Legal review required. These documents describe the current implementation and require review by a qualified lawyer. Deployment-specific provider terms and the signed customer agreement must also be checked; this page is not legal advice.
Providers used depend on the deployment and enabled features. Listing an optional provider does not mean it processes every visitor's data. Confirm the active providers, agreements, regions and retention terms before connecting real customer data. This register does not assert that every listed contract is signed.
| Sub-processor | Purpose | What it may see | Region |
|---|---|---|---|
| Meta (Muse) | Streaming speech recognition when selected as primary | Microphone audio and transcription context | Confirm selected service terms and region before rollout |
| Soniox | Streaming speech recognition; fallback when Meta is selected | Microphone audio and transcription context | Confirm selected service terms and region before rollout |
| Inworld | Streaming text-to-speech in the voice-agent release | Text to be spoken; does not receive the microphone stream from Culvion | Confirm selected service terms and region before rollout |
| Groq / selected upstream model provider | Language-model inference when routed there | Conversation text, which can include details supplied by the caller | Confirm the active route and provider region |
| OpenRouter | Language-model routing for voice and chat when configured | Conversation text and transcript; caller-provided personal details may be included | Confirm routing and upstream-provider regions |
| WorkOS (when enabled) | Authentication and SSO for customer admins | Admin identity, SSO assertions | Confirm service configuration |
| Resend (when enabled) | Transactional email and enquiry notifications | Recipient address and message body, including enquiry details | Confirm service terms |
| Cloudflare (when enabled) | Edge protection and CAPTCHA | Request metadata (IP, headers), CAPTCHA tokens | Global edge; confirm configured services |
| Neon (optional hosted database) | Managed Postgres instead of a self-hosted database | Structured data, with designated sensitive fields encrypted | Confirm selected region; not used by every deployment |
| Upstash (optional hosted cache) | Managed Redis instead of a self-hosted cache | Rate-limit counters, short-lived chat history | Confirm selected region; not used by every deployment |
The standard VPS stack uses self-hosted Postgres and Redis. Per-record AWS KMS key management is not implemented in the current application and is not presented as an active data-protection control.
Zero-retention terms
Sending less data is not the same as zero retention. Retention, training use, deletion options and any zero-retention entitlement depend on the provider, plan and selected route. They must be verified against the applicable terms; this website does not guarantee zero retention or no-training across all providers.
Deletion
Verified erasure clears covered fields in the live application, subject to retention and legal holds. Backups have a separate expiry and restore-reconciliation process. The current application logs external provider-deletion intent only; any provider request and its completion must be handled and verified separately. We do not claim that local erasure has deleted a provider's copy.
Questions
security@culvion.ai
Last updated: 5 October 2026.
