Subprocessors and security
This page lists the companies Pecalium Pty Ltd (ABN 28 701 425 434) uses to run Asterlyn Space, and summarises how we keep it secure. Our privacy policy and data processing addendum refer to it.
Last updated: 27 September 2026
1. Subprocessors
We use these providers to host, operate, secure, bill for and support the Service. Each processes information only as far as it needs to provide its service to us. This is our complete current list.
- DigitalOcean, LLC · Sydney, Australia
- App hosting, database, backups, and storage for uploaded pictures, drawings and renders (DigitalOcean Spaces).
- OpenRouter, Inc. · United States
- Routes AI requests to the model provider below, with Zero Data Retention routing on every request.
- Google LLC · United States
- Gemini AI models, reached through OpenRouter, that read drawings and photos and generate and check renders.
- Stripe, Inc. · United States
- Subscriptions, credit top-ups, invoices, payment methods and billing records.
- SMTP2GO · New Zealand
- Email delivery: sign-up verification, team invitations, password resets, receipts and account notices.
- Better Stack · United States and European Union
- Logs, error monitoring and uptime monitoring used to run and secure the Service.
- Cloudflare, Inc. · United States
- DNS, content delivery, bot protection and hosting for our public website.
Your uploads and renders are stored in Sydney. They leave Australia only when they are sent for AI processing, as described in section 4.
2. Website analytics and advertising
Google (Analytics and Ads), Meta and LinkedIn run on our public marketing website only, through Google Tag Manager. They do not run inside the app and never receive customer content, so they are not subprocessors. They are described in section 9 of our privacy policy.
3. Subprocessor changes
We will update this page before we add or replace a provider that processes customer content, and tell account owners by email. You can object on reasonable data protection grounds within 30 days, as set out in our data processing addendum.
4. AI processing
Asterlyn Space uses AI for every render: to read the drawing or photo, to check your instructions, to generate the render and to check the result against what you drew.
- What is sent: the drawing or photo, reference and material pictures, your chosen colours and finishes, and the instructions built from them. Not your name, email address or billing details.
- Where it goes: OpenRouter, which routes it to Google's Gemini models in the United States.
- What happens to it: every request uses Zero Data Retention routing and refuses providers that collect data. The provider processes it to produce a response, does not keep it afterwards and does not train on it.
- Training: we do not train or fine-tune any AI model on your content.
- Quality testing: we use stored renders to test our own quality checks before we change the Service. This is testing software, not training a model.
AI results can be wrong. Section 8 of our terms explains what to check before you rely on a render.
5. Security controls
- Email and password sign-in, with email verification.
- Two-factor sign-in with an authenticator app, and passkeys.
- Passwords stored hashed, never in readable form.
- Team roles that control who can invite people, manage billing and change settings.
- Every team's projects kept separate from every other team's.
- Encrypted connections (HTTPS) everywhere, with HSTS on our website.
- Uploaded pictures and renders stored encrypted at rest.
- Card details entered directly with Stripe and never stored on our servers.
- Staff access to customer projects limited to a small number of people, used only for support, fault-finding, security and enforcing our terms. Every time staff view the app as a customer, it is logged.
- Logs, error monitoring and uptime monitoring.
- Regular backups for disaster recovery.
- Failed render attempts deleted automatically after 14 days.
6. Your part in security
- Use a strong, unique password and turn on two-factor sign-in or a passkey.
- Keep your team members and their roles current, and remove people who leave.
- Only upload pictures you have the right to upload, and leave out people and personal details.
- Do not upload the restricted information listed in the terms.
- Download the renders you need to keep.
7. Security incidents
If we confirm a security incident affecting customer content, we will tell affected customers without undue delay, share what we know as far as the law allows, and cooperate with any investigation and notifications required, including under the Notifiable Data Breaches scheme.
8. Security testing and vulnerability reports
Do not run penetration tests, scans, load tests, exploits or social engineering against the Service, or try to reach another team's data, without our written permission.
If you think you have found a vulnerability, email legal@pecalium.com with the details. Please give us a reasonable time to fix it before telling anyone else. We will not take action against good-faith research that follows this page.
Contact
- Legal notices and privacy
- legal@pecalium.com
- Billing
- support@pecalium.com
- Product support
- support@asterlynspace.com
Pecalium Pty Ltd (ABN 28 701 425 434), Queensland, Australia.