Subprocessors
Last updated 31 July 2026
Featurelab is built on third-party infrastructure. This page lists the providers that may process personal information on our behalf when you use the service, what each one receives, and why. It supports section 6 of our Privacy Policy.
1. Core service providers
These providers are involved in operating Featurelab for every account. The “what they receive” column describes the data the product actually sends them.
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| Clerk | Authentication, session management and the Google sign-in flow | Email address, name, profile image, authentication and session identifiers, sign-in metadata such as IP address and user agent | United States |
| Convex | Application database and file storage | Account records, projects, scene configuration and version history, asset metadata and extracted text, board content, usage counters, voice-rights attestations, terms acceptances, integration authorisations, and stored file blobs | United States |
| Amazon Web Services | Object storage (S3), video rendering (Lambda), content delivery (CloudFront), automated image moderation (Rekognition) and cost reporting | Uploaded images, screen recordings and audio; generated narration audio; rendered videos; images submitted for the moderation check; request and delivery logs | United States |
| Vercel | Application hosting and delivery, and the AI Gateway that routes every model request | HTTP requests and function logs including IP address and user agent; prompts, narration text and extracted screenshot text passed through the gateway to the model provider below | United States |
| OpenAI (reached through the Vercel AI Gateway) | The models behind in-editor AI assistance, narration drafting and asset-similarity embeddings | Prompts you write, project and scene context, narration text, and text extracted from your screenshots. Images are only included where you ask the assistant to work with them | United States |
| ElevenLabs | Speech synthesis and the voice library | Narration text, the voice identifier and voice settings you select, and any custom voice sample you supply | United States |
| Sentry | Error and performance monitoring | Error events and diagnostic context: URL, browser, and stack traces. Configured with personal information collection disabled and with request bodies and cookies stripped before an event is sent | United States |
Uploaded images are sent to Amazon Rekognition for the moderation check described in section 5 of the Privacy Policy. An image that fails the check is never stored by us; what Rekognition itself retains is governed by the AWS Service Terms, available at aws.amazon.com/service-terms.
2. Feature-specific providers
These are used only when you use the specific feature named. They are not involved in ordinary editing, rendering or account activity.
| Provider | Purpose | Data categories | When it is used |
|---|---|---|---|
| GitHub | Looking up public contribution activity for the contribution-graph scene | The GitHub username you enter, and the public contribution counts returned for it | Only when you build a scene from a GitHub contribution graph |
| github-contributions-api.jogruber.de | Fallback source for the same public contribution data when no GitHub API token is configured | The GitHub username you enter | Same feature, fallback path only. Operated by an independent third-party developer; only the public username is sent |
| Google Fonts | Serving the web fonts used by the editor's typography options | Your IP address and browser information, sent directly by your browser when a font file is requested | On page load, from your browser rather than our servers |
3. Your identity provider
Signing in uses your Google account. Google is your own identity provider rather than a provider we engage to process data on your behalf: it tells Clerk your email address, name and profile image once you approve the sign-in, and it independently records that you signed in to Featurelab under its own privacy terms. We do not send Google your projects, uploads or generated content.
4. What we do not use
We do not use advertising networks, third-party analytics or tracking services, data brokers, or any provider that receives your content for its own purposes. We do not sell personal information. Text extraction from your screenshots runs in your browser and is not sent to a third party for that purpose.
5. Contractual position and transfers
Where required, we put data-processing terms in place with each provider before it processes personal information on our behalf. Each provider’s legal entity, role, contracting country and the transfer mechanism it relies on are recorded in our internal provider register; you can request that detail from privacy@featurelab.video.
Our providers are located outside New Zealand, principally in the United States. Section 7 of the Privacy Policy explains how overseas disclosures are handled.
We select and configure the AI services above with the intention that content you submit is not used to train their general-purpose models, subject to each provider’s applicable terms. Provider terms differ and can change. Where a provider’s terms do not support that position, we will note it on this page.
6. Changes to this list
We update this page when we add, remove or replace a provider. Where our contractual or legal obligations require it, we will give notice of material changes before they take effect. The date at the top of this page reflects the most recent change.