Legal

Subprocessors

Last updated: September 26, 2026. We commit to giving 30 days notice via email before adding a new subprocessor that processes personal data.5 min readKranth AI, Inc.

#Current subprocessors

SubprocessorWhat they doWhere (data residency)Data they see
AnthropicLLM inference (Claude models)USPersona system prompt + your idea_text (when you pick a Claude model)
OpenRouterLLM routing gateway for GPT-family models and as a fallback route for some providersUS (routes onward to the underlying model vendor, e.g. OpenAI)Persona system prompt + your idea_text (when you pick a GPT model, or when we route a provider call through OpenRouter)
Google AI StudioLLM inference (Gemini models) and text embeddings for simulation retrievalUSSame as Anthropic when you pick a Gemini model. Embeddings: idea_text and persona reactions, computed for every simulation
Together AILLM inference (open-weight catalog: Llama, DeepSeek, Qwen, Mistral, Kimi)USSame as Anthropic (when you pick a Together-hosted model)
GroqLLM inference (Llama 4 Scout, Qwen 3) + the automated pre-run safety classifierUSYour idea_text / debate topic passes through Groq's safety classifier before every run, regardless of which model you picked
xAILLM inference (Grok models)USSame as Anthropic (when you pick a Grok model)
CartesiaText-to-speech, and speech-to-text for Interview ModeUSBoth directions of a voice interview. Outbound: the text of every question the panel asks. Inbound: your raw microphone audio, streamed live from your browser while a voice interview is open, and the transcript returned from it. Also: full debate turn text when voice is enabled on a debate
CloudflareDNS, CDN, edge TLS, R2 object storageGlobal edge; R2 "auto" regionRequest metadata. R2 holds: voice-debate audio files (publicly addressable when you share a debate), daily database backups (7-day retention), and opt-in training archives (feature currently disabled)
ResendTransactional email (account verification, password reset, invites, sim/debate notifications, billing alerts) and product and marketing emailUSRecipient email + name + email body (may include sim/debate titles and verdict summaries)
MailstrelSending our individual business emails to prospective customersVariesA prospect's name, work email and company. No customer data
StripePayment processing, tax, invoicing, Customer PortalStripe global (primary US)Card details, billing address, transaction history
GitHubKranth GitHub App (PR-as-simulation) + GitHub sign-inGitHub globalApp: webhook payloads (PR title/body/branch metadata) for repos you install it on. PR content becomes idea_text and flows to your chosen LLM vendor. Sign-in: your GitHub account id + email
GoogleGoogle sign-in (OAuth)USYour Google account id + email (only if you sign in with Google)
TelegramNotification delivery via @kranthaibot (only if you connect it)Varies (UAE/NL)Notification payloads: sim/debate title, score, link; your Telegram chat id
SlackNotification delivery + workspace connect (only if you connect it)USNotification payloads (as Telegram); your workspace id + name. We store no Slack bot token
DiscordWebhook notification delivery (only if you connect it)USNotification payloads (as Telegram)
LinearDebate-from-comment integration (only if you connect it)USIssue titles + comment text you trigger debates from (flows to your chosen LLM vendor); verdict comments posted back
Vylth NexusSingle sign-on identity provider (separate company; arm's-length vendor)EUEmail, name, account id
DiceBearAvatar renderingEU (Germany)An anonymized avatar seed (never your email or name)
Contabo GmbHCloud infrastructure hosting (compute, databases, storage)EU (Germany)All operational data
Google AdsConversion measurement on the marketing siteUS / Google globalVisitor IP, cookie / gclid, conversion events (signup, first sim)
Microsoft AdvertisingBing UET conversion measurement on the marketing siteUS / Microsoft globalVisitor IP, cookie, conversion events
X (Twitter)Conversion pixel on the marketing siteUSVisitor IP, cookie, conversion events

#Voice interviews, specifically

This is called out separately because it is the most sensitive data Kranth handles and a table row does not do it justice.

When you run Interview Mode in voice, your browser opens a direct connection to Cartesia and streams your microphone audio to them for transcription while the room is open. That audio is not routed through Kranth's servers; it goes from your machine to theirs, but Cartesia is our subprocessor for it either way, and you should know it leaves your device.

  • The microphone is open for the whole session, not only while you are speaking. That is what lets you interrupt a panelist mid-sentence.
  • Kranth does not record your audio. The transcript is stored; the recording is not made in the first place. See the Retention policy.
  • Your spoken words become the interview transcript, which is stored, scored by the evasion judge, and included in the report you download.
  • Text mode sends Cartesia nothing inbound. If you would rather not stream a microphone to a third party, choose Type when you start a session: the panel still speaks, and you answer in writing.

We previously used the browser's own speech recognition for this. In Chrome that sends your audio to Google, and in Firefox it does not exist at all. We moved to Cartesia deliberately: it is one vendor we already have an agreement with, rather than a second one you never agreed to, and it removed Google from the path entirely.

#On-prem / Enterprise

Enterprise customers can opt to run their own Ollama on their own infrastructure. In that mode, no third-party LLM subprocessor is involved: your prompt + idea_text stay inside your perimeter. The Groq safety classifier still runs unless your contract says otherwise.

#How we vet subprocessors

  • Each subprocessor has its own privacy + security posture published; we link to theirs from contractual reviews internally.
  • We sign DPAs (or equivalent Data Processing Agreements / Standard Contractual Clauses) with every subprocessor that handles personal data of EU residents.
  • We review the list at least quarterly.

#Notice of changes

  • New subprocessor added: 30 days email notice to account owners.
  • Subprocessor removed: this page updated; no email needed.
  • Material change in what an existing subprocessor does (e.g., they start training on data): 30 days email notice.

You can object to a new subprocessor by emailing [email protected] within the notice window. Objections result in either (a) us not using that subprocessor for your account, where technically feasible, or (b) you getting a refund for the remainder of your subscription term.

#Contact

[email protected] for subprocessor questions.
Kranth AI, Inc., c/o Stable, 2810 N Church St STE 89663, Wilmington, DE 19802, United States

You read the whole thing. Most people don't. Thank you.

Questions about this document? [email protected] · Back to the top