Mizan

Subprocessors

Last updated: August 2026

What this is

The third parties we engage to operate the Service, and what data each one touches. For customers with a DPA in place, this page is the list of subprocessors under that agreement. We'll notify you at least 30 days before adding or materially changing a subprocessor.

Hosting & infrastructure

SubprocessorPurposeData
VercelFrontend hosting and edge deliveryStatic assets, encrypted browser traffic; no application data.
RailwayBackend API, background workers, and cron serviceBackend processing, usage data, credentials (encrypted), logs.
NeonPostgreSQL databaseAll database rows, including usage, receipts, conversations, and encrypted credentials.
Redis (Railway-managed)Caching and BullMQ job queuesTransient cache and queue payloads; cleared on expiry.
ClerkAuthentication and organization managementSign-in sessions, user and organization profiles.

Integrations & payments

SubprocessorPurposeData
StripeWallet top-up checkout and payment processingPayment card details (processed by Stripe only), transaction metadata, payment intent references.
ResendTransactional email (budget alerts, weekly digests, notices)Recipient email address and message content.
Google (Gmail API)Email receipt scanningInbox messages you explicitly authorize us to scan; subject, sender, and body, truncated at ingestion.
Microsoft (Outlook API)Email receipt scanningInbox messages you explicitly authorize us to scan; subject, sender, and body, truncated at ingestion.
OpenRouterKhabir assistant model routing; public model catalog mirrorKhabir chat messages sent for processing; public model metadata.

Model providers

When you route a request through the gateway, the prompt and completion are transmitted to the provider whose model you chose. If you route through your own connected account (BYOK), the request is made under your own agreement with that provider. If the request is billed to your Mizan wallet, it is made under Mizan's agreement with that provider on your behalf. Either way, the provider's own data policies govern the content you submit to it.

ProviderPurposeData
OpenAIInference for openai/* modelsPrompts and completions you route, plus token usage.
AnthropicInference for anthropic/* models; Claude Code analyticsPrompts and completions you route, plus token usage.
GoogleInference for gemini/* modelsPrompts and completions you route, plus token usage.
AWS (Bedrock)Inference for bedrock/* modelsPrompts and completions you route, plus token usage.
GroqInference for groq/* modelsPrompts and completions you route, plus token usage.
MistralInference for mistral/* modelsPrompts and completions you route, plus token usage.
xAI (Grok)Inference for grok/* modelsPrompts and completions you route, plus token usage.
LiteLLMInference for litellm/* modelsPrompts and completions you route, plus token usage.
DeepSeekInference for deepseek/* modelsPrompts and completions you route, plus token usage.
MoonshotInference for moonshot/* modelsPrompts and completions you route, plus token usage.
Qwen (Alibaba)Inference for qwen/* modelsPrompts and completions you route, plus token usage.
MiniMaxInference for minimax/* modelsPrompts and completions you route, plus token usage.
CerebrasInference for cerebras/* modelsPrompts and completions you route, plus token usage.
Z.AIInference for zai/* modelsPrompts and completions you route, plus token usage.

Questions?

Ask for the current list or the status of any subprocessor at naim@app-mizan.com. This page is updated at least 30 days before any material change.