Subprocessor list
Subprocessors
This page describes the third-party service categories that may help 1API Club provide, secure, support, meter, and bill the Service.
Last updated: August 11, 2026.
- Routed customer content
- Not persisted by 1API Club platform storage.
- Gateway API keys
- Verified with a one-way digest rather than a plaintext copy.
- Change path
- Material changes are published, with a documented objection path.
Processing boundary
1API Club does not persist routed customer content in platform storage. Gateway API keys are not stored in plaintext; a one-way digest and limited lifecycle metadata are used to verify, rotate, revoke, secure, and audit a credential.
An upstream AI provider receives the content needed to fulfil a selected API request and may process it under its own terms, retention settings, abuse controls, and data controls. This platform-level boundary does not change processing by an upstream AI provider, customer application, or another independent party.
This list supports the GDPR, UK GDPR, and CCPA/CPRA processing boundaries described in Privacy and the Data Processing Addendum. It does not make a subprocessor or upstream AI provider an agent for purposes outside its own processing relationship.
Service categories
- Hosting, network, and security services
- Deliver the Service, secure requests, detect abuse, and maintain network reliability. Data: Connection and security metadata, account identifiers, API usage metadata, and service configuration data.
- Database and operational storage services
- Store and retrieve account, workspace, billing, usage, audit, and service-configuration records. Data: Account data, workspace and membership data, API key verification data, usage metadata, billing records, audit records, and security records.
- Authentication and identity services
- Authenticate users and protect access to the Service. Data: Email address, authentication identifiers, session and login metadata, and account identifiers.
- Payment and financial services
- Process payments, invoices, credits, refunds, disputes, tax-related records, and fraud review. Data: Billing contact data, payment identifiers and status, invoice and tax data, and dispute evidence.
- Communications and support services
- Deliver transactional messages and assist with customer support. Data: Email address, support messages and attachments a customer submits, and relevant account context.
- Analytics and service-observability services
- Measure service performance, diagnose operational issues, and improve the Service. Data: Device and browser data, service diagnostics, and usage or security metadata that do not include raw routed customer content.
- Upstream AI providers
- Process and return the content necessary to fulfil a selected API request. Data: Routed prompts, instructions, messages, files, tool inputs, outputs, model responses, and request metadata required for the provider-side request.
| Hosting, network, and security services | Deliver the Service, secure requests, detect abuse, and maintain network reliability. Data: Connection and security metadata, account identifiers, API usage metadata, and service configuration data. |
|---|---|
| Database and operational storage services | Store and retrieve account, workspace, billing, usage, audit, and service-configuration records. Data: Account data, workspace and membership data, API key verification data, usage metadata, billing records, audit records, and security records. |
| Authentication and identity services | Authenticate users and protect access to the Service. Data: Email address, authentication identifiers, session and login metadata, and account identifiers. |
| Payment and financial services | Process payments, invoices, credits, refunds, disputes, tax-related records, and fraud review. Data: Billing contact data, payment identifiers and status, invoice and tax data, and dispute evidence. |
| Communications and support services | Deliver transactional messages and assist with customer support. Data: Email address, support messages and attachments a customer submits, and relevant account context. |
| Analytics and service-observability services | Measure service performance, diagnose operational issues, and improve the Service. Data: Device and browser data, service diagnostics, and usage or security metadata that do not include raw routed customer content. |
| Upstream AI providers | Process and return the content necessary to fulfil a selected API request. Data: Routed prompts, instructions, messages, files, tool inputs, outputs, model responses, and request metadata required for the provider-side request. |
International transfers
A service provider may process data outside the country where a customer or data subject is located. Where applicable law requires a transfer mechanism, we use the contractual, statutory, or other lawful safeguard applicable to the processing relationship. A customer may contact [email protected] for information about the safeguards relevant to its processing relationship.
Changes and objections
We may add, replace, or remove service providers as the Service changes. We publish material changes to this list. A customer with a reasonable, documented data-protection objection can contact us before or promptly after a change takes effect; we will work in good faith to address a substantiated objection. If the parties cannot resolve it, Customer may stop using the affected part of the Service in accordance with the applicable agreement.
Contact and related policies
Contact [email protected] for privacy questions or [email protected] for legal questions and objections. Read Privacy, Data Processing Addendum, Terms, and Refunds for the related public policies.