Subprocessors
Last updated: July 30, 2026. This revision is effective immediately.
Introduction
A “subprocessor” is a third-party service provider that Brilliant Design Ltd. engages to process Customer Data on our behalf in the course of providing the App. This page is the living list of those subprocessors, and it is incorporated by reference into our Data Processing Addendum as Schedule 3. We update this page whenever we add, remove, or change a subprocessor, and we notify Team Admins by email at least 30 days before adding or replacing a subprocessor that processes Customer Data.
“Customer Data” has the meaning given to it in our DPA. It does not include aggregated and anonymized Service Data derived from use of the App, which is addressed separately in the DPA.
Current subprocessors
| Subprocessor | Role | Location | Links |
|---|---|---|---|
| Google Cloud Platform | Application hosting (Cloud Run) for the Brilliant back-end, which handles authentication, account and team management, usage metering, request routing, and the Brilliant Platform (profiles, project and drop hosting, git hosting). Object storage (Cloud Storage) for Platform content: published project repositories and their version history in a private bucket served through our back-end, user avatars in a media bucket, and desktop App installer files in a private downloads bucket served via time-limited signed links. Realtime collaboration runs on Google Compute Engine. | United States (us-central1) | Privacy · DPA |
| MongoDB (Atlas) | Primary database for user accounts, teams, seat assignments, subscription state, AI usage metering records, and Platform metadata: profiles (handle, display name, bio, links), project and drop records, checkpoint metadata, stars, follows, web sessions (hashed session identifiers with IP address and user agent), handle history, Figma integration tokens, and analytics events. Project files are stored in Google Cloud Storage rather than MongoDB, with one exception: the bytes of font files embedded in a project are stored in MongoDB. | United States (Google Cloud us-central1, Council Bluffs, Iowa) | Privacy · DPA |
| Resend | Transactional email delivery: sign-in codes (for the App, the Platform web sign-in and the CLI), welcome emails, project collaborator invitations, team invitations, and administrative notifications. | United States | Privacy · DPA |
| Paddle | Merchant of record and payment processing for paid subscriptions and Team plans. Paddle collects billing details and handles taxes; Brilliant does not receive or store full payment card numbers. | Global (per Paddle's data processing locations) | Privacy · DPA |
| Amazon Web Services (S3) | Storage and delivery of signed download links for the desktop App installer (fallback lane; Google Cloud Storage is preferred when available). Processes the IP address of the device that requests a download. | European Union (AWS eu-north-1, Stockholm) | Privacy · DPA |
| Netlify | Hosting for our public status page at status.brilliant.design. Processes request logs and visitor IP addresses for that page. The website at brilliant.design, including the Platform's web pages (profile pages, project pages and the web editor) and project content, is served from Google Cloud. | Global (CDN) | Privacy · DPA |
| Google (Google Analytics) | Aggregated, anonymized website analytics for the marketing website (brilliant.design). Loaded only after user consent via our cookie banner (see our Cookie Preferences). | Global | Privacy · DPA |
| Figma | Optional integration. If you choose to connect Figma, we store the read-only access and refresh tokens Figma issues on our servers, and use them solely to retrieve the files you select from Figma's API. You can revoke the connection at any time from your Figma account. | Global | Privacy · DPA |
A note on AI providers
The App integrates with third-party AI providers (including Anthropic, OpenAI, and Google) under the “Bring Your Own Key” (BYOK) model described in our Terms of Use. When you use BYOK, your Inputs are transmitted directly from your device to the provider you selected, using your own credentials. Those providers are not subprocessors of Brilliant: you have a direct relationship with them, and their own terms and privacy policies apply. Brilliant does not route, store, or process the content of BYOK interactions.
Other third-party services that are not subprocessors
For completeness, a few services interact with your browser or our servers without processing Customer Data on our behalf:
- Google Sign-In. If you choose to sign in with Google, Google processes that sign-in under its own privacy policy and sends us your email address, name and profile picture. We re-host the picture on our own storage rather than linking to Google's.
- Google Fonts and the renderer engine. When the web editor needs a design font that is not bundled, our server fetches the font file from Google Fonts and serves it to you, so that request comes from our server rather than your browser. Two requests do go directly from your browser to Google: a page that renders a design loads the renderer engine from www.gstatic.com and the renderer's default typeface from fonts.gstatic.com, and it may request further typefaces from fonts.gstatic.com for font families or characters it does not already have. Google receives your IP address and user agent for those requests and processes them under its own privacy policy. The fonts on our other web pages are served from our own servers. The desktop App may fetch fonts from Google Fonts directly from your device.
- Paddle checkout script and Cal.com. The pricing page loads Paddle's checkout script (Paddle is listed above as merchant of record), and the demo-booking page embeds Cal.com's scheduler. Both load in your browser and operate under their own privacy policies.
Notice of changes
We notify Team Admins by email at least 30 days before adding a new subprocessor that processes Customer Data. Team Admins may object to a new subprocessor during that notice period by emailing legal@brilliant.design.
Contact
Questions about this list? Email legal@brilliant.design.