Subprocessors

Who else touches your data.

These are the third parties Keelen relies on to run the loop. Each one receives only what its function requires. The AI model providers receive your prompts and repository content only for the credential you connected, and they bill you directly under your own account.

GitHub
Source hosting, plus the OAuth session and the GitHub App installation tokens each run uses.
Data: Repository content and account identity.
Anthropic
AI model provider, used when you connect a Claude credential to a project.
Data: Prompts and the repository content the run reads or writes.
OpenAI
AI model provider, used when you connect a Codex credential to a project.
Data: Prompts and the repository content the run reads or writes.
Zhipu (GLM)
AI model provider, used when you connect a GLM credential to a project.
Data: Prompts and the repository content the run reads or writes.
Moonshot (Kimi)
AI model provider, used when you connect a Kimi credential to a project.
Data: Prompts and the repository content the run reads or writes.
Stripe
Payment processing and subscription management.
Data: Customer and subscription identifiers. We never store card data.
Fly.io
Compute for the API, the scheduler, and the single-use iteration machines.
Data: Everything a run needs while it runs, including the cloned repository and the short-lived tokens.
Cloudflare R2
Object storage.
Data: Iteration trajectories, QA evidence, and design-review screenshots.
Resend
Transactional email delivery (sign-in links and alerts).
Data: Your email address and the message we send you.
Sentry
Error monitoring for the web app and the API.
Data: Exception reports, stack traces, and request metadata.

We update this page when we add or remove a subprocessor.

Back to the privacy policy

Contact: privacy@keelen.ai · Effective 2026-08-13