Sub-processors

Last updated 13 August 2026

The complete list of companies that can reach data we hold on your behalf. This page is the canonical version — the privacy policy and the DPA both point here, so there is only ever one list to keep current.

These pages describe how screen2api actually behaves, and are updated when the product changes rather than left to drift. They are not legal advice. If you need something clarified or expanded before you can sign this off internally, email legal@screen2api.com — we would rather answer the question than have you guess.

Current sub-processors

Sub-processorPurposeData it can reachProcessing location
Supabase Inc.Database, authentication and object storageEverything: account details, captures, uploaded filesEU (eu-west-1)
Vercel Inc.Application hosting, edge network, and cookieless page analyticsRequest data in transit; no capture is stored there. Analytics records page paths and load timings, with no cookie and no identifier that persists between visitsUS, with global edge
Functional Software, Inc. (Sentry)Error trackingStack traces and request context from failures. Credentials and signed URLs are stripped before an event is sent, and captures are never attachedEU (Sentry’s German region)
Sendinblue SAS (Brevo)Account email and the mailing listEmail addresses of account holders and people they invite. No captures, no filesEU (France)

What none of them get

Only Supabase stores captures. Sentry and Brevo never receive one: Sentry because our error events carry stack traces rather than payloads and are scrubbed of anything shaped like a key, a token or a signed URL before they leave the process, and Brevo because it only ever sees an email address and the text of the message we send to it.

Vercel runs the code that handles captures in transit but stores nothing — files go straight to storage under a signed URL.

Your own webhook endpoints

Not a sub-processor of ours, but worth stating plainly: you tell us where to deliver capture URLs, and we deliver them there. Whatever receives them is yours, and what happens to the data afterwards is outside our control and outside this list.

Changes to this list

We give 30 days’ notice before adding or replacing a sub-processor. If you object on reasonable data-protection grounds within that window, you may terminate the affected service without penalty — the terms are in section 6 of the data processing addendum.

To be told when this page changes, email privacy@screen2api.com and we will add you to the notification list. It is a different list from the product one and is not used for anything else.

Contact