Subprocessors
Last updated September 3, 2026
A subprocessor is a third party that processes customer data on our behalf. This page names all of them, what each one does, and what category of data reaches it. It is the canonical list our Data Processing Addendum refers to, so it is kept accurate rather than kept comfortable.
The application server runs in a United States data center. Content delivery and model inference are global: the CDN serves from wherever the reader is, and model providers run in their own regions. Per-vendor locations are not asserted here, because we cannot keep them current and a stale location is worse than none.
Always in the path
These process customer data for every organization, regardless of how you configure yours.
| Subprocessor | Purpose | Data processed |
|---|---|---|
| OpenRouter | Routes every model request to the providers below. It is the only path out to a model anywhere in the product. | Prompt content — conversation messages, agent instructions, knowledge base excerpts, tool results — plus an internal user identifier and session identifier |
| Anthropic | Model provider, for the Claude presets | Prompt content and generated output |
| OpenAI | Model provider, for the GPT presets, and the open-weight model that performs web research | Prompt content and generated output |
| Model provider, for the Gemini preset | Prompt content and generated output | |
| xAI | Model provider, for the Grok preset | Prompt content and generated output |
| DeepSeek | Author of an open-weight model preset. Its models are served by third-party inference hosts, so DeepSeek itself does not necessarily receive requests. | Prompt content and generated output |
| Z.ai | Author of an open-weight model preset, with the same qualifier | Prompt content and generated output |
| Cloudflare | Serves the web application and terminates TLS. Stores uploaded files, published pages, and organization backup exports. | Uploaded files and documents, published page content, backup exports, edge request metadata |
| Resend | Outbound and inbound email. Inbound message bodies and attachments are retrieved back from Resend rather than merely passing through it. | Message bodies, attachments, and email addresses |
| Stripe | Subscription billing. A customer record is created when you sign up. | Account and organization identity — name, email address, organization name — plus plan and invoice amounts. Card details are handled by Stripe and never reach us. |
| IONOS | Application server hosting, in a United States data center | All customer data, at rest and in processing |
| Google Analytics | Product usage analytics inside the web application | Page addresses, which contain agent and document identifiers; IP address; device and browser |
Google appears twice, as a model provider and as an analytics provider. Those are two unrelated relationships processing different data, so they are listed separately rather than merged into one row.
What your configuration adds
These process data only if your organization turns on the feature or connects the account.
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Exa | Web search results during a research run, reached through OpenRouter’s web plugin rather than directly | The search query text |
| ElevenLabs | Voice calls with an agent, where voice is enabled. ElevenLabs holds the microphone, the transcription, and the turn-taking. | Caller audio and the agent’s spoken replies |
| Calendar and Analytics connectors | Whatever the read scopes you granted return | |
| Microsoft | Outlook mail and calendar, Teams, OneDrive, and SharePoint connectors | Whatever the read scopes you granted return |
| GitHub | Repository and organization metadata connector | Whatever the read scopes you granted return |
| Profile connector. It also posts on your behalf when you approve a post. | Profile data returned, and the content of posts sent | |
| Notion | Workspace connector. It reads the pages you grant and writes notes back. | Page content returned, and content sent when writing |
Two of these connections can write, not only read. LinkedIn is granted permission to post on your behalf, and Notion is granted permission to write notes back. Every other connector holds read scopes only.
How model routing works
OpenRouter is a router, not a model provider. Inference is served by the providers named above. Naming the router alone would tell you nothing about who actually runs the model behind a conversation, which is why both layers appear on this page.
Every request we build carries a routing constraint that excludes any endpoint that trains on prompts, and there are exactly two places in the code that construct a model request, so this covers every model call the product makes. Some presets carry additional endpoint exclusions on top of it. That constraint governs training, not retention. An endpoint that passes it may still hold a request briefly for abuse monitoring under its own policy. This is not a zero-retention arrangement and we do not describe it as one.
The individual inference endpoints beneath each provider are not enumerable, and it is worth saying why. Endpoint preferences are preferences, not restrictions: fallbacks stay on by design, so any endpoint hosting a model may serve a request, and the available set moves as OpenRouter onboards new hosts. A constraint applied to every request is a stronger disclosure than a roster of who was vetted once, because a hand-maintained roster goes stale in silence. OpenRouter’s own model pages are the live source for who is currently serving a given model.
For the open-weight presets, the model’s author is not the recipient. A DeepSeek model served by a third-party inference host means DeepSeek the company receives nothing. Both companies are named above because their models are used, not because we can promise they never see a request.
Changes to this list
We give 30 days’ advance notice before a new subprocessor begins processing customer data. Notices are emailed to the account owner of every customer organization. There is no subscribe form, no dashboard, and no feed — the obligation is ours to fulfil, not yours to opt into.
You have 15 days from a notice to object on legitimate data protection grounds. If no reasonable workaround exists, the affected service terminates, rather than your whole agreement. If no objection is raised within that window, the appointment is deemed accepted.
What counts as a change, stated precisely, because the obvious wording would promise more than we can keep: a new direct subprocessor, a preset routed to a model provider not named on this page, or a material loosening of the routing constraint described above. It is not a model version change, and not OpenRouter’s choice of inference host beneath a provider already listed. Removing a subprocessor requires no notice.
What is not on this list
- Asset requests that carry no customer data, such as web fonts and icon delivery. This applies whether the request comes from a reader’s browser or from our own server rendering a page or an email. Nothing about you is in the request.
- Browser push services operated by Google, Apple, and Mozilla. Notification payloads are encrypted before they leave us, so the push service that relays them cannot read them.
- Systems you connect using your own credentials, where your own agreement with that provider governs the relationship rather than ours.
- This marketing website’s own cookies and analytics, which are covered by the Cookie Policy rather than here. This page describes the application.
Questions about anything on this page, or a security review that needs more than it covers: contact us and ask directly. See also Security and the Privacy Policy.