Subprocessors
Last updated · August 21, 2026
These are the third parties Dubsmith engages to run the service. Each is bound by a written contract limiting it to our instructions, requiring appropriate security, and prohibiting use of your content for its own model training. This page is the list referenced by the Privacy Policy and the Data Processing Addendum.
Platform and business operations
These providers handle your account, the application itself, billing, and email.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Convex | Application database, authentication records, review state | Account records, project and job metadata, transcripts and translations | United States |
| Cloudflare | Website and application hosting (Workers), media object storage (R2) | Uploaded source media, rendered deliverables, request metadata | Global edge network; object storage in the configured R2 location |
| Amazon Web Services | Media processing pipeline — API compute, container workloads, transient working storage, job queues | Working copies of media and derived artefacts for the duration of a job | United States and other AWS regions used by the pipeline |
| Stripe | Payment processing, subscription and usage billing | Billing contact details, transaction and metered-usage records. Card details go to Stripe directly and never reach our servers. | United States, Ireland |
| Resend | Transactional email (sign-in, password reset, job notifications) | Email address, name, message content | United States |
Media processing
These providers perform steps of the localization pipeline and see the media itself. Each receives only what its step requires, for the duration of that step.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Google (Gemini, Video Intelligence) | Transcription, translation, emotion and on-screen-text analysis; frame-accurate text tracking | Source audio and video frames, and the text derived from them | United States |
| Fish Audio | Speech synthesis (default voice provider) | Translated text segments and, where voice matching is used, reference audio of the speaker | United States |
| MiniMax | Speech synthesis for Chinese, Japanese and Korean | Translated text segments and reference audio where voice matching is used | Singapore, United States |
| ElevenLabs | Speech synthesis, voice cloning and premium English voices | Translated text segments and reference audio of the speaker being cloned | United States |
| fal.ai | Lip-sync rendering | Video segments containing faces, and the generated dub audio | United States |
| RunPod | On-screen text removal / video inpainting (default) | Video segments and the removal masks derived from them | United States, European Union |
| Replicate | On-screen text removal / video inpainting (legacy path) | Video segments and the removal masks derived from them | United States |
Voice providers. Which speech provider handles a job depends on the target language and the voice mode you choose, so a given job will normally involve one of them rather than all three. Where you use voice matching or cloning, the provider receives reference audio of the speaker — see the consent requirements in the Acceptable Use Policy.
Changes to this list
Before a new subprocessor begins processing customer personal data, we update this page and give business customers at least 15 days’ notice by email to the address on the account. Customers under the Data Processing Addendum may object on reasonable data-protection grounds within that window; the process and remedy are set out there.
To be notified of changes, or to ask about a specific provider, email contact@dubsmith.io.

