← Back

Subprocessors

Last updated 31 July 2026

Featurelab is built on third-party infrastructure. This page lists the providers that may process personal information on our behalf when you use the service, what each one receives, and why. It supports section 6 of our Privacy Policy.

1. Core service providers

These providers are involved in operating Featurelab for every account. The “what they receive” column describes the data the product actually sends them.

ProviderPurposeData categoriesProcessing location
ClerkAuthentication, session management and the Google sign-in flowEmail address, name, profile image, authentication and session identifiers, sign-in metadata such as IP address and user agentUnited States
ConvexApplication database and file storageAccount records, projects, scene configuration and version history, asset metadata and extracted text, board content, usage counters, voice-rights attestations, terms acceptances, integration authorisations, and stored file blobsUnited States
Amazon Web ServicesObject storage (S3), video rendering (Lambda), content delivery (CloudFront), automated image moderation (Rekognition) and cost reportingUploaded images, screen recordings and audio; generated narration audio; rendered videos; images submitted for the moderation check; request and delivery logsUnited States
VercelApplication hosting and delivery, and the AI Gateway that routes every model requestHTTP requests and function logs including IP address and user agent; prompts, narration text and extracted screenshot text passed through the gateway to the model provider belowUnited States
OpenAI (reached through the Vercel AI Gateway)The models behind in-editor AI assistance, narration drafting and asset-similarity embeddingsPrompts you write, project and scene context, narration text, and text extracted from your screenshots. Images are only included where you ask the assistant to work with themUnited States
ElevenLabsSpeech synthesis and the voice libraryNarration text, the voice identifier and voice settings you select, and any custom voice sample you supplyUnited States
SentryError and performance monitoringError events and diagnostic context: URL, browser, and stack traces. Configured with personal information collection disabled and with request bodies and cookies stripped before an event is sentUnited States

Uploaded images are sent to Amazon Rekognition for the moderation check described in section 5 of the Privacy Policy. An image that fails the check is never stored by us; what Rekognition itself retains is governed by the AWS Service Terms, available at aws.amazon.com/service-terms.

2. Feature-specific providers

These are used only when you use the specific feature named. They are not involved in ordinary editing, rendering or account activity.

ProviderPurposeData categoriesWhen it is used
GitHubLooking up public contribution activity for the contribution-graph sceneThe GitHub username you enter, and the public contribution counts returned for itOnly when you build a scene from a GitHub contribution graph
github-contributions-api.jogruber.deFallback source for the same public contribution data when no GitHub API token is configuredThe GitHub username you enterSame feature, fallback path only. Operated by an independent third-party developer; only the public username is sent
Google FontsServing the web fonts used by the editor's typography optionsYour IP address and browser information, sent directly by your browser when a font file is requestedOn page load, from your browser rather than our servers

3. Your identity provider

Signing in uses your Google account. Google is your own identity provider rather than a provider we engage to process data on your behalf: it tells Clerk your email address, name and profile image once you approve the sign-in, and it independently records that you signed in to Featurelab under its own privacy terms. We do not send Google your projects, uploads or generated content.

4. What we do not use

We do not use advertising networks, third-party analytics or tracking services, data brokers, or any provider that receives your content for its own purposes. We do not sell personal information. Text extraction from your screenshots runs in your browser and is not sent to a third party for that purpose.

5. Contractual position and transfers

Where required, we put data-processing terms in place with each provider before it processes personal information on our behalf. Each provider’s legal entity, role, contracting country and the transfer mechanism it relies on are recorded in our internal provider register; you can request that detail from privacy@featurelab.video.

Our providers are located outside New Zealand, principally in the United States. Section 7 of the Privacy Policy explains how overseas disclosures are handled.

We select and configure the AI services above with the intention that content you submit is not used to train their general-purpose models, subject to each provider’s applicable terms. Provider terms differ and can change. Where a provider’s terms do not support that position, we will note it on this page.

6. Changes to this list

We update this page when we add, remove or replace a provider. Where our contractual or legal obligations require it, we will give notice of material changes before they take effect. The date at the top of this page reflects the most recent change.