// last updated July 23, 2026
Subprocessor List
This is Speechify, Inc.'s authoritative technical list of external services that may process customer data for Vidify. Contracting entities remain subject to the applicable account order form or provider agreement.
How to read this list
This register covers providers enabled for Vidify's customer-facing launch product. Parked, operator-only, and private feature paths do not receive public customer data and are not listed. A listed provider receives customer data only when needed for the listed service or when the user invokes the corresponding feature. “Published DPA” means the provider publishes processor terms; it does not represent that every account-level signature, enterprise addendum, or regional setting has been confirmed. Those confirmations are production launch requirements.
Core infrastructure and business services
- Railway — Railway Corporation; configured United States deployment region. Application, worker, LiteLLM, PostgreSQL, and scheduled-backup hosting. Published privacy and data-processing terms; no model training purpose.
- Cloudflare — Cloudflare, Inc. or the entity identified in the account agreement; United States storage region with Cloudflare's global network. Private R2 media and encrypted database-backup storage. Published DPA and subprocessor program; no model training purpose.
- Clerk — Clerk, Inc.; United States and disclosed subprocessor locations. Authentication, Google Sign-In, sessions, and identity lifecycle. Published DPA; no model training purpose.
- Stripe — Stripe, LLC, Stripe Payments Europe, Limited, or the entity identified at checkout; United States and disclosed global processing locations. Checkout, subscriptions, invoices, refunds, disputes, and payment processing. Published DPA; no model training purpose.
- Resend — Plus Five Five, Inc.; United States and disclosed subprocessor locations. Transactional and lifecycle email. Published processor terms; no model training purpose.
- PostHog — PostHog, Inc.; United States project region. Consent-gated product analytics, feature flags, identified support context, and masked session replay. Published DPA. The production account retains analytics events for up to 12 months and session recordings for 30 days.
- Sentry — Functional Software, Inc.; United States project region. Sanitized application errors and performance traces. Published DPA. Error retention is published at 30 days in the Privacy Policy and must be reconfirmed against the live plan before launch.
- Modal — Modal Labs, Inc.; United States. Ephemeral agent sandboxes, deleted on exit and never paused or persisted. A sandbox receives the account-scoped workspace, memory, asset metadata, commands, and files required to perform an agent turn. Modal's terms forbid training on Customer Data with no model-level carve-out, and its DPA is incorporated on standard terms. SOC 2 Type II.
AI, media, browser, and research services
- OpenAI — OpenAI, L.L.C. or the entity identified in the account agreement; United States. Agent language models and transcription. OpenAI states that API data is not used for model training unless the customer opts in. Default abuse-monitoring retention can be up to 30 days; some Responses API application state can also persist for 30 days. Vidify disables response storage for one-shot requests.
- Google — Google LLC; United States and Google's disclosed processing locations. Paid Gemini API models for brand research, Search grounding, image work, media understanding, planning, and quality analysis. Paid-service terms state prompts and responses are not used to improve Google products; Search-grounded prompts, context, and outputs may be retained for 30 days.
- fal.ai — Features & Labels, Inc.; United States and disclosed model-provider locations. Selected image generation/editing and sound-effect models used in launch ads. Vidify sends
X-Fal-Store-IO: 0on API requests. fal's API no-training terms depend on the selected model's enterprise status, which must be confirmed before enabling that model for customer content. Vidify does not expose fal.ai voice conversion. - fal.ai partner models — Model operators contracted by Features & Labels, Inc.; Operator locations disclosed by fal.ai. Generation routed by fal.ai to underlying model operators, including Kling/Kuaishou, ByteDance, and ElevenLabs. Content is transferred to the operator, and downstream training rights sit in fal-to-vendor agreements that are not public. Position still under confirmation.
- Atlas Cloud — Atlas Cloud, Inc.; United States; generation runs on ByteDance's disclosed infrastructure. Video generation and editing (ByteDance Seedance) routed through Atlas Cloud to ByteDance's official model infrastructure. Reference media is transferred to the operator for generation, and outputs are retrieved from ByteDance-hosted storage and persisted to Vidify's own storage. Downstream retention and training rights sit in Atlas-to-vendor agreements; position still under confirmation.
- Apify — Apify Technologies s.r.o.; Czech Republic and disclosed subprocessor locations. Public website, social, and advertising-library research. Apify publishes a DPA. Vidify does not use Apify to access private or login-gated content; target-site terms, intellectual-property rights, and privacy obligations still apply to each collection instruction.
- Speechify AI API — Speechify, Inc. or the affiliate identified in the API agreement; United States and disclosed service-provider locations. Stock text-to-speech for narration. Vidify sends the requested script and a stock voice identifier; it does not send source voice recordings for cloning or conversion. Counsel must confirm whether this is internal processing by Vidify's legal operator or an affiliate subprocessor.
Changes and objections
We will update this page before a new subprocessor begins processing customer personal data, and will give notice of the addition or replacement of a subprocessor at least 30 days in advance, as required by Section 4.3 of the Data Processing Terms. A customer may object during that period on reasonable data-protection grounds by emailing [email protected] with the affected account, provider, and grounds. We will review the objection in good faith and discuss a commercially reasonable alternative where one is available.