Subprocessors
Last updated: September 22, 2026
These companies process personal data for the Darak API and developer platform: your team's account details, and request metadata (IP address, user agent, request parameters) in your request logs. Listing data returned by the API is Darak's own data and isn't covered here.
We give at least 30 days' notice before adding a subprocessor, in the changelog and by email to organization owners.
| Subprocessor | What it does for us | Data it processes | Where |
|---|---|---|---|
| Vercel | Hosts the API, dashboard and docs | All of the above, in transit and in memory while serving requests | United States (primary), global edge network |
| Neon | Database | Accounts, organizations, keys (hashed), request logs, usage, audit log | United States (AWS us-east-1) |
| Cloudflare | DNS, TLS and network protection for darak.app domains | Request metadata (IP address, headers) | Global |
| Resend | Sends email: sign-in links, invitations, security and usage notices | Names and email addresses | United States |
| "Continue with Google" sign-in, when you choose it | Name, email address and account identifier from Google | Global | |
| PostHog | Product analytics on the dashboard and API usage events | Account identifiers, pages visited, API call metadata (no request parameters) | United States |
| Stripe | Payments, subscriptions and invoices | Billing contact, company and tax details, payment method (held by Stripe) | United States, global |
Questions: contact us.