ClusterFast Legal
ClusterFast uses the subprocessors below to operate the service. This register is referenced from our Privacy Policy and may be updated as providers change. Privacy contact: support@clusterfast.app.
| Provider | Purpose | Data categories | Location / transfer | Safeguards |
|---|---|---|---|---|
| OpenAI | LLM inference for briefs, segmentation, research, and campaign generation | Prompts, structured context, generated outputs, usage metadata | United States | API terms, data processing agreement where available, prompt minimization, no training opt-out where supported |
| Google OAuth | Optional client authentication | Email, name, Google subject identifier, OAuth tokens during login | United States / global | OAuth 2.0, limited scopes, state signing |
| Meta Graph API | Optional ad account connection and campaign launch when enabled by the user | Meta user ID, ad account/page identifiers, encrypted access tokens, campaign payloads | United States / global | User-initiated connection, encrypted token storage, disconnect and erasure workflows |
| CityHost VDS | Application hosting, database hosting, backups | All service data stored for production operation | Ukraine / EU region depending on provider configuration | Private network exposure, encrypted secrets, restricted SSH access |
| GitHub Actions | CI testing and deployment automation | Source code, build logs, deployment metadata | United States / global | Repository access controls, secret management, least-privilege deploy keys |