| Subprocessor | Purpose | What it processes |
|---|---|---|
| Cloudflare, Inc. | Hosting, edge delivery, Workers, D1, R2, Durable Objects | Account identity, shared-document sync data, audit logs (only when you sign in and use cloud features) |
| Stripe, Inc. | Subscription billing and payments | Billing email and payment details (only for paid plans; card data is held by Stripe, never by us) |
| Resend, Inc. | Transactional email (invites, notifications, sign-in links) | Recipient email address and message content (only when you invite teammates or enable notifications) |
| Your chosen AI provider(s) | AI planning and generation, under bring-your-own-key (BYOK) | Only the prompt content you send — routed with your key to the provider you chose (Anthropic, OpenAI, Google, or a local model). We never proxy or resell your inference unless you explicitly configure our proxy. |
Cloud data is processed on Cloudflare's global network. Audit-log retention windows are configurable by workspace owners on Enterprise plans; older rows are archived to object storage and disclosed in the admin console. A lapsed workspace keeps read access to everything it created — nothing is held hostage.
We will update this page before a new subprocessor begins processing customer data. For a data processing agreement (DPA) or questions, email help@flow-graph.com.