Legal

Sub-processors

Last updated 23 September 2026.

These are the companies that process customer data on our behalf when we run Peutly for you. Each is bound by data-protection terms, and where data leaves the European Economic Area we rely on the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework. This list is part of our Data Processing Agreement.

Current sub-processors

CompanyPurposeDataLocation
Amazon Web Services EMEA SARLApplication hosting, file storage, content delivery, transactional email, video export renderingAll customer data, including recordings, assets, viewer sessions and leadsEU (Frankfurt, eu-central-1). Published demo files are cached at CDN edge locations worldwide
MongoDB, Inc. (Atlas)Managed databaseAccount data, demo structure and text, viewer sessions, engagement events, leadsEU (AWS Frankfurt, eu-central-1)
Anthropic, PBCAI assistantOnly when someone in your workspace uses the AI assistantDemo text, captured on-screen text, step screenshots, chat messages and files you attachUnited States
OpenAI, L.L.C.AI voice-over (text to speech)Only when you generate a voice-overThe narration script you write for a stepUnited States
Supabase, Inc.Sign-in with Google, Apple or SAMLOnly for sign-ins through an identity providerEmail address and identity-provider token of the person signing inUnited States
Stripe Payments Europe, Ltd.Subscription billingBilling contact and payment details (card data is handled by Stripe and never reaches Peutly)Ireland, with processing by Stripe group companies including in the United States
Google LLC (Google Fonts)Web font delivery in the dashboard and demo playerIP address and browser user-agent of the person loading the pageGlobal

AI providers

Anthropic and OpenAI receive data only when someone in your workspace uses the AI assistant or generates a voice-over. We use both through their commercial APIs, under terms that do not allow them to train their models on the data we send. Peutly does not train models on your data either.

The AI assistant can read the text captured from your product's screens and the step screenshots, so it can suggest edits that match what is on screen. A workspace admin can switch that off in the workspace settings, after which the assistant only sees the text you wrote in the editor.

Integrations you switch on

The services below are not our sub-processors. They only receive data when you connect them with your own account, and they act for you, not for us. You are responsible for having a lawful basis for them, and for asking viewers' consent where the law requires it, for example before analytics cookies are set.

  • Google Analytics 4: Loaded in the viewer's browser inside your published demo, using your measurement ID. Sets Google Analytics cookies.
  • Segment: Loaded in the viewer's browser inside your published demo, using your write key.
  • Heap: Loaded in the viewer's browser inside your published demo, using your app ID. Sets Heap cookies.
  • Outgoing webhooks: Peutly sends lead and engagement events, including form fields a viewer submitted, to an HTTPS endpoint you configure.

Changes to this list

We will announce a new sub-processor at least 30 days before it starts processing customer data, by email to workspace admins and by updating this page. If you have a reasonable data-protection objection, tell us at privacy@peutly.com within that period. We will try to find a way around it, and if we cannot, you may end the affected part of your subscription and receive a pro-rata refund of fees paid in advance.