The third-party services Svmmon shares Customer data with, as required by GDPR Article 28(2). This list is referenced by the Data Processing Addendum.
We notify Customers of new sub-processors at least 30 days before they begin processing Customer data. If you want email notifications of changes, email support@svmmonapp.com and we will add you to the notification list.
These run the product. Without them, Svmmon does not function.
Stripe, Inc.
Purpose: Payment processing, subscription management, tax calculation, invoice generation.
Data: Email, name, billing address, tax ID (if provided), card data (never seen by Svmmon — collected directly by Stripe), subscription state.
Location: United States (with EEA infrastructure for EU customers).
Supabase, Inc.
Purpose: Database hosting, file storage, authentication.
Data: All Customer-uploaded content, account email, hashed credentials, generated slideshow metadata, performance logs.
Location: AWS US-East-1 (primary) — region pinned by the Customer's assigned project.
Vercel, Inc.
Purpose: Application hosting, edge functions, CDN.
Data: In-flight HTTP requests, IP addresses, user-agent strings, performance telemetry. No persistent storage of Customer data.
Location: Global edge network; serverless functions run in iad1 (US East).
Anthropic, PBC
Purpose: AI text generation for hooks, slide content, captions, analysis.
Data: Profile and prompt content the Customer chooses to generate from. Per Anthropic's data-handling terms, inputs are not used to train models.
Location: United States.
Railway Corp.
Purpose: Background worker hosting — runs long jobs (such as TikTok-recreation scraping/rendering) that can't finish inside the app's serverless time limit.
Data: In-flight job payloads keyed by user ID: the source URLs/content a Customer chooses to recreate and the resulting slide images written to storage.
Location: United States.
Only invoked when a Customer explicitly connects their account via OAuth.
TikTok / ByteDance
Purpose: OAuth + posting to the Customer's linked TikTok account. Only when the Customer connects an account.
Data: OAuth tokens, posted content (slideshows).
Location: United States / Singapore / Ireland.
Meta Platforms (Instagram Graph API)
Purpose: OAuth + posting to the Customer's linked Instagram account. Only when the Customer connects an account.
Data: OAuth tokens, posted content.
Location: United States / Ireland.
Google LLC (YouTube Data API)
Purpose: OAuth + posting to the Customer's linked YouTube account, plus YouTube research queries.
Data: OAuth tokens, posted content, research queries.
Location: United States / Ireland.
Telegram Messenger Inc.
Purpose: Operational notifications to Customer's Telegram (opt-in only).
Data: Notification text containing the Customer's chosen account references.
Location: International (Dubai, UK, BVI operating entities).
Only invoked when a Customer runs a query in the Research tool. These receive Customer search queries only, not account data.
Apify Technologies, s.r.o.
Purpose: TikTok + Instagram research data fetching.
Data: Customer's research queries (handles, hashtags). Does not receive Customer account info.
Location: Czech Republic / EU.
Tavily AI
Purpose: Web search for the Research tool.
Data: Search queries.
Location: United States.
NewsAPI.org
Purpose: News search for the Research tool.
Data: Search queries.
Location: United States.
RapidAPI (Reddit + YouTube proxy endpoints)
Purpose: Reddit + secondary YouTube research data fetching.
Data: Search queries.
Location: United States.
Pexels GmbH
Purpose: Stock-photo lookup for the image library.
Data: Search queries.
Location: Germany / EU.
Openverse (WordPress.org / Automattic Inc.)
Purpose: Copyright-free image search for the image library.
Data: Search queries only. No account info.
Location: United States.
Runs on the marketing site only. Consent-gated in the EU, EEA, and UK.
Affiliateo
Purpose: Affiliate referral attribution on the marketing site — credits the affiliate who referred a visitor.
Data: IP address, browser user-agent, approximate geolocation, and persistent localStorage identifiers (affiliateo_ref, affiliateo_visitor_id, affiliateo_campaign_id). In the EU/EEA/UK this loads only after the visitor accepts the cookie banner.
Location: United States.