Subprocessors
Every third party that can see customer data, and what each one sees.
The rule we are applying
Anyone outside [COMPANY_LEGAL_NAME — not configured] who can see customer data is on this list, including the ones a competitor would leave off — the AI provider that reads your photographs, and the hosting company whose disk they sit on. The "in use" column reflects this deployment as it is configured right now, not a general capability list.
| Who | What they do for us | What they can see | Where | Status |
|---|---|---|---|---|
|
Anthropic PBC (Claude)
Model in use: deepseek-v4-flash-vision-exp. | Reads the photograph and returns the fields on it. | The image itself, any message text sent with it, and the document-type hint. This is the whole content of what you photographed. | United States | Not enabled |
|
DeepSeek
Enabled on this deployment. Data sent to DeepSeek is processed outside the United States and the EEA. | Optional cheap first pass on easy documents before Claude is asked. | The same image and message text as above, for the documents routed to it. | China | In use |
|
SignalWire
The texting channel is not fully carrier-registered yet; email is the reliable route. | Receives inbound picture messages and sends reply texts. | Sender phone number, message text and the attached images. | United States | In use |
|
Cloudflare
Applies to the recommended inbound-email setup; a self-hosted MX record avoids it. | Routes mail sent to your @in.snapfiled.com address into Snapfiled. | The inbound email in full: sender, subject, body and attachments. | United States (global anycast network) | In use |
|
Outbound email relay
Configured host: smtp.resend.com. | Sends sign-in links, invites and reply emails. | Recipient address and the message body, which can contain a summary of a capture. | Depends on the relay configured | In use |
| Stripe | Subscription billing. | Your billing name, email and payment details. Card numbers are entered on Stripe and never reach Snapfiled servers. | United States | Not enabled |
|
Object storage (S3-compatible)
Not in use; photographs are stored on the application server’s own disk. | Stores the photographs. | The image files. | us-east-1 | Not enabled |
|
Hosting provider (the VPS)
The provider must be named here before this document is published. | Runs the application, the Postgres database and, by default, the file store. | Everything Snapfiled holds. | Wherever the server is; see the operator | In use |
|
Your CRM
This is your own system, under your own agreement with that vendor. Snapfiled is not its processor. | Where approved records are filed — HubSpot, JobNimbus, Follow Up Boss, Pipedrive, or your own webhook. | The approved record: names, phone numbers, email addresses, addresses, claim details, notes. | Set by the CRM you chose | In use |
The one that matters most
Anthropic receives the full contents of every photograph you send, because that is how the document gets read. There is no way to use Snapfiled without that happening. If a document is too sensitive to leave your building, do not photograph it into Snapfiled.
Changes
Before we add a subprocessor that can see capture content, we email account owners. You can object; see clause 7 of the DPA. Subscribe to changes by emailing [email protected].