Skip to main content

    The third parties that process data on our behalf to deliver Draftless, what each one receives, and why.

    1. What this covers

    Draftless uses third-party "sub-processors" to deliver the service. This page lists each category, the data it receives, and its data-handling posture. Each provider's own terms govern its processing; this page is a summary, not a substitute for those terms.

    2. Infrastructure

    • Managed Postgres / backend host — account, application and billing data. Database, auth, storage and server functions. Encrypted at rest and in transit; region per plan.
    • Object storage — generated and uploaded media, for persistence and delivery. Versioned and access-controlled.
    • Error monitoring (Sentry) — error events, request identifiers and limited context, for reliability and debugging, plus session replays for a sample of sessions and for sessions where an error occurs. Personal data is scrubbed from breadcrumbs where possible.
    • Email delivery — email address and message content, for transactional email: authentication, receipts and notifications.
    • Stripe — billing identifiers and payment metadata, for payments and subscriptions. Stripe is the PCI merchant of record; card data never reaches our servers.
    • Google Play Billing — purchases in the Android app. Google receives the payment details; we receive a purchase token and order ID only.
    • ElevenLabs — voice samples you upload for voice cloning, to create the cloned voice.

    3. AI model providers

    These receive the prompt and any input media you submit for a given generation. They do not receive account credentials or billing data.

    • AI gateway (text/LLM routing) — prompt text and context. Training and retention follow the upstream model's terms.
    • FAL (image, video and audio models) — prompt plus input media. Retention and training posture are provider-dependent per endpoint.
    • Model vendors reached through the gateway or FAL — prompt plus input media. We select the no-training option wherever a provider offers one.

    Providers we call directly, with their training posture as we read their terms:

    • fal.ai — prompt plus input media. Uses only anonymised usage data; we send a no-storage header so request payloads are not kept.
    • OpenAI — prompt plus input media. Does not train on your inputs.
    • BytePlus (Seedance video) — prompt plus input media. Does not train on your inputs.
    • Lovable AI gateway (Google Gemini models) — prompt and context. Not confirmed — terms unclear.
    • Kling (direct and via fal) — prompt plus input media. Not confirmed — terms unclear.
    • Runway — prompt plus input media. Not confirmed — terms unclear.
    • Replicate — prompt plus input media. Not confirmed — terms unclear.
    • ElevenLabs — text, voice samples and audio. Not confirmed — terms unclear.
    • Higgsfield (Soul) — prompt plus input media. May retain or learn from inputs; labelled in the app and, if you have not allowed training, used only after you confirm.
    • Ideogram — prompt plus input media. Not confirmed — terms unclear.
    • Recraft — prompt plus input media. Not confirmed — terms unclear.
    • Stability AI — prompt plus input media. Not confirmed — terms unclear.
    • Luma AI — prompt plus input media. Not confirmed — terms unclear.
    • fluxapi.ai (Black Forest Labs models) — prompt plus input media. Not confirmed — terms unclear.
    • sunoapi.org (Suno music) — prompt. Not confirmed — terms unclear.
    • Memories.ai — video for analysis. Not confirmed — terms unclear.

    4. Your controls

    • Prompts and inputs are sent to AI sub-processors only to fulfil the generation you requested.
    • You can delete generated assets, and deleting your account cascades through your data.
    • Brand kits and uploaded media are processed only to fulfil your requests.

    5. Change management

    Material changes to this list are communicated to customers under the notice clause of our Data Processing Agreement, with the opportunity to object where contract or law provides one.

    6. Contact

    To request the current provider detail for your account:

    Email: privacy@draftless.dev

    Draftless
    Legal

    © 2026 Draftless. All rights reserved.