Sub-processors

Version 1.7 | Last Updated: 28 August 2026

What this page is for. Under GDPR, UK GDPR, LGPD, and similar laws, the third parties that handle personal data on our behalf fall into two distinct legal roles: sub-processors act only on our documented instructions under a data-processing agreement and cannot use the data for their own purposes; independent controllers determine their own purposes and means of processing under their own terms once data is shared with them. We list both here for transparency. We update this page when a sub-processor is added, removed, or materially changed, and publish material additions at least 30 days in advance for users who subscribe to the change feed (email privacy@socialgryd.com with subject "Subscribe: Subprocessors" to join).

1. Infrastructure, Hosting, Media Delivery, and Firebase Services

Sub-processorServiceData categoriesLocation
Google Cloud / Firebase (Google LLC and Google Ireland Ltd)Firebase Auth, Firestore, Cloud Storage, Cloud Functions, Firebase Cloud Messaging (FCM), Firebase Analytics, Crashlytics, Performance Monitoring, App Check, Remote Config, Hosting, and Dynamic Links. Operates under the Google Cloud Data Processing Addendum as our processor; "Google signals", ads-personalisation joins, and similar controller-side enrichment features are disabled on our project.Platform personal data and operational logs, excluding Maps queries (which flow to Google Maps Platform as an independent controller; see Section 5).EU (multi-region) and US, per service configuration
Mux, Inc.Video infrastructure for user-uploaded video: ingest, encoding/transcoding, adaptive HLS packaging, a 480p MP4 static rendition, automated thumbnail/poster generation, and CDN-backed playback delivery. New video uploads route to Mux; videos uploaded before the migration continue to be served from Google Cloud Storage and our Cloud Run transcoding pipeline (dual-read). Mux acts only on our documented instructions under the Mux Data Processing Addendum (updated 1 April 2025); it may not use the content for its own purposes and does not sell it. We do not use Mux Data (Mux's viewer-analytics product). No analytics SDK is integrated, so no playback analytics beyond the request logs inherent to CDN delivery are collected by Mux on our behalf. Retention: the encoded video and its derivatives are stored at Mux for as long as the associated post is available on the Platform; when a post or account is deleted, the corresponding Mux asset is deleted as part of our deletion process (see Privacy Policy Section 20).The uploaded video file and its machine-generated derivatives (HLS renditions, the MP4 preview, the poster image). This is user-generated content that may itself contain personal data (for example faces, voices, or location cues visible in the footage). A post identifier is sent so the asset links back to the post. On playback, Mux's delivery network necessarily receives standard request metadata (viewer IP address and device/user-agent). No account identifiers (name, username, email, profile photo, user ID) are sent to Mux.United States, with global CDN edge delivery. Mux is certified under the EU-US Data Privacy Framework and offers EU Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers. Mux's own sub-processors (cloud hosting and content-delivery providers) are listed in Exhibit 3 of the Mux DPA.

2. AI and Machine Learning

Sub-processorServiceData categoriesLocation and retention
Anthropic PBCClaude family (currently Claude Haiku 4.5) for post categorisationPost text (truncated to ~1,000 characters) and machine-generated media descriptions. No account identifiers (name, username, email, profile photo, user ID) are sent with the request.United States. Under Anthropic's Commercial Terms, Anthropic is prohibited from using customer API inputs or outputs to train its foundation models. Anthropic's standard Trust & Safety retention of up to 30 days applies to API inputs and outputs on the Anthropic side; Zero Data Retention is configured per-account and is not currently enabled on SocialGryd's account. In addition, the inbound post text and the AI-generated category label are written to Google Cloud Logging (our processor under the Firebase DPA) for up to 30 days as part of routine Cloud Functions diagnostics, and the assigned category labels themselves are stored on the post for its lifetime.
Google LLCGoogle Cloud Vision API (SafeSearch image moderation) for automated content checks on user-uploaded community images. The result is an "adult / violence / racy" likelihood label used to send flagged images to the moderation queue; no human reviews the image unless flagged.Image bytes (≤ 5MB JPEG/PNG/WebP). No account identifiers (uid, email, display name) are sent with the request. The image-storage path includes the uploader's UID, but that is not transmitted to Vision; only the image bytes are.Processing region: us-central1 (the same Google Cloud region as our Firestore + Cloud Functions, under our existing Google Cloud customer agreement and DPA). Google's published Cloud Vision data-use policy applies: no use of customer image data to train Google's models, transient processing only, no human review in normal operations, no long-term retention of submitted images beyond the synchronous API call.

3. Analytics and Product Telemetry

Sub-processorServiceData categoriesLocation
Google Ireland Limited / Google LLCGoogle Analytics 4 for consented website measurement. Advertising storage, Google signals and ad personalisation are disabled.Page URL and title, referral source, device and browser information, approximate location derived from IP, and interaction events. No account name, email address, meal content or health records are intentionally sent.EU and United States under Google's data-processing terms and applicable transfer safeguards
Amplitude Inc. (planned)Product analytics, funnels, A/B test measurement, cohort analysis. Not yet routing personal data in production.Event names, event properties, pseudonymous user ID, device metadata, IP (truncated)US, with EU data residency where configured

4. Email Delivery

Sub-processorServiceData categoriesLocation
Resend Inc.Transactional and marketing email delivery. Inbound delivery-event webhooks from Resend are signed using the Svix webhook-signature standard; we verify those signatures locally. Svix-the-company is Resend's sub-processor for webhook delivery, not ours. See Resend's own privacy stack for that disclosure.Email address, email subject and body, delivery events (opens, bounces, clicks)US / Global (via AWS SES infrastructure)

5. Independent Controllers (Not Sub-Processors)

The recipients listed in this section are not our sub-processors. Once data flows to them, whether through your use of a Platform feature, your authentication choice, your purchase, or the operating system's push-delivery machinery, they determine the purposes and means of processing under their own terms and act as independent data controllers in their own right. They may use the data they receive for their own service-improvement, fraud-prevention, security, billing-integrity, abuse, and analytics purposes, subject to their own privacy policies and the applicable law of the country where they are established. We list them here for transparency so you understand where your data flows; we do not control what they do with it once the API call or OS-level event reaches them.

RecipientRole we use them forData they receiveTheir terms / privacy policy
Google LLC and Google Ireland Ltd (Google Maps Platform)Maps SDK, Places API, Geocoding API, Distance Matrix, used to render maps, autocomplete place searches, and look up coordinatesIP address, search queries you type into a place picker, approximate or precise coordinates when you use a location-dependent feature, device and browser identifiersGoogle Maps Platform Terms of Service and the Google Privacy Policy. Google is a controller for Maps queries under the Maps Platform Controller-Controller Data Protection Terms; the Google Cloud DPA that governs our Firebase relationship does not apply to Maps API calls.
Apple Inc. (Sign in with Apple)OAuth identity-provider for authentication on iOS, macOS, and the webAuthentication request, Apple ID-derived stable user identifier, optional name and (private or relayed) email, sign-in events for Apple's account-security and abuse-detection systemsSign in with Apple agreement and the Apple Privacy Policy.
Google LLC (Google Sign-In)OAuth identity-provider for authentication on Android, iOS, and the webAuthentication request, Google account-derived stable user identifier, name, email, profile photo URL, sign-in events for Google's account-security and abuse-detection systemsGoogle Privacy Policy and the Google APIs Terms of Service.
Apple Inc. (Apple Push Notification service, APNs)Push-notification delivery on iOSAPNs device token, notification payload at delivery time, delivery feedback (token validity, unregistered state). We do not send personally identifying content in the payload by default; safety, proximity, and service notifications may include short text the recipient already has access to.Apple Privacy Policy and the Apple Developer Program Licence Agreement. Apple controls APNs infrastructure.
Apple Inc. (App Store / In-App Purchase)iOS in-app purchase and subscription billingApple original transaction ID, receipt, subscription status, purchase events for fraud-detection and tax purposesApp Store Terms and Apple Privacy Policy.
Google LLC (Google Play Billing)Android in-app purchase and subscription billingPlay purchase token, subscription status, purchase events for fraud-detection and tax purposesGoogle Play Terms of Service and Google Privacy Policy.

6. Internal Operations and Productivity (Business Contact Data Only)

These tools are used by the SocialGryd team for internal operations. They do not receive end-user Platform content except where a support ticket, investigation, or business contact requires.

Sub-processorService
Google LLC (Google Workspace)Business email, Drive, Docs, Meet
Linear Orbit, Inc.Product issue tracking
Slack Technologies / SalesforceInternal team communications
Notion Labs, Inc.Internal documentation and knowledge base
GitHub / MicrosoftSource-code hosting

7. Planned Services (Not Yet Routing Personal Data)

We will update this page, notify users where material, and obtain consent or offer objection where required, before routing personal data to any of the following in production.

8. Transfer Safeguards and Transfer Impact Assessment

Where a sub-processor is located outside the EEA or UK, we rely on European Commission adequacy decisions (including the EU-US Data Privacy Framework for certified recipients), Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with any necessary supplementary measures, and the UK IDTA or UK Addendum, as described in the Privacy Policy Section 19.

Consistent with the CJEU's judgment in Schrems II (C-311/18) and EDPB Recommendations 01/2020, we conduct a Transfer Impact Assessment ("TIA") before enabling any onward transfer to a third country, covering (i) the legal basis of the transfer, (ii) the destination country's law and practice relevant to government access, (iii) any supplementary technical (encryption, pseudonymisation), organisational, and contractual measures, and (iv) ongoing monitoring. The TIA is kept on record under Article 30 GDPR. A redacted summary covering the most significant transfers is available on request at dpo@socialgryd.com.

9. How to Object to a Sub-processor

Customers with an applicable data-processing agreement may object in writing within 30 days of notice of a new sub-processor by emailing privacy@socialgryd.com. If we cannot accommodate the objection, we will work with you in good faith to find an alternative, and failing that, either party may terminate the affected service under the agreement.

End users may object to particular processing activities under GDPR Article 21 and the Privacy Policy.

10. History of Changes