Legal
Smol API sub-processors
The companies that process data for us so that the Smol API can run, what each one handles, and how we announce a change.
1. Current sub-processors
A sub-processor is a company that processes data on our behalf so that we can run the Smol API. These are all of them.
| Sub-processor | Purpose | Data involved | Handles your files | Location |
|---|---|---|---|---|
| Cloudflare Cloudflare, Inc. | Hosting and processing: runs the API (Workers), the processing engine (Containers), temporary file storage for jobs (R2), and the account, job and usage records (D1 and Durable Objects). | The files you send and the files we return, file names, job metadata, account data, API key hashes, usage records, and the network data any request carries (such as IP address). | Yes | United States company. Runs a global network, so data can be handled in any country where it operates. Privacy policy |
| Stripe Stripe, Inc. | Payments: stores the card, charges it, issues invoices, retries failed payments and calculates tax. | Account email and name, card and billing details (entered directly with Stripe), tax ID, totals of metered usage, invoices. | No | United States, and other countries where Stripe operates. Privacy policy |
| Resend [TO BE COMPLETED: legal entity name of Resend] | Transactional email: sign-in codes and account, billing and service notices. | Account email address and the text of the message. | No | United States. Privacy policy |
2. Who handles your files
2.1Only Cloudflare handles the files you send and the results we return. The API, the processing engine and the temporary storage for jobs all run on its platform. The engine’s containers have no outbound internet access.
2.2Stripe and Resend never receive your files, their names or their contents. Stripe receives account and billing details and totals of metered usage. Resend receives your email address and the text of the messages we send you.
2.3We do not offer a fixed storage region today. Storage limited to the European Union is planned but is not available yet.
3. How changes are announced
3.1Before a new sub-processor starts to handle customer data, we give at least 30 days’ notice in two ways: by email to the address on each account, and by updating this page.
3.2Customers with a Data Processing Addendum may object during that period, as set out in section 6 of the addendum.
3.3If we must replace a sub-processor urgently, for security or to keep the service running, we give as much notice as we can.
4. What is not on this list
4.1Destinations you choose. If you ask us to fetch an input from an address, deliver a result to your own storage, or call your webhook, we send data to that address on your instruction. Those parties are yours, not our sub-processors.
4.2Our sub-processors’ own suppliers. Each company above publishes its own list.
4.3Advertising and analytics services. The developer pages, the documentation and the dashboard load no advertising or analytics scripts, and no such service receives API data: your files, your requests and your usage. To measure our own advertising we report three account events (an account created, a checkout started, an invoice paid) to Meta and to X, as described on the API privacy page. They receive those events as advertising services to us, not as sub-processors of customer data.
5. History of changes
- Draft 0.1, : first list (Cloudflare, Stripe, Resend).
Questions about this list: [email protected].