Sub-Processors

Effective 2026-09-04. This list covers providers used by Krewva's iOS, macOS, and Windows applications and public website. The formal Privacy Policy controls if this list or the Trust Charter differs.

Current list version: 2026-09-04.

What this list means

A sub-processor or operational provider receives only the information needed for the service or feature you use. Provider handling can have its own terms and retention rules. Krewva does not promise zero provider retention and makes no promise of zero retention.

The consent contract is the same on iOS, macOS, and Windows. Screen access, feature enablement, AI-processing consent, Task acceptance, Step approval, and outbound action authority remain separate.

Current AI and speech providers

OpenAI

Current AI processing for enabled Krewva features. After feature enablement and AI-processing consent, bounded request data may pass through Krewva to OpenAI for visual or text processing. API data is not used for model training unless Krewva explicitly opts in; default abuse-monitoring logs may be kept for up to 30 days.

Draft a Reply may send one fresh image of the active window for reviewable suggestions. Do a Task visual discovery may send a separate fresh image of the active window for Task candidates only. Krewva does not send the local-OCR pixels on its local path.

OpenAI Voice Input

Speech processing for Voice Input during a user-started dictation. Krewva does not keep raw audio in local Voice Input history.

Infrastructure and website providers

Amazon Web Services

Backend compute, database, identity and authentication, credential encryption, notifications, and selected release storage. Krewva applies its account, audit, and consent rules to data stored there.

Cloudflare

Public website hosting, waitlist processing, KV storage, and rate limiting. Website form data is handled for the waitlist service, not for desktop screen processing.

Sentry — Functional Software, Inc.

Error and crash diagnostics. Raw image pixels are request scoped and excluded from ordinary logs, Sentry, and support bundles. Diagnostics may contain content-free request and failure metadata.

Stripe

Payment processing if you use a paid Krewva plan. Krewva does not store full payment-card numbers; Stripe receives the payment information needed to process the transaction.

Connected-account providers

If you connect an account, Krewva accesses the content and permissions that the provider makes available under the scopes you grant. This can include Google Workspace, Slack, Apple services, or another supported source. Those providers remain responsible for their own services and may have separate retention and revocation rules.

Screen-flow reminder

Do a Task local OCR tries semantic text first; if needed, bounded local OCR keeps raw pixels on the device and selected derived text may support a Task. Do a Task visual discovery is a separate enabled and AI-consented upload to OpenAI for Task candidates only. Task acceptance and Step approval remain separate. Capture is user-triggered, active-window only, not continuous, and the capture path must fail closed for denied, revoked, protected, or changed targets. Draft a Reply capture produces reviewable suggestions and never sends by itself.

Changes and questions

Krewva will update this page when the provider list changes. For questions about this list or your data, write to privacy@krewva.com. A person reads it.

For practical data controls and request options, see Your data. Your choices..