Subprocessors
Every third party that receives user data, what it receives, and why.
Last updated: 2026-08-18
This list is referenced from our Privacy Policy. It is split into four groups, because they carry different commitments. The first are processors we engage: we contract with them directly and instruct them to use your data only for the purpose shown. The second are announced before they have received anything, so a change is never a surprise — not everything there is a processor we instruct, and today it is our payment provider, which sells to you in its own name. The third are reached by your own browser or phone on your behalf — we do not engage them, cannot instruct them, and will not claim commitments we have no agreement to back. The fourth are websites you chose to share a link from. They are all listed, because the data flow is real and hiding it would defeat the point of this page.
| Subprocessor | Purpose | Data shared | Region |
|---|---|---|---|
| Processors we engageWe contract with each of these directly and instruct it to process data only for the purpose shown. | |||
| Amazon Web Services (AWS) | Cloud hosting — compute (EC2), database (RDS PostgreSQL), object storage (S3), auth + transactional auth email (Cognito), queues (SQS), functions (Lambda); and PII detection (Comprehend), which analyses note content to find personal identifiers so they can be masked before text-generation AI calls. | All application data: account identifiers, content, uploads, logs. Note content is also sent to Comprehend for personal-identifier detection. | us-east-2 (Ohio, USA) |
| Cloudflare, Inc. | Authoritative DNS for muzings.ai, and reverse proxy / CDN for the public marketing site at muzings.ai. | DNS query metadata, plus — for visits to the marketing site only — your IP address and request metadata. No account content: the app and the API are served directly from our own infrastructure and do not pass through Cloudflare. | Global (anycast) |
| Google LLC | Optional “Sign in with Google” federation via Cognito; AI text generation via the Gemini API for capture‑time enrichment, including the web search (Google Search) that grounds it — a query derived from the note is sent to Google to identify unfamiliar named entities; reading the images you capture, via the Gemini API, to turn a photo or screenshot into a note; delivering push notifications to Android devices via Firebase Cloud Messaging; and — when a link you saved cannot be read directly (it needs a login, or the site blocks automated readers) — searching the web for that link’s address to find out what is at it. | For Google sign‑in: your email address and Google account identifier. For enrichment: the note content you submit for the suggestion, and search queries derived from it. The note itself is sent with people’s names, email addresses, phone numbers, and card and ID numbers replaced by placeholders; the exception is the names of public things — a film, product, company, place or event — which are sent as written, because a search for a placeholder identifies nothing. A person’s name is never sent as a search query, and neither is any of the structured identifiers just listed (see the Privacy Policy for how that is enforced). For image capture: the photograph or screenshot itself — this is the first step for every image you capture, and any note you attach to it is sent alongside. Before an image leaves us it is rebuilt from its raw pixels, which permanently removes the embedded GPS coordinates and device serial number; the one camera tag we keep is the capture date, which becomes the note’s date (see the Privacy Policy). For identifying a link we could not read: the web address you saved, sent to Google Search — nothing else about you or your note. This happens only after a direct read of that page has already failed, and only if link previews are switched on. For push notifications on Android: your device’s push token, and the notification itself — which, for a daily “things to revisit” reminder, contains the title of the note being resurfaced. If you would rather not have note text sent this way, turn the daily review off in your profile and no notification is sent. Google does not use the Gemini API content to train its models: we call it on a paid‑tier Google Cloud project, under an executed data‑processing addendum — Google’s no‑train commitment for the Gemini API applies to paid‑tier API traffic, and we do not rely on the free tier. If link identification is enabled, a link you saved that we could not read directly — for example one behind a login — is sent to Google so its search index can say what is at that address; that is the address itself, nothing else. | Global |
| Expo (650 Industries, Inc.) | Building the mobile app and delivering over‑the‑air updates to it — the mechanism that lets us ship a fix to the installed app without a new store release. | For update delivery: your device’s IP address, platform, app version and update channel, sent each time the app checks for an update. No note content, and no push token. | USA |
| Let’s Encrypt (ISRG) | TLS certificate issuance for muzings.ai domains. | Domain names only. No user data. | USA |
| Anthropic, PBC | AI text generation — capture classification/filing, chat answers, and ranking your notes for recall. Also a second‑pass reading of captured images: when the first pass (see Google LLC) cannot read an image reliably, the image is sent to an Anthropic model at higher resolution to try again. Enrichment of unfamiliar terms runs on Google’s Gemini API instead (see Google LLC), and Anthropic performs no web search for us. | The note content you submit for AI features, and the questions you ask in chat — which, for a note captured from a photo, includes the date the photo was taken, because that is the note’s date and it is what lets the AI resolve “next Tuesday” against when you wrote it. For image capture: the photograph or screenshot itself, but only for those images the first pass could not read reliably — not every image you capture — together with any note you attached to it. The image’s embedded GPS coordinates and device serial number have already been destroyed at our boundary and are never transmitted. Not used to train AI models (API inputs/outputs are excluded from model training); processed under provider data-processing terms. | USA |
| OpenAI, L.L.C. | AI embeddings (semantic recall) on all platforms, and server‑side voice‑note transcription — for every voice capture made in a desktop browser, and on a phone whenever the device’s own speech recognition is unavailable or fails. | Note content (for embeddings) and the audio you record (for transcription). On a phone we try your device’s built‑in speech service first (see the group below) and only send the audio to OpenAI if that is unavailable or errors — so on mobile this is a fallback rather than the normal path, but it is a real one. Not used to train AI models (API data is excluded from training); processed under provider data‑processing terms. | USA |
| Announced in advance — not receiving anything yetWe list a third party here before it handles any of your data, so a change is never something you find out about after the fact. Nothing in this group has received anything: the feature it supports is not switched on. Not everything listed here is a processor we instruct — where a company acts as merchant of record it is the seller in its own right, decides for itself how it handles what you give it, and its row says so. On the day one of these starts, it moves to the group that describes the relationship we actually have with it, and the date at the top of this page changes when it does. | |||
| FastSpring (Bright Market, LLC) | Payments — FastSpring will act as merchant of record for subscriptions: it sells the subscription to you in its own name, and handles checkout, card processing, sales tax, invoicing and refunds. Not yet active: billing is switched off and no purchase can currently be made. | Nothing so far. Once billing opens: your email address and an account reference so a purchase can be matched to your account, plus whatever you enter at checkout. Card details are entered on FastSpring’s own checkout and never reach our servers or our logs. No note content, uploads or recall history is ever sent. Being merchant of record means FastSpring is not a processor acting on our instructions for that purchase: it is the seller, it decides how it handles the payment and billing details you give it, and that data is covered by FastSpring’s own privacy notice as well as this one. We cannot instruct it on that data and will not claim commitments on its behalf — the same limit we state for anything else we do not contract for. What comes back to us is that a purchase happened, and its order reference. | USA (Santa Barbara, CA) |
| Third parties reached through your browser or deviceThese are not processors we engage. When you use a feature that relies on your browser’s or your phone’s own built-in service, that software sends the data to its vendor under your relationship with them — we do not contract with them for it, cannot instruct them, and cannot make commitments on their behalf. They are listed here because the data flow is real and you should be able to see it. | |||
| Apple Inc. | Live voice‑to‑text via Safari’s built‑in Web Speech API — the primary transcriber for voice capture on iOS and iPadOS. | For voice capture in Safari on iOS / iPadOS: the audio you speak, sent to Apple’s speech‑recognition service to produce the transcript. Apple’s handling of that audio is governed by Apple’s own terms with you, not by an agreement with us. | USA |
| Google LLC (browser & device speech recognition) | Live voice‑to‑text via Chrome’s built‑in Web Speech API — a real‑time preview while you speak on desktop Chrome — and via Android’s built‑in speech recogniser in the mobile app. | The audio you speak, sent by Chrome or by Android to Google’s speech‑recognition service to produce the transcript. Google’s handling of that audio is governed by Google’s own terms with you, not by our Gemini API agreement above. | Global |
| Websites you share a link fromWhen you save a link, our servers request that page so we can read its title and show you what you saved instead of a bare address. That request goes to whichever site you shared — we do not choose it, have no agreement with it, and cannot make commitments on its behalf. It is sent nothing about you beyond the request itself: no account identifier, no cookies, no other notes, and nothing that identifies you as the person who saved it. What that site can see is that the link was asked about, the network address of our server, and the time. We ask once, shortly after you save; we do not re-request a link on a schedule, and deleting the note ends any further requests for it. You can see exactly which links you have saved on any note that has one. | |||
| Websites you save links from | Reading a shared link’s title, creator and description so a saved link shows what it is instead of a bare web address, and so you can find it again later by describing what it was rather than remembering the address. Nothing is read for advertising, profiling, or training a model. | The link you saved. For most sites that means a request to the address itself; where the platform publishes a preview API (YouTube, Spotify, TikTok and similar), we send the link to that platform's API instead. If the page offers a preview image, we fetch it once and keep our own copy, so that afterwards displaying your note never contacts the image's host again. No account identifier, no cookies, and nothing about you or your other notes are sent. The recipient can see that the link was asked about and the network address of our server. What we keep from the reply is the title, creator and short description, stored on your note so you can search for it; that text is deleted with the note, and with your account. The preview image is deleted with the note too, and with your account. | Global — wherever the site you saved, or the platform it is on, happens to be located. We cannot know or restrict this in advance, because the recipient is whichever site you chose to save. |
Change notice
We intend to give at least 30 days’ notice before adding or replacing a subprocessor, so customers can review the change and object if needed. Before a new subprocessor starts processing your data, or if one is replaced, we will email the address on your account and post a notice on this page.