Subprocessors
These are the third parties that process data on our behalf. We give 30 days' notice by email before adding a new one.
| Subprocessor | Role | Data | Location |
|---|---|---|---|
| Cloudflare | API gateway, static hosting, temporary file storage (R2) | Files, request metadata | Global edge, storage in US |
| Amazon Web Services | Compute for file processing (Lambda) | Files during processing only | us-east-1, USA |
| Hostinger | Database hosting (self-managed Postgres on a VPS) | Account data and usage records. No file content | USA |
| Google Cloud | Overflow compute (Cloud Run) | Files during processing only | us-central1, USA |
| Stripe | Payment processing | Billing data, card details | USA, global |
| SendGrid | Transactional email | Email address, message content | USA |
| Sentry | Error monitoring | Error traces, request ids. No file content | USA |
Notes on scope
Compute providers never persist your files. AWS Lambda and Google Cloud Run hold a file only in ephemeral storage during processing and it is gone when the invocation ends.
Stripe never shares card details with us. Card data goes directly from your browser to Stripe. We store only a customer reference and the last four digits.
Sentry receives no file content. Error reports carry stack traces, request identifiers and metadata. File contents are explicitly excluded.
Changes
Subscribe to changes at hello@justapi.tech. Under our DPA you may object to a new subprocessor, and if we cannot resolve it you may terminate without penalty.