Skip to content
← Legal

Subprocessors

Last updated October 4, 2026

In short

  • These are the companies that process personal data for us so we can run {{site.name}}.
  • Each one gets only the data it needs for its job.
  • We don't sell personal data or share it with advertisers.

1. Our subprocessors

Subprocessor Purpose Data Location
Cloudflare, Inc. Hosting and serverless compute (Workers), database (D1), content delivery and bot protection. Web Analytics only if you agree to it All data stored in or passing through the Service; for analytics, cookieless page-view statistics United States (headquarters); global network
OpenRouter, Inc. Routing AI generation requests to model providers Prompts (your inputs, voice and the tool's instructions) and outputs United States
AI model providers, reached through OpenRouter (currently Moonshot AI's Kimi models, with DeepSeek models as a backup, run by hosting companies such as Fireworks, Together AI or DeepInfra) Generating text with the selected model Prompts and outputs Mainly the United States; some in the EU
Resend Service emails (email verification, password resets, account notices) and forwarding contact-form messages to our inbox Name, email address and the content of the email United States
Google LLC "Sign in with Google", only if you use it Sign-in request data; Google shares your name, email address and Google account ID with us United States
Stripe Payments, subscriptions, top-up purchases and the customer portal where you manage or cancel your plan Payment card details, and as needed your billing name, email address and billing address; plan and payment records (we never see or store your full card number) United States and other countries where Stripe operates

2. Good to know

  • Google (for sign-in) and Stripe (for payments) also process some data as independent controllers, under their own privacy policies.
  • We don't use your content to train AI models. Model providers process requests under our agreements with them and their own terms; some may keep requests for a limited time, for example to detect abuse.
  • Where the GDPR or the UK GDPR requires safeguards for transfers outside the EEA or the UK, we rely on adequacy decisions or the Standard Contractual Clauses, as explained in our Privacy Policy.
  • If you're in Türkiye, the recipients of your data and the basis for transfers abroad are also described in our KVKK notice.

3. Changes

We update this page when we add or replace a subprocessor. Questions? Email privacy@example.com.

Last updated: October 4, 2026