Lucent Subprocessors

Last updated: May 22, 2026

Lucent AI, Inc. ("Lucent," "we," "us," or "our") engages the third-party vendors listed below as subprocessors to help us operate, provide, improve, and support the Lucent product available at app.lucenthq.com (the "Services"). These vendors process personal data on our behalf when we deliver the Services to our business customers.

This list covers the Lucent product only. It does not cover the lucenthq.com marketing website or other properties.

We may update this list from time to time as we add or remove subprocessors. Material changes will be reflected on this page with an updated "Last updated" date.

Capitalized terms not defined on this page have the meanings given in our Privacy Notice or applicable agreement with our customers.

Data Subjects

The personal data processed by these subprocessors may relate to:

  • Customers — Lucent account users (for example, name, email, organization, and billing information)
  • End-users — users of our customers' applications whose sessions Lucent records and analyzes

Subprocessors

Legal namePurposeData types processedLocationAlways / conditional
Supabase, Inc.Primary database (PostgreSQL), authentication, and object storage for session replays, videos, thumbnails, and screenshotsCustomers: name, email, organization/profile, auth credentials/OAuth tokens (encrypted at rest). End-users: session IDs, anonymous IDs, user IDs/emails/names when identified via SDK, rrweb replay events (DOM, clicks, console, network metadata), IP address, user agent, page URLs, session videosUnited States (project region configurable)Always
Vercel Inc.Hosts the Lucent web application (app.lucenthq.com) and API routesCustomer account data in HTTP requests/responses, auth cookies, server logsUnited StatesAlways
Render Services, Inc.Hosts backend API, SDK ingest, and background workersEnd-user session replay payloads via SDK; customer/org metadata in API calls; job orchestration payloadsUnited StatesAlways
Modal Labs, Inc.Serverless compute for session video rendering (Playwright + rrweb to MP4)End-user session replay JSON, generated session videos, derived event timelinesUnited StatesAlways (when session video processing runs)
Google LLC (Google Cloud Platform / Vertex AI)Primary AI/LLM provider for session analysis; temporary media storage (GCS) for video upload to GeminiEnd-user session videos, behavioral event summaries, URLs, issue-detection prompts; may include on-screen PII visible in recordingsUnited States (region configurable)Always (default AI route)
Google LLC (Gemini API / AI Studio)Alternate AI/LLM routeSame as Vertex AIUnited StatesConditional (when AI Studio mode is enabled)
Anthropic, PBCLLM for session insights, investigation synthesis, and Slack bot repliesRedacted session timelines/metadata, investigation context, issue descriptions; Slack message content when customers mention the Lucent botUnited StatesConditional (when Anthropic is configured)
Inngest, Inc.Async workflow orchestration (session processing, notifications, scheduled jobs)Session IDs, org IDs, job metadata, notification payloadsUnited StatesAlways
Resend, Inc. (Plus Five Five, Inc.)Transactional email deliveryCustomer email addresses, names, org names, issue titles/descriptions/previews, invitation and onboarding contentUnited StatesAlways
LoopsMarketing and onboarding email automationCustomer email, first/last name, company, org role, plan, product-usage flagsUnited StatesAlways
Stripe, Inc.Subscription billing and payment processingCustomer name, email, billing address, payment method metadata, subscription/plan statusUnited States and global processing per StripeAlways for billing flows; conditional for orgs that never enter checkout/billing
Functional Software, Inc. (Sentry)Error monitoring and application observabilityError/stack traces, user IDs, emails, request contextUnited StatesAlways in production
Upstash, Inc.Redis rate limiting (SDK ingest, OAuth client registration)Hashed/rate-limit identifiers, IP addresses (OAuth DCR), API key identifiersUnited StatesAlways in production
PostHog, Inc.Lucent's own product analytics on the dashboard (not customer PostHog projects)Lucent customer user ID, email, name, org ID, in-app product usage eventsUnited StatesAlways in production dashboard
ProductlaneIn-app feedback and support widgetLucent customer email (via signed JWT), feedback/support submissionsUnited StatesAlways (widget loaded on dashboard)
Slack Technologies, LLC (Salesforce)Lucent internal operational Slack workspace only (signups, upgrades, onboarding traces)Customer org name, owner name/email, org ID, upgrade activityUnited StatesAlways
Google LLCOAuth sign-in provider (via Supabase Auth)Customer email, name, Google account identifier when "Sign in with Google" is usedUnited StatesConditional (only when customer chooses Google login)

Notes on Subprocessors

  • PII redaction: Text sent to Anthropic for insights and investigations is redacted before transmission. Primary session analysis sends video and event summaries to Gemini and may include visible on-screen end-user content from recordings.
  • GitHub, Inc.: Used only to clone Lucent's own repository inside Modal sandboxes. It does not process customer or end-user personal data and is not listed above.

Customer-Controlled Integrations

The integrations below are not Lucent subprocessors. They are optional integrations that a customer connects to their own accounts. Lucent accesses data the customer authorizes; the vendor relationship is primarily between the customer and the provider. When Lucent pulls or pushes data through these connections, Lucent acts as the customer's processor.

IntegrationPurposeData types (when connected)LocationEnabled by
PostHog, Inc.Import session replays from customer's PostHog projectEnd-user session replays, person properties (email, name when present), feature-flag metadataCustomer's PostHog region (US/EU cloud or self-hosted)Customer
Slack Technologies, LLCIssue notifications, ticket creation, bot interactions in customer's workspaceIssue titles/descriptions, session links, Slack user IDs, channel metadataCustomer's Slack workspace regionCustomer
Linear Orbit, Inc.Create/link tickets in customer's Linear workspaceIssue details, assignee/team metadata, Lucent user who triggered actionCustomer's Linear regionCustomer
Atlassian Pty Ltd (Jira)Create/link tickets in customer's JiraIssue details, project metadataCustomer's Atlassian cloud regionCustomer
Asana, Inc.Create/link tasks in customer's Asana workspaceIssue details, project/workspace metadataCustomer's Asana regionCustomer
Intercom, Inc.Correlate sessions with customer's Intercom contactsEnd-user contact ID, email, name, conversation metadataCustomer's Intercom regionCustomer
Datadog, Inc.Import session replays from customer's Datadog RUMEnd-user session replays, RUM metadataCustomer's Datadog site (for example, datadoghq.com or datadoghq.eu)Customer
Amplitude, Inc.Import session replays from customer's Amplitude projectEnd-user session replays, user/device metadata, feature-flag exposuresCustomer-selected regionCustomer
Functional Software, Inc. (Sentry)Import session replays from customer's Sentry projectEnd-user session replays, error/replay metadataCustomer's Sentry regionCustomer

Contact

Questions about this list or our data processing practices may be directed to privacy@lucenthq.com.