Skip to content

Narrative Council · Hajar Labs LLC

Subprocessors

Version 2026-09-01-public-3

# Subprocessors **Effective date:** September 1, 2026 **Last updated:** September 1, 2026 Hajar Labs LLC uses service providers to operate Narrative Council. This page describes the current role-based list for the public service. A provider may process only the information necessary for its role and under applicable contractual, security, and legal controls. | Provider or category | Role | Information that may be involved | | --- | --- | --- | | Stripe | Payment processing and tax calculation | checkout and transaction identifiers; Stripe handles full payment-card data | | Google Gemini | Bounded source extraction | selected image or audio source material and minimal request context | | AssemblyAI | Client-requested voice transcription | recorded audio, transcription context, and session metadata | | Cloudflare Workers AI | Retrieval embeddings and bounded fallback model execution | scoped source chunks, embeddings, bounded strategic work packets, and request metadata | | Cloudflare Vectorize | Vector search and storage | embeddings, index metadata, and tenant-scoped identifiers | | Cloudflare R2 | Object storage | uploaded originals, generated exports, and object metadata | | Cloudflare AI Gateway | Configured AI request transport or observability | approved model requests and request metadata when enabled | | OpenRouter and its exact allowlisted downstream model-hosting endpoint | Primary strategic reasoning and quality-review transport | bounded strategic work packets and request metadata; prompt logging and provider data collection are disabled and zero-data-retention routing is required | | Tavily | Public-web research only | public queries, URLs, and public results; not private uploaded content | | Authentication, email, database, cloud-runtime, and security providers | Account access, messages, records, hosting, and protection | information necessary for the applicable service | The table is not a promise of a particular processing location, retention period, or model-training setting. Those facts depend on current provider terms, the exact OpenRouter downstream endpoint, and the active production configuration. We will update this page before a newly active provider or endpoint is allowed to receive client work. Direct OpenAI, DeepInfra, and the direct DeepSeek API are not current default subprocessors for new public engagements unless an authorized current provider profile and manifest permit them; approved DeepSeek and GLM models can be hosted by Cloudflare Workers AI as described above. Business clients may review the public Data Processing Addendum. Privacy questions or subprocessor concerns may be sent to keith@narrativecouncil.com.