Sub-processors
Third-party providers that process data on behalf of Fruxon, and the AI providers you can connect with your own API keys.
Last updated: August 2026
1. Overview
This page lists two distinct categories. Sub-processors (sections 2–3) are vendors Fruxon engages under contract to process data on our behalf; they are covered by the commitments in our Data Processing Addendum (DPA), including advance notice of changes. Customer-connected AI providers (section 4) are LLM providers you connect using your own API keys; you engage them directly under your own agreements, and they are not Fruxon sub-processors. This page is referenced by the Terms of Service and the DPA.
2. Infrastructure Sub-processors
Core infrastructure services used to host and operate the platform.
| Sub-processor | Purpose | Data Processing Location |
|---|---|---|
Google Cloud Platform (Google LLC) | Cloud hosting, compute, storage, KMS, Pub/Sub, Secret Manager | EU / US (configurable per deployment) |
Cloud SQL for PostgreSQL (Google LLC) | Primary relational database | Same region as GCP deployment |
3. Service Sub-processors
Additional third-party services used for specific platform functions.
| Sub-processor | Purpose | Data Processing Location |
|---|---|---|
Firebase (Google LLC) | User authentication | United States |
Stripe, Inc. | Payment processing and billing | United States |
Mixpanel, Inc. | Product analytics | United States |
Twilio, Inc. | SMS and messaging connectors | United States |
4. Customer-Connected AI Providers
Fruxon operates on a bring-your-own-key (BYO-Key) model: your agents call LLM providers using API keys you supply, under your own agreement with each provider. Data is sent to a provider only when you configure it and initiate agent executions. Because you engage these providers directly, they are not Fruxon sub-processors — each provider's own terms govern your data once it reaches them. This list is provided for transparency:
| Provider | Purpose | Data Processing Location |
|---|---|---|
OpenAI (OpenAI, L.P.) | LLM inference | United States |
Anthropic (Anthropic, PBC) | LLM inference | United States |
Google — Gemini (Alphabet Inc.) | LLM inference | United States |
Google — Vertex AI (Alphabet Inc.) | LLM inference | Region configurable by customer |
DeepSeek (DeepSeek AI, Hangzhou) | LLM inference | China |
xAI — Grok | LLM inference | United States |
Amazon Web Services — Bedrock | LLM inference | Region configurable by customer |
VoyageAI | Embedding / LLM inference | United States |
Hugging Face | LLM inference | United States / EU |
OpenAI-compatible custom endpoints | LLM inference (customer-specified) | Customer-determined |
Provider data-use practices differ and may change. Some providers may use API inputs and outputs to train or improve their models, while others offer no-training terms. If your requirements prohibit training on your data, review the provider's terms before enabling it.
DeepSeek — China data processing and model training
DeepSeek processes data on servers located in China, and its terms permit the use of API inputs and outputs to train and improve its models, with no opt-out available. If you configure DeepSeek as a provider, prompts and agent data are transmitted to and processed in China and may be used for training. This may have implications under GDPR, data residency requirements, and other data protection regulations. You are responsible for ensuring compliance with applicable data transfer requirements before enabling DeepSeek.
5. Change Notification
We update this page when we add or remove sub-processors. If you have a DPA with us, we will notify you of material changes to our sub-processors (sections 2–3) at least 30 days in advance via email. The customer-connected AI provider list is maintained for transparency and updated as provider support changes. Subscribe to updates by emailing privacy@fruxon.com.
6. Contact
Questions about our sub-processors? Contact us at privacy@fruxon.com.