Sub-processors
A sub-processor is a company that processes personal data on our behalf. We keep the list short and publish it, because you cannot judge a privacy promise without knowing who else touches the data. Your prompts, input media and rendered outputs are not on this page — they never leave your device, so no processor ever receives them.
1Active sub-processors
These are confirmed from our own code and deployment configuration.
| Processor | Service | Personal data processed | Location | Transfer basis (from Korea) | DPA status |
|---|---|---|---|---|---|
| Cloudflare, Inc. United States |
Workers (application compute), D1 (database), R2 (backups), Assets/CDN, TLS, WAF and bot management | Email address, hashed API-key records, pseudonymous device and session ids, tier, trial dates, website analytics events, install/download logs (IP, user-agent, referrer, country), payment-webhook metadata, and transient network metadata (IP) for every request | Cloudflare's global edge network. No jurisdiction pin is configured today, so we make no single-region storage claim | Adequacy decision for the Republic of Korea, plus Standard Contractual Clauses / UK Addendum under Cloudflare's data-processing addendum | Cloudflare's standard DPA/SCC terms apply to all customers under their Enterprise/Workers agreement — execution date pending confirmation from account records |
2To confirm before launch
Listed for honesty, not as a claim: each row is either not in use yet or not yet verified. Nothing here is treated as active until it has a signed data-processing agreement and appears in the table above.
| Candidate | Would process | Status |
|---|---|---|
| Transactional email provider | Email address, message content of magic-link, licence-delivery and support mail | Sending service not yet finalized — will move into the table above with an executed DPA once selected |
| GitHub (Microsoft) | Public GitHub usernames that appear in public repository activity | Public data only; documented here in case any personal data ever flows |
| Analytics backend | Anonymous id and event properties, if a hosted analytics product is ever adopted | Not in use — analytics stay in our own database today. A hosted tool would be added here first |
| Crash/error aggregator | Runtime and hardware information, installation id | Not in use — diagnostics stay in our own database |
3How we change this list
- →A processor must have a signed data-processing agreement before it touches personal data.
- →We publish an addition here, and announce it in advance where feasible — target notice period 30 days for processors that touch personal data.
- →Notification channel: the veizik.com mailing list and account email.
- →If you object to a new sub-processor, tell us at support@veizik.com before it takes effect.
4Korean users — 위탁 및 국외이전
Under PIPA, the processors above are 수탁자 (consignees) and the processing takes place outside Korea, which makes it 국외이전. The recipient, purpose, data categories, transfer country and retention are the columns in the table above; the retention periods are in the Privacy Policy §7. You may object to an overseas transfer by writing to support@veizik.com, though we cannot operate the service without hosting, so an objection in practice means closing the account.
5Contact
Questions about this list: support@veizik.com. Data requests: how data requests work. Transfer safeguards (SCC copies) are available on request.