Legal · Sub-processors

Sub-processors

DevShot's external vendors and contractually confidential service categories, what they process, and where to find their compliance evidence. Last updated . Material changes are announced 30 days in advance to active customers via the email address on file.

Vendors

Railway

Hosting for the DevShot console + tunnel process.

Data accessed
In-memory request traffic; container stdout logs purged on restart.
Region
EU-West — primary.
Trust center
https://railway.com/security
DPA
Available on request.

Resend

Transactional email (signup confirmation, magic-link login, billing receipts).

Data accessed
Customer email address and the outbound message body.
Region
EU + US.
Trust center
https://resend.com/legal/security
DPA
Available on request.

External AI model and speech services

AI generation, review, computer-use reasoning, and optional speech synthesis requested in Studio.

Data accessed
Prompts, selected project context or source files, tool results and screenshots, generated outputs, and generated reply text sent for optional voice synthesis. Voice audit logs contain character count and consent version, not the voice text.
Region
United States; EEA transfer safeguards are required before personal-data production use.
Trust center
Provider identity and compliance evidence are available to business customers on request, subject to contractual confidentiality.
DPA
Provider data terms, transfer safeguards, and enterprise DPA status are available on request.

Customer-supplied S3 providers (AWS S3, Cloudflare R2, Backblaze B2, MinIO)

Per-VM qcow2 / raw overlay storage. The customer chooses and connects the provider.

Data accessed
Full VM disk images. The customer is the data controller for these buckets — DevShot only processes the connection metadata (provider URL, bucket name, masked credentials).
Region
Customer-selected.
Trust center
Provided by the customer's chosen S3 vendor.
DPA
The customer's DPA with their S3 vendor governs.