#Current subprocessors
| Subprocessor | What they do | Where (data residency) | Data they see |
|---|---|---|---|
| Anthropic | LLM inference (Claude models) | US | Persona system prompt + your idea_text (when you pick a Claude model) |
| OpenRouter | LLM routing gateway for GPT-family models and as a fallback route for some providers | US (routes onward to the underlying model vendor, e.g. OpenAI) | Persona system prompt + your idea_text (when you pick a GPT model, or when we route a provider call through OpenRouter) |
| Google AI Studio | LLM inference (Gemini models) and text embeddings for simulation retrieval | US | Same as Anthropic when you pick a Gemini model. Embeddings: idea_text and persona reactions, computed for every simulation |
| Together AI | LLM inference (open-weight catalog: Llama, DeepSeek, Qwen, Mistral, Kimi) | US | Same as Anthropic (when you pick a Together-hosted model) |
| Groq | LLM inference (Llama 4 Scout, Qwen 3) + the automated pre-run safety classifier | US | Your idea_text / debate topic passes through Groq's safety classifier before every run, regardless of which model you picked |
| xAI | LLM inference (Grok models) | US | Same as Anthropic (when you pick a Grok model) |
| Cartesia | Text-to-speech, and speech-to-text for Interview Mode | US | Both directions of a voice interview. Outbound: the text of every question the panel asks. Inbound: your raw microphone audio, streamed live from your browser while a voice interview is open, and the transcript returned from it. Also: full debate turn text when voice is enabled on a debate |
| Cloudflare | DNS, CDN, edge TLS, R2 object storage | Global edge; R2 "auto" region | Request metadata. R2 holds: voice-debate audio files (publicly addressable when you share a debate), daily database backups (7-day retention), and opt-in training archives (feature currently disabled) |
| Resend | Transactional email (account verification, password reset, invites, sim/debate notifications, billing alerts) and product and marketing email | US | Recipient email + name + email body (may include sim/debate titles and verdict summaries) |
| Mailstrel | Sending our individual business emails to prospective customers | Varies | A prospect's name, work email and company. No customer data |
| Stripe | Payment processing, tax, invoicing, Customer Portal | Stripe global (primary US) | Card details, billing address, transaction history |
| GitHub | Kranth GitHub App (PR-as-simulation) + GitHub sign-in | GitHub global | App: webhook payloads (PR title/body/branch metadata) for repos you install it on. PR content becomes idea_text and flows to your chosen LLM vendor. Sign-in: your GitHub account id + email |
| Google sign-in (OAuth) | US | Your Google account id + email (only if you sign in with Google) | |
| Telegram | Notification delivery via @kranthaibot (only if you connect it) | Varies (UAE/NL) | Notification payloads: sim/debate title, score, link; your Telegram chat id |
| Slack | Notification delivery + workspace connect (only if you connect it) | US | Notification payloads (as Telegram); your workspace id + name. We store no Slack bot token |
| Discord | Webhook notification delivery (only if you connect it) | US | Notification payloads (as Telegram) |
| Linear | Debate-from-comment integration (only if you connect it) | US | Issue titles + comment text you trigger debates from (flows to your chosen LLM vendor); verdict comments posted back |
| Vylth Nexus | Single sign-on identity provider (separate company; arm's-length vendor) | EU | Email, name, account id |
| DiceBear | Avatar rendering | EU (Germany) | An anonymized avatar seed (never your email or name) |
| Contabo GmbH | Cloud infrastructure hosting (compute, databases, storage) | EU (Germany) | All operational data |
| Google Ads | Conversion measurement on the marketing site | US / Google global | Visitor IP, cookie / gclid, conversion events (signup, first sim) |
| Microsoft Advertising | Bing UET conversion measurement on the marketing site | US / Microsoft global | Visitor IP, cookie, conversion events |
| X (Twitter) | Conversion pixel on the marketing site | US | Visitor IP, cookie, conversion events |
#Voice interviews, specifically
This is called out separately because it is the most sensitive data Kranth handles and a table row does not do it justice.
When you run Interview Mode in voice, your browser opens a direct connection to Cartesia and streams your microphone audio to them for transcription while the room is open. That audio is not routed through Kranth's servers; it goes from your machine to theirs, but Cartesia is our subprocessor for it either way, and you should know it leaves your device.
- The microphone is open for the whole session, not only while you are speaking. That is what lets you interrupt a panelist mid-sentence.
- Kranth does not record your audio. The transcript is stored; the recording is not made in the first place. See the Retention policy.
- Your spoken words become the interview transcript, which is stored, scored by the evasion judge, and included in the report you download.
- Text mode sends Cartesia nothing inbound. If you would rather not stream a microphone to a third party, choose Type when you start a session: the panel still speaks, and you answer in writing.
We previously used the browser's own speech recognition for this. In Chrome that sends your audio to Google, and in Firefox it does not exist at all. We moved to Cartesia deliberately: it is one vendor we already have an agreement with, rather than a second one you never agreed to, and it removed Google from the path entirely.
#On-prem / Enterprise
Enterprise customers can opt to run their own Ollama on their own infrastructure. In that mode, no third-party LLM subprocessor is involved: your prompt + idea_text stay inside your perimeter. The Groq safety classifier still runs unless your contract says otherwise.
#How we vet subprocessors
- Each subprocessor has its own privacy + security posture published; we link to theirs from contractual reviews internally.
- We sign DPAs (or equivalent Data Processing Agreements / Standard Contractual Clauses) with every subprocessor that handles personal data of EU residents.
- We review the list at least quarterly.
#Notice of changes
- New subprocessor added: 30 days email notice to account owners.
- Subprocessor removed: this page updated; no email needed.
- Material change in what an existing subprocessor does (e.g., they start training on data): 30 days email notice.
You can object to a new subprocessor by emailing [email protected] within the notice window. Objections result in either (a) us not using that subprocessor for your account, where technically feasible, or (b) you getting a refund for the remainder of your subscription term.
#Contact
[email protected] for subprocessor questions.
Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States