Subprocessors
Last updated: 26 September 2026
Jein (jein.dev) uses the service providers below to run the service. This list is Annex 2 of our Data Processing Agreement (https://jein.dev/dpa/). It also shows which provider handles which data, so you can see where content sent to the API goes.
Subprocessors for Customer Data
These providers process the content that customers send to the API ("Customer Data" under the Data Processing Agreement). Changes to this section follow the notice and objection procedure below.
| Subprocessor | Service | Data processed | Location of processing | Transfer mechanism |
|---|---|---|---|---|
| DigitalOcean, LLC (USA) | Hosting: application platform, managed PostgreSQL database, container registry | API request content, in memory only while a request runs | Frankfurt, Germany (region FRA1) | Processing in the EU. For possible access from the USA: EU-U.S. Data Privacy Framework (adequacy decision; listed as active in the official DPF list on 25 September 2026) and EU Standard Contractual Clauses in the DigitalOcean DPA |
| Cloudflare, Inc. (USA), engaged by DigitalOcean | Edge network of the application platform: receives connections, terminates TLS, filters attacks and bots, forwards requests | API requests in transit; API responses are not cached | Edge location nearest to the client, which can be outside the EU | EU-U.S. Data Privacy Framework (adequacy decision; listed as active in the official DPF list on 25 September 2026; active; re-certification under review); EU Standard Contractual Clauses under DigitalOcean's DPA |
API request content is never written to disk, database or logs (see the Data Processing Agreement, section 2). Customer Data that a customer sends to our support e-mail nevertheless is handled as section 2.4 of that agreement describes.
Other processors
These providers process personal data for which we are the controller (for example account data or website statistics), as described in our Privacy Policy (https://jein.dev/privacy/). They never receive API request content.
| Processor | Service | Data processed | Location of processing | Transfer mechanism |
|---|---|---|---|---|
| DigitalOcean, LLC (USA) and Cloudflare, Inc. (USA) | Hosting and edge network, as above | Account, API key, usage and log data; connection data of website visitors | As above | As above |
| Okta, Inc. (Auth0) (USA) | Login, identity and account e-mails (address verification, password reset) | E-mail address, password hash, login events | Region of our Auth0 tenant, see note below | EU-U.S. Data Privacy Framework (adequacy decision; listed as active in the official DPF list on 25 September 2026; Okta’s entry covers Auth0, LLC and Auth0 International LLC) and EU Standard Contractual Clauses in the Okta DPA |
| Plausible Insights OÜ (Estonia) | Website analytics on https://jein.dev, only after consent | Page views, engagement events (scroll depth, time on page) and tracked clicks, as individual records without IP address, user agent or cookie id | EU (Germany, Finland; content delivery in the EU) | No transfer to a third country |
DigitalOcean's own subprocessors are listed at https://www.digitalocean.com/trust/subprocessors.
Note on Auth0: Auth0 stores identity data in the region of our Auth0 tenant. Until that region is stated here, assume the data may be processed in the USA, covered by the safeguards in the table.
Not subprocessors
These providers receive no personal data of our customers and are listed for transparency only:
- GitHub, Inc. (USA): source code, continuous integration and release builds.
- Hugging Face, Inc.: our servers download the published Laya model weights from Hugging Face when they start. No customer data is sent.
We serve all fonts and scripts of the website and dashboard ourselves. The only third-party script is the Plausible analytics script, loaded from plausible.io and only after consent.
Changes
We inform customers at least 30 days before we add or replace a subprocessor for Customer Data, by e-mail to the address of their account and by updating this page. Customers may object within that period on reasonable data protection grounds, as described in section 8 of the Data Processing Agreement. Where a subprocessor intends to engage or replace its own subprocessors for Customer Data, we inform customers without undue delay after we receive the subprocessor's notice, and in any case before the change takes effect where that notice allows this; customers may object within 30 days of our notice.
| Date | Change |
|---|---|
| 24 September 2026 | First version of this list |
| 26 September 2026 | Replaced provider statements with official DPF status checked on 25 September 2026; recorded Cloudflare’s re-certification review and Auth0 coverage under Okta |