Legal

Subprocessors

Last updated: September 15, 2026

These are the third parties that process data on our behalf to run the Service, as described in Section 6 of our Privacy Policy. We list every vendor that can receive your recordings or transcript text, because the question courts and firms ask first is who hears the audio.

We review the data-handling terms and controls of each vendor and record the result in our vendor register. Where a vendor offers a zero-retention or delete-on-completion mode, our software uses it and records the outcome for every run.

Vendors that process case content

VendorPurposeData it receivesLocation
AssemblyAISpeech recognitionHearing audio. The vendor's transcript copy is deleted as soon as we have retrieved it.United States
ElevenLabsSpeech recognition (Scribe)Hearing audio, sent in the vendor's zero-retention mode: nothing is stored after the response.United States
SpeechmaticsSpeech recognitionHearing audio. The vendor's job is deleted as soon as we have retrieved the result.United Kingdom / European Union (cloud); or on-premises inside a court's own network
pyannoteAISpeaker diarization (who spoke when)Hearing audio. The vendor deletes the upload within 48 hours and the result within 24 hours. Request metadata may be retained for service, billing, debugging, and audit purposes.Varies by the processing region selected for the account
Google (Gemini API)Speaker-identity suggestions, targeted re-listening, term extractionTranscript text excerpts. In Private mode, names on file are replaced with placeholders before sending. Not used to train Google's models.Global Google infrastructure

Which speech-recognition vendors run on a given hearing depends on the accuracy tier you choose; every run records which vendors it used. Private mode additionally encrypts your recording and transcript at rest under a key only you hold, and masks the names on file before any text reaches the language-model vendor. Free-text mentions inside testimony are not detected or masked.

Vendors that run the Service but never receive case content

VendorPurposeData it receivesLocation
Google CloudHosting, database, encrypted file storage, secrets, logsAll Service data, encrypted at rest and in transitUnited States (us-central1)
Amazon Web Services (SES)Transactional emailYour email address and generic notices. Emails never contain case names, file names, or case numbers.United States
StripePayments and subscriptionsEmail address, plan, and payment details entered on Stripe's own pagesUnited States
SentryError reportingError messages and stack traces, the page address, and browser type when something in the Service fails. No case content, file names, or form contents.United States
GitHubSource code hosting and deploymentNo customer dataUnited States

Changes to this list

We update this page before a new vendor begins processing customer data. If you have a written agreement with us that requires notice of subprocessor changes, we will notify the contact on file. Questions: privacy@depositions.app.