contents of those messages: a welcome when you register, an invitation if a colleague adds you, what your account is doing — a video finished, a batch finished, a job failed, a file about to expire, credits running low or run out — and what your billing is doing, such as a payment received, a card declined or automatic top-up switching itself off. Platform news too, if you have not unsubscribed; a notice when one of our legal documents changes; and, for an address on the waiting list, the single message it was left for. The ones about your work name the file they are about, and a failure names a scrubbed reason. No file of yours is ever attached, and you can turn off everything except the ones about money, access, and a notice that one of these documents is changing.
The transactional email we send youGoogle Ireland Limited, EU — with onward transfer to the United States under Google's own termsRuns no model
A mailbox. No model.
Keeps it: As their own terms provide.
Announced 2026-08-27; in service since 2026-08-18. No advance period ran: the 30-day rule was adopted 2026-09-07.
Telegram
Operational fragments — a workspace id, a job id, an error code, an invoice id, a batch id, and the numbers behind a failure — so we notice it before you report it. A field is let through either because it is on the list of names an operator needs, or because its value is a bare number, amount or id; anything else is withheld and named rather than transmitted. One exception, and it is free text: when we grant or take back credits by hand, the reason our operator typed goes with the alert, capped at 120 characters and with any email address removed. No files, no email addresses, no wording of yours.
The private chat our own alerts go toTelegram's own infrastructure, outside the EURuns no model
A chat app. No model.
Keeps it: Telegram's own.
Announced 2026-08-20; in service since 2026-08-17. No advance period ran: the 30-day rule was adopted 2026-09-07.
Slack
The same fragments, through the same two gates and with the same single exception, and only if Telegram is switched off.
The same alerts, only when Telegram is not configuredUnited StatesRuns no model
A chat app. No model.
Keeps it: Slack's own.
Announced 2026-08-20; in service since 2026-08-11. No advance period ran: the 30-day rule was adopted 2026-09-07.

Checked 2026-08-30. Every Yes or No above was read out of that company’s own published terms on that date — or, for a row added since, on the day its own note names, because bumping one date for one new row would claim we had re-opened all of them — and each links to the terms it was read from, so you can check ours against theirs rather than take the word for it. The rows that say “Runs no model” are our own statement instead, and it is a statement about what those companies run rather than about what we send them: a machine, a bucket, a database, a payment processor, a mailbox and two chat apps. Two of those rows touch your files — the host your upload passes through on its way to storage, which keeps no copy of it, and the storage it rests in, which does — and what keeps them out of a training set is that there is no model on that side to train. Nothing here watches for a provider’s own announcement, and we do not claim to: what forces a re-read is the clock, and our own build fails on every push if this date is more than 120 days old.

What the dubbing row means for you. Cralio has no models and trains nothing — there is no clause anywhere in our terms giving us a licence to, and the absence is deliberate. But every mode that localizes a video you uploaded sends it to HeyGen — every mode except captions in the video’s own language — and their terms let them use what they receive to improve their models. Statics, Music, Generate and a recut never reach them at all — a recut goes to one company and it is not this one. We do not negotiate that away on your behalf and we will not pretend to. Two things follow. If material cannot leave on those terms, choose a mode that does not reach them — subtitles in the source language never do. And the consent you hold from the people in your video has to cover it, which is why it is written into the biometric notice and into what you confirmed when you opened the account.

No longer used. ElevenLabs — removed 2026-08-30. The client, the retry path and the environment variables are gone, so no job of any age can reach them any more. Legacy jobs submitted under the old dubbing provider are no longer retryable. We never built or stored a voiceprint and there was never a way to upload a voice.

Dubbing providers are only called for the modes that need them. A subtitles-only job reaches no model provider except the one that transcribes it, and a re-render of subtitles you have edited reaches none at all. Both still hand you a burned video, which rests in the same storage as every other delivery and is signed like any other, so besides that transcription and that storage the one thing that leaves either of them is the hash the timestamping service countersigns.

The same is true across the other products, and it is worth knowing which way round. Every static creative, every generated track and every clip or still drawn from a prompt goes to Google — there is no way to make one that does not. A recut is the one job that carries a prompt and goes somewhere else: it goes to Luma and to nobody else, and to nothing of Google’s. What does not go to a model is the visualiser video built from a finished track: the spectrum, the artwork and the title are drawn on our own machines with ffmpeg, so exporting one calls no model provider and nothing of it reaches Google, HeyGen or OpenAI. It is a delivery sold as its own piece of work, so it rests in the same storage as every other delivery, and the only other thing that leaves is the hash the timestamping service countersigns.

How many times your creative makes that trip, counted. Three, usually. Reading the wording off the creative, drawing the new one, and transcribing the drawn pixels so we can check them character by character against the line you approved. When that check finds a line missing, the drawing and the checking run again — automatically, and you are never charged for a re-draw. That takes the creative to five, and a second re-draw to seven. There is no fourth attempt: you get the last one, with the lines that did not survive named on the job page so you can fix those and re-draw only them.

Counted rather than estimated, over 209 creatives: 151 of them — 72% — made three trips and were done. 58 needed a second drawing, and it rescued 24 of those. The third drawing was added on 24 August 2026 for the remaining 34 — 16% of creatives, and the share that reaches seven trips. How often a third drawing rescues one of those was counted on 1 September 2026: nine of forty-seven passed. That count was taken on test images rather than on live traffic, and only on drawings that had already failed once after being shown the check’s own report — both of which push the figure down, so nineteen per cent is a floor rather than a rate. It is recorded beside the corpus and has not been used to move a price, and what a third drawing does on live traffic has never been counted. We would rather publish the tail than a tidier number that is only true most of the time.

One more is possible and that one is never automatic. If you buy a second opinion on a finished creative, it goes back with your approved copy beside it, and what returns is an opinion in text. Nothing is sent for that unless you ask and pay for it. A track is up to four: generating the audio, naming it, drawing a cover if you asked for one, and — when there is a cover to read back, or lyrics the model wrote in a language you chose — one last call that reads the cover’s own text and checks the words came out in that language.

You send Music words, not files. There is nothing to upload to it. One picture does travel on a track, and it is not yours: the cover Google drew goes back to Google on that last call, so its lettering can be read off the pixels the way a static creative’s is. For part of 20 August you could attach your own photographs to steer the cover art, and this page said so; that option was removed the same evening, so those pictures no longer go anywhere because there is no longer a way to give us one. It is named rather than quietly deleted because the sentence was published, and a promise that shrinks should be visible shrinking.

Generate sends words and pictures, and every generation goes to Google. A still is one call. A clip is one call that starts a long-running job we then poll until the file is ready, so it is one journey rather than several. Anything you attach to steer the shot goes up with the prompt — up to five images, and that includes a picture of a person where the tool is the one that holds a face or a product steady across the clip. Nothing else about your account goes with it. Pressing the rewrite button beside the prompt box is one more call to the same company, carrying the prompt and whatever you attached, and it costs you nothing.

A recut sends the video itself, and to one company only. Reframing takes a finished cut and returns it in another shape — a vertical master as a widescreen, a square or an ultrawide — and the sides that were never shot are drawn rather than cropped in. What travels is the file you asked to have recut, fetched once over a link of ours that expires, and the sentence describing the shot if you typed one — it is optional, and where you leave it empty an empty one is sent. The shape and the resolution go with them either way, and nothing else about your account does. It reaches no dubbing provider, no transcription provider and nothing of Google’s. Nothing is sent until you say so. The first time you submit after this company was added, the screen names this page among the documents that have moved and refuses the submission until you accept them — before anything is priced, reserved or uploaded. One tick covers this page as it stands: it is not a company you can decline while keeping the rest of the service.

The last three rows receive no file of any kind. They are on the list anyway, because a page that claims to be the complete list should not make you notice that the sentence above it says files.

When we add or replace a subprocessor that receives video, audio or images, the change is posted on this page, and in Annex II of the data processing addendum, with the day it was announced — and nothing of yours reaches it until you have accepted this page with that company on it. That is the whole of the rule, and it replaced a different one on 11 September 2026: until that day the addendum promised 30 days between the posting and the first use, and a customer who never read the posting was taken to have agreed once the days ran out. Now the first job you submit after the change stops at the submit button: the screen names the documents that have moved, this page among them, and refuses until you accept them — before anything is priced, reserved or uploaded. It is one acceptance for this page, not one per company. Between 11 and 14 September 2026 each company had a tick of its own and you could decline one and keep every tool that did not reach it; that was withdrawn, and what you have in its place is the notice, the refusal before anything moves, and the days and the refund below. That addendum forms part of our terms rather than waiting on a signature, and its clause 6 gives you 14 days from the posting to end the part of the service that depends on a company you will not authorise and to have back what you prepaid for it. Re-wording a row asks again, and that is deliberate rather than a side effect: what you authorise is the text in that row — what the company receives, where it is, whether it trains on it, how long it keeps it — identified by a hash of those exact words, and if we widen any of them the old permission stops counting and we ask before the next job runs. Every row on this page that was published before that date says in its own cell that no advance period ran for it, because none of them had one. The build enforces this and this is exactly what it enforces: tests/test_subprocessor_notice.py fails the build, on every push, when code names a provider — as a mode you can submit, or as a credential this repository holds — that no door asks your permission for. Three things it cannot see, said here rather than left for you to discover. It does not catch us widening what a provider already on this list receives: Generate shipped on 4 September 2026 and the Google row was not corrected to describe it until the 6th. It cannot see a recipient that needs no key from us, which is the timestamping service named above. And it knows a key by the shape of its name — an environment variable ending in KEY, SECRET, TOKEN, PASSWORD or the like, read by that literal name in our own source — so a key for a new company, named outside that shape or read indirectly, would be invisible to it. One case sits outside the permission and only one: if a provider stops being available and we cannot run the service without a replacement, we appoint one at once and post it the same day, and your 14 days run from that posting. A new product or a new feature is not that case. The rows in the table above and the rows of Annex II are drawn from the same single file, so those two lists can never disagree; the sentences around them, this one included, are written by hand. One recipient is named on this page in prose and on no row: the timestamping service above receives a hash and no personal data, we hold no contract with it, and it is not a subprocessor, so neither the register nor Annex II carries it.

A change here is posted, and since 14 September 2026 it is mailed as well. Until that day no email could announce one: this register was not a document an account accepted, the mail this product sends when a legal document changes fired only for the terms and the privacy policy, and editing the register reached nobody’s inbox. It is one of those documents now, so that mail fires for it too — and no unsubscribe stops it, because it is not news. It goes out after the change is posted rather than before it, on a check that runs once a day, and the first run after this page became one of those documents only records where it stands; every edit after that is a message. If a message about this page names a date 30 days away, that date is the one the terms and the privacy policy use and it is not a waiting period here: nothing about this register waits 30 days, and the first job you submit after the change asks you to accept it. So the page is still the notice and the submit button is still what stops the file; the mail is what reaches you when you have not opened the product since. The unsubscribe link in a message switches off the one kind of mail it arrived in, and an unsubscribe with no kind attached stops everything except money, access and a notice that a legal document is changing.