Legal
Subprocessors
Service providers that may process personal data or user content for BriefScroll.
Last updated: 2026-07-21
Current providers
These providers receive personal data or user content when the described feature is active:
- Clerk: authentication, account management, session handling, Organizations team membership and role management, and Billing checkout/subscription state.
- Cloudflare: hosting, Workers, R2 storage for article bodies, PDFs, uploaded documents, transient article-image uploads, generated media, KV, queues, AI Gateway, rate limits, browser rendering, inbound email routing for newsletter forwarding, and outbound email sending for alerts and digests (your email address and the message we send pass through Cloudflare to deliver).
- Neon: Postgres database hosting and related database services.
- AI providers: OpenRouter routes generative prompts and outputs to Google or DeepSeek for generic summaries, clean reads, images, claim checks, search, Assistant turns, long-thread compaction, Research setup, and explanations. For Research setup, Google receives your prompt and up to 80 relevant owned-library candidate labels with opaque keys and content types, but not article bodies, source content, note text, or highlight text. Cloudflare AI Gateway carries ScaleDown classifications and, only after the separate provider-review gate is enabled, routine article summaries; Workers AI provides embeddings and audio. Direct provider credentials and the old Cloudflare route remain temporarily for rollback.
- PostHog: server-side feature events, explicit feedback surveys, crash reporting, experiment evaluation, and optional page lifecycle analytics. Page-view and page-leave events can be disabled in Settings or by Do Not Track or Global Privacy Control. On-screen text, anything you type, search queries, and article identifiers are removed before forwarding. Autocapture, PostHog cookies, session replay, and advertising profiles are off.
- Discussion metadata providers: Hacker News, GitHub, and Reddit for article-URL discussion discovery and refresh where enabled.
- Claim-evidence providers (only when you ask to find evidence and the feature is enabled): Brave Search for web search and the Google Fact Check Tools API for published fact checks. The query sent can include claim text from the article you asked to check, but never your account details, notes, highlights, or broader private library. We retrieve short attributed snippets with a direct link to the original page and never rehost the source. Public reference lookups (Crossref, Wikidata, SEC EDGAR, World Bank, and other public reference sources) send only public identifiers and no personal data.
- Stripe: subscription billing, invoices, tax support, fraud checks, and payment processing through Clerk Billing.
- Outbound email (alerts and digests) is sent through Cloudflare Email Sending; we send your email address and the message to deliver it. Outbound email is off by default and you can turn it off any time, and every alert and digest email carries a one-click unsubscribe link.
- Notion: only if you connect it as a sync target. Your highlights and notes (with their source link, date, and tags) are sent to the Notion database you choose, using the integration token you provide. Disconnect anytime; pages already created stay in Notion.
Review standard
Each provider should be reviewed for data sent, retention, security, DPA terms, AI training posture, and whether paid security or privacy review is needed.
Changes
Before adding a new provider that receives personal data or user content, update this page and review privacy, security, AI, billing, and international-transfer impact.