Skip to content
Sub-processors

Who processes data on our behalf.

A versioned register of third-party processors used to operate LumenFlow Cloud, with purpose, region, and an honest DPA column.

Register version 1.0.0

Current register

The DPA column states only what is signed. No customer DPA exists until one is counter-signed.

ProcessorPurposeRegionDPA
SupabaseDatabase hosting and authentication.EU (AWS eu-central-1); US infrastructure also used for auth edgesNo DPA is signed with this processor yet.
VercelApplication hosting and edge delivery.EU (Vercel fra1 / AWS eu-central-1)No DPA is signed with this processor yet.
StripePayment processing for paid plans (web only).United States / global Stripe infrastructureNo DPA is signed with this processor yet.
OpenAIText inference and, for mobile dictation, voice transcription via the OpenAI Realtime API (forwarded server-side).United StatesNo DPA is signed with this processor yet.
AnthropicText inference under the managed-inference tier.United StatesNo DPA is signed with this processor yet.
Google GeminiText inference under the managed-inference tier.United States / Google Cloud regionsNo DPA is signed with this processor yet.
GitHubOptional connected tool — when a workspace connects its own GitHub account, LumenFlow can read and write to authorised repositories.United StatesNo DPA is signed with this processor yet.
Expo / EASMobile push token issuance and over-the-air update delivery for the mobile app.United StatesNo DPA is signed with this processor yet.

Change log

  1. v1.0.0 effective 2026-09-22

    Initial public sub-processor register.

    • Published the initial versioned list aligned with the privacy-policy processors (Supabase, Vercel, Stripe, OpenAI, Anthropic, Google Gemini, GitHub, Expo / EAS).
    • DPA column records that no customer DPA is signed yet.