CoreClips AI, operated by Critso
Last updated: July 17, 2026 (draft)
This page lists the third-party subprocessors Critso uses to provide CoreClips AI (the Service), as referenced in our Privacy Policy, Data Processing Agreement, and AI Transparency page. Each subprocessor is contractually bound to data protection and confidentiality obligations consistent with our own commitments to customers. We will update this list when we add or replace a subprocessor. Enterprise customers under a Data Processing Agreement may object to a new subprocessor as described in that agreement.
| Subprocessor | Purpose | Data involved | Notes |
|---|---|---|---|
| Cloudflare (R2 Storage) | Stores uploaded video files, transcripts, and generated outputs | Uploaded video/audio content, generated outputs | Confirmed in production code |
| [PLACEHOLDER: compute/hosting provider] | Hosts the application backend and processing workers | All data processed by the Service passes through this infrastructure | Not confirmed from code — backend deploys to a self-managed virtual machine via SSH with no named cloud provider in deployment configuration. Must be confirmed with infrastructure/DevOps before publishing — a subprocessor list that's inaccurate here is one of the most commonly checked items by enterprise security teams. |
| Vercel | Hosts the customer-facing web application (frontend) | Data in transit through the web interface; no customer video content is processed by Vercel itself | Confirmed via deployment configuration |
| [PLACEHOLDER: Supabase, if confirmed] | Managed PostgreSQL database hosting | Account data, metadata about videos/jobs/organizations; video files themselves are stored separately in Cloudflare R2, not in the database | Database layer is built with explicit compatibility for Supabase's connection infrastructure, and one schema migration is titled for Supabase, but the live database connection was not inspected as part of this draft — confirm with infrastructure before publishing |
| Subprocessor | Purpose | Data involved | Notes |
|---|---|---|---|
| Razorpay | Processes subscription payments and pay-as-you-go credit purchases | Payment card/bank details (handled directly by Razorpay — Critso does not store full card numbers), billing name and email, transaction amounts | Confirmed in production code. The Terms of Service, Privacy Policy, and Refund Policy on this site have been corrected to name Razorpay, consistent with this list. |
| Subprocessor | Purpose | Data involved | Notes |
|---|---|---|---|
| OpenAI | Speech-to-text transcription (default provider) and AI-assisted text generation (summaries, highlights) | Audio/video content submitted for transcription; transcript text submitted for summarization | Confirmed default/production provider in code |
| Google (Gemini) | AI-assisted text generation (summaries, highlights) — used as the default/fallback text-generation provider | Transcript text and related prompts submitted for summarization | Confirmed default/production provider in code |
| ElevenLabs | Speech-to-text transcription (optional alternative provider, selectable via configuration) | Audio/video content submitted for transcription | Confirmed as a complete, production-ready integration; not the default provider |
| xAI (Grok) | Speech-to-text transcription (optional alternative provider, selectable via configuration) | Audio/video content submitted for transcription | Confirmed as a complete, production-ready integration; not the default provider |
All AI providers listed above are contractually prohibited from using Customer Content to train their models, consistent with our commitment in the AI Transparency page. [PLACEHOLDER: confirm this contractual position is actually in place with each named provider under their current enterprise/API terms — API-tier usage of most major LLM providers excludes training by default, but this should be verified against the specific agreement/tier Critso is on with each provider, not assumed.]
| Subprocessor | Purpose | Data involved | Notes |
|---|---|---|---|
| Google Workspace / Gmail (SMTP) | Sends transactional email — account verification codes, password resets, retention warnings, invite emails, contact form notifications | Recipient email address, and the content of the specific email (e.g. a verification code) | Confirmed in production configuration. [PLACEHOLDER: confirm whether Critso intends to migrate to a dedicated transactional email provider (e.g. SendGrid, AWS SES, Postmark) for deliverability/scale reasons — using a general Gmail SMTP account for production transactional email is unusual for an enterprise-facing product and worth flagging to engineering leadership independent of this legal document.] |
| Subprocessor | Purpose | Data involved | Notes |
|---|---|---|---|
| Vimeo | Allows customers to import video content directly from Vimeo into the Service, and optionally export to Vimeo | The video URL/ID provided by the customer, and the video content itself | Only invoked when a customer chooses to use this feature |
| YouTube | Allows customers to import video content directly from YouTube into the Service | The video URL provided by the customer, and the video content/captions | Only invoked when a customer chooses to use this feature |
| Subprocessor | Purpose | Data involved | Notes |
|---|---|---|---|
| RunPod | GPU-accelerated video export processing | Video content being exported | Feature-flagged — only active for organizations with this feature enabled; confirm with engineering whether this is in active use for any current customer before deciding whether to include it in a published list |
No third-party analytics or tracking vendor (such as Google Analytics, Mixpanel, PostHog, or Segment) was found integrated into the Service as of this draft. [PLACEHOLDER: if one is added in the future, it must be added to this list, and the Privacy Policy cookie section updated accordingly, before it goes live.]
Questions about our subprocessors can be sent to [PLACEHOLDER: privacy@critso.com].