Subprocessors
Last updated: 20 August 2026
IAM-Token uses the vendors below to run the Service for customers in the United Kingdom, the United States, and elsewhere. Model providers are instructed by your routing choice (or auto-routing). Payments and email are our processors. This list is incorporated into the Data Processing Addendum.
We will post material additions here and, for business customers, email the account owner at least 30 days before a new subprocessor that will process Customer Data, except in an emergency (security fix or provider outage). Object by writing to privacy@iam-token.com. If we cannot reasonably work around a timely objection, you may stop using the affected feature.
| Vendor | Role | Customer Data | Location / notes |
|---|---|---|---|
| Stripe, Inc. Privacy | Payment processing, Customer Portal, saved cards for auto-recharge | Name, email, customer id, charges, payment-method tokens. Not card PAN on our systems | United States (Stripe may process in other regions under its terms) |
| SMTP2GO (default) / SendGrid or SMTP if configured Privacy | Transactional email | Email address and message body (verification codes, login codes, password reset, receipts, contact form) | Provider-dependent; SMTP2GO commonly AU/US/EU PoPs |
| OpenAI, Anthropic, Google, Mistral, DeepSeek, xAI, Groq, NVIDIA, and other catalog providers | Model inference (customer-instructed) | Request payload needed to complete the call | Usually United States; some providers offer other regions under their own terms |
| E2B (optional) Privacy | Code-execution sandbox | Model-generated code and document specs for a short run | Enabled only if the deployment turns this on (default off) |
| Infrastructure host (the environment we or you deploy into) | Application, database, and object storage | Account, usage, billing references | As configured for that deployment. Regional-only routing is not a general product feature yet |
Independent providers
When a completion is generated, the model provider processes that request under its terms. Gateway zero-data-retention is not the same as provider ZDR. See Privacy Policy section 4.
We do not currently use Google Analytics, advertising networks, or session-replay vendors.