Subprocessors

Last updated: June 29, 2026

Tokmeter uses the following third-party processors to deliver the Services. Each operates under a written data processing agreement and is reviewed before onboarding.

Subscribe to changes by emailing privacy@tokmeter.ai or via our contact form — we provide 30 days' notice of new subprocessors that materially change data handling.

ProcessorPurposeCategories of dataRegion
Lovable Cloud (Supabase)Primary application database, auth, and storageAccount, org, usage rollups, audit logUS (multi-region available on Enterprise)
CloudflareCDN, edge compute, TLS termination, DDoS protectionNetwork metadata, hashed IPsGlobal edge
PaddleSubscription billing, tax compliance, merchant of recordBilling contact, plan, country, tax IDUK / US
ResendTransactional & system email deliveryEmail address, message content (auth links, receipts, DSR notices)US / EU
OpenAIAI Gateway proxy (only when org enables the gateway and routes to this provider)Prompt/response if org enables body captureUS
AnthropicAI Gateway proxy (only when org enables it)Prompt/response if org enables body captureUS
Google (Vertex / Gemini)AI Gateway proxy (only when org enables it)Prompt/response if org enables body captureUS / EU

Customer-controlled processors

When your organization connects a provider (OpenAI, Anthropic, Vertex, Bedrock, Azure OpenAI, Copilot, Cursor, LangSmith, n8n, OTel exporter), that provider becomes a processor of your data on your instructions. Tokmeter only reads the billing and usage metadata exposed by that provider's admin/billing API; we never call the chat/completions endpoints with read-only credentials.

Transfer safeguards

For transfers out of the EEA/UK/Switzerland we rely on the EU Standard Contractual Clauses and the UK IDTA/Addendum. For transfers out of Canada we rely on PIPEDA-compliant contractual commitments with each processor.