Overview
When you use Vincony, your prompts and data may be transmitted to third-party sub-processors in order to deliver the Service. This page lists those sub-processors and explains how your data flows to them.
Important: User prompts submitted to AI model providers are processed according to each provider's own privacy and data-retention policies. Vincony's commitment not to use your content for AI model training applies solely to data held and controlled by Vincony — it does not extend to the downstream model providers. We encourage you to review each provider's privacy policy if this matters to your use case.
Core Infrastructure
- Hetzner Online GmbH (Germany / Finland, EU) — Dedicated servers hosting Vincony's self-hosted database, authentication, and storage stack, operated by Vincony. Primary data storage is in the European Union. hetzner.com/legal/privacy-policy
- Cloudflare (San Francisco, USA — global network) — CDN, WAF, DNS, and DDoS protection. cloudflare.com/privacypolicy
Payments
- Stripe (San Francisco, USA / Dublin, Ireland) — Payment processing, invoicing and refunds; marketplace and partner payout disbursement (Stripe Connect). stripe.com/privacy
AI Routing and Models
Vincony routes prompts to AI model providers via the following routing layers and model providers. Each provider processes prompts to generate responses and applies its own data-handling policies.
Routing: - Vercel AI Gateway — Request routing and model abstraction - AIML API — AI model API gateway - OpenRouter — Aggregated model routing (provides access to many third-party models)
Direct model providers: - OpenAI (San Francisco, USA) — GPT and DALL-E model family. openai.com/privacy - Anthropic (San Francisco, USA) — Claude model family. anthropic.com/privacy - Google (Mountain View, USA) — Gemini model family. policies.google.com/privacy
Models available via OpenRouter (non-exhaustive): - Mistral AI, Cohere, Perplexity AI, Groq, xAI (Grok), and other models accessible through OpenRouter's network. Each provider's own terms and data policies apply.
Media Generation
- ElevenLabs (New York, USA) — Voice and audio generation. elevenlabs.io/privacy
- Suno (Cambridge, USA) — AI music generation. suno.com/privacy
- Resend (San Francisco, USA) — Transactional email delivery. resend.com/privacy
Web Data and Search Enrichment
- Firecrawl — Web scraping and data extraction (used by AI agent features). firecrawl.dev/privacy
- DataForSEO — Web search results and SEO data. dataforseo.com/privacy-policy
Web Agents
- Browserbase (USA) — Cloud browser sessions used by web-agent features. browserbase.com
Vector Search
Semantic search and memory features run on Vincony's self-hosted vector storage (EU servers) as of July 2026 — no third-party vector processor. (Pinecone was removed as a sub-processor on 12 July 2026.)
Google Services
- Google (Mountain View, USA) — OAuth sign-in ("Continue with Google") and Google Search Console integration for connected sites. See the "Google User Data" section of our Privacy Policy for what data is accessed and how it is used. policies.google.com/privacy
Integrations
- Composio — Third-party app integration layer (used by AI agent / tool-use features). When you connect a third-party application (e.g. Google Drive, Notion, Slack) through Vincony's agent tools, that connection is facilitated by Composio on your instruction. The data shared with those third-party applications is governed by their own terms and privacy policies. composio.dev/privacy
Analytics
- Google Analytics 4 (GA4) — Platform usage analytics. Only activated after you have given explicit cookie consent (PECR). policies.google.com/privacy
Error Tracking (First-Party)
- GlitchTip — Self-hosted error tracking operated by Vincony on our own EU infrastructure. Error reports do not leave Vincony-controlled servers; listed here for transparency (first-party, not a third-party sub-processor).
Content Moderation
- An image-moderation service is used to screen AI-generated visual content against prohibited content categories. This service may process image data submitted for generation.
Sub-processor Updates
We will update this page and notify customers of material changes. We provide at least 14 days' notice of new sub-processors via email and/or an in-app notification. You may object to the addition of a new sub-processor by contacting [email protected] within the notice period.
Last updated: July 12, 2026