Subprocessors — DRAFT
The rule that decides who is on this list: a nearshore or frontier provider is a subprocessor the moment a prompt routes there, on your own key and by your own configuration. It does not matter that we never hold the prompt, never see the key, and take no cut of the tokens. Your prompt reaches a company other than you because software we wrote sent it, and the honest disclosure names that company. [OPS-051]
Every inference row below is your account, not ours: we have no contract with those providers on your behalf, so the terms that govern your prompts there are the ones between you and the provider, and this page links to them rather than standing in for them. With no key stored, none of the inference rows can ever receive anything. [invariant 1] [invariant 3]
Inference providers
Each receives the prompt and context of a request the router sends to its lane,
after secret redaction, and only if you stored a key for it. The id in the second
column is the word after rr keys set. [RR-034]
| Subprocessor | Id | Lane | Whose account | Their terms |
|---|---|---|---|---|
| Anthropic | anthropic | frontier | Yours | privacy · DPA |
| OpenAI | openai | frontier | Yours | privacy · DPA |
| DeepSeek | deepseek | frontier | Yours | privacy · no DPA found |
| Together AI | together | nearshore | Yours | privacy · terms · no standalone DPA found |
| Fireworks | fireworks | nearshore | Yours | privacy · DPA (PDF) |
| Groq | groq | nearshore | Yours | privacy · DPA |
| slop.city | slop | nearshore | Yours | privacy · no DPA found; invite-only beta |
Infrastructure
The parties on our side of the line, and the only ones that can see anything from a user who never adds a key. What they see is a page load and a registry fetch.
| Subprocessor | Role | What they receive, and when | Whose account | Their terms |
|---|---|---|---|---|
| Vercel | hosts getrumrunner.com and the registry API | Ordinary HTTP request metadata for page and registry fetches; the aggregate telemetry payload only when you have enabled and sent it; the waitlist address and consent record once the waitlist ships. [RR-052] [RR-091] | Ours | privacy · DPA |
| Stripe | payments — not yet live; listed now so it is not forgotten when checkout ships | Name, email, card and billing address at checkout, once there is a checkout. [OPS-024] | Ours | privacy · DPA |
| ImprovMX | inbound mail forwarding for hello@getrumrunner.com | Every email a person sends to hello@, in transit to the mailbox behind it. [RR-092] | Ours | privacy · no DPA found |
| Outbound mail provider | confirmation and notice email — not yet chosen | Recipient address and the message; this row is a placeholder until the sending half of the mail work picks one. [RR-092] | Ours | added with the pick |
GoDaddy registers and resolves the domains and is deliberately not on this list: no user content, address or telemetry passes through a name lookup. Named here once so the question reads as answered rather than missed.
How this list stays true
We do not sell, rent or share any of the above with anyone not on this list. [OPS-051]
The list is updated in the same change as any change to the program's providers — never in a follow-up. A test in the product repo fails when a provider the program can route to is missing from this page, so adding one without disclosing it is a red build rather than an oversight. Changes to this list are dated here and emailed to subscribers before they take effect. [OPS-050 §8]
Read alongside the privacy policy and the terms of service. This page is the list both of them cite.