Sub-processors
Last updated: 2026-05-13
This page lists the third-party services Leivar uses to operate the Service. Each entry shows what the sub-processor does, the categories of personal data we send, the region(s) the sub-processor operates in, and the legal transfer mechanism we rely on for international transfers (typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and / or the EU–US Data Privacy Framework where the vendor is certified).
We update this list when we add or remove a sub-processor. Continued use of the Service after we update this page constitutes acceptance of the new sub-processor for the purposes of any data-processing agreement you have with us. If you have a written DPA with us that requires advance notice of new sub-processors, that DPA controls.
| Sub-processor | Purpose | Data | Region | Transfer |
|---|---|---|---|---|
| Supabase | Primary database (PostgreSQL), authentication, file storage, edge functions. | All account, content, and operational data. Hashed passwords. OAuth tokens for connected platforms (encrypted at rest). | AWS, region per project (currently US-East). | SCCs + UK IDTA where applicable. |
| Vercel | Hosting for the web app, serverless functions, and cron jobs. | Request logs (URL, status, latency, IP, user agent) for up to 30 days. | Global edge + US/EU regions per function. | SCCs + UK IDTA + DPF where applicable. |
| Stripe | Payment processing, subscriptions, invoicing, tax (Stripe Tax). | Email, billing name, billing address (where required for tax), payment method (held by Stripe, not us), subscription state. | US, EU, and other regions per Stripe. | SCCs + UK IDTA + Stripe DPF certification. |
| Anthropic | Claude models for chat orchestration, research, and reasoning. | Prompts and any content you ask the Manager to operate on for that turn. | US. | SCCs + UK IDTA. Anthropic does not train on API inputs by default. |
| OpenAI | GPT models for certain reasoning, image generation, and editing. | Prompts and image inputs sent to GPT or GPT-Image. | US. | SCCs. OpenAI does not train on API inputs by default. |
| Google (Gemini, Imagen, YouTube Data API) | Gemini models for routing and certain agents; Imagen for image generation; YouTube Data API for direct YouTube publishing and metrics. | Prompts, image inputs, video uploads when you publish to YouTube, OAuth tokens for your YouTube channel. | Global. | SCCs + EU–US DPF. |
| fal.ai | Image and video generation (FLUX, Whisper transcription, SAM segmentation, SadTalker, others). | Prompts, reference images, audio for transcription. | US. | SCCs. |
| Kie.ai | Aggregator for video models (Veo, Sora, Seedance) and Suno music generation. | Prompts, reference media. | Per Kie. | SCCs. |
| Fish Audio | Text-to-speech and voice cloning. | Text scripts, consent audio recordings, voice fingerprints. | US. | SCCs. |
| Higgsfield | Specific video model integration. | Prompts, reference media. | Per Higgsfield. | SCCs. |
| Ayrshare | Cross-platform publishing to Instagram, TikTok, X, LinkedIn, Facebook (i.e. every supported social platform except YouTube). | Posts to be published, OAuth tokens for connected accounts, retrieved metrics and comments. | US. | SCCs. |
| Telegram | Optional messaging bridge — only if you connect a Telegram chat to the Service. | Telegram chat ID, messages you send to the bot, webhook secret. | Global. | SCCs where applicable; this connection is opt-in. |
| Browserbase | Managed headless-browser substrate for site-recipe research tasks (Sprint E1 onwards). | URLs the agent visits on your behalf; transient screenshots; not your account data. | US. | SCCs. |
| Firecrawl | Fallback scraper for sites that block our native fetch + cheerio path. | Public URLs the agent fetches on your behalf. | US. | SCCs (DPA execution pending — see note below). |
| OpenRouter | Model-router fallback for the fast tier when Google AI is unavailable. | Prompts routed for that turn. | US. | SCCs (DPA execution pending — see note below). |
| Rendi | Cloud FFmpeg rendering for certain video composition steps. | Video composition specs, text overlays, media URLs to render. | Per Rendi. | SCCs (DPA execution pending — see note below). |
| Resend | Transactional + lifecycle email delivery (support replies, trial and post-purchase emails). | Recipient email address, name, and message content. | US. | SCCs + DPF where applicable (DPA execution pending). |
| Google Drive (storage connector) | Optional — only if you connect Google Drive to import your own files. | OAuth tokens for the Drive account you connect (encrypted at rest) and the files you choose to import. | Global. | SCCs + EU–US DPF; this connection is opt-in. |
| Dropbox (storage connector) | Optional — only if you connect Dropbox to import your own files. | OAuth tokens for the Dropbox account you connect (encrypted at rest) and the files you choose to import. | US. | SCCs; this connection is opt-in. |
| Pexels | Royalty-free stock photo/video API. | Search queries only; no account data leaves us. | US/EU. | Public-API; no personal data transferred. |
| Pixabay | Royalty-free stock music API. | Search queries only; no account data leaves us. | EU. | Public-API; no personal data transferred. |
Transfer-mechanism status: the legal mechanisms above describe the instrument we rely on (Standard Contractual Clauses, the UK IDTA, and/or the EU–US Data Privacy Framework where the vendor is certified). Execution of signed data-processing agreements with each sub-processor, and appointment of our EU/UK Article 27 and LGPD representatives, is being completed before public launch and is tracked as a launch blocker. Until then, treat the per-row mechanism as the intended instrument rather than a confirmed executed agreement.
Questions or objections
If you object to a specific sub-processor or want a copy of the relevant transfer-mechanism clauses, write to kamugishaibrah@gmail.com.