Gemnd subprocessors
Status: draft — legal-owner-inputs development fixture; not for release
Effective date: {{owner:effective_date}}
Version: 2026-10-08.1
These are the companies selected to process personal data on our behalf to run Gemnd. This list forms part of our Privacy Policy. [counsel] A region is confirmed only by the applicable processing agreement and exact endpoint; owner and pending markers are development-only release inputs, not established locations.
AI providers
This is the selected processor list, not a statement that every pending route is ready for production. Gemnd is offered only in the United States; that service territory does not establish a processor's location. Provider nationality and headquarters are not evidence of where a request is processed.
[pending: before release, confirm an enforceable exclusion of China and Hong Kong for the full lifecycle of the selected media routes, including storage, support and external web or image grounding. Current OpenRouter credentials and regional catalogs do not establish US in-region availability for FLUX 3 Image or Grok Imagine Video 1.5 Lite. A global endpoint is not a no-China guarantee.]
The app lists these providers, with the same purposes, before it asks for your AI-processing consent. When the list changes, the app asks you again before any new processing.
| Processor | What it does for Gemnd | What it receives | Region |
|---|---|---|---|
| OpenRouter | Routing of companion replies, summaries, memory processing, text safety checks, and image and video generation | Conversation text, memories, persona text, look and selfie request text, reference portraits and generated media, sent to the providers in this table | {{owner:dpa_region_openrouter}} |
| Together AI | Hosts DeepSeek V4.1 Flash for companion replies, summaries and memory processing; hosts tev1-4b-experimental as a parallel text-safety hedge | Conversation text, memories and persona text for replies; messages, replies and request text for safety, through OpenRouter. Text routes require ZDR and data collection denied | {{owner:dpa_region_together_ai}} |
| TypeSafe | Jev 1.13 primary text content-safety and crisis checks | Your message with the reply before it, each sentence of a reply, companion persona text, and look and selfie requests, through OpenRouter. Text routes require ZDR and data collection denied | {{owner:dpa_region_typesafe}} |
| OpenAI | Image and video-frame content-safety checks (omni-moderation and GPT-5.4 mini) | Generated media with context text; no training, but abuse-monitoring logs may be retained up to 30 days | {{owner:dpa_region_openai}} |
| Deepgram | Speech recognition for dictation and calls when your iPhone can't recognize speech itself; voice synthesis for calls and read-aloud | Your voice when on-device recognition is unavailable; reply text to be spoken | {{owner:dpa_region_deepgram}} |
| Black Forest Labs, through OpenRouter | FLUX 3 Image at 2K for companion looks, expressions and selfies | Look and selfie request text and the companion's reference portrait. OpenRouter records 30-day retention. [pending: exact endpoint retention, written no-training confirmation and grounding controls] | [pending: exact processing route and full-lifecycle no-China/Hong-Kong commitment] |
| xAI, through OpenRouter | Grok Imagine Video 1.5 Lite video generation for companion animations, custom expressions and video selfies | Video request text and the companion's reference frame. Asynchronous video output is retained briefly, so this is not a ZDR route. [pending: exact retention period and no-training confirmation] | [pending: exact processing route and full-lifecycle no-China/Hong-Kong commitment] |
DeepSeek supplies the model weights used by Together AI; Gemnd does not send requests to DeepSeek's own service. Text no-training and ZDR requirements do not establish geography and do not make the image or video routes zero-retention eligible.
Infrastructure and other services
| Processor | What it does for Gemnd | What it receives | Region |
|---|---|---|---|
| Google Cloud | Hosting, databases, caching, secrets, encryption keys, logging and monitoring | All account and conversation data, stored and processed for us | {{owner:hosting_region}} |
| Self-hosted E5 embedding model | Computes numerical search data for memories on our own servers; the local development host is the labelled d2-embedding-host fixture | Memory text processed in our hosting environment, not sent to an external embedding provider | {{owner:hosting_region}} |
| Cloudflare | Storage of generated avatar images and videos; domain name records (app traffic does not pass through Cloudflare) | Generated avatar media | {{owner:dpa_region_cloudflare}} |
| {{owner:call_media_provider}} | Real-time audio for calls | Call audio while a call is active | {{owner:dpa_region_call_media}} |
| Serper | Web search when your companion looks something up | The search the companion writes, which can reflect your conversation | {{owner:dpa_region_serper}} |
| {{owner:email_delivery_provider}} | Sign-in codes, deletion confirmations and other account email | Your email address and the message | {{owner:dpa_region_email_delivery}} |
| Sentry (Functional Software, Inc.) {{owner:crash_reporting_vendor_confirmed}} | Error and crash diagnostics, and app performance timings | From the app: device, OS and app version, stack traces, whether each app session ended in a crash, and how long app start, replies, call connection and media delivery took (timings and outcomes only, with no message text or identifiers), none of it linked to your account. From our servers: the service, failure category, release, request timings and filtered diagnostic events, and a keyed hash of your account ID, with no message text, request bodies or email | {{owner:dpa_region_sentry}} |
| {{owner:support_mailbox_provider}} | The support mailbox | Messages you send to support | {{owner:dpa_region_support_mailbox}} |
Payments
Purchases in the iOS app are made through Apple's App Store. Apple processes the payment under its own terms and privacy policy, and we receive the purchase records we need to give you your plan. [counsel: Apple's role as an independent controller]
Changes
We update this page before a new processor starts handling personal data. [counsel: notice period and how users are told]