Subprocessor Registry
Parties that may process minimum necessary data to operate AI Blueprint.
Service registry
| Provider/service | Purpose | Minimum data | Location/transfer | Retention/training |
|---|---|---|---|---|
| Cloud Infrastructure (Coolify and private PostgreSQL) | Application hosting, database, workers, and backups | Service data subject to access controls | Singapore | AI Blueprint retention schedule; not an AI-training service |
| Hostinger International Limited | Domain and transactional SMTP email | Email, name, locale, template, and delivery metadata | May involve international processing under Hostinger policy | Internal mailbox/job lifecycle and Hostinger policy |
| Google LLC | User-selected OAuth sign-in | Basic Google identity, verified email, OAuth tokens, and authentication metadata | Account configuration and Google policy | Account/token lifecycle and Google policy |
| PT Midtrans | Checkout, status, webhook, refund, and reconciliation | Name/email, order, amount, method, status, and transaction reference | Midtrans service and terms | Transaction duties and Midtrans policy; AI Blueprint does not receive full payment credentials |
| OpenRouter, Inc. and route-selected upstreams | Route AI processing | Minimum prompt/context, output, tokens, model, and request metadata | May be processed internationally by OpenRouter and upstreams | OpenRouter says content logging is opt-in, but the production-account setting and upstream policies have not been verified as Zero Data Retention; route/provider policy applies |
| OpenAI, L.L.C. | AI processing when an OpenAI target is active directly or as upstream | Minimum prompt/context, output, tokens, model, and request metadata | May be processed internationally under the OpenAI service | OpenAI says API data is not used for training by default unless opted in and abuse logs are generally retained up to 30 days; production-organisation controls were not independently verified |