Nocta.aiSTUDIO
PRODUCT
Try-OnShots & AnglesUpscale & EnhanceExplorePricingResources
LEGAL

Subprocessors

Third-party providers that process data on our behalf.

Last updated 28 July 2026
Provisional wording — final legal text requires review before launch. The contact, support, takedown, removal and appeal forms now send to an operations mailbox, but only where this deployment configures outgoing mail: each form states, after you submit, whether your request actually left the server, and issues a reference only when it did. Deleting an image from your Library Trash is the one erasure the product carries out itself; it never reaches the images generated from that asset, and the Privacy centre still simulates data export and account deletion without performing either.
Providers processing data on our behalf. Providers already in use are named; a row marked as pending is a category for which no provider has been selected.
PROVIDERPURPOSEDATALOCATIONTRANSFERSTATUSUPDATED
Google (Gemini image models)AI image generationUploaded images, generated assetsTo be documentedTo be documentedIn use — preview28 July 2026
StripePayments, subscriptions and billing portalBilling and transaction dataTo be documentedTo be documentedIn use — preview28 July 2026
Self-hosted object storage (MinIO)Private storage of uploaded and generated imagesUploaded images, generated assetsOur own infrastructureNo third-party transferSelf-hosted — not a third party28 July 2026
Self-hosted authentication (Auth.js)Sign-in and account security, with optional Google Sign-InAccount dataOur own infrastructureNo third-party transfer unless Google Sign-In is enabledSelf-hosted — Google Sign-In available as an option28 July 2026
Email providerTransactional emailEmail address, message contentPendingPendingPending selectionPending
Analytics providerUsage measurement, with consentUsage dataNot applicableNot applicableNone used today28 July 2026
ON THIS PAGE

About this list

Providers already used by the service are named above. A row still marked as pending is a category for which no provider has been selected and to which nothing is sent today.

Image generation runs on Google. When image generation is enabled, the images you upload — including photographs of real people — and the assets generated from them are sent to Google for processing. Google is the only image-generation provider this service supports.

Payments run on Stripe, using its hosted checkout and billing portal. Card details are entered on pages operated by Stripe and never reach our servers.

Uploaded and generated images are stored on S3-compatible object storage that we operate ourselves (MinIO). No third-party storage provider receives them. Sign-in and accounts are handled by our own servers; Google Sign-In is an optional provider that stays off unless it is configured.

No analytics or marketing tracker is loaded today, which is why that row names no provider.

What is still missing

The processing location and the applicable transfer mechanism are not yet documented for the named providers. Those cells state that openly rather than implying that nothing is transferred, and they must be completed before launch.

Keeping it current

This page must be updated whenever a provider is added, replaced or removed. The date above records the last change to this list.

Read the FAQ↑ Back to top