🤟 Signlo

Signlo — Subprocessors

Effective date: 3 September 2026
Provider: Signlo, Inc., a Delaware corporation, 8 The Green #25812, Dover, DE 19901, United States


These are the companies that process your data on Signlo's behalf. We publish the full list because you cannot judge a privacy policy without knowing who is actually on the other end of it.

This list is the as-built set, audited against the running code — not an aspirational list of vendors we have accounts with. It is a companion to the Privacy Policy.

Current subprocessors

Processor Purpose Data Region DPA / legal page DPF
Supabase Database, sign-in, storage, edge functions Account, profile, content metadata, messages US supabase.com/legal not verified
Cloudflare Video/photo hosting + CDN (Stream/Images/R2), Turnstile, TURN, Workers AI embeddings Sign-language video/photos, captions (embeddings), network addresses US + global edge; one EU-jurisdiction R2 bucket www.cloudflare.com/trust-hub/gdpr certified
Vercel Web app hosting Web traffic incl. IP addresses US + global edge vercel.com/legal certified
PostHog Product analytics (opt-out in settings) Usage events keyed to user id / install id US posthog.com/terms not verified
Sentry (Functional Software) Crash reporting (no message/video content; sendDefaultPii off) Crash traces, user id, device data US sentry.io/legal certified
Expo Push-notification delivery Push tokens, notification title/text US expo.dev/privacy not verified
Google (FCM) Android push transport Push tokens, notification payloads US/global firebase.google.com/terms/data-processing-terms certified
Apple (APNs) iOS push transport Push tokens, notification payloads US/global www.apple.com/legal n/a (Apple relies on SCCs)
Amazon (SES) Sign-in codes and account email Email address, email content US aws.amazon.com/compliance/gdpr-center certified
Anthropic Caption/message TEXT translation via Signlo's relay (never video) Text submitted for translation US www.anthropic.com/legal certified
Microsoft (PhotoDNA) CSAM hash matching — only an irreversible ~1 KB content fingerprint leaves Signlo Content fingerprints US www.microsoft.com/en-us/photodna certified
NCMEC CyberTipline child-safety reports (Signlo is the registered ESP, #7701) Reported media + reporter email, as US federal law requires US www.missingkids.org/legal n/a (legal obligation, not a processor)
Stripe Payments (test mode during beta; ON at public launch per operator decision 2026-09-02) Payment metadata; card details never touch Signlo US/global stripe.com/legal/dpa certified
Google (STUN) Call connectivity (unconditional on starting a call) Network addresses/candidates global policies.google.com certified (Google LLC)

Reading this table

DPF means the provider is certified under the EU-U.S. Data Privacy Framework according to its own public certification status. Entries marked "not verified" rely on the Standard Contractual Clauses in that provider's data processing agreement instead, which is a valid transfer basis on its own.

We link each provider's root legal page rather than a deep link to its DPA. Deep links rot; the root page is where the current agreement will still be when this one is out of date.

Two that are not ordinary processors

NCMEC receives child-safety reports because US federal law requires it, not because we instruct them to process data for us. See our Child Safety Standards.

Microsoft PhotoDNA never receives your video. Only an irreversible fingerprint of roughly one kilobyte leaves Signlo, and it cannot be turned back into the image it came from.

Changes

We update this page when the set of processors changes. If you rely on this list and want to be told in advance, write to privacy@signlo.com.