Last updated August 29, 2026
This page lists the main service-provider and processor categories Filmclusive currently uses to operate product, storage, billing, analytics, AI, speech, email, and connected-service features.
This page is a transparency supplement to the Privacy Policy. Some providers are used only when a user enables the related feature, gives consent, starts checkout, connects Google, uploads a file, or chooses an AI or audio workflow.
Purpose: Authentication, database, backend processing, storage, security, and application infrastructure.
Data involved: Account identifiers, profile and team records, project data, permissions, logs, security events, files, and operational metadata.
Purpose: Object storage and CDN delivery for selected upload and media workflows.
Data involved: Uploaded files, media assets, storage paths, access metadata, and deletion or cleanup records.
Purpose: Checkout, subscriptions, billing portal, payments, donations, ticketing, invoices, refunds, and payment status.
Data involved: Customer identifiers, billing contact details, checkout/session IDs, transaction metadata, subscription status, invoice records, refund and dispute metadata.
Purpose: Optional product analytics and performance measurement after analytics consent and Do Not Sell checks.
Data involved: Minimized route categories, allowlisted event properties, performance metrics, and limited browser signals when enabled.
Purpose: Website hosting, deployment, server execution, request delivery, and operational logging.
Data involved: Source and build artifacts, deployment metadata, HTTP request metadata such as IP address and coarse location, runtime and build logs, response status, and application content handled during a request.
Purpose: User-authorized Gmail, Google Calendar, and Google People features. Google Sheets routes are currently disabled.
Data involved: OAuth connection state and encrypted credentials; Gmail messages, headers, bodies, snippets, labels, filters, attachments, and approved outgoing mail; calendar availability or owned-calendar events; contact details; and related connection, cache, or sync records for enabled features.
Purpose: User-requested YouTube video metadata, statistics, and available caption metadata for supported media workflows.
Data involved: User-supplied YouTube video ID, API credential metadata, ordinary request metadata, and returned video or caption metadata.
Purpose: Display user-selected YouTube, Vimeo, Spotify, SoundCloud, or Bandcamp media.
Data involved: Media identifiers and ordinary browser connection data, including IP address, device or browser metadata, provider cookies or account state, and playback requests when an embed loads.
Purpose: Optional AI processing for selected document, script, note, or workflow features.
Data involved: The content, prompts, files, and metadata submitted to the enabled AI workflow.
AI data controls: Filmclusive blocks outbound requests unless the account has opted in, is not a known minor, and the deployment has a current paid-service, no-training, zero-retention evidence record. Provider safety or legal exceptions may still apply.
Purpose: Optional AI processing for selected generation, summarization, extraction, or workflow features.
Data involved: The content, prompts, files, and metadata submitted to the enabled AI workflow.
AI data controls: Filmclusive uses the Responses API with store set to false and blocks outbound requests unless the account has opted in, is not a known minor, and the deployment has a current no-training and zero-retention evidence record. Provider safety or legal exceptions may still apply.
Purpose: Text-to-speech generation for selected audio features.
Data involved: Text submitted for speech generation and operational metadata needed to return the requested audio.
AI data controls: Filmclusive blocks synthesis unless the account has opted in, is not a known minor, and the deployment has a current evidence record for Google Cloud Text-to-Speech stateless, no-content-logging processing.
Purpose: Browser-managed speech recognition when a user enables voice transcription.
Data involved: Microphone audio and recognized text as handled by the browser or device speech service.
AI data controls: Filmclusive does not upload audio in this path. The browser or device provider may process audio remotely under its own terms, retention, and training controls, which Filmclusive cannot configure or verify.
Purpose: Error monitoring and incident diagnostics.
Data involved: Error classes, minimized stack locations, coarse route categories, release and environment labels, and limited operational correlation references. Session replay, performance tracing, breadcrumbs, direct user context, and request payloads are disabled or removed before transmission.
Purpose: Security and operational alert delivery.
Data involved: Security alert summaries, operational incident metadata, and limited identifiers needed to route internal alerts.
Purpose: Scheduling and meeting workflows when users choose Zoom-related meeting options.
Data involved: Meeting links, scheduling metadata, meeting preferences, and related event details.
Purpose: Merchandise product listing, order, and fulfillment workflows when store features are used.
Data involved: Product selections, order details, shipping or fulfillment metadata, and provider order identifiers.
Purpose: Transactional email, invitations, roster notices, opportunity checks, support replies, confirmations, workflow notifications, and delivery events through the configured SMTP provider. Legacy live Mailgun, Postmark, and SendGrid webhook endpoints are under provenance review.
Data involved: Recipient and sender contact details, message content, delivery, open, click, bounce, complaint, unsubscribe or suppression metadata, provider event identifiers, and related audit records.
Purpose: Opted-in iOS notification and Apple Wallet pass-update delivery.
Data involved: Device or Wallet push token, application topic, notification title and body, category, bounded navigation route, badge or sound, event reference, and delivery metadata.
Purpose: Globally coordinated rate limiting and abuse prevention.
Data involved: Opaque keyed-HMAC rate-limit identifiers, short-lived counters, reset timestamps, and ordinary provider request metadata. Raw identifiers and route names are excluded from the Redis key.
Purpose: Optional connected-profile authorization, repository hosting, CI/CD, and release verification.
Data involved: OAuth connection state, encrypted local access token, GitHub account ID, username and scopes, source and workflow files, commit and pull-request metadata, checks, build or test logs and artifacts, and injected CI credentials.
Purpose: Bot protection, optional edge rate limiting, edge workers, release admission, and customer-requested managed DNS.
Data involved: Turnstile tokens, optional keyed rate-limit digests and short-lived counters, request security metadata, worker payloads, domain names, DNS zones and records, and provider identifiers.
Purpose: Customer-requested domain registration, contact updates, renewal, and registrar lifecycle operations.
Data involved: Domain names, registrant and administrative contact details, provider transaction IDs, pricing, and registration status.
Purpose: Optional connected social-account and publishing features authorized by the user.
Data involved: OAuth tokens, provider account IDs, username and profile metadata, granted scopes, and selected publishing content.
Purpose: User-requested place lookup, geocoding, routing, and distance calculations.
Data involved: Location queries, origin and destination, place IDs, coordinates, and returned place metadata.
Purpose: User-requested weather, public maps, nonprofit verification, public-web research, demo avatars, and Substack content through Open-Meteo, the U.S. National Weather Service, ArcGIS and NYC Open Data, CharityAPI or GuideStar, Brave Search, DiceBear, and AllOrigins.
Data involved: The minimum location query or coordinates, organization identifier, public-web query, public content URL, or fixed demo label needed for the selected feature, plus ordinary request metadata. Filmclusive does not use an external service to infer a visitor location from their IP address.
Essential providers are used to authenticate users, secure the service, store data, process uploads, and deliver core product workflows. Optional providers are used only when the relevant feature is enabled, such as analytics, Google-connected services, Stripe checkout, AI processing, or speech generation.
Do Not Sell, Global Privacy Control, analytics consent, Google Limited Use consent, and AI-processing consent may limit whether certain optional processing runs in the current application.
Filmclusive may add, replace, or remove providers as the product changes. We update this page when a material provider category changes or when a new provider materially changes how user information is processed.