sub-processors · updated 2026-09-13

Sub-processors

We use the following sub-processors to deliver the service. Each entry states the purpose, the data they see, and their region. Changes to this list are announced by email before they take effect.

Current sub-processors

Cloudflare, Inc.
Purpose: Edge routing and DDoS protection, TLS termination, API router runtime (Cloudflare Workers), console application runtime (Cloudflare Workers), database for accounts and billing (Cloudflare D1), artifact storage (Cloudflare R2), outbound email delivery.
Data they see: Request routing metadata (IP addresses, HTTP headers, paths) during edge transit; account data (email, key prefixes, credit balances, billing metadata) in D1 database; console application data (account sessions, billing records) in Worker runtime; outbound emails (recipient address, email content).Prompts and completions transit the edge but are not stored by Cloudflare; they are routed to the inference provider.
Region: Global edge network; D1 database and R2 storage in the EU where the platform allows region selection.
Paddle.com Market Ltd (Paddle)
Purpose: Payment processing, tax calculation, invoicing, saved payment method storage. Paddle is the merchant of record.
Data they see: Payment card details (we never see your card), billing address, purchase amounts, customer reference. Paddle returns a customer reference and last four card digits so the console can show your saved payment method.
Region: UK and EU (Paddle entity).
Nebius
Purpose: GPU compute infrastructure for running inference models.
Data they see: Prompts and completions in memory onlyfor the duration of the inference request. For purchased-credit traffic with training off (the default), prompts and completions arenever written to durable storage on Nebius infrastructure. Billing metadata (token counts, timestamps, no content) and operational logs (status codes, latency, no content) exist on the compute host for up to 30 days.
Region: Europe (London, United Kingdom).
Note: The exact legal entity name is available on request before sending production data that requires named-vendor review. Mail support@tiyuvta.ai.
Email delivery provider
Purpose: Transactional email delivery (account sign-in links, billing notifications, service announcements).
Data they see: Recipient email address, email content (no prompts or completions).
Region: Delivered via Cloudflare email infrastructure.
Note: Email is sent through Cloudflare's own email binding, so this is Cloudflare rather than a separate vendor - there is no additional party in this path.

What sub-processors do not see

Changes to this list

Adding or replacing a sub-processor is announced by email at least 30 days before it takes effect, like every change that widens what happens to your data. You may object before the change takes effect; if we cannot accommodate the objection, you may terminate the service. The date at the top moves with every change.

Data Processing Addendum

See the Data Processing Addendum for processor roles, security measures, and data subject rights.