MOZEN
FonctionnalitésBlogDocsGalerieTarifs
Français
English简体中文繁體中文日本語FrançaisDeutschEspañolPortuguês한국어
Commencer
English简体中文繁體中文日本語FrançaisDeutschEspañolPortuguês한국어
FonctionnalitésBlogDocsGalerieTarifs Commencer

Subprocessors

v1.1 · 2026-07-14

1. Purpose, Scope, and Definitions

This Subprocessors List (the "List") explains which third parties Mozen ("Mozen," "we," or "the Service") engages to process personal information on our behalf in the course of providing our unified knowledge workspace and generative AI services, together with the function, data categories, country/region of processing, and retention of such processing. This List forms part of the Privacy Policy and should be read together with the Privacy Policy and the Terms of Service; where this List and the Privacy Policy are inconsistent regarding a specific processing activity, the more specific interpretation that is more favorable to you shall prevail.

This List is prepared pursuant to, and in support of, the following legal obligations: Article 28(2) and 28(4) of the EU General Data Protection Regulation (GDPR) (authorization of, and contractual obligations relating to, the engagement of sub-processors by a processor); Article 13(1)(e) GDPR (disclosure to data subjects of the recipients or categories of recipients of personal data); and Article 17 of the Personal Information Protection Law of the People's Republic of China (PIPL) (informing individuals of recipient information).

  • "Controller / personal information handler": with respect to User Content and account data, Mozen generally acts as the data controller (in the GDPR context) / personal information handler (in the PIPL context), determining the purposes and means of processing.
  • "Processor / engaged party": a third-party provider that processes personal information on Mozen's behalf and on Mozen's instructions, i.e., a "subprocessor" as referred to in this List. Where Mozen acts as a processor on behalf of a customer in other scenarios, the same providers below constitute "sub-processors" within the meaning of GDPR Article 28.
  • "Personal information / personal data": information relating to an identified or identifiable natural person, including User Content, account, technical and usage, and payment-status data.
  • "User-connected third parties": external services that you yourself proactively authorize and with which you establish a relationship directly (see Section 6); these are not subprocessors engaged by Mozen.

Mozen is currently provided by an individual independent operator under the name Mozen and is not a registered company or a separate legal entity. For the operator's personal safety and privacy protection, the operator's residential address is not displayed on public pages; for privacy or data rights requests relating to this List, please contact privacy@mozen.ai, and for legal notices or formal service-of-process information requests, please contact legal@mozen.ai. We will handle requests after completing the necessary identity verification and will provide service-of-process information where legally required.

2. Authorization, Selection, and Contractual Obligations of Subprocessors (GDPR Article 28)

To provide the Service, you generally authorize Mozen to engage the subprocessors listed in this List to process personal information. In selecting and managing subprocessors, we observe the following principles:

  • Diligent selection: we engage only providers that can offer sufficient guarantees and implement technical and organizational measures meeting the requirements of applicable law.
  • Contractual binding: to the extent required by applicable law and where the provider offers the corresponding instrument, our relationship with each subprocessor is governed by a data processing agreement, data processing addendum, Standard Contractual Clauses (SCCs), or the provider's equivalent terms, requiring them to process only on instructions, maintain confidentiality, adopt security measures, assist with data-subject rights and security-incident obligations, and delete or return data upon termination.
  • Processing boundary: a subprocessor may process personal information only to the extent necessary to provide the agreed services to Mozen and may not use your User Content for its own unrelated purposes. For the standard AI integration path, we require model providers not to use User Content sent via the API to train their general-purpose foundation models (see Section 4 and Section 5 of the Privacy Policy).
  • Onward engagement: the providers listed here may each use their own downstream sub-contractors (for example, underlying cloud, CDN, or regional infrastructure). Such downstream engagement is governed by each provider's own subprocessor governance and contracts; we disclose at the provider level and do not enumerate their entire downstream chains.
  • Honest statement: Mozen is operated by an individual independent operator and does not currently hold independent security certifications such as SOC 2 or ISO 27001, and this List makes no such claim. Our diligence regarding subprocessors relies on their public commitments, contractual terms, and prevailing industry practice.

For advance notice of, and your objection mechanism regarding, the addition or replacement of subprocessors, see Section 7.

3. Core Infrastructure and Payment Subprocessors

The table below lists Mozen's current core infrastructure and payment subprocessors. The data categories listed represent the maximum scope that the provider may access within its function, not the full set involved in every instance of processing; we transfer data to each provider on a minimum-necessity basis.

EntityFunctionCategories of data processedCountry/region of processingRetention
SupabasePrimary database (Postgres), user authentication, object storage, and backend infrastructureAccount and identity information; User Content and metadata; collaboration and synchronization data (Y.Doc updates/snapshots); AI interaction records and points transactions; technical and usage logs; security and compliance recordsPrimary database located in Singapore (ap-southeast-1). Singapore does not currently hold an EU adequacy decision; transfers concerning EU/UK users rely on safeguards such as Standard Contractual Clauses and supplementary measuresRetained for the duration of the account; after deletion/deactivation, backups, snapshots, and audit logs are retained for a short period to support recovery, synchronization consistency, and disaster recovery, per Section 10 of the Privacy Policy
CloudflareR2 object storage, global edge network and CDN distribution (media.mozen.ai / cdn.mozen.ai), edge proxy, and network security protectionMedia and files you upload (images, audio, video, e-books, fonts, exports, etc.); cached objects; request metadata (IP, User-Agent, timestamps); security signals used for hotlink protection and rate limitingGlobal edge nodes (distributed on a proximity basis; may be cached and processed across multiple countries/regions)Objects retained while referenced/not deleted; edge caches expire per caching policy; deleting media removes it from authorized objects (see Section 10 of the Privacy Policy)
PaddleMerchant of Record / authorized reseller: processing of payments, subscriptions, renewals, taxes, customer portal, receipts, and refundsCheckout and billing information; order number and transaction status; subscription and trial status; information required for tax/invoicing; payment-gateway customer identifier; refund and dispute records. Full bank card numbers/CVV are collected directly by Paddle and are not stored directly by MozenProcessed by Paddle as an independent controller across its global payment infrastructure (including the EU, UK, US, and other regions)Retained by Paddle per its terms and tax/anti-fraud obligations; on Mozen's side, order, accounting, and reconciliation records are retained to perform the contract and for compliance, auditing, and dispute handling (see Section 8 of the Privacy Policy)

With respect to payments, Paddle always acts as the Merchant of Record / authorized reseller, establishing a payment-related legal relationship directly with you, and may send you receipts, renewal reminders, cancellation confirmations, or refund notices. Paddle's processing as an independent controller is governed by its own privacy policy.

4. AI Inference and Generation Subprocessors

Mozen's AI features (autonomous execution by Agents and Skills; text/image/audio/video/font generation; speech synthesis (TTS); speech transcription; embedding retrieval; deep research, etc.) use model routing to send, per task, your prompts, selected content, relevant context, reference materials, media files, or task results to one or more of the model inference providers below. Any single request is generally routed only to the provider(s) needed to complete that task, not sent to all providers at once.

Important cross-border notice: Mozen's AI model providers include both providers located in Mainland China and providers located in the United States and other regions; which one processes a given request depends on the task's model-routing configuration (which may change). This means that, depending on the feature and model used, the content you submit to the AI may be transferred to China, the United States, or other countries/regions for processing. Transfers to China constitute an international transfer to a country without an adequacy decision for EU/UK and similar users (see "International Transfers and Data Residency" in the Privacy Policy); the use of overseas providers (such as those in the United States) by Mainland China users constitutes an outbound provision of personal information. If you have concerns, please consider carefully whether to use the relevant AI features or to submit sensitive information in prompts.

De-identification before sending: before sending to model services, the system performs basic de-identification of sensitive tokens such as email addresses, phone numbers, ID card numbers, bank card numbers, and those in URLs, and may block or flag high-risk requests through content security policies; basic de-identification is a best-effort risk mitigation and is not equivalent to full de-identification.

Data categories and retention (applicable to all AI providers below): the data categories processed are generally prompts, conversation context, selected content, reference materials, relevant note/whiteboard excerpts, media inputs (images/audio, etc.), and tool-call parameters and results (after basic de-identification); speech synthesis and transcription additionally involve audio and text, and OCR involves images. Each provider retains data for a short period under its API data policy (typically for abuse monitoring/security); under standard integration paths, we require that they not use User Content received via API to train their general-purpose foundation models; on Mozen's side, we retain only the necessary task status and credit records.

A. AI providers located in Mainland China (data transferred to China for processing):

  • DeepSeek: large language model inference (text generation, conversation, Agent reasoning, tool calls).
  • Moonshot AI (Kimi): large language model inference.
  • MiniMax: large language model and embedding inference.
  • ByteDance Doubao / Volcengine Ark (Beijing): large language model inference.
  • Zhipu AI (GLM): large language model inference.
  • Volcengine OCR (ByteDance): optical character recognition (OCR).
  • SiliconFlow: model inference and speech synthesis (multilingual voice models such as CosyVoice2, MOSS-TTSD, and fish-speech).

B. AI providers located in the United States and other regions:

  • Google (Gemini): large language and multimodal inference (United States / Google global infrastructure).
  • xAI (Grok, United States): large language model inference.
  • OpenRouter (United States): AI model aggregation/routing — forwards requests to upstream model providers on its platform (which may include Anthropic, OpenAI, and others), which may be located in the United States and other countries/regions.
  • Anthropic (Claude, United States): large language model inference (may be accessed via aggregators such as OpenRouter).
  • OpenAI (United States): large language and image model inference (may be accessed via aggregators such as OpenRouter).
  • Replicate (United States): hosted model inference (image/media generation, etc.).
  • fal.ai (United States): image/media generation inference.
  • Cloudflare Workers AI (United States / global edge): edge model inference.
  • Azure Speech (Microsoft): speech synthesis (TTS), processed via its East Asia region endpoint.

The above is Mozen's actual current configuration and may change as model routing and product needs evolve; additions or replacements will be notified under Section 7. Aggregation providers (such as OpenRouter) further route requests to upstream model providers on their platforms, which are subject to their respective policies.

5. Retrieval, Search, and External Fetching Subprocessors

The AI's web search, deep research, and academic retrieval capabilities send queries to external data sources and fetch/read external web pages and literature content. The table below lists subprocessors and public data sources of this type.

EntityFunctionCategories of data processedCountry/region of processingRetention
SerperWeb search API (providing retrieval results for AI web search and deep research)Search query strings you initiate or that the AI generates (which may include keywords you provide in prompts) and necessary request metadataPrimarily the United StatesQuery logs retained by the provider per its terms; Mozen retains only the necessary task status and result references

External web and PDF fetching (read_url / deep research): when the AI performs deep research, it fetches and reads external web pages and full-text PDFs at the target addresses given by you or the task, and applies security checks such as SSRF protection to outbound requests. The websites fetched are independent third parties not controlled by this List; their logging of the fetch requests is subject to their own policies, and Mozen processes the fetched body content only within the scope necessary to complete the research.

Academic retrieval public APIs (not Mozen subprocessors): academic retrieval is performed through public academic APIs, including OpenAlex, Semantic Scholar, CrossRef, PubMed, Europe PMC, and arXiv. What Mozen sends them are retrieval queries (such as titles, keywords, DOIs), not the substance of your User Content; these public data sources are operated by their respective institutions under their own terms of use and do not process personal information on Mozen's behalf. They are therefore not listed as subprocessors engaged by Mozen, but are disclosed here as recipients of data so that you are informed.

Video and code search sources: when you use video- or code-related search, the corresponding queries are sent to the YouTube Data API (Google, United States, for video search) and the GitHub API (United States, for code/repository search); what is sent is the search query string rather than the body of your User Content, processed by each provider under its own terms.

6. User-Connected Third Parties (Not Mozen Subprocessors)

The services listed in this section are connected at your own proactive authorization, are established and controlled directly by you, and have a relationship with you within a scope you authorize. For these services, you (and not Mozen) decide whether to connect, what data to connect, and when to revoke; they are not subprocessors engaged by Mozen, and Mozen is not responsible for their independent processing activities. Mozen invokes the relevant authorization only to the extent necessary to complete the import, export, synchronization, backup, or publishing you request.

  • Google Drive: external storage/import/backup target. Data may be processed on Google's global infrastructure (including the US), subject to Google's own terms and privacy policy.
  • OneDrive (Microsoft): external storage/import/backup target. Data may be processed on Microsoft's global infrastructure, subject to Microsoft's own terms and privacy policy.
  • Baidu (e.g., Baidu Netdisk): external storage target; data is processed primarily within China, subject to its own terms and privacy policy, and may be governed by Chinese local law.
  • WebDAV (any server): you may connect to any external storage endpoint that supports the WebDAV protocol. That endpoint is designated and controlled by you, and its country/region, security level, and retention policy are determined entirely by the provider you choose; Mozen has no control over it and provides no warranty.

Credential handling: for the above connections, Mozen stores the necessary OAuth tokens or external storage credentials encrypted in a server-side secure zone and displays them in masked form in the interface, using them solely to perform the operations you request; you may revoke authorization or disconnect at any time.

Browser local storage: Mozen also uses local persistence in the browser on your device (IndexedDB / localStorage / sessionStorage) to maintain the login session, offline editing cache, and local copies of Y.Doc. This data resides on your device and does not constitute a transfer to a third party, but its retention is controlled by your browser and device (see Section 6 of the Privacy Policy).

For the user-connected third parties and external fetch targets above, please read and comply with their respective terms and privacy policies.

7. Change Notice, Objection Mechanism, and Email Subscription

  • Advance notice: before adding a subprocessor or replacing an existing one, we will provide advance notice by reasonable means, including updating the version number and changelog of this List, in-app notifications, website announcements, and emails to users who have subscribed to subprocessor change notices. To the extent permitted by applicable law, an emergency replacement (for example, where the original provider suddenly becomes unavailable or a security or compliance risk arises) may be notified as soon as practicable after the replacement.
  • Objection mechanism: if you have a reasonable, data-protection-related objection to a newly added or replaced subprocessor, you may raise it within a reasonable period after the notice is published by contacting privacy@mozen.ai, stating your specific reasons. We will evaluate your objection in good faith and seek a reasonable resolution (for example, explaining the safeguards adopted, adjusting data routing, or providing an alternative where feasible). If the matter ultimately cannot be resolved and the subprocessor is indispensable to providing the core Service, you may, in accordance with the Privacy Policy and the Terms of Service, stop using the relevant features, withdraw the corresponding authorization, or deactivate your account; where mandatorily required by applicable law, you retain the right to terminate or object to processing under the law.
  • Email subscription: you may request to subscribe to or unsubscribe from "subprocessor change notices" via privacy@mozen.ai. Once subscribed, we will send you a notification email when there is a material addition or replacement of a subprocessor. Whether or not you subscribe, the latest List as published on this page always prevails.
  • Authoritative version: the latest effective version of this List is as published on this page. Where translated versions exist in various language interfaces, they are provided for convenience of reference only; in case of ambiguity between a translation and the authoritative Simplified Chinese/English versions, the authoritative version prevails.

8. Version and Changelog

Current version: v1.1 Effective date: 2026-06-21

The version number and effective date of this List are updated as subprocessors are added, removed, or change in function or place of processing. The changelog is as follows:

  • v1.1 (2026-07-14): AI provider list calibration — added xAI (Grok); clarified that Anthropic and OpenAI may be accessed via aggregators such as OpenRouter; removed the separate APIMart listing (its upstream providers are already disclosed in the list). This is a technical list alignment; final wording is subject to legal review.
  • v1.0 (2026-06-21): Initial release. Establishes the core infrastructure and payment subprocessors (Supabase — database/authentication/storage, Singapore; Cloudflare — R2 object storage/global edge/CDN; Paddle — Merchant of Record); the AI inference and generation subprocessors (providers located in Mainland China (DeepSeek, Moonshot AI/Kimi, MiniMax, ByteDance Doubao/Volcengine, Zhipu GLM, SiliconFlow) and in the United States/other regions (Google, OpenRouter, APIMart, Replicate, fal.ai, Cloudflare, Azure Speech)); the retrieval and search subprocessor (Serper, primarily in the United States); the honest disclosure of external fetching (read_url/deep research) and academic retrieval public APIs (OpenAlex, Semantic Scholar, CrossRef, PubMed, Europe PMC, arXiv); and the user-connected third-party block (Google Drive, OneDrive, Baidu, WebDAV). Expressly prepared pursuant to GDPR Article 28(2)/(4), Article 13(1)(e), and PIPL Article 17, and establishes the change-notice, objection, and email-subscription mechanisms.

9. Contact Information

For questions about this List, subprocessor processing activities, recipients of data, or international transfers, as well as data rights requests or objections, please contact: privacy@mozen.ai. For legal notices or formal service-of-process information requests, please contact: legal@mozen.ai. For payment- and refund-related questions (including transactions processed by Paddle), please contact: billing@mozen.ai, and for general support, please contact: support@mozen.ai. To protect the security of your account, payments, and workspace, we may need to verify your identity before processing a request.

MOZEN

La technologie portant le poids de l'encre, L'espace insufflant l'esprit du zen.

Produit Fonctionnalités Tarifs Nouveautés
Ressources Docs Blog
Mentions légales Confidentialité Conditions Politique de remboursement Cookie Policy
© 2026 Mozen Conçu pour le flow