Who processes what
Each row comes from the audit of the Fleet code and its deployment configuration, with the file that shows the connection. Where a processor's location or retention could not be established from what we control, the cell says unknown rather than a guess.
| Processor | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Identity provider (Auth, OAuth 2.1 server) and the operations database for the hosted service. | Account email and user id, organization and membership records, hashed session and invitation tokens, job records and events, spend reservations, hashed OpenRouter key ids, learning records. | US East (project verified as us-east-1) |
| Railway | Hosting for the API and the two private services, their private network, TLS termination, and the sandbox VMs that run validations. | Everything the services hold in memory or on their disks, including the repository mirror and receipt files on the validator; platform request logs (their content and retention are Railway's). | unknown (region not verified for this project) |
| GitHub | Source of the repositories Fleet verifies; the check-runs Fleet posts. | Repository contents read with a read-only token; check-run summaries with counts and ids only. GitHub also receives the GitHub App installation on your organization. | GitHub's infrastructure (United States and elsewhere, per GitHub) |
| OpenRouter, and the model providers it routes to | Model calls made by jobs (never by the API itself), each under a per-job key capped at the job's budget; key management and usage for settlement. | Task text and the repository content a job needs, sent with data collection set to deny on every request; usage and cost per key. | unknown (provider-side retention and location are OpenRouter's and each provider's) |
| jsDelivr | Serves the pinned supabase-js module to the OAuth consent page (which the Fleet API hosts). | The browser's request for the script (IP address and user agent reach the CDN); no Fleet data. | global CDN |
| Resend | Email for access and support requests sent from this site, through the Oracis intake API: the internal alert to Oracis, the acknowledgement to you, and delivery events back to us. | The form fields you submit (name, email, organization, message) for the alert; your name and address for the acknowledgement; delivery, bounce and complaint events for the messages we send. | unknown (Resend's infrastructure) |
| Cloudflare | DNS for oracis.ai and its subdomains, including fleet.oracis.ai. Traffic is not proxied through Cloudflare. | DNS queries for the fleet.oracis.ai name only; no page, form or API traffic passes through Cloudflare. | global |
Changes
A processor is added to this page before it receives any data, and the change is noted in the page's revision in the footer index. Members of a pilot organization are told by email when a processor that receives their organization's data is added.
Not used
No analytics, advertising, session-replay or error-reporting service processes data for the hosted service or this site. Fleet's own local tooling reaches other services (for example a model marketplace) but the hosted service you connect to does not.