Subprocessors
Provider roles planned for Ownspoken's public service.
Effective September 16, 2026Version 2026-09-16-public-1
Current launch roles
Hajar Labs uses service providers to operate Ownspoken. A provider may receive only the information needed for its role and under the active account, product, contractual, security, and legal controls.
- Cloudflare — application hosting, D1 records, private R2 objects, durable work, PDF rendering, email delivery, security, and optional Workers AI document conversion.
- Google Firebase Authentication — Google and email-link identity verification. Google Cloud Run may be used only for a demonstrated extraction or rendering requirement, not as a second application authority.
- Stripe — hosted checkout, subscriptions, invoices, payment methods, tax-related checkout data, and billing lifecycle events.
- OpenRouter and the exact allowlisted downstream hosting endpoint — bounded AI work packets and request metadata for reasoning and generation. Provider fallback is disabled for qualified routes.
- DeepInfra — the preferred platform-owned upstream credential path for selected qualified models when enabled through the allowlisted route.
- Parallel — public-web search, extraction, and shared public company monitoring; private uploaded content is not intended for public-search queries.
Provider changes
This page describes roles, not a promise of a specific processing location, retention period, or model-training policy. Those facts depend on the exact active endpoint and current terms. We will update this page before a materially new provider is allowed to receive customer content. Send questions or a reasonable data-protection objection to keith@narrativecouncil.com.