Subprocessors

Who else touches your data.

These are the third parties Keelen relies on to run the loop. Each one receives only what its function requires. AI model providers receive prompts and repository content for a delegated run using the connected credential. Provider billing and access terms depend on the credential route.

GitHub
Source hosting, plus the OAuth session and the GitHub App installation tokens each run uses.
Data: Repository content and account identity.
Anthropic
AI model provider, used when you connect a Claude credential to a project.
Data: Prompts and the repository content the run reads or writes.
OpenAI
AI model provider, used when you connect a Codex credential to a project.
Data: Prompts and the repository content the run reads or writes.
Zhipu (GLM)
AI model provider, used when you connect a GLM credential to a project.
Data: Prompts and the repository content the run reads or writes.
Moonshot (Kimi)
AI model provider, used when you connect a Kimi credential to a project.
Data: Prompts and the repository content the run reads or writes.
xAI (Grok)
AI model provider, used when you connect a Grok credential to a project.
Data: Prompts and the repository content the run reads or writes.
Stripe
Payment processing and subscription management.
Data: Customer and subscription identifiers. We never store card data.
Fly.io
Compute for the API, the scheduler, and the single-use iteration machines.
Data: Everything a run needs while it runs, including the cloned repository and the short-lived tokens.
Cloudflare R2
Object storage.
Data: Iteration trajectories, QA evidence, and design-review screenshots.
Resend
Transactional email delivery (sign-in links and alerts).
Data: Your email address and the message we send you.
Sentry
Error monitoring for the web app and the API.
Data: Exception reports, stack traces, and request metadata.

We update this page when we add or remove a subprocessor.

Back to the privacy policy

Contact: privacy@keelen.ai · Effective 2026-09-11