Subprocessors
Last updated: August 23, 2026
Overview
ROJI Inc. ("ROJI," "we," "us," or "our") engages the third parties listed below to help deliver the roji.ai platform (the "Services"). Each is bound by a data processing agreement consistent with our Data Processing Agreement and applicable data protection law.
This page is maintained under Section 7 of the DPA. We update it at least 30 days before a new subprocessor begins processing personal data.
ROJI runs on Google Cloud Platform. Effectively all customer data — the database, uploaded files, the event bus, secrets, and the containers running every service — lives in Google Cloud, in the us-central1 region. The other entries below are narrow, single-purpose, and each one is named with the specific data that reaches it.
Subscribing to updates
To be notified when this list changes, email privacy@roji.ai with the subject "Subprocessor Updates." Objections are handled under Section 7.4 of the DPA.
1. Google Cloud Platform — primary infrastructure
Google LLC / Google Cloud EMEA. All resources below run in us-central1 (Iowa, United States) unless noted.
| Service | What we use it for | Data it touches |
|---|---|---|
| Cloud Run | Runs every ROJI service: the API, the web app, the admin console, the OAuth consent service, the MCP server, and the background workers | All customer data, in transit and in processing |
| Cloud SQL for PostgreSQL | The primary application database, and the persistence layer for our workflow engine | Everything we store: accounts, users, email addresses, service listings, orders, payment records, credential metadata |
| Cloud Storage | Two buckets. One holds order deliverables and attachments — the actual work product a business delivers. One holds credential-verification documents, which are encrypted on our side before upload with a per-file key wrapped by Cloud KMS | Customer content; credential documents |
| Cloud KMS | Holds the key that wraps the per-file keys for the credential-evidence bucket | Key material only — never customer data |
| Secret Manager | Stores every credential the platform needs: database URLs, signing keys, third-party API keys | Secrets only — never customer data |
| Pub/Sub | The domain-event bus that drives notifications, workflows, search indexing and outbound webhooks | Event payloads: entity identifiers, business and account names, order state, and the email addresses the notification consumer needs |
| Memorystore (Valkey) | Rate limiting and idempotency keys | Rate-limit keys derived from request identity; idempotency keys |
| Compute Engine | Three virtual machines we operate ourselves — see "Run on our own infrastructure" below | Whatever those services hold (workflow history, the search index) |
| Cloud Build, Artifact Registry | Building and storing the container images we deploy | Source code and build-time secrets. No customer data |
| Cloud Scheduler | Triggers recurring maintenance jobs | Trigger metadata only |
| Cloud Logging, Cloud DNS | Infrastructure logs for the virtual machines and build system; internal service discovery | Application and system logs; request metadata |
2. Everything else
| Subprocessor | What we use it for | Data it touches | Location |
|---|---|---|---|
| Stripe, Inc. | All payments. Buyers' cards, businesses' payout accounts, the charge at order, refunds, and the KYB identity checks a business goes through before it can be paid | Card details, entered directly into Stripe's own form — they never reach ROJI's servers. Buyer name and email. For businesses: the legal-entity, beneficial-ownership and bank details Stripe collects during onboarding. Order amounts and references | United States / global |
| Google (Firebase Authentication) | Sign-in. Google sign-in, session tokens, and the identity behind every account | Email address, display name, profile photo URL, and the authentication identifiers Google issues | Google infrastructure |
| Mailgun (Sinch) | Every transactional email we send — invitations, order notifications, verification and credential notices, receipts | Recipient email addresses and the full rendered message, which contains names and order details. Open and click tracking is enabled, so Mailgun also records recipient engagement, IP address and user agent | United States (api.mailgun.net) |
| Dash0 GmbH | Application performance monitoring and alerting: distributed traces from our services, and browser performance data from our web apps | Telemetry — route names, request URLs, timings, service identity. From browsers, page-view and web-vitals data, and the IP address and user agent that any request carries. No customer content is deliberately attached to a trace | AWS us-west-2 (United States) |
| Anthropic, PBC | One optional feature: drafting. When you ask ROJI to turn a description of your business into a draft service listing, application, or profile, that text is sent to a Claude model | Only the free text you paste into a drafting field, up to 8,000 characters — typically your own website copy or a description of what you do. It can contain personal data because you may choose to include it. Nothing else in your account is sent. Skipping the drafting feature means nothing reaches Anthropic | United States |
| Cloudflare, Inc. | Authoritative DNS for roji.ai, and the redirect that sends www.roji.ai to the apex domain | DNS query metadata; request metadata for the www redirect only. Cloudflare is not in the serving path for roji.ai pages, the API, or the MCP endpoint — those are served directly from Google Cloud | Global edge network |
| GitHub, Inc. (Microsoft) | Source hosting and continuous integration | Source code and build secrets. No production customer data | United States |
Run on our own infrastructure — not subprocessors
Three components people often assume are hosted services are not. We run both ourselves, on Google Compute Engine instances inside our own project, with no data reaching the vendor:
- Temporal — our workflow engine. Self-hosted from the open-source distribution, persisting to our own Cloud SQL instance. Temporal Technologies Inc. receives nothing.
- Typesense — our search index. Self-hosted from the open-source distribution on a machine with no public IP. Typesense Inc. receives nothing. The index does contain personal data (names, email addresses) and is covered by the Google Cloud entry above.
- c15t — the cookie-consent banner. It runs entirely in your browser in offline mode: your choice is stored on your own device, and c15t GmbH receives nothing. The record we keep of that choice is written to our own database (see the Cookie Policy) and is covered by the Google Cloud entry above.
AI and training
The only AI subprocessor is Anthropic, and only for the drafting feature described above. Data sent for drafting is not used to train models. We do not send customer data to any other model provider.
What is deliberately not here
We run no analytics or advertising vendors — no Google Analytics, no product-analytics SDK, no advertising or measurement pixels. No third party receives a record of your visits to this site.
International transfers
For subprocessors outside the European Economic Area, the United Kingdom or Switzerland, we rely on:
- Standard Contractual Clauses approved by the European Commission
- the UK International Data Transfer Agreement or Addendum, where applicable
- supplementary technical and organisational measures where needed
Contact
ROJI Inc. Email: privacy@roji.ai Website: https://roji.ai