Trust

Subprocessors

The third parties that process customer or public visitor data on our behalf, and what each one sees.

Version 2026-09-1 · in effect since 2026-09-03

SubprocessorStatusWhat it doesWhat it processesWhereEffectiveChange record
SupabaseActiveManaged Postgres, authentication and object storage for captured filesAccount identity, request metadata, and the artifacts a capture producesSouth America (São Paulo)2026-01-01
VercelActiveHosting for the API control plane and the dashboardAPI and dashboard traffic in transit, including the URL submitted for captureSouth America (São Paulo)2026-01-01
RailwayActiveHosting for the render plane — the browsers that perform capturesThe target URL and the bytes captured from it, for the duration of the jobUnited States (East)2026-01-01
ResendActiveTransactional and lifecycle email deliveryRecipient email address and the message subject and bodyUnited States2026-01-01
CloudflareActiveCookieless aggregate analytics and real-user performance monitoring for public marketing pagesPublic page path, referrer host, coarse country, device and browser attributes, and performance timings; never query strings, account identifiers or capture inputsGlobal (Cloudflare network)2026-09-03Announced 2026-08-30. Activated on 2026-09-03 at the operator's direction, four days after publication and before the standard notice target.

How this list changes

A new subprocessor is normally published here before it starts processing data. Our operational target is 30 days of advance notice, but it is not a guaranteed minimum. If the operator makes a change effective sooner, the table records the original announcement date and the exception instead of presenting the target as if it had been met.

This page is generated from the same catalog the infrastructure checks. It shows active providers and announced changes. The effective date and change record in the table are authoritative.

How long the data stays

A capture that is not cached is deleted after 30 minutes when you receive it in the response, and after 24 hours when you fetch it asynchronously. A cached capture lives for the cache_ttl you chose, in a namespace belonging only to your organization.

What never reaches a subprocessor

API keys are stored only as a hash. Signing secrets, cookie values, Authorization headers, storage credentials and provider keys are encrypted, kept apart from the request record, and destroyed with the job. They are never written into logs, and never into the metadata any of the parties above can read.

Full detail is in the security documentation.