Skip to content
Cleft
Download

Third-Party Vendors

Effective Last updated

At Cleft, we carefully select third-party vendors who share our commitment to data protection and user privacy. This page provides complete transparency about every vendor we work with.

All vendors meet our data protection standards and comply with GDPR, CCPA, and other applicable privacy regulations.

Vendor overview

  • 37 vendors in total.
  • 20 vendors process personal identifiable information (PII), such as notes, account info, or payment details. All have signed Data Processing Agreements.
  • 17 vendors handle no personal customer data; they support our business operations, marketing, and development.

Vendors processing personal data

These 20 vendors handle personal identifiable information and are subject to our strictest data protection requirements.

Cloud infrastructure and data processing

Amazon Web Services (AWS)Processes personal data

Services: Hosting and managing cloud infrastructure, and transactional email delivery (Amazon SES)

Personal data: Hosts encrypted user data; sends account, billing, and security email

Data centers: EU, Global (multiple locations)

HQ: Seattle, Washington, USA

Secure hosting infrastructure only. AWS provides encrypted storage but cannot access your actual notes or content. Transactional email (account, billing, security notices) is sent via Amazon SES.

Homepage · Privacy · DPA

AppleProcesses personal data

Services: Developing and distributing applications through the Apple ecosystem

Personal data: App Store account data and on-device processing

Data centers: Global (multiple locations)

HQ: Cupertino, California, USA

The Whisper transcription model runs locally on your device. Apple handles App Store transactions but doesn't access your Cleft content.

Homepage · Privacy

CloudflareProcesses personal data

Services: CDN, DNS, and DDoS protection services

Personal data: Website traffic and DNS queries

Data centers: Global (multiple locations)

HQ: San Francisco, California, USA

Website traffic patterns and DNS queries only. No access to Cleft content or user data.

Homepage · Privacy · DPA

AI processing partners

OpenAIProcesses personal data

Services: Primary LLM provider for note enhancement

Personal data: Processes transcript text only

HQ: San Francisco, California, USA

Transcript text only (never audio) for AI processing. Your data is never used for model training.

Homepage · Privacy · DPA

GroqProcesses personal data

Services: Backup LLM provider to ensure service reliability

Personal data: Processes transcript text only

Data centers: Global (multiple locations)

HQ: Mountain View, California, USA

Alternative AI processor for text enhancement. Same privacy protections as OpenAI.

Homepage · Privacy

Payment and billing

StripeProcesses personal data

Services: Handling online transactions securely

Personal data: Payment processing (PCI compliant)

HQ: San Francisco, California, USA

Payment processing only. We never see your actual payment details.

Homepage · Privacy · Legal

RevenueCatProcesses personal data

Services: Managing in-app subscriptions and purchases

Personal data: Subscription data and analytics

Data centers: Global (multiple locations)

HQ: San Francisco, California, USA

Subscription management and analytics. No access to your notes or content.

Homepage · Privacy · Terms

Revolut BusinessProcesses personal data

Services: Business banking and financial services

Personal data: Financial transactions and account data

Data centers: EU

HQ: London, United Kingdom

Internal business banking transactions only. No customer data or personal information.

Homepage · Privacy · Terms

Customer management and communications

HubSpotProcesses personal data

Services: Managing marketing activities and customer interactions

Personal data: Contact info and support interactions

Data centers: EU

HQ: Cambridge, Massachusetts, USA

Contact information and customer support interactions only.

Homepage · DPA

MailerliteProcesses personal data

Services: Marketing email campaigns only (newsletters and opt-in updates)

Personal data: Email addresses for marketing (opt-in)

Data centers: Global (multiple locations)

HQ: Vilnius, Lithuania

Marketing only: email addresses for newsletter delivery (opt-in). Not used for transactional or account email, and no access to personal content.

Homepage · Privacy · Terms

Business intelligence and monitoring

Google WorkspaceProcesses personal data

Services: Communication, document creation, and collaboration

Personal data: Internal business communications

Data centers: EU

HQ: Mountain View, California, USA

Internal team communications only. No user data processing.

Homepage · Privacy · DPA

MetabaseProcesses personal data

Services: Analysing business data and generating reports

Personal data: Aggregated business analytics

Data centers: EU (self-hosted)

HQ: N/A (open-source project)

Aggregated business metrics only. No individual user data.

Homepage · Privacy · Terms

1PasswordProcesses personal data

Services: Team password management and secure credential storage

Personal data: Internal team credentials and access management

Data centers: EU

HQ: Toronto, Ontario, Canada

Internal team passwords and credentials only. No customer data or personal information.

Homepage · Privacy · Terms

SentryProcesses personal data

Services: Monitoring and resolving application errors

Personal data: Error logs (no personal content)

HQ: San Francisco, California, USA

Application error logs only. No personal content included in crash reports.

Homepage · Privacy · Terms

Website and design services

WebflowRetiredProcesses personal data

Retired: Being retired in 2026. Our public website now runs on Cloudflare (listed under Cloud infrastructure above); Webflow no longer hosts the site or receives form submissions.

Services: Previously designed and hosted our public-facing website and forms

Personal data: Website form submissions (historical)

Data centers: Global (multiple locations)

HQ: San Francisco, California, USA

Formerly handled website contact forms and landing page interactions. No new data is sent to Webflow.

Homepage · Privacy · Terms

SoFriendlyProcesses personal data

Services: Enhancing user experience through design consulting

Personal data: Design consultation materials

Data centers: Global (multiple locations)

HQ: San Francisco, California, USA

Design assets and user experience materials only.

Homepage · Privacy · Terms

NamecheapProcesses personal data

Services: Domain registration and DNS management

Personal data: Domain registration information

Data centers: Global (multiple locations)

HQ: Phoenix, Arizona, USA

Domain registration details and DNS configuration only.

Homepage · Privacy · Terms

Scheduling, integrations, and automation

NangoProcesses personal data

Services: OAuth integration management (e.g. the Notion connection)

Personal data: Integration authorization tokens

Data centers: Global (multiple locations)

HQ: San Francisco, California, USA

Manages the OAuth tokens for integrations you connect (such as Notion). Handles authorization only, not your note content. DPA on file.

Homepage · Privacy

FilloutProcesses personal data

Services: Form building and data collection (replaces SavvyCal)

Personal data: Form submissions and contact information

Data centers: Global (multiple locations)

HQ: San Francisco, California, USA

Form submissions and scheduling data only.

Homepage · Privacy · Terms

ZapierProcesses personal data

Services: Automating workflows across different tools

Personal data: Integration data flows

Data centers: Global (multiple locations)

HQ: San Francisco, California, USA

Only data flows you explicitly configure in integrations.

Homepage · Privacy · Terms

Business operations vendors

These 17 vendors support our business operations, marketing, and development but never access your personal information or content.

Social media and marketing

Facebook / MetaNo personal data

Services: Social media marketing and brand engagement

Homepage · Privacy

InstagramNo personal data

Services: Social media marketing and brand engagement

Homepage · Privacy

LinkedInNo personal data

Services: Social media marketing, talent and brand engagement

Homepage · Privacy

X (Twitter)No personal data

Services: Social media marketing and brand engagement

Homepage · Privacy

ThreadsNo personal data

Services: Social media marketing and brand engagement

Homepage · Privacy

MastodonNo personal data

Services: Social media marketing and brand engagement

Homepage

RebrandlyNo personal data

Services: Link management and branded short URLs

Homepage

Development and collaboration

GitHubNo personal data

Services: Managing source code and collaboration

Homepage · Privacy

SlackNo personal data

Services: Facilitating internal communication and collaboration

Homepage · Privacy

FigmaNo personal data

Services: Designing user interfaces collaboratively

Homepage · Privacy

Anthropic (Claude)No personal data

Services: Internal development and business operations (coding, drafting, support triage)

Used internally for development and running the business. It does not process your notes or content. Any review of inbound feedback or email is done on text we manually scrub of personal data first, human-directed and never automated.

Homepage · Privacy · Terms

Documentation and content

MintlifyNo personal data

Services: Documentation platform hosting (replaced GitBook)

Public documentation content only.

Homepage · Privacy · Terms

Screen StudioNo personal data

Services: Product video creation

Media and podcast

TransistorNo personal data

Services: Hosting and distributing podcasts

Homepage · Privacy

DescriptNo personal data

Services: Audio and video editing

Homepage · Privacy

Analytics (anonymous only)

Fathom AnalyticsNo personal data

Services: Collecting website analytics with a focus on privacy

Anonymous page views and bounded website interaction events only. No personal data collected.

Homepage · Privacy

TelemetryDeckNo personal data

Services: In-app anonymous analytics and performance monitoring

Data centers: EU (Germany)

HQ: Würzburg, Germany

Anonymous app usage patterns and performance metrics only. Zero personal information.

Homepage · Privacy · Terms

Vendor data practices

Data retention. Our vendors are contractually required to retain data only as long as necessary for service delivery, delete data upon our request, and follow the same data retention policies we maintain.

Data security. All vendors must encrypt data in transit and at rest, maintain SOC 2 Type II compliance or equivalent, undergo regular security audits, and report any security incidents within 24 hours.

Data access.Vendor access to your data is limited to what’s necessary for service delivery, logged and monitored, subject to strict confidentiality agreements, and never used for the vendor’s own purposes.

Vendor selection process

We maintain strict criteria when selecting third-party vendors to ensure the highest level of data protection:

  • Privacy standards: GDPR, CCPA, and international privacy law compliance.
  • Security certifications: we prefer and prioritize vendors aligned with SOC 2 Type II, ISO 27001, and other recognized industry security standards.
  • Data Processing Agreements: clear contractual obligations about data handling.
  • Incident response: a proven track record of security and transparency.
  • Business continuity: financial stability and reliable service delivery.

Your rights regarding vendor data

You have the right to:

  • Know which vendors process your data.
  • Request deletion of your data from all vendors.
  • Receive copies of vendor DPAs upon request.
  • Be notified of any vendor data breaches.
  • Opt out of specific vendor services where possible.

Contact

For questions about our vendors or data processing, including vendor DPA requests, contact our Data Protection Officer at dpo@cleftnotes.com or our general privacy inbox at privacy@cleftnotes.com. If you have concerns about any of our vendors or their data practices, the DPO is the right contact.