| Subprocessor | Purpose | What it processes |
|---|---|---|
| Cloudflare, Inc. | Hosting, edge delivery, Workers, D1, R2, Durable Objects | Account identity; private/shared document data and revision metadata when cloud protection or sharing is used; content-free activation events; audit records |
| Stripe, Inc. | Card-backed trials, subscription billing, and payments | Billing email, card/payment details, and subscription status (card data is held by Stripe, never by us) |
| Resend, Inc. | Transactional email (invites, notifications, sign-in links) | Recipient email address and message content (only when you invite teammates or enable notifications) |
| OpenRouter and the model provider selected by FlowGraph | The one-map hosted Free Preview and other explicitly labeled hosted AI | The goal/prompt and generated response for the AI action you invoke; no unrelated vault content |
| Your chosen AI provider(s) | AI planning and generation under BYOK, Codex, or a local/provider connection | Only the content you send through that route, under that provider's terms. Local-model processing can remain on your machine. |
Cloud data is processed on Cloudflare's global network. Audit-log retention windows are configurable by workspace owners on Enterprise plans; older rows are archived to object storage and disclosed in the admin console. A lapsed workspace keeps read access to everything it created — nothing is held hostage.
We will update this page before a new subprocessor begins processing customer data. For a data processing agreement (DPA) or questions, email help@flow-graph.com.