Subprocessors

The third-party services that may process customer data for Nuje.

Each vendor that can process customer data is covered by a Data Processing Agreement (DPA) or equivalent terms before launch.

Vendor Purpose Data processed DPA / status
Fly.ioApplication compute and request routingApplication traffic and runtime secretsDPA required before launch; vendor SOC 2 report on file
NeonManaged Postgres databaseApplication database content and metadataDPA required before launch; PITR restore drill required
Cloudflare R2Private object storage for mediaUploaded files and object metadataDPA required before launch; private bucket only
WorkOSAuthentication and identityUser identifiers, emails, and session tokensDPA required before launch; production AuthKit configured
ResendTransactional invite emailRecipient email addresses and invite metadataRequired for invite email delivery
SentryServer error reportingError metadata after source redactionDPA required before launch; PII scrubbing configured
Grafana CloudTraces and metricsOperational telemetry after source redactionDPA required before launch; logs are not ingested
AnthropicClaude model calls via your own key (BYOK), optional fallback on paid plans, and managed agentsPrompts, tool context, and managed-agent session data when a workspace key or paid-plan platform key is configuredAvailable on paid plans; on Free, Claude requires a workspace key (BYOK)
Voyage AISemantic search embeddingsText submitted for embeddings when configuredAvailable on paid plans; on Free, search uses keyword matching
OpenRouterFree-tier model calls and workspace OpenRouter keys (BYOK)Prompts, eligible image inputs, tool context, and usage metadataActive subprocessor; account privacy / zero-data-retention (ZDR) and spend-alert evidence required

Current controls

See also our security posture.