CUTLIST
N°00Subprocessors

Who elsetouches your data.

The privacy policy tells you what leaves the machine for a model to read. This page is the other half: the providers that run the machine itself - the host, the database, the object store - because they hold your account and your footage at rest, and a rigorous answer to “who has my data” has to name them too.

Last updated 2026-08-12· draft, not lawyer-reviewed

01The list

Every party that touches it,and what it gets.

A subprocessor is any third party that stores or processes your data on our behalf. Each one below is named, with the personal data it actually receives and the reason it needs it.

Anthropic

The model provider
Receives

Sampled JPEG frames, each scaled to fit inside 512 pixels; transcript excerpts; any text read off the screen; and a one-sentence description of the audio texture. Never the video file itself and never the soundtrack.

Why

Detection, the multimodal review, clip titles and post captions - the intelligence the product is. It is the one place your content leaves our infrastructure. Nothing is sent for training, and we grant nobody the right to use it that way.

Vercel

Application host
Receives

Every request to the site and the studio. That includes what you type into a form - your email and name at sign-up - and the ordinary request metadata (an IP address, a user agent) any web host writes to a log.

Why

Runs and serves the application. Your footage and your clips do not live here: they sit in the object store and the database below, and the app only mints the URLs that move them.

Neon

The database
Receives

Every account row and everything a job derives: your email, your name and your scrypt password hash; your Google account id if you used it and your Stripe ids if you paid; and the word-level timings, titles and captions cut from your footage - the text of what was said on camera.

Why

The managed Postgres the application reads and writes. It is where your account and your projects exist between requests. Nothing here is ever sold, and it is not shared beyond running the service.

Modal

The render worker
Receives

Your footage itself, in full. The worker runs there: it downloads the source, decodes it, transcribes the audio, samples frames and encodes the finished clips. This is the one place the whole file is handled rather than an excerpt of it.

Why

To actually cut the clips. Transcription and frame sampling happen on this machine rather than at a third party, which is why the model provider above only ever receives excerpts. The container is destroyed when the job ends and keeps nothing.

Cloudflare R2

Object storage
Receives

Your uploaded footage and the rendered artifacts - clip videos, poster frames and SRT files. Your browser and our worker read and write it directly over short-lived signed URLs, so the bytes never pass through the application.

Why

Holds the large files a video tool has to move around. Your footage and clips sit here only until the retention sweep deletes them - source uploads 14 days after upload, clips 30 days after they render.

Google

Sign-in, only if you use it
Receives

That you chose to sign in to Cutlist with Google, and - back from Google to us - your email address, Google's own verified flag for it, and your name. Nothing about your footage.

Why

Authenticates 'Continue with Google'. None of your footage, transcripts or clips goes anywhere near it, and it is asked for nothing beyond those three fields.

This list is generated from how this deployment is configured, not typed out by hand. A provider appears only when the code actually routes data to it - the object store on the bucket driver, Google when sign-in is keyed, Stripe when a plan can be charged, the mailer when it has an API key - so an unkeyed build never claims one it does not use, and a keyed one never stays quiet about one it does. These 6 are the whole set of vendors the product touches - there is no unlisted one - and none of your data is sold to any of them or to anyone else.

02Where it happens

All of it, in theUnited States.

Every provider above processes data in the United States, the same fact the privacy policy states about the service and the model.

If you are in the EEA, the UK or Switzerland, using Cutlist means your footage is transferred to and processed in the US. We have not put a specific transfer instrument - the EU Standard Contractual Clauses, or the EU–US Data Privacy Framework - in place yet. We say that plainly rather than imply a safeguard we have not signed. The international-transfer question, and your right to complain to a supervisory authority, are covered in the privacy policy.

03A signed DPA

Available on request,by email.

If your business handles footage of other people, its procurement will want a signed Data Processing Agreement. Today that is a manual process, and here is how it works.

Email hello@heckraiser.com and we will send a Data Processing Agreement to sign. It is handled by a person, the same way account deletion is - not a self-serve clickthrough, and not a pre-signed template that would dress this up as more settled than it is.

And the honest ceiling, because it belongs here rather than three weeks into a questionnaire: like every legal page on this site, this is a young product’s draft. A signed DPA does not come with a SOC 2 report, an ISO certificate or any claim of enterprise legal readiness we have not earned. The security page lists exactly what is and is not built.

Draft · not lawyer-reviewed

Read this before you rely on it

This page was written by the people who built the product, from the configuration that decides which providers are in the path. It is accurate about who touches your data. It has not been reviewed by counsel, and it is not legal advice.

A provider missing, or one named that should not be: hello@heckraiser.com