Cupidsgram
Subprocessors
Last updated: September 2026
What this page covers
Cupidsgram works with the service providers below to run the product. Each provider processes data on our behalf and under our instructions. We list them here so you can see exactly who is involved and what they handle. This list is current as of the date above and will be updated whenever we add or change a provider.
Subprocessors
| Provider | Location | Purpose | Data involved |
|---|---|---|---|
| Cloudflare | United States | Photo and video storage (R2), media delivery (edge Worker/CDN), video hosting and playback (Stream), DDoS/WAF protection. | Uploaded photos and videos, media URLs, request metadata. |
| Vercel | United States | Application hosting (Next.js). | Request metadata required to serve the application; no analytics tracking. |
| Turso | United States / Global edge | Primary database (SQLite/libSQL) storing all account, post, and billing data. | Account details, posts, captions, settings, payment records. |
| Inngest | United States | Background job orchestration — email sending, media processing, automated content creation. | Event payloads needed to run the job (e.g. post and tenant identifiers). |
| Resend | United States | Transactional email delivery (verification, password reset, receipts, alerts). | Recipient email address, email content. |
| Brevo | France (EU) | Transactional email delivery — automatic fallback provider if Resend is unavailable or rate-limited. | Recipient email address, email content. |
| OpenRouter | United States | AI caption generation — routes caption requests to the model provider selected for each request. | The photo(s) being captioned (transmitted to the model provider, not retained) and caption context (first names, relationship start date). |
| Google (via OpenRouter) | United States | Gemini models generate suggested captions. | See OpenRouter above. API terms: no training on your data, no retention of the photo. |
| OpenAI (via OpenRouter) | United States | GPT models generate suggested captions (fallback tier). | See OpenRouter above. API terms: no training on your data, no retention of the photo. |
| Meta Platforms | United States (Meta Platforms Ireland Ltd. for EU users) | Advertising measurement — the Meta Pixel on our pages and server-side purchase/signup events, so we can tell which ad produced a buyer. For this processing Meta also acts as an independent controller under its own business-tools terms, not only on our instructions. | Page, checkout and signup events, purchase amount and currency, browser identifiers (_fbp/_fbc), IP address, user-agent, and a SHA-256 hash of the buyer's email. Stored on our side for 90 days, then deleted. |
| Whop | United States | Payments and subscription management. | Payment method details (processed by Whop, never stored by us) and purchase records. |
International transfers
Some providers operate outside the European Economic Area. Where we transfer personal data outside the EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the providers' own data-protection commitments. A copy of the relevant safeguards, or a data processing agreement with a specific provider, is available on request.
AI captioning note
When you use the AI caption feature, the photo(s) are transmitted to OpenRouter, which forwards them to the model provider for that request (Google or OpenAI). The photo is used only to write your caption, is not retained by the provider, and is not used to train models. Only the resulting caption text is stored on our servers. See the Privacy Policy for details.
Questions
If you have questions about a specific processor or want a copy of a data processing agreement, contact us at hello@cupidsgram.com.