Legal

Subprocessors

Last updated July 24, 2026

These are the third-party vendors we use to run DepoFlow. Because the default workflow processes everything on your machine, most vendors only ever see thin account or billing records — case content reaches a vendor only when you explicitly invoke the feature that needs it. Each vendor is bound by contract to use the data solely to provide its service to us. See the Privacy Policy for how we handle data generally.
VendorPurposeData ReceivedLocationWhen It Applies
RailwayApplication and database hostingAccount records, job envelopes (witness, matter, duration, status), billing recordsUnited StatesAlways (cloud account)
Cloudflare (R2)Object storage for cloud filesFiles you explicitly share or render in the cloud; installer downloadsUnited StatesOnly when you use a cloud file feature
StripePayment processingName, email, payment card details (entered directly with Stripe), transaction historyUnited StatesWhen you purchase credits or a subscription
ResendTransactional email deliveryEmail address, message content (verification, receipts, notifications)United StatesAlways (account email)
KitNewsletter and product announcementsEmail address, subscription preferencesUnited StatesOnly if you opt in to marketing email
ModalGPU compute for cloud-accelerated transcriptionAudio for the specific job you submitted, processed transientlyUnited StatesOnly when you opt in to cloud acceleration for a job
Recall.aiLive transcription of remote depositionsMeeting audio and live transcript for the session you startUnited States or European Union (selectable region)Only when you start a live transcription session

Changes to This List

Before adding a subprocessor that will handle case content, we update this page and notify account holders by email, giving firm customers a reasonable opportunity to object. Vendors that only handle account or billing records are added to this page as they come into use. Questions: privacy@depoflow.com.