Skip to content

Subprocessors ​

Last updated: September 24, 2026

A subprocessor is an outside company that stores or processes customer data so that Scry can run. This page lists every one we use, what it gets, and where it runs. We built this list from our own code, not from memory. How we use the data is covered in the privacy policy.

Changes. We update this page before a new subprocessor starts receiving customer data. Customers with an agreement that names our subprocessors get an email at least 14 days before the change.

Infrastructure and storage ​

SubprocessorWhat we use it forData it receivesLocationTheir terms
Cloudflare, Inc.Runs our backend services (Workers): uploads, build processing, the Storybook viewer, the design-diff service, the MCP server and the feedback form. Stores Storybook builds and screenshots (R2) and service records (D1, KV, Queues). Receives mail sent to our support addresses and forwards it. DNS and network edge.Uploaded Storybook builds, story screenshots, Figma renders you sync, diff results and review decisions, encrypted Figma connection tokens, MCP sign-in tokens, feedback form answers, email sent to our support addressesUnited States (R2 storage, Eastern North America); Workers run on Cloudflare's global networkDPA · Subprocessors
Google LLC (Firebase Authentication, Cloud Firestore)Sign-in, and the database for accounts, organisations, projects, builds, API keys and links between Figma layers and storiesAccount name, email address and sign-in provider id; project, build and membership records; Figma link records (layer, page and file names, node id, story id and title, Storybook URL); product event countsUnited States (Firestore multi-region nam5)Data processing terms · Subprocessors
Google LLC (Gmail)Hosts the inbox that our support, feedback, privacy and security addresses forward toEmail you send to those addresses, and our repliesGoogle's global infrastructurePrivacy policy
Vercel Inc.Hosts the developer dashboard, the search API, this documentation site and scrymore.com. Vercel Web Analytics counts page views on the dashboard and scrymore.com.Everything the dashboard and search API handle, in transit; page views without cookiesUnited States (functions in Washington, D.C., iad1); static pages from Vercel's global edge networkDPA · Subprocessors
Zilliz, Inc. (Zilliz Cloud, managed Milvus)Search index for componentsText and image embeddings, generated component descriptions, story ids and titles, project idsUnited States (Google Cloud us-west1)Terms · Trust center · Subprocessors

AI and machine learning ​

We use these services to process data for you. None of them may train models on your data. We do not train models on your data either. See AI features in the privacy policy.

SubprocessorWhat we use it forData it receivesLocationTheir terms
OpenAI, L.L.C. (API)Writes a short description of each story screenshot when a Storybook is indexedStory screenshots and their file names, which are derived from story idsUnited StatesDPA · Subprocessors
Jina AI GmbH (Embeddings API; acquired by Elastic N.V. in October 2025)Turns screenshots, descriptions and search queries into embeddings for search and for matching Figma layers to storiesStory screenshots, generated descriptions, search query text (not stored by Scry), thumbnails of Figma layers when you run Suggest links. Jina's terms say it does not use customer inputs to train its models.Not published by Jina (Jina AI GmbH is in Berlin, Germany)Elastic customer DPA · Jina legal
OpenRouter, Inc.Routes design-diff requests to the model provider. Every request is sent with OpenRouter's data_collection: deny setting, so it is only routed to providers that do not collect the data. Prompt logging and training are turned off in our OpenRouter account, so it does not store prompts or responses; it keeps request metadata such as token counts.Figma and Storybook screenshots, the Figma layer structure, the rendered page structure (DOM) and implementation source used for the comparisonUnited StatesTerms · Privacy
Model providers reached through OpenRouter: OpenAI (GPT models) and Anthropic, PBC (Claude models)Run the design-diff modelsSame as OpenRouter, per request. So far every design-diff request has been served by OpenAI; for the Claude model we use, OpenRouter lists Anthropic as the only provider.United StatesOpenAI DPA · Anthropic commercial terms
Anthropic, PBC (API, direct)Fallback for design diff when OpenRouter is unavailable. Off in production.Same as OpenRouterUnited StatesCommercial terms
Google LLC (Gemini API)The MCP server's generate_image toolThe prompt and any reference images you send to that tool. We use paid-tier image models on a billing-enabled account, so Google does not use them to improve its products; it keeps them for a limited time to detect abuse.Any country where Google has facilities (Google's terms for the Gemini API)Gemini API terms · Data processing terms

Monitoring and analytics ​

SubprocessorWhat we use it forData it receivesLocationTheir terms
Functional Software, Inc. (Sentry)Error reports from the dashboard, search API, backend services and CLI. In the dashboard, a screen recording of a session that hit an error, with all text masked and all images and inputs blocked. Starting with the analytics release: error reports from the Scry Link Figma plugin.Scrubbed error reports and stack traces, app version, masked session replays (dashboard only). No API keys, no email addresses.United StatesDPA · Subprocessors
PostHog, Inc. (starting with the analytics release)Product analytics for the dashboard and the Figma plugin: which features are used, and where people get stuckA pseudonymous id (your Scry account id, or a one-way hash of your Figma user id), event names with counts and fixed categories, page paths without query strings, opaque project and organisation ids. No names, email addresses, file, layer or story names, design content or search text.United States (PostHog Cloud US)DPA · Subprocessors
Langfuse GmbH (Langfuse Cloud, part of ClickHouse) (starting with the AI telemetry release)Traces of our AI calls, so we can debug a bad result and measure how often people keep what the AI findsPrompts and model outputs for AI features, references to screenshots (not the images), pseudonymous user and project ids, promote and dismiss decisionsUnited States (Langfuse Cloud US)DPA · Subprocessors
Cloudflare, Inc. (AI Gateway) (starting with the AI telemetry release)Routes and meters our AI requestsRequests in transit. We turn off request and response logging, so prompts, images and outputs are not stored. It keeps one row per request: model, token counts, cost, duration, status, and tags for service, feature, project, user id and run id.Cloudflare's global networkCovered by the Cloudflare DPA above

Integrations you choose to connect ​

These companies receive data only when you connect them, and you can disconnect them.

SubprocessorWhat we use it forData it receivesLocationTheir terms
GitHub, Inc.Sign in with GitHub. The Scry GitHub App opens component-request issues in the repositories you choose.For sign-in, GitHub shares your name, email and avatar with us. For the App, we send the issue title, notes, requester display name and a signed link to the preview image.United StatesCustomer terms and DPA · Subprocessors
Figma, Inc.When you connect Figma to a project, we read the files and layers you link through Figma's API to compare them with your StorybookYour Figma access token (sent back to Figma), file keys and node ids we requestUnited StatesPrivacy

Not on this list ​

  • Your own services. In --local mode, the Scry CLI sends data straight to the OpenAI, Jina and Milvus accounts whose keys you pass. Scry never sees it. When the CLI posts a pull-request comment, it uses your repository's own GitHub token.
  • Your Storybook host. The Figma plugin loads your Storybook straight from the URL you enter.

Questions ​

Email privacy@scrymore.com.

Updated at: