Skip to content

Subprocessors

Last updated: August 23, 2026

Overview

ROJI Inc. ("ROJI," "we," "us," or "our") engages the third parties listed below to help deliver the roji.ai platform (the "Services"). Each is bound by a data processing agreement consistent with our Data Processing Agreement and applicable data protection law.

This page is maintained under Section 7 of the DPA. We update it at least 30 days before a new subprocessor begins processing personal data.

ROJI runs on Google Cloud Platform. Effectively all customer data — the database, uploaded files, the event bus, secrets, and the containers running every service — lives in Google Cloud, in the us-central1 region. The other entries below are narrow, single-purpose, and each one is named with the specific data that reaches it.

Subscribing to updates

To be notified when this list changes, email privacy@roji.ai with the subject "Subprocessor Updates." Objections are handled under Section 7.4 of the DPA.

1. Google Cloud Platform — primary infrastructure

Google LLC / Google Cloud EMEA. All resources below run in us-central1 (Iowa, United States) unless noted.

ServiceWhat we use it forData it touches
Cloud RunRuns every ROJI service: the API, the web app, the admin console, the OAuth consent service, the MCP server, and the background workersAll customer data, in transit and in processing
Cloud SQL for PostgreSQLThe primary application database, and the persistence layer for our workflow engineEverything we store: accounts, users, email addresses, service listings, orders, payment records, credential metadata
Cloud StorageTwo buckets. One holds order deliverables and attachments — the actual work product a business delivers. One holds credential-verification documents, which are encrypted on our side before upload with a per-file key wrapped by Cloud KMSCustomer content; credential documents
Cloud KMSHolds the key that wraps the per-file keys for the credential-evidence bucketKey material only — never customer data
Secret ManagerStores every credential the platform needs: database URLs, signing keys, third-party API keysSecrets only — never customer data
Pub/SubThe domain-event bus that drives notifications, workflows, search indexing and outbound webhooksEvent payloads: entity identifiers, business and account names, order state, and the email addresses the notification consumer needs
Memorystore (Valkey)Rate limiting and idempotency keysRate-limit keys derived from request identity; idempotency keys
Compute EngineThree virtual machines we operate ourselves — see "Run on our own infrastructure" belowWhatever those services hold (workflow history, the search index)
Cloud Build, Artifact RegistryBuilding and storing the container images we deploySource code and build-time secrets. No customer data
Cloud SchedulerTriggers recurring maintenance jobsTrigger metadata only
Cloud Logging, Cloud DNSInfrastructure logs for the virtual machines and build system; internal service discoveryApplication and system logs; request metadata

2. Everything else

SubprocessorWhat we use it forData it touchesLocation
Stripe, Inc.All payments. Buyers' cards, businesses' payout accounts, the charge at order, refunds, and the KYB identity checks a business goes through before it can be paidCard details, entered directly into Stripe's own form — they never reach ROJI's servers. Buyer name and email. For businesses: the legal-entity, beneficial-ownership and bank details Stripe collects during onboarding. Order amounts and referencesUnited States / global
Google (Firebase Authentication)Sign-in. Google sign-in, session tokens, and the identity behind every accountEmail address, display name, profile photo URL, and the authentication identifiers Google issuesGoogle infrastructure
Mailgun (Sinch)Every transactional email we send — invitations, order notifications, verification and credential notices, receiptsRecipient email addresses and the full rendered message, which contains names and order details. Open and click tracking is enabled, so Mailgun also records recipient engagement, IP address and user agentUnited States (api.mailgun.net)
Dash0 GmbHApplication performance monitoring and alerting: distributed traces from our services, and browser performance data from our web appsTelemetry — route names, request URLs, timings, service identity. From browsers, page-view and web-vitals data, and the IP address and user agent that any request carries. No customer content is deliberately attached to a traceAWS us-west-2 (United States)
Anthropic, PBCOne optional feature: drafting. When you ask ROJI to turn a description of your business into a draft service listing, application, or profile, that text is sent to a Claude modelOnly the free text you paste into a drafting field, up to 8,000 characters — typically your own website copy or a description of what you do. It can contain personal data because you may choose to include it. Nothing else in your account is sent. Skipping the drafting feature means nothing reaches AnthropicUnited States
Cloudflare, Inc.Authoritative DNS for roji.ai, and the redirect that sends www.roji.ai to the apex domainDNS query metadata; request metadata for the www redirect only. Cloudflare is not in the serving path for roji.ai pages, the API, or the MCP endpoint — those are served directly from Google CloudGlobal edge network
GitHub, Inc. (Microsoft)Source hosting and continuous integrationSource code and build secrets. No production customer dataUnited States

Run on our own infrastructure — not subprocessors

Three components people often assume are hosted services are not. We run both ourselves, on Google Compute Engine instances inside our own project, with no data reaching the vendor:

  • Temporal — our workflow engine. Self-hosted from the open-source distribution, persisting to our own Cloud SQL instance. Temporal Technologies Inc. receives nothing.
  • Typesense — our search index. Self-hosted from the open-source distribution on a machine with no public IP. Typesense Inc. receives nothing. The index does contain personal data (names, email addresses) and is covered by the Google Cloud entry above.
  • c15t — the cookie-consent banner. It runs entirely in your browser in offline mode: your choice is stored on your own device, and c15t GmbH receives nothing. The record we keep of that choice is written to our own database (see the Cookie Policy) and is covered by the Google Cloud entry above.

AI and training

The only AI subprocessor is Anthropic, and only for the drafting feature described above. Data sent for drafting is not used to train models. We do not send customer data to any other model provider.

What is deliberately not here

We run no analytics or advertising vendors — no Google Analytics, no product-analytics SDK, no advertising or measurement pixels. No third party receives a record of your visits to this site.

International transfers

For subprocessors outside the European Economic Area, the United Kingdom or Switzerland, we rely on:

  • Standard Contractual Clauses approved by the European Commission
  • the UK International Data Transfer Agreement or Addendum, where applicable
  • supplementary technical and organisational measures where needed

Contact

ROJI Inc. Email: privacy@roji.ai Website: https://roji.ai