Effective 2026-09-04
Sub-processors
This page lists every third-party service that processes personal data or customer content on our behalf. It is referenced from our Privacy Policy and is the source of truth for the current list.
We will announce any change to this list by email at least 30 days before the new sub-processor starts handling data.
Current sub-processors
| Provider | Role | Data types | Location | DPA |
|---|---|---|---|---|
| Supabase | Authentication, application database | Email, hashed sign-in tokens, video metadata, captions, scheduling records | Ireland / Germany (EU region) | DPA |
| Vercel | Application hosting (Next.js frontend + API) | Request logs, IP addresses (short-term) | Multi-region including EU | DPA |
| Cloudflare | CDN, DNS, DDoS protection, R2 video/clip storage | Request logs, uploaded videos, generated clips | Multi-region including EU | DPA |
| Modal.com | Serverless video processing worker (ffmpeg + transcription) | Video files during processing only; deleted immediately after | US (with EU region available) | DPA |
| Stripe | Payment processing, subscription management | Billing email, VAT number, payment method (Stripe holds the card, not us) | US and Ireland | DPA |
| Resend | Transactional email (sign-in links, receipts, alerts) | Email address, message content, delivery status | US and EU | DPA |
| TikTok | Publishing platform — only if you connect your TikTok account | Video clips you elected to publish; OAuth tokens (stored by us, sent to TikTok on publish) | Ireland / US / Singapore | DPA |
| Google (YouTube) | Publishing platform — only if you connect a YouTube channel | Video clips published as Shorts; OAuth tokens for the YouTube Data API | US and Ireland (EU region available) | DPA |
| Meta (Instagram + Facebook) | Publishing platform — only if you connect an Instagram or Facebook Page | Video clips published as Reels; OAuth tokens for the Meta Graph API | US and Ireland | DPA |
Platform data handling — what we do with your connected accounts
Each publishing platform (TikTok, YouTube, Instagram, Facebook) is connected through its own official OAuth flow. That platform — not us — decides whether to authorise access and asks you to confirm the exact scopes we request.
TikTok scopes we request:
user.info.basic— read your public handle and display name, so we can show you which account is connected and audit publish activity.video.upload— upload video files to your account, which is required to publish clips.video.publish— mark uploaded videos as published on your feed at the time you scheduled.
YouTube scopes we request:
youtube.upload— upload video files to your channel to publish them as Shorts.
Instagram + Facebook scopes we request:
instagram_content_publish— publish Reels to your Instagram Business account.pages_manage_posts— publish Reels to your Facebook Page.pages_read_engagement— read basic Page info so we can show you which Page is connected.
Every platform issues short-lived access tokens and long-lived refresh tokens on connection. Both are stored encrypted in our database and are only used from server-side jobs that publish your scheduled clips. We never share them. You can revoke a connection at any time from Settings, or from the platform's own authorised-apps screen — either revocation deletes both tokens on our side.
We do not download, cache, or otherwise process any platform content that is not the immediate response to a publish request we initiated on your behalf.
Contact
Questions about our sub-processors: privacy@clipflow.app.