Subprocessors

These are the third parties that process data on our behalf. We give 30 days' notice by email before adding a new one.

Subprocessor Role Data Location
Cloudflare API gateway, static hosting, temporary file storage (R2) Files, request metadata Global edge, storage in US
Amazon Web Services Compute for file processing (Lambda) Files during processing only us-east-1, USA
Hostinger Database hosting (self-managed Postgres on a VPS) Account data and usage records. No file content USA
Google Cloud Overflow compute (Cloud Run) Files during processing only us-central1, USA
Stripe Payment processing Billing data, card details USA, global
SendGrid Transactional email Email address, message content USA
Sentry Error monitoring Error traces, request ids. No file content USA

Notes on scope

Compute providers never persist your files. AWS Lambda and Google Cloud Run hold a file only in ephemeral storage during processing and it is gone when the invocation ends.

Stripe never shares card details with us. Card data goes directly from your browser to Stripe. We store only a customer reference and the last four digits.

Sentry receives no file content. Error reports carry stack traces, request identifiers and metadata. File contents are explicitly excluded.

Changes

Subscribe to changes at hello@justapi.tech. Under our DPA you may object to a new subprocessor, and if we cannot resolve it you may terminate without penalty.