Legal
Subprocessors
Last updated: [EFFECTIVE DATE] · Version: 1.0-draft
FrugalAI uses these subprocessors to provide the Service. Each processes data under a data processing agreement with us and safeguards consistent with our DPA.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Database and authentication | Account data, org/team records, encrypted BYOK keys, request ledger (hashes, routing, costs), cache entries, billing records | United States |
| Vercel | Dashboard and website hosting | Dashboard traffic, server logs | United States (global edge) |
| Cloudflare | Gateway runtime | Request traffic in transit through the gateway, runtime logs | Global edge |
| Stripe | Payments | Billing identity, payment method (held by Stripe, never by FrugalAI), invoices | United States |
| OpenAI | Semantic-cache embeddings; sampled quality judging (when enabled) | Cacheable prompt text for embeddings; a small sampled fraction (on the order of 2%) of prompt-and-response pairs for scoring. Only the hash and score persist. | United States |
| Resend | Transactional email | Recipient email address, message content | United States |
Cross-provider note. When semantic caching or quality evaluation is enabled, the OpenAI flows above occur regardless of which model provider serves your requests. Disabling those features stops the flows: organizations can turn both off at any time in the dashboard (Policies, "Privacy controls"), which leaves exact-match caching and routing fully functional. Your own model providers (the ones you connect with your keys) are your direct vendors, not our subprocessors, and are governed by your agreements with them.
Change notice
We give at least 30 days notice before adding or replacing a subprocessor that processes Customer Content, by updating this page and emailing organization billing contacts. To receive notices at additional addresses, email privacy@frugalai.io. Objection rights and remedies are in Section 6 of the DPA.
Version history
| Date | Change |
|---|---|
| [EFFECTIVE DATE] | Initial published list: Supabase, Vercel, Cloudflare, Stripe, OpenAI, Resend. |
Version 1.0-draft · sha256 aaa4b6177602