Nibit Subprocessors

Version
2026-08-01
Permanent URL
/legal/subprocessors/2026-08-01

Effective date: 1 August 2026

Last reviewed: 1 August 2026

1. What this page is

A subprocessor is a third party that processes personal information on Nibit's behalf in order to operate the Services. This page lists them. It is referenced from Privacy Policy section 6.2, which explains the categories; this page carries the detail - what each provider does, where it processes data, what data it sees, and on what legal footing personal information reaches it.

Two things this page is not:

  • It is not a list of everyone Nibit does business with. Vendors that never touch user data - accounting software, for instance - are out of scope.
  • It is not a claim that Nibit has negotiated bespoke terms with each provider. The rows below are drawn from what the product actually calls at runtime, and each provider is engaged under its own published data processing terms, which Nibit accepts as part of its account. Where a row says a provider retains something for a period, that period comes from the provider's published terms.

2. Current subprocessors

ProviderWhat it does for NibitData it can processContracting entityProcessing regionRetention
RailwayApplication and service hostingAnything transiting or held by the application - account data, note content, attachments, logsRailway Corporation, a Delaware corporation (US)United StatesUntil deleted by Nibit; platform logs 30 days
NeonManaged PostgreSQL databaseAccount and profile records, notebooks, pages, metadata, collaboration and chat records, subscription stateA Databricks company (US) - see section 2.1United StatesUntil deleted by Nibit; backups on a rolling 35-day cycle
TigrisObject storageAttachments, images, thumbnails, recordings, exportsTigris Data, Inc., a Delaware corporation (US)United StatesUntil deleted by Nibit; orphaned objects collected within 7 days
CloudflareWeb delivery, workers, DNS, proxying, securityIP address, request metadata, user agent, and any content transiting the proxyCloudflare, Inc., a Delaware corporation (US)Global edge - served from the location nearest youLogs and security analytics up to 30 days
OpenAIAI features, transcription, text-to-speechPrompt and request content you submit to an AI feature, and generated outputOpenAI, L.L.C., a Delaware company (US)United StatesUp to 30 days for abuse monitoring, then deleted. Not used to train models - see section 3
StripePayment processing, subscription billing, taxName, email, billing address, payment method details (entered on Stripe's own pages and never on Nibit's servers), transaction history, subscription stateStripe, Inc., a Delaware corporation (US)United StatesPer Stripe's own retention duties as a regulated payment processor; Nibit's own billing records 7 years under tax law
ResendTransactional emailEmail address, message content, delivery eventsResend, Inc., a Delaware corporation (US)United StatesMessage content and delivery events 30 days
KlipyGIF and sticker searchSearch terms you type in the picker, and request metadataKIKLIKO, Inc., San Francisco, California (US)United StatesPer Klipy's own privacy policy - see section 4
Google (YouTube Data API)Video details for a YouTube link you importThe video identifier only - see section 5Google LLC, a Delaware company (US)United StatesPer the YouTube API Services Terms
SupadataTranscript of a YouTube video you importThe video identifier only - see section 5Dumpling Software UG, Berlin, GermanyEuropean UnionPer Supadata's own terms

Transfers. Nibit is established in the Netherlands, so every row in the table above except Supadata is a transfer of personal information out of the European Economic Area, and Chapter V of the GDPR governs each one. This is the part of the page that changed most when Nibit moved from the United States to the Netherlands: the infrastructure is in the same places it always was, but Nibit is now the exporter rather than the destination, and each provider needs a named safeguard rather than none.

The safeguard for every US provider above is the European Commission's standard contractual clauses, incorporated into that provider's published data processing terms, which Nibit accepts as part of its account. Where a provider is separately certified under the EU-US Data Privacy Framework, its certification supplies an adequacy basis that we may rely on as well; that is a per-company fact we check when taking a provider on and re-check when we review this page, and it never displaces the clauses underneath. For users in the United Kingdom, the international data transfer addendum applies alongside the clauses. Supadata is in Germany, so no transfer safeguard is needed for it, and Cloudflare serves from the edge nearest you before traffic reaches the rest of the stack.

If you are in India, your data is transferred to the Netherlands and the United States; the Digital Personal Data Protection Act permits this, as neither is a restricted country. Privacy Policy section 9 covers all of this in full, including what we do beyond the paperwork.

2.1 Transfer safeguard for each provider

Checked against the US Department of Commerce's Data Privacy Framework list on 17 August 2026. That list is the only authoritative source for this, and a provider's own claim to be "DPF compliant" is not a substitute for an entry on it.

ProviderEntity on the DPF listEU-US DPFUK ExtensionWhat carries the transfer
CloudflareCloudflare, Inc.ActiveActiveSCCs, with DPF adequacy available
GoogleGoogle LLCActiveActiveSCCs, with DPF adequacy available
RailwayRailway CorporationActive, re-certification under reviewActive, re-certification under reviewSCCs, with DPF adequacy available
ResendResendActive, re-certification under reviewActive, re-certification under reviewSCCs, with DPF adequacy available
NeonDatabricks, Inc., which lists "Neon, LLC" as a covered entityActive, re-certification under reviewActive, re-certification under reviewSCCs. See the note below before relying on the adequacy basis
OpenAINot listedNoneNoneSCCs alone
StripeTo completerun the DPF check for Stripe, Inc. at the next sweep, the same way as the rows above--SCCs, and Stripe acts as merchant of record for the sale itself
TigrisNot listedNoneNoneSCCs alone
KlipyNot listedNoneNoneSCCs alone

Three providers have no adequacy basis at all. OpenAI, Tigris, and Klipy do not appear on the list under any name, so the standard contractual clauses in their published terms are the only thing making those transfers lawful, together with the assessment described in Privacy Policy section 9. OpenAI is the provider that sees the substance of what you write, which makes it the one worth naming explicitly rather than leaving to be inferred from a table.

Re-certification under review is an active status. The Department of Commerce keeps an organisation on the active list while it reviews that organisation's annual re-certification, and the organisation may keep receiving data throughout. It is recorded here as it appears rather than flattened to "Active", because the two are not quite the same thing and the difference belongs to the reader rather than to us.

The Neon entity question. There are two separate records, and which one applies decides whether the adequacy basis exists:

  • Neon Inc., of Wilmington, Delaware, is listed as Inactive - Lapse on all three frameworks. Its own certification has expired.
  • Databricks, Inc. is active and names Neon, LLC among its covered entities.

Neon's platform terms now sit under the Databricks Master Cloud Services Agreement, which points to the second record, but the contracting entity is a matter of fact and not of inference.

To completeconfirm from the Neon account and its data processing terms which entity Nibit actually contracts with. If it is Neon Inc., there is no Data Privacy Framework basis for that transfer and the clauses carry it alone; if it is Neon, LLC, the Databricks certification supplies one. Correct the contracting entity in the table above once confirmed. The clauses apply either way, so this changes what we may additionally rely on and not whether the transfer is lawful.

Nothing above displaces the standard contractual clauses. Where a provider is certified, the certification is a second basis that sits on top of the clauses, and it never replaces them.

Payment provider. Nibit has not yet engaged a payment provider or merchant of record. When one is engaged it appears in the table above before it processes its first payment, not after - see Privacy Policy section 3.7 and Terms section 8.

3. AI processing, specifically

OpenAI is the one provider that sees the substance of what you write, and only when you use an AI feature. Under the API terms Nibit contracts on:

  • content submitted through the API is not used to train or improve OpenAI's models;
  • OpenAI may retain a request and its output for up to 30 days for abuse and misuse monitoring, then deletes it;
  • Nibit does not train any model of its own on your content.

The first two are OpenAI's published position for its API, set out in its data controls documentation. The terms Nibit contracts on are the OpenAI Services Agreement, and OpenAI's own handling of what it receives is governed by OpenAI's privacy policy.

We publish the 30-day window rather than claiming nothing is retained, because the second claim would be untrue. If Nibit moves to a zero-retention arrangement, this section changes before the architecture does.

What runs where. Nibit uses OpenAI's text models for generation and for reading text out of images, PDFs, and slides you import, its speech-to-text model for voice notes, and its text-to-speech model for Read Aloud and podcast audio. Every one of them is covered by the terms above.

Swapping one OpenAI model for another does not change who receives your data, what they may do with it, or where it is processed, so it is not a subprocessor change and the 30 days' notice in section 7 does not apply to it. Changing provider is a subprocessor change, and the notice does apply.

4. The GIF picker, specifically

Klipy is an advertising-supported service, and its own privacy policy governs what it does with a request it receives. Nibit sends it the search term you type and standard request metadata. Nibit does not send your account identity, your email address, or the contents of your notes, and Nibit does not run Klipy's advertising units inside the Services.

This is the one provider in the table whose own business model involves advertising. It is called out here rather than buried, because section 6 says Nibit has no advertising relationships, and the two statements need to sit next to each other to both be true.

5. The two providers that do not see who you are

Google's YouTube Data API and Supadata are contacted by Nibit's servers, not by your device. The request carries only the video identifier taken from the link you supplied. Your account identity, your email address, and your IP address are not sent to them.

This means those two providers can see that *someone* using Nibit imported a particular video. They cannot see that it was you.

6. Providers we do not use

To be explicit about the absences, because they are the kind of thing people reasonably assume:

  • No advertising networks, ad SDKs, or advertising pixels in the Services. Nibit does not run advertising and does not share data for cross-context behavioural advertising. Klipy's own service is ad-supported; section 4 explains exactly what it receives.
  • No session-replay or heatmap tools. Nothing records your screen or replays your session.
  • No third-party product analytics. This is true as of the last reviewed date at the top of this page. If analytics are ever added, the row appears in section 2 first, Privacy Policy section 3.5 is updated, and the tool is configured to exclude note content, note titles, and share URLs.

If any of these changes, this page changes first.

7. Notice of changes

We may add or replace a subprocessor as the Services change. When we do:

  • this page is updated and the "last reviewed" date at the top changes;
  • we give 30 days' notice on this page before a new subprocessor begins processing personal information, except where a provider must be replaced immediately to keep the Services running or secure - in which case we update this page as soon as we can and say why;
  • material additions - a new category of provider, or a provider in a new region - are also announced by in-product notice or email, as described in Terms section 18; and
  • where a data processing agreement gives you a right to object to a new subprocessor, that right applies.

8. Questions

Ask at privacy@nibit.ai. If you need the data processing terms or transfer documentation for a due-diligence review, say so and we will tell you what we can share.

Each published version of this list has a permanent, dated URL - for example, /legal/subprocessors/2026-08-01 - so a review carried out against a past version stays checkable.