Skip to content

Draft — not yet in force

This is a draft, published so you can read it rather than being told it exists. It has not been reviewed by a lawyer, and parts of it describe how Control is designed to work rather than what has shipped — Control is in private beta and no payment has been taken. Details still to be settled are shown like this: to be confirmed.

Subprocessors

Every external company that touches your data on Control's behalf. The complete list, not a selection.

Effective date: effective date Last updated: effective date


1. What this page is

Control is built by a small team on top of a small number of external services. Those services process some of your personal data on our behalf, on our instructions, under a written data processing agreement. They are called subprocessors.

This page lists every one of them. It is the complete list — not a selection.

We do not sell your personal data, and none of the companies below are permitted to use it for their own purposes.

2. The list

2.1 Core infrastructure

Subprocessor What it does for Control Personal data it processes Where it processes it DPA / terms
Vercel Inc. Hosting, serverless functions, global edge CDN, scheduled jobs All data in transit through the application; IP addresses; request logs. Content passes through but is not stored at the edge. United States, with edge points of presence worldwide including the EU and the GCC vercel dpa url
Supabase, Inc. PostgreSQL database, authentication, one-time sign-in code delivery Everything we store: account details, items, notes, original captured input, personal facts, people, captures, receipts, usage records, session records eu-central-1 (Frankfurt, Germany) supabase dpa url
kms provider Key management — holds the master key that wraps each tenant's data encryption key Cryptographic key material only. No personal data. kms region kms dpa url

2.2 AI processing

This is the category that matters most. Read §3 of the Privacy Policy for what is actually sent.

Subprocessor What it does for Control Personal data it processes Where it processes it DPA / terms
ai provider (primary) Interprets your captured text into tasks, events, dates, people and tags; extracts candidate personal facts The sentence you wrote or spoke; up to ~20 personal facts selected as relevant; titles and IDs of a small number of your existing items; the current date, time and your timezone. No name, no email address, no payment data, no account identifier tied to your identity. ai provider region ai provider dpa url
ai provider fallback (failover) The same, when the primary provider is unavailable or failing The same as above ai provider fallback region ai provider fallback dpa url
stt provider (paid plans only) Server-side speech-to-text for voice capture Your audio recording; a short biasing vocabulary of proper nouns from your own data (names of people you've mentioned, your tags, organisations) to improve accuracy stt provider region stt provider dpa url

Both AI providers operate under a zero-retention agreement: they do not store the content of our requests after processing, and they do not use it to train or improve their models.

Browser speech — not our subprocessor, and that is the point

When you use voice capture on the free tier, Control uses the speech recognition built into your own browser. That is not a service we buy, configure or control, and it is listed here because the distinction is easy to get wrong in the user's favour and we will not do that:

Who processes it What they receive Our relationship to them
Google LLC (Chrome, and Chromium-based browsers) The audio your browser captures while the microphone is open None. Google is your browser vendor's processor, not ours. We have no contract with them covering this, and no ability to impose one.
Apple Inc. (Safari, iOS) The same None, for the same reason.

Control never receives your audio on this tier. Only the finished text reaches us, and from that point it is handled exactly like text you typed. That is true and worth saying — but it must never be written as "your voice never leaves your device", because it does. The Web Speech API is a browser interface, not a guarantee of on-device processing.

What your browser does with that audio is governed by your browser's own privacy policy, not by ours. If you would rather no third party received it, do not use the microphone — typing is always available, and every feature works without it.

Control shows this in the app the first time you open the microphone, rather than only here.

(The paid-tier alternative, stt provider above, moves the audio to a processor we DO hold a contract with. That is the reason it exists.)

Every request to an AI provider is logged as a Data Receipt you can inspect in Settings → Privacy, showing which fact keys (never their values) and which items were included.

2.3 Communications

Subprocessor What it does for Control Personal data it processes Where it processes it DPA / terms
Resend (Plus Five Five, Inc.) Transactional email — billing notices, deletion confirmations, data export links, service announcements Your email address, your display name, and the content of the message United States resend dpa url

Push notifications — your browser's push service, and what it can and cannot see

If you turn notifications on, Control sends them through the push service your browser vendor operates. We do not choose it and we have no contract with it — the same relationship described for browser speech above. Which one it is depends on the browser you use: Google's for Chrome and Chromium browsers, Apple's for Safari, Mozilla's for Firefox, Microsoft's for Edge.

Who processes it What they receive Our relationship to them
Google LLC (Firebase Cloud Messaging — Chrome, Chromium browsers, Android) A subscription endpoint their own service issued to your browser, and an encrypted notification payload None. They are your browser vendor's service, not ours.
Apple Inc. (Apple Push Notification service — Safari, iOS) The same None, for the same reason.
Mozilla Corporation (autopush — Firefox) The same None, for the same reason.
Microsoft Corporation (Windows Notification Service — Edge) The same None, for the same reason.

They cannot read the notification. Under the Web Push standard (RFC 8291), the payload is encrypted with a key derived from a keypair and a secret that your own browser generates and never shares with the push service. Control holds those keys; the push service does not. It carries a sealed envelope it cannot open.

What it can see, and we will not claim otherwise: that a message was sent to your device, when, and how big it was. We pad every notification to a fixed size specifically so the size reveals nothing about the contents. It can also, in principle, decline to deliver.

What we send. One notification at most per day, in the morning, and only when there is something on your list that needs reconciling. The text is a question about an item you captured yourself — "Meeting with the client — did that happen?" — which means an item title of yours does travel inside that encrypted payload and does appear on your lock screen. Nothing else goes with it: no name, no email address, no account identifier.

Turning it off stops it entirely, on every device, from the You page. We also delete a device's subscription as soon as its push service tells us the device is gone.

2.4 Analytics and monitoring

Subprocessor What it does for Control Personal data it processes Where it processes it DPA / terms
PostHog, Inc. Product analytics — which features get used, activation, retention. Cookie-based on the public marketing site only, and only with your consent. Inside the authenticated app, events are sent from our server; no PostHog script runs on authenticated pages. Pseudonymous user identifier, event names, page paths, device and browser type, approximate location from IP address. Not your task content, notes or fact values. posthog region posthog dpa url
Functional Software, Inc. (Sentry) Error and performance monitoring Error messages, stack traces, browser and device details, pseudonymous user identifier, the page you were on. Content is scrubbed, but fragments may appear incidentally in error payloads. sentry region sentry dpa url

2.5 Payments

Company Role Personal data it processes Where Terms
merchant of record Merchant of record — the legal seller for your purchase. Handles checkout, card processing, subscription management, invoicing, and collection and remittance of VAT/GST/sales tax. Your name, email address, billing address, country, payment card details, transaction and subscription history mor region mor dpa url · mor privacy policy url

Note on status: merchant of record is not our processor for the payment transaction — as merchant of record they are an independent controller of your payment data, under their own privacy policy. They act as our processor only for the limited subscription-status data they pass back to us. We never receive your full card number.

2.6 Identity providers (not subprocessors)

If you choose to sign in with Google, Microsoft, GitHub, Discord or Slack, that company processes your data as an independent controller under its own privacy policy. We receive only your verified email address and basic profile information. We are not able to see anything else in those accounts, and we do not request any additional permissions.

3. Notice before we add a new subprocessor

We commit to the following.

  1. We will publish the change here first. This page is the authoritative list and is updated before a new subprocessor begins processing.
  2. We will give at least 30 days' notice before a new subprocessor starts processing personal data, by email to the address on your account and by an in-app notice.
  3. You can object. If you have a reasonable, data-protection-based objection to a new subprocessor, email contact email within the notice period. We will try to find an alternative. If we cannot, you may cancel your subscription and receive a pro-rata refund of the unused portion of your current billing period, and export all your data first.
  4. Emergency substitutions. If a subprocessor fails or terminates our contract without warning and we must substitute immediately to keep the service running, we will make the change and notify you as soon as possible afterwards, with the same right to object and cancel.
  5. We will keep this page current. Removals are recorded in the change log below as well as additions.

3.1 Subscribe to changes

To be notified of changes to this page, email contact email with the subject "subprocessor updates". Account holders are notified automatically.

4. What we require of every subprocessor

Before a subprocessor is engaged, we require:

  • a written data processing agreement incorporating GDPR Art. 28 terms;
  • EU Standard Contractual Clauses and the UK International Data Transfer Addendum, where the transfer needs them;
  • a transfer impact assessment covering the destination country;
  • documented security measures appropriate to the data involved;
  • a commitment to notify us of breaches without undue delay;
  • confidentiality obligations on their personnel;
  • a commitment to delete or return data at the end of the relationship;
  • for AI providers specifically: zero retention of request content, and no training on it.

5. Change log

Date Change Notice given
effective date Initial list published —

6. Questions

Email contact email.


This is a draft prepared for legal review. It is not legal advice and has not been reviewed by a qualified lawyer. Every entry must be verified against signed contracts and configured regions before this page is published.