Effective date: 3 September 2026
Provider: Signlo, Inc., a Delaware corporation, 8 The
Green #25812, Dover, DE 19901, United States
These are the companies that process your data on Signlo's behalf. We publish the full list because you cannot judge a privacy policy without knowing who is actually on the other end of it.
This list is the as-built set, audited against the running code — not an aspirational list of vendors we have accounts with. It is a companion to the Privacy Policy.
| Processor | Purpose | Data | Region | DPA / legal page | DPF |
|---|---|---|---|---|---|
| Supabase | Database, sign-in, storage, edge functions | Account, profile, content metadata, messages | US | supabase.com/legal | not verified |
| Cloudflare | Video/photo hosting + CDN (Stream/Images/R2), Turnstile, TURN, Workers AI embeddings | Sign-language video/photos, captions (embeddings), network addresses | US + global edge; one EU-jurisdiction R2 bucket | www.cloudflare.com/trust-hub/gdpr | certified |
| Vercel | Web app hosting | Web traffic incl. IP addresses | US + global edge | vercel.com/legal | certified |
| PostHog | Product analytics (opt-out in settings) | Usage events keyed to user id / install id | US | posthog.com/terms | not verified |
| Sentry (Functional Software) | Crash reporting (no message/video content; sendDefaultPii off) | Crash traces, user id, device data | US | sentry.io/legal | certified |
| Expo | Push-notification delivery | Push tokens, notification title/text | US | expo.dev/privacy | not verified |
| Google (FCM) | Android push transport | Push tokens, notification payloads | US/global | firebase.google.com/terms/data-processing-terms | certified |
| Apple (APNs) | iOS push transport | Push tokens, notification payloads | US/global | www.apple.com/legal | n/a (Apple relies on SCCs) |
| Amazon (SES) | Sign-in codes and account email | Email address, email content | US | aws.amazon.com/compliance/gdpr-center | certified |
| Anthropic | Caption/message TEXT translation via Signlo's relay (never video) | Text submitted for translation | US | www.anthropic.com/legal | certified |
| Microsoft (PhotoDNA) | CSAM hash matching — only an irreversible ~1 KB content fingerprint leaves Signlo | Content fingerprints | US | www.microsoft.com/en-us/photodna | certified |
| NCMEC | CyberTipline child-safety reports (Signlo is the registered ESP, #7701) | Reported media + reporter email, as US federal law requires | US | www.missingkids.org/legal | n/a (legal obligation, not a processor) |
| Stripe | Payments (test mode during beta; ON at public launch per operator decision 2026-09-02) | Payment metadata; card details never touch Signlo | US/global | stripe.com/legal/dpa | certified |
| Google (STUN) | Call connectivity (unconditional on starting a call) | Network addresses/candidates | global | policies.google.com | certified (Google LLC) |
DPF means the provider is certified under the EU-U.S. Data Privacy Framework according to its own public certification status. Entries marked "not verified" rely on the Standard Contractual Clauses in that provider's data processing agreement instead, which is a valid transfer basis on its own.
We link each provider's root legal page rather than a deep link to its DPA. Deep links rot; the root page is where the current agreement will still be when this one is out of date.
NCMEC receives child-safety reports because US federal law requires it, not because we instruct them to process data for us. See our Child Safety Standards.
Microsoft PhotoDNA never receives your video. Only an irreversible fingerprint of roughly one kilobyte leaves Signlo, and it cannot be turned back into the image it came from.
We update this page when the set of processors changes. If you rely on this list and want to be told in advance, write to privacy@signlo.com.