Subprocessors
The third parties that process customer or public visitor data on our behalf, and what each one sees.
Version 2026-09-1 · in effect since 2026-09-03
| Subprocessor | Status | What it does | What it processes | Where | Effective | Change record |
|---|---|---|---|---|---|---|
| Supabase | Active | Managed Postgres, authentication and object storage for captured files | Account identity, request metadata, and the artifacts a capture produces | South America (São Paulo) | 2026-01-01 | — |
| Vercel | Active | Hosting for the API control plane and the dashboard | API and dashboard traffic in transit, including the URL submitted for capture | South America (São Paulo) | 2026-01-01 | — |
| Railway | Active | Hosting for the render plane — the browsers that perform captures | The target URL and the bytes captured from it, for the duration of the job | United States (East) | 2026-01-01 | — |
| Resend | Active | Transactional and lifecycle email delivery | Recipient email address and the message subject and body | United States | 2026-01-01 | — |
| Cloudflare | Active | Cookieless aggregate analytics and real-user performance monitoring for public marketing pages | Public page path, referrer host, coarse country, device and browser attributes, and performance timings; never query strings, account identifiers or capture inputs | Global (Cloudflare network) | 2026-09-03 | Announced 2026-08-30. Activated on 2026-09-03 at the operator's direction, four days after publication and before the standard notice target. |
How this list changes
A new subprocessor is normally published here before it starts processing data. Our operational target is 30 days of advance notice, but it is not a guaranteed minimum. If the operator makes a change effective sooner, the table records the original announcement date and the exception instead of presenting the target as if it had been met.
This page is generated from the same catalog the infrastructure checks. It shows active providers and announced changes. The effective date and change record in the table are authoritative.
How long the data stays
A capture that is not cached is deleted after 30 minutes when you receive it in the response, and after 24 hours when you fetch it asynchronously. A cached capture lives for the cache_ttl you chose, in a namespace belonging only to your organization.
What never reaches a subprocessor
API keys are stored only as a hash. Signing secrets, cookie values, Authorization headers, storage credentials and provider keys are encrypted, kept apart from the request record, and destroyed with the job. They are never written into logs, and never into the metadata any of the parties above can read.
Full detail is in the security documentation.