Subprocessor Notice

Version: 2026-08-08
Effective date: August 8, 2026

This Notice describes third parties that may process personal data for Infer by Flow7. Infer’s current legal operator is identified in the Legal Operator Notice.

Ordinary marketing pages may describe infrastructure generically. This Notice provides additional transparency for account, payment, email, identity, security, and Customer Personal Data processing.

1. Named providers

Provider Role and purpose Data that may be processed Typical location/status
Stripe, Inc., Sold through Link, LLC, and applicable Stripe/Link affiliates Hosted Checkout, payment processing, Managed Payments merchant-of-record services, tax, billing address/name collection, fraud, disputes, refunds, invoices, receipts, and transaction support Contact, billing, address, payment identifiers, transaction, wallet-funding, tax, risk, refund, and dispute data United States and documented global Stripe/Link locations; active for paid transactions
Plus Five Five, Inc. (Resend) Transactional email, including verification, password reset, invitations, receipts/operational notices, and delivery records Email address, name when used, message content, delivery and diagnostic metadata United States and documented service locations; active
Google LLC Optional Google OAuth login OAuth identifier, email, name/profile fields authorized at login, and authentication metadata Global; conditional when Google login is used
Cloudflare, Inc. DNS, CDN, edge security, bot/rate protection, and enabled infrastructure features IP/network/security data and content in transit depending on enabled services Global network; conditional on enabled production features
OpenRouter, Inc. Gateway for Official API / First-Party Endpoint routes Customer request and output in transit; model, usage, route, security, and request metadata United States and selected underlying model-provider locations; active for applicable routes
Havenbyte LLC d/b/a ModelFlare Gateway for Low Cost, Balanced, and Stable routes Customer request and output in transit; model, usage, route, diagnostics, security, and cost metadata United States and selected infrastructure/model-provider locations; active for applicable routes

2. Infrastructure provider categories

Infer uses managed providers in the following categories. The exact provider can change as the production architecture evolves:

These providers may process account, organization, ledger, payment identifiers, security events, operational metadata, and transient Customer Content to the extent technically necessary. Infer configures ordinary logs not to intentionally capture complete prompt or response bodies and limits provider access according to role.

A Business User with a material data-protection need may request the current production legal-entity inventory at privacy@flow7.org. Infer may provide security-sensitive infrastructure detail under confidentiality rather than on a public marketing page.

3. Underlying model providers

A model developer or host reached through OpenRouter or ModelFlare may be a Subprocessor or further Subprocessor for the request selected by the customer. Depending on the model catalog and route, providers can include entities associated with model families such as OpenAI/GPT, Anthropic/Claude, Google/Gemini, xAI/Grok, DeepSeek, Kimi/Moonshot, and others displayed in the Service.

Before or at route selection, Infer will make reasonably available:

Customer’s affirmative selection of a specifically presented model or route authorizes the underlying model-processing provider needed for that request.

An Official API / First-Party Endpoint route is locked to the selected model developer’s first-party endpoint through infrastructure intermediaries and does not silently fall back to an unrelated third-party model host. This does not imply a partnership, endorsement, or direct customer agreement with the model developer.

4. Data-processing expectations

Infer requires model-processing and infrastructure suppliers, through contract, account settings, route configuration, or another applicable mechanism, to process data only as needed for the selected service and to maintain appropriate security and confidentiality.

Public supplier documentation is informational and does not replace binding terms where a binding processor agreement is legally required. Route-level technical settings, including zero-retention, no-training, provider allowlists, and data-collection denials, apply only where the selected supplier and model endpoint support them.

5. Notice and objection

Infer will provide at least 30 calendar days’ notice before a new direct Subprocessor begins processing Customer Personal Data when reasonably practicable. For an urgent change required by law, security, supplier failure, model availability, or service continuity, notice may occur later but will be provided as soon as reasonably practicable.

A Business User may object within 15 calendar days after notice on reasonable data-protection grounds by emailing privacy@flow7.org. Infer and the customer will seek a reasonable alternative route, configuration, or provider. If no reasonable alternative exists, Infer may disable the affected feature or the customer may terminate the affected processing and request a refund of eligible unused paid credit.

A customer’s affirmative selection of a newly disclosed model or route after the provider information is presented constitutes authorization for that provider.

6. Supplier disclosure by context

7. Contact

Subprocessor questions and objections: privacy@flow7.org

The current operator and postal address are in the Legal Operator Notice.