AI Reserve Developer Documentation

Trust & Disclosures

Subprocessors

This page maintains the current list of Subprocessors engaged by Audacity Advisory Corp (operating as AI Reserve) to process Personal Data on behalf of clients, including their functions and jurisdictions, as referenced in Annex 5 of our Data Processing Addendum. It also identifies model providers that act as independent controllers rather than subprocessors, as the DPA requires. This page may be updated from time to time.

Last reviewed: July 23, 2026

Definitions


A Subprocessor is a third party engaged by AI Reserve to process Personal Data on our clients' behalf, acting only on our documented instructions.

Under our Data Processing Addendum, a provider that processes data for its own purposes — for example, a model provider whose terms permit it to train or fine-tune on inputs — is an independent controller, not a subprocessor. Such providers are identified separately in the Independent controllers section below. Requests are only sent to those providers when a user or client explicitly selects one of their models.

Per-provider detail on training, retention, and processing region is on the Provider Data Handling page.

Infrastructure & platform subprocessors


These providers support the operation of the AI Reserve platform itself and may process Personal Data in the course of providing their services.

Subprocessor Function Jurisdiction
Google Cloud Platform Cloud hosting, compute, databases, object storage, secret management, and logging for all AI Reserve services United States
Google Firebase Authentication Identity and sign-in for the AI Reserve portal (web application) United States
Auth0 by Okta OIDC identity brokering for keyless desktop-application sign-in (e.g. Claude Desktop) United States
IPinfo IP geolocation and anonymizer screening for the machine API. Receives request IP addresses only — never request content United States

Model providers acting as subprocessors


When a user or client selects a model, the request content is processed by the model's provider. The following providers process request data only to deliver inference, do not train on API inputs under their current enterprise terms, and act as subprocessors. A request is sent only to the provider serving the specific model selected — no provider receives traffic for models it does not serve.

Subprocessor Function Jurisdiction
OpenAI, L.L.C. Model inference (GPT model family; embeddings; image generation) United States
Anthropic, PBC Model inference (Claude model family, direct API) United States
Amazon Web Services (Bedrock) Model inference for -bedrock routed models (Anthropic Claude, Meta Llama, Mistral, DeepSeek serverless) — model publishers do not receive request data United States
Google (Gemini API) Model inference (Gemini model family; image generation), paid tier United States (processing may occur globally — see data handling)
xAI Corp. Model inference (Grok model family) United States
Perplexity AI, Inc. Model inference with web search grounding (Sonar model family) United States
Together Computer, Inc. (Together AI) Hosted inference of open-weight models (e.g. Qwen, DeepSeek V4 Pro, Kimi K2.7, MiniMax, GPT-OSS-20B) United States
Fireworks AI, Inc. Hosted inference of open-weight models (e.g. GLM, Qwen, Kimi K2.6, DeepSeek V4 Flash, GPT-OSS-120B) United States
OpenRouter, Inc. Routing layer for certain open-weight model routes (Meta Llama, Mistral). OpenRouter itself does not store request content by default; the downstream serving endpoint's policy applies — per-route endpoints pending verification United States (routing); downstream endpoint varies
fal — Features & Labels, Inc. (fal.ai) Hosted video and image generation United States

Model providers acting as independent controllers


The following model providers' current terms permit them to process request data for their own purposes (including using inputs to train or improve their services). Under our DPA they are therefore independent controllers, not subprocessors, and are identified as such. Requests reach these providers only when a user or client explicitly selects one of their directly-served models. Open-weight DeepSeek and Moonshot models served by US aggregators (Fireworks, Together) or AWS Bedrock do not send data to these companies.

Provider Function Jurisdiction Why independent controller
Hangzhou DeepSeek Artificial Intelligence Co., Ltd. Model inference, direct DeepSeek API (deepseek-chat, deepseek-reasoner) China (PRC) — data collected, processed, and stored on servers in the PRC Privacy policy states inputs are used to train and improve its models and services
Moonshot AI (Kimi) Model inference, Moonshot's own API (kimi-k3, moonshot-v1-*) China (PRC-headquartered). International platform terms state Singapore-located servers; endpoint serving our account pending verification Platform privacy policy states user content is used to train and refine its models
NVIDIA Corporation (hosted NIM API catalog) Model inference (Nemotron model family) United States Published API-catalog trial terms permit NVIDIA to use inputs/outputs to improve its products and services, including AI models. Whether different terms govern our account tier: pending verification — classified conservatively as independent controller until confirmed

Other service providers


Data enrichment (Harmonic). The platform's business-data features use a company-data enrichment provider that receives only public company identifiers (such as company names and website domains) — never client request content, prompts, completions, or personal data of client users.

Updates to this list


This list is maintained on the Platform per Annex 5 of our Data Processing Addendum and is reviewed periodically. When we engage a new subprocessor that will process Personal Data, we update this page and provide any notice required by the DPA. Items marked pending verification reflect characteristics we have not yet confirmed from official documentation — confirm before relying on them.

Questions about this list or our DPA: contact product@aireserve.com.