Demo Pine is operated by RyanTech LLC, a South Carolina limited liability company doing business as "Demo Pine" and "DemoPine" ("Demo Pine", "we", "us", "our").
This page is the current list of the third parties that process Customer Content on your behalf, the categories of data each one receives, and where each one processes it. It is the list referred to in Section 16.1 of our Terms of Service and it is the same list as Section 8 of our Privacy Policy. If the two ever disagree, tell us at [email protected] and we will correct whichever is wrong.
This page does not create or reduce any right. The operative commitments are Sections 16.1–16.4 of the Terms and our Data Processing Addendum, which is incorporated into the Terms and applies without signature. This page states how we perform them.
1. What a sub-processor is here
1.1 Definition. A sub-processor is a third party we engage to process Customer Content on your behalf (Terms, Section 2). Customer Content is everything you or your Members put into the Service or that the Service captures at your direction — screenshots, screen recordings, tab audio, HTML captures of pages, click data, step text, overlay copy, logos, brand kits, demo settings, uploaded files, imported bundles, and anything a demo viewer submits to a lead-capture form on your demo.
1.2 Your authorization. You give us general written authorization to engage the sub-processors on this list (Terms, Section 16.2). We remain responsible for their performance of our obligations under the Terms and the DPA.
1.3 The written terms behind each one. Each provider in Section 2 is bound by a written agreement that limits it to processing personal data on our documented instructions, imposes confidentiality, and requires appropriate security measures. Where a provider offers a data processing addendum, we are on it.
1.4 Two roles, two tables. Some providers do not act on our instructions for everything they do. Stripe and Google determine their own purposes for at least part of their processing, so they are independent controllers for that part and appear separately in Section 4. We cannot instruct them about it, and requests concerning that processing must go to them.
1.5 Scope note. Every provider in Section 2 also handles some data for which we are the controller — your account, your sign-in sessions, and our billing and diagnostic records. We list them once, with the full set of categories each receives, rather than splitting each entity across two tables.
2. Sub-processors that process Customer Content
| Legal entity | Service provided | Data categories received | Processing location |
|---|---|---|---|
| Fly.io, Inc. | Application hosting for app.demopine.com — the application server and the retention worker. All server-side processing runs here, including the brand scanner's outbound fetches | All request data in transit: credentials in transit, demo content and structured demo data, uploaded media on the paths that pass through the server, lead-capture submissions, SAML assertions, SCIM directory payloads, AI prompt text on its way to our model provider, and our application error and diagnostic logs (which can contain email addresses). Fly's own request logs contain client IP addresses | United States. Our Fly application's primary region is iad (Ashburn, Virginia). We have not provisioned machines in any other region |
| Neon, Inc. | Managed PostgreSQL database | Account records (name, email, salted scrypt password hash, profile image URL, Google OAuth tokens); sign-in session records including IP address and user-agent; workspace, membership, and invitation records; demo metadata and structured demo data (steps, overlay copy, callouts, brand kits, settings); share-link records and revocation tombstones; demo analytics events; lead-capture submissions; AI metering records (no prompts, no images, no outputs); billing projections and stored Stripe webhook payloads; SSO configuration and SHA-256 hashes of SCIM tokens. Captured media files are not stored here | United States (AWS US East). The project is provisioned in a single US region |
| Cloudflare, Inc. | Object storage (R2) for all captured media and published-demo payloads, retrieved only over signed URLs that expire after one hour; content delivery for Demo Pine domains; static hosting (Cloudflare Pages) for demopine.com | Screenshots, tab video, tab audio, verbatim HTML page clones, and published share payloads. Visitor and uploader IP addresses and request headers, in the ordinary course of serving a request and in Cloudflare's own request logs. Media uploads go directly from the browser to R2 over a presigned URL, so Cloudflare receives the uploader's IP address without the bytes passing through our server. Cloudflare supplies the two-letter country code recorded with demo analytics where the request traverses its edge | R2 bucket: Eastern North America (ENAM). CDN and Pages are served from Cloudflare's global edge; we do not control which edge location handles a given request, and we do not control the retention of Cloudflare's request logs |
| Anthropic PBC | AI text generation for the built-in writing assistant | Only at the moment you invoke an AI feature: the instruction text, the demo text you are working on, and — where the step is a screenshot step — that step's screenshot. Screenshots over 5 MB are not sent, and no image is sent for video, page-capture, or audio steps. A screenshot sent this way can contain personal data captured from a real screen. We retain none of it — we keep only the model, the feature, the credits consumed, and token counts | United States. We have not been given, and do not claim, a more specific region |
| Zoho Corporation (ZeptoMail) | Transactional email only. We send exactly two kinds of message: password resets and workspace invitations | Recipient email address and the full message content, including the single-use password-reset link, the workspace invitation link, and the inviter's name and workspace name that an invitation displays | United States. We send to ZeptoMail's default US endpoint (api.zeptomail.com). An EU endpoint exists and is not currently configured. We do not have independent visibility into where Zoho processes a message once it reaches that endpoint |
3. Notes on each sub-processor
3.1 Fly.io — the brand scanner runs from here. When you supply a website URL, or when one is derived from your email domain, the fetch is made by our servers on Fly's network. Our servers' IP address, and the user-agent string carrying the identifier DemoPineBrandScanner, appear in the target site's logs (Terms, Section 15.1).
3.2 Neon — what is and is not in the database. Captured media never lands in PostgreSQL; it goes to Cloudflare R2. What the database holds is the structured half of a demo — steps, overlay copy, settings — which is subject to the 2 MB structured-data limit in Terms Section 9.6, and which we do not inspect or validate.
3.3 Cloudflare — the outstanding caveat. Media URLs handed out under the retired public domain media.demopine.com, before we moved to expiring signed URLs, remain readable until we detach that domain from the bucket at Cloudflare. That is an operational step we have not yet completed, and we disclose it in Terms Section 12.1 and Privacy Policy Section 4.5 rather than leave you to find it.
3.4 Anthropic — retention and training. Our agreement with Anthropic prohibits it from using inputs or outputs submitted through its commercial API to train its models (Terms, Section 13.5). Anthropic's commercial terms do permit it to retain inputs and outputs for a limited period for trust-and-safety and abuse-monitoring purposes. That period is set by Anthropic, not by us, and we do not control it. This is the disclosure referred to in Terms Section 13.1.
We will not engage an AI sub-processor that does not make an equivalent no-training commitment. If we change model providers, we will update this page before the change takes effect and give the notice in Section 8.
3.5 Zoho (ZeptoMail) — nothing else is sent by us. Receipts, payment-failure notices, and renewal notices come from Stripe, not from us and not through ZeptoMail. We operate no marketing mailing list and send no marketing email, so no email vendor receives a list of our customers for that purpose.
3.6 The Chrome extension has no sub-processor. The Demo Pine Capture extension makes no network requests of its own and contains no analytics or telemetry. Captured data reaches a sub-processor only once the extension hands the capture to the Demo Pine app and the app uploads it. Google's role in distributing the extension through the Chrome Web Store is a distribution relationship, not processing of Customer Content.
4. Independent controllers — not sub-processors
These two are listed for transparency. They determine their own purposes for at least part of what they do, we cannot instruct them about that part, and it is governed by their own policies.
| Legal entity | What it does | What it receives | Processing location |
|---|---|---|---|
| Stripe, Inc., and Stripe Payments Europe, Ltd. for EU customers | Payments, subscriptions, invoicing, and the hosted billing portal. Stripe acts as our processor for the transaction records we instruct it to keep, and as an independent controller for fraud prevention, financial-crime compliance, and its own regulatory obligations | The email address of the admin who starts checkout, the workspace name, the plan and seat count, internal workspace identifiers, the billing address Stripe collects, card details entered directly into Stripe (which never reach our servers), transaction records, and the device signals Stripe.js collects on our billing page. Stripe also sends the billing emails listed in 3.5 | Stripe determines its own processing locations. Stripe, Inc. is a United States entity; Stripe Payments Europe, Ltd. is an Irish entity |
| Google LLC | Optional sign-in provider, and the host of your profile image if you signed in with Google | Your sign-in attempt, your IP address, and our application identity. On each app page load where you have a Google profile image, your browser requests that image from Google, so Google receives your IP address and the referring page. Google returns your email address, name, and profile image URL | Google determines its own processing locations |
Neither of these receives Customer Content. Stripe receives billing data; Google receives sign-in and avatar-request data. Neither is sent a demo, a capture, a lead submission, or a share payload.
5. Vendors that are yours, not ours
5.1 Your identity provider. If you connect SSO (SAML) or directory provisioning (SCIM), that provider is your vendor. You are responsible for it, for the data it sends us, and for your agreement with it. It is your sub-processor, not ours (Terms, Section 16.5).
5.2 Bring-your-own-key AI. If you supply your own model-provider API key, your browser calls that provider directly. The request never touches our servers and never touches any sub-processor of ours. That traffic is governed by your agreement with that provider, and nothing on this page applies to it (Terms, Section 13.4).
6. What is deliberately not on this list
We would rather name an absence than let you assume one. As of the last-updated date above, Demo Pine uses:
- no product-analytics, marketing-analytics, or session-replay vendor;
- no error-tracking, crash-reporting, or application-performance-monitoring vendor — application logs stay in our hosting provider's log stream;
- no advertising network, ad pixel, tag manager, or data broker;
- no marketing-email or CRM vendor, and no mailing list;
- no customer-support or live-chat platform — support runs on ordinary email;
- no third-party font, script, or asset CDN on
demopine.com; the marketing pages serve their web fonts fromdemopine.comitself.
If we introduce any of these, it will appear on this page with the notice in Section 8 before it starts processing.
7. International transfers
Demo Pine is operated from the United States and our infrastructure is hosted in the United States. If you are outside the United States, Customer Content will be transferred to and processed in the United States.
The transfer mechanisms we rely on — the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss adaptations, and, where a provider holds it, EU-US Data Privacy Framework certification — are set out in Section 9 of the Privacy Policy and in the DPA, and are not restated here. We carry out transfer impact assessments for the sub-processors in Section 2 and will share them with customers on request to [email protected].
Demo Pine has no establishment in the European Union or the United Kingdom. Our representative under Article 27 of the GDPR and the UK GDPR is: [[EU_REPRESENTATIVE]].
8. How we notify you of a change
8.1 The commitment. We will give at least 30 days' notice before adding or replacing a sub-processor that processes Customer Content or other customer personal data. Notice is given in both of these ways:
- By email to Workspace owners, at the address we hold for them, where that address is working; and
- by updating this page, with the change recorded in the changelog in Section 11.
The 30-day period runs from the later of those two.
8.2 How to be added to the notification list — read this, because there is no button.
✉️ There is no subscribe widget on this page, and we are not going to describe one that does not exist. Notification is a list we keep by hand. Email
[email protected]with the subject linesubprocessor notificationsand tell us which address to use, and we will add it and confirm. We will then email that address whenever this page changes, on the same schedule as the notice to Workspace owners. Use this if you are not a Workspace owner and would otherwise not be emailed — a privacy officer, a procurement or vendor-risk contact, a security reviewer, or a shared inbox. Ask us the same way to be removed. We use the addresses on this list for sub-processor notices and for nothing else.
8.3 If you are a Workspace owner you need do nothing. The email in 8.1(1) goes to you whether or not you are on the list in 8.2.
8.4 Nothing here narrows the commitment. The 30 days, the email to owners, and the update to this page are owed under Terms Section 16.3 regardless of whether anyone subscribes. The list in 8.2 is how we reach people the owner email would miss; it is not a condition of the notice.
9. Your right to object
9.1 The window. If you reasonably object to a new sub-processor on data-protection grounds within the 30-day notice period, write to [email protected] and tell us the grounds. We will work with you in good faith to offer an alternative.
9.2 If we cannot offer one. You may terminate the affected subscription, and we will refund the prepaid fees allocable to the remainder of your then-current term, calculated on a straight-line daily basis. This is a deliberate, narrow exception to the otherwise non-refundable fee policy in Terms Section 6.11, and it is listed there as Section 6.11.1(4).
9.3 What this right does not cover. It is a right to object to a new or replacement sub-processor on data-protection grounds within the notice window. It is not a general right to object to the providers already on this list at the time you subscribed, and it is not triggered by a provider's own internal changes — a new region, a corporate reorganization, or a change to its own vendors — that do not change who processes Customer Content for us.
10. Contact
RyanTech LLC (d/b/a Demo Pine)
A South Carolina limited liability company
2764 Pleasant Road, Suite A #599, Fort Mill, SC 29708, USA
| What you need | Where to write |
|---|---|
| Sub-processor questions, notification list, objections, DPAs, transfer impact assessments | [email protected] |
| Legal notices | [email protected] |
| Support and billing | [email protected] |
Terms of Service: https://demopine.com/terms · Privacy Policy: https://demopine.com/privacy · Data Processing Addendum: https://demopine.com/dpa
11. Changelog
Every addition, replacement, or removal of a sub-processor is recorded here with the date the change took effect.
| Date | Version | Change |
|---|---|---|
| August 1, 2026 | 1.0 | Initial publication of this page. The sub-processors listed in Section 2 — Fly.io, Neon, Cloudflare, Anthropic, and Zoho (ZeptoMail) — and the independent controllers in Section 4 — Stripe and Google — were already in use and already disclosed in Section 8 of the Privacy Policy. No sub-processor was added, replaced, or removed by this publication, so the 30-day notice period in Section 8 is not engaged by it |
Demo Pine is a product of RyanTech LLC. Cloudflare, Stripe, Anthropic, Google, Fly.io, Neon, and Zoho are trademarks of their respective owners.