Yapr
← Back to Yapr

Legal

Sub-processors

Every third-party service that can touch user data in Standard mode, what it does, and the safeguards on each. In Strict mode, none of them are contacted.

Last updated16 July 2026
Strict modeNo processors contacted

This page lists the third-party sub-processors Yapr uses in Standard mode to provide translation and voice features. Our Privacy Policy §12 points here, and we keep this register and that section in sync.

In Strict mode, none of these processors are contacted — the conversation never leaves your device. We share only the minimum necessary with each processor, who acts on our instructions under a Data Processing Agreement, and we use no-training / no-retention settings where the provider offers them.

Core service processors

Sub-processor Purpose Data shared Location Transfer mechanism (EU/UK/CH → US)
ElevenLabs Voice cloning; and in cloned-voice conversations: speech-to-text, translation orchestration, and text-to-speech in your voice (one connection) Enrollment samples (transient), conversation audio (transient), your voice ID / voiceprint (biometric) United States EU–US Data Privacy Framework (incl. UK Extension & Swiss) [reverify "Active" at signing]
OpenAI Speech-to-text + translation (Speed/system-voice and Rooms paths; also the translation step inside cloned-voice conversations) Conversation audio / text (transient; processed, not stored by us); no-train settings where available United States [DPF or SCCs + Transfer Impact Assessment — verify DPF cert]
Anthropic (Claude) Translation (fallback for some languages) Text to translate (transient) United States [DPF or SCCs + Transfer Impact Assessment — verify DPF cert]
Supabase Authentication, database, file storage, backend functions (hosting/infra); ephemeral Rooms session signaling (setup only — Rooms call media travels peer-to-peer, or via the Cloudflare TURN relay below when the two phones are on different networks) Account identity + service metadata (no conversation content) [US, or EEA region — hosting-region decision pending] SCCs [or no transfer if moved to an EEA region]
Cloudflare, Inc. Network relay (TURN) for cross-network Rooms calls — relays end-to-end DTLS-SRTP-encrypted call media it cannot read, and processes IP/connection metadata IP / connection metadata; encrypted call media (unreadable to Cloudflare) United States DPA + EU–US Data Privacy Framework / SCCs

Authentication, billing & diagnostics

Sub-processor Purpose Data shared Location Transfer mechanism
Google Sign-In Authentication (if you choose it) Per Google's authentication flow United States Per Google's authentication terms
Resend (if email-code sign-in is enabled) Sign-in email delivery (one-time codes) — active only if email-code sign-in is enabled Email address + sign-in codes United States DPA + Data Privacy Framework certified
RevenueCat (if adopted) Purchase / subscription management Purchase tokens + entitlements (no conversation data) United States [DPF or SCCs — verify if adopted]
Sentry (if adopted, with your consent) Crash diagnostics PII-scrubbed crash reports United States [DPF or SCCs — verify if adopted]

How transfers are protected

Yapr's processors operate primarily in the United States. For personal data transferred from the EU/EEA, UK, or Switzerland, we rely — in order of preference — on the EU–US Data Privacy Framework (and its UK Extension / Swiss counterpart) where the processor holds an active certification, otherwise on Standard Contractual Clauses plus a documented Transfer Impact Assessment. Full detail is in our Privacy Policy §12.

Changes to this list

We update this register when we add, remove, or materially change a sub-processor. Material changes are also reflected in the Privacy Policy.

See also our Privacy Policy, Terms of Service, and Biometric Data Schedule. Questions: privacy@yap-r.com.