Subprocessors
Last updated: August 2026
What this is
The third parties we engage to operate the Service, and what data each one touches. For customers with a DPA in place, this page is the list of subprocessors under that agreement. We'll notify you at least 30 days before adding or materially changing a subprocessor.
Hosting & infrastructure
| Subprocessor | Purpose | Data |
|---|---|---|
| Vercel | Frontend hosting and edge delivery | Static assets, encrypted browser traffic; no application data. |
| Railway | Backend API, background workers, and cron service | Backend processing, usage data, credentials (encrypted), logs. |
| Neon | PostgreSQL database | All database rows, including usage, receipts, conversations, and encrypted credentials. |
| Redis (Railway-managed) | Caching and BullMQ job queues | Transient cache and queue payloads; cleared on expiry. |
| Clerk | Authentication and organization management | Sign-in sessions, user and organization profiles. |
Integrations & payments
| Subprocessor | Purpose | Data |
|---|---|---|
| Stripe | Wallet top-up checkout and payment processing | Payment card details (processed by Stripe only), transaction metadata, payment intent references. |
| Resend | Transactional email (budget alerts, weekly digests, notices) | Recipient email address and message content. |
| Google (Gmail API) | Email receipt scanning | Inbox messages you explicitly authorize us to scan; subject, sender, and body, truncated at ingestion. |
| Microsoft (Outlook API) | Email receipt scanning | Inbox messages you explicitly authorize us to scan; subject, sender, and body, truncated at ingestion. |
| OpenRouter | Khabir assistant model routing; public model catalog mirror | Khabir chat messages sent for processing; public model metadata. |
Model providers
When you route a request through the gateway, the prompt and completion are transmitted to the provider whose model you chose. If you route through your own connected account (BYOK), the request is made under your own agreement with that provider. If the request is billed to your Mizan wallet, it is made under Mizan's agreement with that provider on your behalf. Either way, the provider's own data policies govern the content you submit to it.
| Provider | Purpose | Data |
|---|---|---|
| OpenAI | Inference for openai/* models | Prompts and completions you route, plus token usage. |
| Anthropic | Inference for anthropic/* models; Claude Code analytics | Prompts and completions you route, plus token usage. |
| Inference for gemini/* models | Prompts and completions you route, plus token usage. | |
| AWS (Bedrock) | Inference for bedrock/* models | Prompts and completions you route, plus token usage. |
| Groq | Inference for groq/* models | Prompts and completions you route, plus token usage. |
| Mistral | Inference for mistral/* models | Prompts and completions you route, plus token usage. |
| xAI (Grok) | Inference for grok/* models | Prompts and completions you route, plus token usage. |
| LiteLLM | Inference for litellm/* models | Prompts and completions you route, plus token usage. |
| DeepSeek | Inference for deepseek/* models | Prompts and completions you route, plus token usage. |
| Moonshot | Inference for moonshot/* models | Prompts and completions you route, plus token usage. |
| Qwen (Alibaba) | Inference for qwen/* models | Prompts and completions you route, plus token usage. |
| MiniMax | Inference for minimax/* models | Prompts and completions you route, plus token usage. |
| Cerebras | Inference for cerebras/* models | Prompts and completions you route, plus token usage. |
| Z.AI | Inference for zai/* models | Prompts and completions you route, plus token usage. |
Questions?
Ask for the current list or the status of any subprocessor at naim@app-mizan.com. This page is updated at least 30 days before any material change.