Sub-processors
Last updated: May 10, 2026
Envisio uses a small number of trusted third-party service providers (“sub-processors”) to operate the service. This page lists each sub-processor, what they do, what data they receive, and where they are located. Material changes to this list are posted at least 30 days before they take effect. To be notified by email, contact support@envisio.design.
Infrastructure & authentication
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Clerk | User authentication and session management | Email, name, account metadata | United States |
| Vercel | Application hosting and content delivery | IP address, request metadata, application traffic | United States (primary); global edge network including EU regions |
| Vercel Speed Insights | Anonymous performance telemetry (Core Web Vitals) | Aggregated, non-identifying performance metrics | United States |
| PostHog | Product analytics — only active after you accept analytics cookies | Page views and product events linked to your account (user ID, email) | United States |
| Sentry | Error monitoring and crash reporting | Error reports: IP address, browser metadata, request state at failure | United States |
| Resend | Transactional email delivery (account, billing, support) | Email address, message content | United States |
| Vercel Blob (AWS S3) | Storage of uploaded photos and saved redesigns | Source images, generated images, file metadata | United States (AWS us-east-1) |
| Neon (AWS) | Application database | Account records, generation history, billing references | United States (AWS us-east-1) |
AI processing
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Google (Gemini API, paid tier) | Image generation (redesign output) and room-type classification from the uploaded photo | Source room photo, generation prompt, output image (no account identifiers) | United States |
| Anthropic (Claude API) | Generating the style prompt that guides the image model | Style selection, room metadata (text only — no images) | United States |
Payments
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| UniPay | Acts as Merchant of Record; processes payments, calculates and remits sales tax / VAT, handles billing and refunds | Name, email, billing address, payment method details, transaction history | Georgia |
Data retention by sub-processor
| Provider | Retention of inputs / outputs |
|---|---|
| Anthropic | Auto-deleted 7 days after each API request; up to 2 years if flagged by abuse-detection |
| Google (Gemini paid tier) | Logged for a limited period for abuse-monitoring only; not used for model training |
| Clerk, Resend, Vercel, storage, database | As required to operate the service; see each provider's privacy policy |
| UniPay | As required by law and tax authorities (typically 7–10 years for transaction records) |
Training restrictions
None of the AI sub-processors above use Envisio user data to train their foundation models. Anthropic and Google have each contractually committed to this on their respective paid API tiers.
International data transfers
All sub-processors are located in the United States or operate global infrastructure. Transfers from the EEA, UK, or Switzerland rely on Standard Contractual Clauses approved by the European Commission and equivalent UK / Swiss frameworks.
Data Processing Agreement
A Data Processing Agreement (DPA) is available on request for business customers and partners. Contact support@envisio.design to request one.