How to read this schedule
1. Core and conditional subprocessors
| Provider | Purpose | Data | Processing location | When used |
|---|---|---|---|---|
| Cloudflare | Public edge, DNS, Gateway Worker execution, logs, KV, Durable Objects, and private R2 object storage | Network and request data; gateway content in transit; optional I/O logs and data contributions; operational metadata | Workers execute on Cloudflare's global network. Phaseo's private R2 buckets are located in Western Europe (WEUR); they do not currently have an EU jurisdictional restriction. | Core |
| Vercel | Host and deliver the Phaseo web application | Website and dashboard traffic, account-facing requests, device and operational metadata | Global delivery network; deployment processing locations require factual confirmation | Core |
| Supabase | Authentication and primary relational database | Account, workspace, configuration, billing reference, request, usage, security, and support metadata | AWS eu-west-2 (London), verified against the production project on 30 August 2026 | Core |
| Upstash | Redis-backed response caching and cache-related routing data | Workspace-scoped cache keys, model outputs, response metadata, and short-lived routing/cache records | Production database region requires factual confirmation | When the Redis binding is enabled |
| OpenAI | Classify a configured sample of opted-in data contributions | Best-effort-redacted prompt and response content and classifier instructions | According to the Phaseo OpenAI API account and applicable transfer terms; factual confirmation required | Only when data contribution and upstream classification are enabled |
2. Phaseo-managed AI providers
Phaseo compared the active production Gateway routes with the production Worker's managed credential bindings on 30 August 2026. Thirty-eight provider families met both conditions. The legal role is determined by the API recipient and its contract, not by the developer of a model available through that API.
Processor terms located
Current processor terms or a DPA were located for the relevant business service. Account configuration, contracting entity, transfers, and feature-specific terms still require confirmation.
- Amazon Web Services (Bedrock)
- Anthropic
- Google Cloud (Vertex AI)
- Groq
- Mistral AI
- OpenAI
Processor contract pending
Phaseo intends these providers to act only as subprocessors, but has not yet recorded sufficient Article 28 contract evidence. They are provisional for personal-data processing.
- AionLabs
- AkashML
- Alibaba Cloud
- AtlasCloud
- Baseten
- BytePlus
- Cerebras
- DeepInfra
- GMICloud
- Meta Model API
- Morph
- Nebius Token Factory
- NovitaAI
- SiliconFlow
- Venice
- Wafer
- Xiaomi
- z.AI
Restricted review
Training, opt-out-dependent, or unclear own-purpose terms remain. These providers should not receive unrestricted Customer Personal Data through the managed pool until the issue is resolved.
- Arcee AI
- Cohere
- DeepSeek
- ElevenLabs
- Fireworks AI
- Google AI Studio
- MiniMax
- Moonshot AI
- Poolside
- Sakana AI
- Together AI
- Voyage AI
- Weights & Biases
This is a preliminary role register, not a representation that every listed managed route is approved for personal data. Phaseo must either complete the outstanding contract and configuration checks or remove the affected provider from the managed pool before executing the DPA.
3. Customer-selected AI providers
Phaseo sends request content and necessary metadata to the provider selected by the customer, the requested model, or the customer's routing configuration. The available set changes as routes are added, disabled, or degraded. The live provider directory is the maintainable source for currently available providers.
When Phaseo uses its own provider account, the provider is intended to be Phaseo's subprocessor for inference and must satisfy the managed-provider review above. When the customer supplies the credentials or holds the provider contract, the provider is normally a customer-directed recipient or the customer's own processor. A provider may separately act as a controller where it processes data for its own purposes, including training where permitted by its terms.
4. Other service providers
These vendors support Phaseo's billing, communications, product operations, documentation, or support. They may be processors for Phaseo when Phaseo acts as a controller, but are not automatically subprocessors for all Customer Data under the DPA.
| Provider | Role | Data |
|---|---|---|
| Stripe | Billing and payment processing | Billing identity, transaction, invoice, refund, and payment-method data |
| Resend | Transactional and operational email | Recipient contact details, email content, and delivery events |
| Statsig | Feature flags and experiments | Stable, user, workspace, environment, and feature-evaluation identifiers; authenticated email where configured |
| Google Analytics | Consent-based website analytics | Page, device, referrer, event, and coarse location data |
| Vercel Web Analytics | Consent-based website analytics | Page, device, referrer, and performance telemetry |
| PostHog | Product analytics where the production key is enabled | Product events, page, device, and usage telemetry; raw gateway content is excluded by design |
| Axiom | Operational observability where the production key is enabled | Workspace and request telemetry; sampled best-effort-redacted request details where configured |
| Mintlify | Documentation hosting | Documentation requests, network data, and documentation analytics |
| incident.io | Public status page and incident communications | Status-page traffic and incident-subscription contact details when supplied |
| Tawk.to | Optional live support chat | Contact details, chat content, device, and page context |
| Notion | Support ticket and internal workflow management | Contact details, ticket content, and related account context |
| Discord | Internal operational notifications and customer-configured alert delivery | Masked contact data, operational or billing summaries, and customer-selected alert content |
5. Customer-directed destinations
When a customer configures an observability endpoint, webhook, email recipient, Slack workspace, Microsoft Teams channel, Discord destination, OAuth application, or compatible AI assistant, Phaseo sends the selected data to that destination on the customer's instruction. Those recipients are not Phaseo-appointed subprocessors merely because Phaseo provides the connection.
6. Changes and objections
Phaseo publishes material changes to this page with a new review date. Under the DPA review draft, Phaseo will notify the Customer's account email at least 30 days before a new Subprocessor begins processing Customer Personal Data and will accept written objections during that period.
The public product does not yet offer a general subprocessor-change subscription. Customers reviewing an execution copy should confirm the notice contact with [email protected].
7. Change history
- 30 August 2026
- Initial evidence-backed schedule. Added the short-lived Upstash response cache, optional OpenAI data-contribution classification, and separate customer-directed and controller-operation categories.