Technology & Vendor Register
Reviewed: August 25, 2026.
This public Register identifies storage/access technologies, subprocessors and other recipients used for Idelio. It supplements the Privacy Policy, Cookie & Tracking Policy, AI Transparency & Responsible Use Notice and Data Processing Addendum. SFER LABS LLC remains responsible for the disclosures and contractual roles described in those documents.
1. Purpose and update model
This is the document normally updated when a provider, cookie, local-storage key, pixel, SDK or similar technology is added, removed or replaced within a purpose and data category already disclosed in the stable legal documents. The date and affected row must be updated when a change takes effect.
The stable documents and user controls must also be reviewed before activating a materially new purpose, new data category, sensitive-data use, targeted advertising, session replay, customer-content training/fine-tuning or a new high-impact AI use. A Register update alone does not authorize such a change.
The entries below reflect the production environment and applicable provider configurations as of the review date.
2. Device technologies
| Identifier/provider | Category and purpose | Typical data | Duration | Runs before consent |
|---|---|---|---|---|
| Idelio consent record / idelio.pro | Strictly necessary; stores and proves privacy choices | categories chosen, timestamp, region and notice version | 6 months; renewed when preferences or applicable requirements change | Yes |
| Idelio attribution record (idelio_attribution sessionStorage) / idelio.pro | Functional; first-party campaign attribution recorded with a waitlist signup the visitor submits | utm_* and ad click identifiers from the entry URL, external referrer and entry path; no cross-site identifier | sessionStorage, cleared when the tab closes; stored with the signup record only if the visitor submits the waitlist form | Yes; first-party only, sets no cookie and transmits nothing unless the visitor submits the form |
| Idelio authentication and Google OAuth | Strictly necessary; sign-in, OAuth state and session security | account/session ID, OAuth state and authentication time | session; security and authentication tokens up to 30 days | Only when needed for requested sign-in |
| Paddle checkout | Strictly necessary; checkout, fraud, payment and subscription state | transaction/session ID, device and fraud signals | session; transaction, tax and fraud records under Paddle's legal and contractual schedules | Only when checkout is requested |
| Cloudflare | Strictly necessary; CDN, traffic security, bot and abuse protection | IP, device/browser and security signals | approximately 30 minutes for bot-management identifiers; up to 1 year for a security clearance where used | Yes, where strictly necessary |
| Plausible Insights | Analytics; audience, traffic, attribution and product measurement | URL/referrer, transient IP/User-Agent processing, event and campaign data | no persistent analytics cookie in the configured mode; event and aggregate retention under Idelio's analytics schedule | No in opt-in regions unless a documented exemption applies |
| Google Tag Manager / gtm on idelio.pro | Advertising infrastructure; tag container that loads and governs advertising and analytics tags | loads tags; sets no tracking cookie itself | not applicable (container only) | Container loads; every tag stays denied until consent (Consent Mode default: denied) |
| Google Analytics 4 with Google Signals and Google Ads linking | Advertising and analytics; measurement, remarketing, conversion and cross-device via Signals | IP, device/browser, event data, Google-account signals and advertising identifiers | Google advertising/analytics cookies up to 2 years; consent-gated | Cookieless measurement signals (no cookies or identifiers) before consent, for aggregate modeling only (Consent Mode); full analytics with storage after the analytics category is accepted; Signals and Google Ads features only after the advertising category is accepted |
| Meta pixel (Meta Platforms Ireland) | Advertising; conversion measurement and audience matching for Meta ads | IP, device/browser, event data, the _fbp cookie and hashed identifiers where applicable | _fbp cookie up to 3 months; consent-gated | No in opt-in regions until the advertising category is accepted |
| Sentry | Necessary security and error diagnostics | device/session, errors, URL and redacted diagnostic context | error-event data up to 90 days; session replay disabled | Only as strictly necessary for security and fault diagnosis |
| Support tool | Functional; user-requested support chat or widget | account/session, messages, attachments and device data | Not active until listed | No, unless strictly required for a requested support session |
| Advertising, audience and social-media tools | Advertising; conversion, retargeting, audience matching and cross-context activity | online identifiers, engagement, campaign and inferred interests | Not active until provider and duration are listed | No |
| Session replay | Advanced diagnostics; masked interaction reconstruction | interaction events and redacted/masked interface data | Off by default; not active until listed | No |
3. AI and content-processing providers
| Provider/service | Role and purpose | Typical data | Locations and transfers | Retention, review and training position |
|---|---|---|---|---|
| Anthropic | Processor/subprocessor; language generation | prompts, Output, request and safety metadata | United States and other documented service locations; SCCs/UK Addendum where required | May retain ordinary API content up to 30 days and flagged material longer; automated abuse monitoring and limited authorized review may occur; no general ZDR promise; shared-model training disabled where contractually available |
| Recraft | Processor/subprocessor; image and vector generation | prompts, uploads, Output and request metadata | United States and other documented provider locations; SCCs/UK Addendum where required | Temporary retention, automated abuse monitoring and exceptional authorized review may occur; no no-store or no-training promise applies unless stated in writing for the feature |
| Ideogram AI | Processor/subprocessor; image generation | prompts, uploads, Output and safety signals | United States and other documented provider locations; SCCs/UK Addendum where required | Temporary retention and longer retention or review of flagged content may occur; no general ZDR or no-training promise |
| Black Forest Labs / FLUX | Processor/subprocessor; image generation | prompts, uploads, Output and safety/usage data | United States, EEA and other documented provider locations; SCCs/UK Addendum where required | Production API route; temporary retention and safety review may occur; EAP or beta routes are not used for ordinary customer content |
| Google Gemini | Processor/subprocessor; language or multimodal generation | prompts, Output, files, request and security metadata | Google's documented service locations; SCCs/UK Addendum where required | Paid enterprise/API configuration; logging, abuse monitoring and flagged-content review may occur; no general ZDR promise |
| fal.ai | Processor/subprocessor and inference gateway | prompts, files, Output, CDN URLs and usage data | United States and other documented gateway or model-provider locations; SCCs/UK Addendum where required | File expiration and deletion are configured; gateway and underlying providers may perform logging, safety review and longer retention for flagged content |
| Replicate | Processor/subprocessor and model marketplace | prompts, files, Output, prediction logs and usage data | United States and other documented provider or model-owner locations; SCCs/UK Addendum where required | API route; prediction and file retention follow the configured plan, with longer safety, abuse or legal-hold exceptions and limited authorized review |
| Adobe Firefly | Processor/subprocessor; image generation and provenance | prompts, uploads, Output and provenance data | Adobe's documented service locations; SCCs/UK Addendum where required | Enterprise/API customer-content controls apply; provenance and Content Credentials are used where supported; safety and legal retention exceptions may apply |
Only providers actually enabled in production should remain in this section. Idelio may route requests among listed providers based on feature, availability, quality, safety, language, geography and cost. Unless a specific row expressly states otherwise, users must assume that provider-side automated abuse monitoring, limited authorized human review, temporary retention and longer retention of flagged or legally preserved content may occur.
4. Infrastructure and operational providers
| Provider/service | Role and purpose | Typical data | Locations and transfers | Retention/configuration |
|---|---|---|---|---|
| Paddle | Authorized reseller/Merchant of Record or payment provider as identified at checkout; may be an independent controller | identity, contact, transaction, tax location and fraud/device signals | Provider locations; own transfer safeguards | Transaction, tax and fraud retention under Paddle terms and applicable law |
| Google OAuth | Identity provider; processor/independent-controller allocation depends on service | OAuth ID, name, email, avatar and session/security data | Provider locations; own safeguards and SCCs where applicable | Minimum scopes only; no contacts or Drive access unless separately disclosed |
| Vercel | Subprocessor; web hosting, CDN and deployment | IP, request logs and application payload where routed | United States and other documented service locations; SCCs/UK Addendum where required | Logs up to 90 days; deployment content for the service term and secure deletion or backup rotation after removal |
| Railway | Subprocessor; application hosting | requests, application data and logs | United States and other documented service locations; SCCs/UK Addendum where required | Application data for the service term; logs and backups retained under the configured schedule and normally removed within 90 days after deletion |
| Neon | Subprocessor; database | account, project, Input, Output and operational data as architected | United States and EEA regions selected for the service; SCCs/UK Addendum where required | Data for the account or project term; deleted data and backups removed through the configured secure rotation, normally within 90 days |
| Cloudflare | Subprocessor and possible independent security processing; CDN, DNS and bot mitigation | IP, request, device and security data; potentially cached content | Global network subject to configured regions and safeguards | Cached content follows configured TTLs; security and access records are retained under the active product and plan, up to 12 months unless law or an incident requires longer |
| Upstash | Subprocessor; cache and queues | session, cache or job identifiers and limited payload | United States and EEA regions selected for the service; SCCs/UK Addendum where required | Cache and queue entries use a configured TTL not exceeding 30 days unless required for an active job; security/account logs follow provider schedules |
| ClickHouse Cloud | Subprocessor; analytics warehouse | product events, account/pseudonymous ID and performance data | United States or EEA region selected for the service; SCCs/UK Addendum where required | No prompt or Output fields; account-linked telemetry retained up to 24 months unless a shorter configured period applies |
| Temporal Cloud | Subprocessor; workflow orchestration | job identifiers/status and limited payload if required | United States or EEA region selected for the service; SCCs/UK Addendum where required | Customer content is minimized in workflow histories; completed workflow data retained up to 90 days unless a shorter configured period applies |
| Resend | Subprocessor; transactional and marketing email | email, message content and delivery/open/click metadata | United States and other documented service locations; SCCs/UK Addendum where required | Message and delivery logs retained up to 90 days; suppression, security and legal records may be kept longer; optional tracking is enabled only where lawful |
| Sentry | Subprocessor; error monitoring | device/session, errors, URLs and redacted diagnostic context | United States and other documented service locations; SCCs/UK Addendum where required | Content and personal data are redacted; session replay is disabled; error-event data retained up to 90 days |
5. Support, marketing and other recipients
| Provider category | Status and role | Typical data | Activation rule |
|---|---|---|---|
| Support/chat provider | Not enabled unless separately listed; usually processor/subprocessor | account, messages, attachments and session/device data | Identify provider, role, domain/SDK, DPA, region, retention and consent classification before activation |
| CRM, enrichment and purchased-lead providers | Not enabled unless separately listed; may be processor or independent controller | business contact, employer, professional profile, source, engagement and inferences | Verify lawful source/provenance, notice timing, opt-out/suppression, contract, role, location and retention before activation |
| Advertising, audience, retargeting and social providers | Not enabled unless separately listed; may involve sale/sharing/targeted advertising | online identifiers, device/network activity, campaign, engagement and inferred interests | Prior consent in opt-in regions; U.S. Privacy Choices and GPC where required; provider, pixel/SDK/domain, role and retention must be listed first |
| Professional advisers, auditors, insurers, authorities and transaction counterparties | Recipients as necessary for advice, compliance, claims, safety or a corporate transaction | only data reasonably necessary for the relevant matter | Confidentiality and legal-necessity controls; case-specific retention |
6. Change notices and contact
For a new Subprocessor that processes Customer Personal Data under the Data Processing Addendum, SFER LABS LLC will update this Register and provide the notice and objection period required by that Addendum to customers subscribed to change notices. Other routine Register changes take effect on the date stated in the affected row or revision history.
Register questions and change-notice subscriptions: [email protected].