AI & sub-processor disclosure (DRAFT)
Draft for legal review — not legal advice. Last updated: 2026-07-15.
This document lists the third-party sub-processors that may process personal data on our behalf, what they receive, and data-residency notes. It supports the Privacy Policy and should be kept current as providers are enabled. A signed Data Processing Agreement (DPA) is required with each active sub-processor before launch.
1. Current status
The application is built against a provider abstraction with a mock fallback (no data leaves our systems if every configured provider is unavailable). As of this update, the following are live in production: DeepSeek for text generation and fal.ai for both professional and inspirational image generation. Anthropic, OpenAI, and Google are configured in the provider registry but are not the active choice right now; if that changes, update this table (see § 5). Donation links (§ 3) are handled separately — Craftale itself never touches that data.
2. Sub-processors
| Sub-processor | Purpose | Personal data it may receive | Status | Residency / safeguard |
|---|---|---|---|---|
| Contabo | Hosting — runs the app, database, and file storage | All stored data (encrypted at rest where available) | Active | Germany (EU) — confirm data-centre location and DPA terms directly with Contabo |
| DeepSeek | AI text generation (titles, descriptions, SEO, hashtags) | Brand/item text you submit (never photos) | Active — current primary text provider | China-based; no EU adequacy decision. SCCs alone may not be sufficient given China's data-access regime — this needs a proper transfer-impact assessment, not just a standard clause, before relying on it at real scale. Flagged for priority counsel review. |
| fal.ai | AI image generation — professional staged product photos and inspirational images | Brand/item text; uploaded item photos (for professional staging) | Active — current image provider (currently routing professional shots through a Bytedance Seedream model and inspirational images through Flux Schnell; the exact underlying model can change without notice — confirm current models in /admin/settings when this matters) |
Confirm fal.ai's data-residency/DPA terms and which region their inference runs in |
| Anthropic (Claude) | AI text generation | Brand/item text you submit (no photos) | Configured but not currently active in production | US-based → SCCs; DPA required before enabling |
| OpenAI | AI text/image generation | Brand/item text; uploaded item photos if used for images | Configured but not currently active in production | US-based → SCCs; DPA required before enabling |
| Google (Gemini / Imagen) | AI text/image generation | Brand/item text; uploaded item photos if used for images | Configured but not currently active in production | Review EU options; DPA + SCCs before enabling |
| Stripe | Payments — in-app subscription checkout, once paid plans are enabled | Billing/contact data; card data handled by Stripe (we don't store it) | Sandbox/test mode — not processing real transactions while subscriptions are off during the donation pilot | DPA in place via Stripe; PCI-DSS |
| Google / Meta (OAuth) | Optional social sign-in | Basic profile (email, name) when the user chooses it | Dormant — not configured | Per provider terms if enabled |
Notes: text-only providers (Anthropic, DeepSeek) never receive uploaded photos — only image-capable providers (fal.ai, OpenAI, Gemini) do, and only for photo generation.
3. Donation links (not sub-processors)
The Support page currently links to Stripe Payment Links (donate.stripe.com) and Ko-fi (ko-fi.com/julienika) for one-off donations. These are plain outbound hyperlinks, admin-configured — clicking one takes you off Craftale entirely to that service's own site, where you transact directly with them, under their terms and privacy policy. Craftale's server never calls their APIs and never receives your payment or contact details from a donation. For that reason these are not Craftale's GDPR sub-processors in the same sense as the table above (we don't send them data on your behalf) — they're independent controllers for whatever data you choose to give them directly. The Privacy Policy discloses this relationship; it should still be reviewed by counsel, since the "independent controller via outbound link" characterisation is the Company's own analysis of how these specific integrations work, not a certified legal conclusion.
4. Data-residency guidance
- Prefer EU-region endpoints for hosting and, where offered, for AI providers.
- For US-based providers, rely on EU Standard Contractual Clauses and any provider EU-data-processing addendum; document the transfer basis.
- DeepSeek specifically needs more than a standard SCC checkbox — China does not have an EU adequacy decision, and a genuine transfer-impact assessment (considering local government data-access powers) is the kind of thing that should happen before this provider is relied on for real user data at any meaningful scale. This is the single most important open item in this document.
- Record each provider's sub-processor list, retention, and training-use terms (confirm content is not used to train their models beyond producing your results) — DeepSeek's and fal.ai's current terms have not yet been reviewed for this.
5. Change management
- Update this table whenever a provider is enabled/disabled or a model changes
— the admin AI-settings page (
/admin/settings) is the live source of truth for exactly which provider/model is active at any moment; this document is a point-in-time snapshot of it, not a substitute for checking it. - Notify users of new sub-processors that materially change data handling, as required by the Privacy Policy and DPAs.
- Keep a Record of Processing Activities (RoPA) and a data-breach procedure (out of scope for this draft — set up before launch).
Content-complete. Still have counsel review — with the DeepSeek transfer-impact question as the priority item, and the "donation links are not sub-processors" characterisation in § 3 as the second — before treating this as binding. See the README.