Sub-processors
Last updated: October 5, 2026
Overview
Copy and Funnel Accelerator LLC uses the third-party service providers listed below to help operate StefanBrain. These providers may process customer data only as needed to provide, secure, maintain, or improve StefanBrain and the user-requested workflows inside the service.
Current sub-processors
ActiveCampaign
- Purpose
- Onboarding, product education, lifecycle, and marketing communications for trial users, members, and related product audiences.
- Data processed
- Email address, StefanBrain user and business identifiers, trial lifecycle dates, membership/account type, lifecycle tags, and communication subscription status.
- Location and residency
- Processed according to ActiveCampaign's service terms and infrastructure configuration.
Amazon Web Services (AWS)
- Purpose
- Cloud hosting, application and database infrastructure, file storage, the runtime that executes every chat turn, job queues, and video rendering.
- Data processed
- Account data, workspace metadata, chat history, uploaded files, generated outputs, connected account and store data, operational logs, and related service data.
- Location and residency
- United States and other AWS regions as needed to provide the service and maintain availability.
Anthropic
- Purpose
- AI model processing for chat titles and suggestions, funnel reviews, Copy Chief, Angle Finder, page building, video planning, onboarding call analysis, and related AI workflows.
- Data processed
- Prompts, chat messages, user-requested connected account context, uploaded content, onboarding call transcripts, and generated outputs needed to complete the requested AI task.
- Location and residency
- Processed according to Anthropic's commercial/API data handling, retention, and residency controls.
Apify
- Purpose
- Scraping public social media comment threads and Reddit posts for research tools.
- Data processed
- Post URLs and search terms from member requests, and the public posts and comments returned.
- Location and residency
- Processed according to Apify's service terms and data handling controls.
Arcjet
- Purpose
- Fraud and abuse checks on trial requests: email validation, IP address reputation, bot detection, and rate limiting.
- Data processed
- Email addresses, IP addresses, and request headers of trial requests.
- Location and residency
- Processed according to Arcjet's service terms and data handling controls.
AssemblyAI
- Purpose
- Audio and video transcription for user-requested analysis workflows and message composer dictation.
- Data processed
- Audio files, video files, video URLs, voice audio streamed during dictation, transcript text, and related processing metadata when transcription is requested.
- Location and residency
- Processed according to AssemblyAI's service terms and data handling controls.
Browserbase
- Purpose
- Hosted browser sessions for funnel reviews, web page reading, website traffic lookups, and ad library research.
- Data processed
- URLs, rendered page content, and screenshots of the pages a requested task visits, and session recordings of funnel reviews.
- Location and residency
- Processed according to Browserbase's service terms and data handling controls.
Browserless
- Purpose
- Headless browser rendering, webpage capture, and screenshot support for requested analysis workflows.
- Data processed
- URLs, rendered webpage content, screenshots, and technical metadata needed to complete browser rendering or capture tasks.
- Location and residency
- Processed according to Browserless service terms and infrastructure configuration.
BytePlus
- Purpose
- AI video and image generation (Seedance) for videos and animated static ads.
- Data processed
- Video prompts, reference images and frames, and the generated videos.
- Location and residency
- Processed according to BytePlus's service terms and data handling controls.
Calendly
- Purpose
- Scheduling onboarding calls for trial users.
- Data processed
- Names, email addresses, and booking details of people who schedule onboarding calls.
- Location and residency
- Processed according to Calendly's service terms and data handling controls.
Cloudflare
- Purpose
- Custom domains for pages members publish with Build.
- Data processed
- Custom domain names, and the visitor requests and page content served on those domains.
- Location and residency
- Processed according to Cloudflare's service terms and data handling controls.
Cohere
- Purpose
- Reranking knowledge search results.
- Data processed
- Search queries drawn from member requests, and passages from the StefanBrain knowledge base.
- Location and residency
- Processed according to Cohere's service terms and data handling controls.
Composio
- Purpose
- Connector platform that signs in to and runs many connected services, such as Gmail, Google Drive, Notion, Slack, Klaviyo, and X.
- Data processed
- OAuth grants and API keys for connected services, the requests StefanBrain sends to those services and their results, and files uploaded to them.
- Location and residency
- Processed according to Composio's service terms and data handling controls.
Decodo
- Purpose
- Residential proxy network for downloading public videos and for Google ad transparency research.
- Data processed
- Download and research requests for public links, which pass through its network.
- Location and residency
- Processed according to Decodo's service terms and data handling controls.
Doppler
- Purpose
- Secrets management and secure runtime configuration.
- Data processed
- Application secrets, service credentials, API keys, and configuration values. Doppler is not used for routine storage of chat content or uploaded files.
- Location and residency
- Processed according to Doppler's service terms and infrastructure configuration.
ElevenLabs
- Purpose
- Voiceovers, voice clones, songs, and captions for generated videos.
- Data processed
- Narration scripts and lyrics, voice samples members attach for cloning, generated speech and music, and video audio transcribed for captions.
- Location and residency
- Processed according to ElevenLabs's service terms and data handling controls.
Entri
- Purpose
- Guided DNS setup when members connect a custom domain.
- Data processed
- Custom domain names and the DNS records to add.
- Location and residency
- Processed according to Entri's service terms and data handling controls.
Exa
- Purpose
- Web search for research tools, and backup page reading.
- Data processed
- Search queries and page URLs from member requests, and the results returned.
- Location and residency
- Processed according to Exa's service terms and data handling controls.
Google (Gemini)
- Purpose
- AI model processing for chat responses, video analysis, and video ad copy.
- Data processed
- Prompts, chat messages, user-requested connected account context, uploaded content, videos submitted for analysis, and generated outputs needed to complete the requested AI task.
- Location and residency
- Processed according to Google's Gemini API data handling, retention, and residency controls.
Google Workspace
- Purpose
- Team email. Follow-up drafts to members who cancel are created in the team's Gmail.
- Data processed
- Member names and email addresses, prior email correspondence with the team, and follow-up drafts.
- Location and residency
- Processed according to Google Workspace's service terms and data handling controls.
Lightreel
- Purpose
- Short-form video research.
- Data processed
- Research questions from member requests, and the results returned.
- Location and residency
- Processed according to Lightreel's service terms and data handling controls.
Monday.com
- Purpose
- Member access records. StefanBrain reads who has access from Monday.com and writes team member updates back.
- Data processed
- Member names, email addresses, and membership status.
- Location and residency
- Processed according to Monday.com's service terms and data handling controls.
OpenAI
- Purpose
- AI model processing for image generation, ad copy, creative analysis, Copy Chief reviews, and follow-up drafts to members who cancel.
- Data processed
- Prompts, source images and files, creative context, generated outputs, and request metadata. For follow-up drafts: the member's first name, cancellation survey answers, and prior emails with the team.
- Location and residency
- Processed according to OpenAI's API data handling, retention, and residency controls.
OpenRouter
- Purpose
- AI model routing for chat, Build pages, funnel reviews, and static ad animation. Member chats reach Google's Gemini models through OpenRouter.
- Data processed
- Prompts, chat messages, user-requested connected account context, uploaded content, and generated outputs needed to complete the requested AI task.
- Location and residency
- Processed according to OpenRouter's data handling controls and those of the model provider it routes to.
Otter.ai
- Purpose
- Onboarding call transcripts. StefanBrain reads the team's recorded onboarding calls to prepare onboarding analysis.
- Data processed
- Transcripts of onboarding calls with members, with call titles and dates.
- Location and residency
- Processed according to Otter.ai's service terms and data handling controls.
Pinecone
- Purpose
- Vector search over the StefanBrain knowledge base.
- Data processed
- Search queries drawn from member requests, and passages from the knowledge base.
- Location and residency
- Processed according to Pinecone's service terms and data handling controls.
PostHog
- Purpose
- Product analytics and usage measurement.
- Data processed
- Product usage events, device and browser metadata, approximate location data, session information, and account identifiers used for analytics.
- Location and residency
- Processed according to PostHog's service terms and configured analytics infrastructure.
Resend
- Purpose
- Email delivery: sign-in codes, trial and team emails, account notices, and emails members send from chat.
- Data processed
- Recipient email addresses and email content, including emails members ask StefanBrain to send.
- Location and residency
- Processed according to Resend's service terms and data handling controls.
Sentry
- Purpose
- Error and performance monitoring for the web app and workers.
- Data processed
- Error messages, stack traces, page URLs without query strings, browser and device details, and internal ids. Request bodies, cookies, and fields holding content or credentials are removed before sending.
- Location and residency
- Processed according to Sentry's service terms and data handling controls.
SerpApi
- Purpose
- Amazon product and search results, and Google Trends, for research tools.
- Data processed
- Search terms and product identifiers from member requests, and the results returned.
- Location and residency
- Processed according to SerpApi's service terms and data handling controls.
Slack
- Purpose
- Internal team notifications: trial requests, cancellation and billing alerts, and incident reports.
- Data processed
- Names and email addresses of trial requesters and members, cancellation reasons, and account details in alerts.
- Location and residency
- Processed according to Slack's service terms and data handling controls.
Stripe
- Purpose
- Checkout, subscriptions, invoices, retention discounts, and the API wallet.
- Data processed
- Names, email addresses, billing details, payment methods, subscriptions, invoices, and wallet top-ups.
- Location and residency
- Processed according to Stripe's service terms and data handling controls.
Supadata
- Purpose
- Published caption tracks for YouTube, Instagram, TikTok, and X videos.
- Data processed
- Public video links from member requests, and the caption text returned.
- Location and residency
- Processed according to Supadata's service terms and data handling controls.
Customer-authorized platforms
StefanBrain can connect to Slack, Google, Shopify, Meta, TikTok, and other customer-authorized services when a customer enables those connectors. Those platforms are generally the customer's selected source or destination systems rather than StefanBrain sub-processors. Data is exchanged with those platforms only as needed for the user-authorized connector features. StefanBrain also reads public websites, such as ad libraries and online stores, the way a visitor's browser does. Those sites are sources, not sub-processors.
AI processing and model training
StefanBrain sends customer content to AI providers only to fulfill user-requested tasks. StefanBrain does not sell customer data and does not use customer content to train generalized AI or machine learning models. We do not opt in to third-party provider model training on customer content unless expressly authorized.
Changes
We may update this page when we add, remove, or materially change a sub-processor. The updated list will be posted here with a revised last updated date.