Pipefork Subprocessor Registry
Last reviewed: 2026-09-25 Review cadence: Before production provider changes and at least quarterly
Scope
This registry identifies the providers currently configured to process personal data when Pipefork provides the Service. A provider may receive data only when the relevant feature is used. The precise data depends on the customer's configuration and request content. For questions about processing locations or international transfer safeguards, contact support@pipefork.com.
Pipefork-Selected Providers
| Provider | Service provided | Personal data that may be processed | Current use | Provider information |
|---|---|---|---|---|
| Vercel | Website and control-plane hosting, network delivery, operational logs, and Speed Insights | Account and session data, technical request metadata, limited application logs, and cookieless browser performance measurements | Active | DPA, Speed Insights privacy |
| Supabase | Authentication, database, and storage | Account, workspace, legal acceptance, API configuration, operational and request-log records | Active | DPA |
| Google Cloud | Cloud Run API runtime, Secret Manager, and operational logs | Runtime requests and responses in transit, request metadata, and encrypted secret material | Active for managed runtime | Cloud Data Processing Addendum |
| Upstash | Shared rate limiting and runtime cache | Workspace and request identifiers, counters, and cached step outputs when caching is enabled | Active for control-plane rate limiting and managed runtime; response caching depends on configuration | DPA |
| Cloudflare | Turnstile protection for sign-in | Browser and security signals and verification tokens | Active on protected sign-in forms | Turnstile privacy addendum |
| Kilo Code | Managed AI Builder model access when selected | Prompts, relevant API context, generated outputs, and request metadata | Enabled as a Pipefork-managed AI provider | Privacy Policy |
| OpenRouter | Managed AI Builder model routing when selected | Prompts, relevant API context, generated outputs, and request metadata | Enabled as a Pipefork-managed AI provider | Privacy Policy, model-provider policies |
| Stripe | Test checkout and billing | Billing contact, checkout, subscription, and payment metadata | Enabled in test mode; receives data when a test billing flow is used | DPA |
Kilo Code and OpenRouter may route AI Builder requests to the model host selected for a request. The downstream host and its data practices can vary by model and provider configuration. Pipefork does not use Customer Content to train AI models; this statement does not replace the terms that apply to a selected model provider.
Customer-Selected Providers
Workspace-configured upstream APIs, BYOK LLM providers, customer-owned external secret providers, and private runners are chosen and controlled by the customer. They are not Pipefork-selected subprocessors. The customer is responsible for their provider terms, lawful basis, notices, retention, deletion, and international transfer safeguards.
Changes
Pipefork updates this registry when its production provider set materially changes and gives notice where required by the Data Processing Addendum or applicable law. The Privacy Policy describes the categories and purposes of processing; the Data Processing Addendum governs Customer Personal Data processed on behalf of customers.