Who receives your data.
Every third party in the path, what actually reaches them, and where they are. This is a statement of fact rather than a legal document, which is why it exists while the rest of this section does not.
| Who | What for | What reaches them | Where |
|---|---|---|---|
| OpenAI | Model inference, when you route to one of their models. | The prompt and any content you send with it. | United States |
| Anthropic | Model inference, when you route to one of their models. | The prompt and any content you send with it. | United States |
| OpenRouter | Model inference for models we do not hold a direct account with. | The prompt and any content you send with it. | United States |
| Stripe | Card payments and top-ups. | Billing name, email and payment details. Card numbers never reach Vatan. | United States and Ireland |
| Resend | Transactional email: verification, password reset, notifications. | Email address and the content of the message sent to you. | United States |
| Hetzner | Hosting and the database. | Everything the platform stores, at rest. | Germany |
Two things worth saying plainly
A model provider only receives what you route to it. If you never call an Anthropic model, nothing of yours reaches Anthropic. Which providers are in your path is your choice, made per request.
Vatan itself keeps no prompt or response body. A usage record holds the model, the token counts, the cost and the timings, which is what makes a charge recomputable without keeping your text. The detail is on the security page.
We will publish a notice period for changes to this list with the data processing agreement. Until then, ask on the quote form and we will tell you what is actually true today.