Lucent Subprocessors
Last updated: May 22, 2026
Lucent AI, Inc. ("Lucent," "we," "us," or "our") engages the third-party vendors listed below as subprocessors to help us operate, provide, improve, and support the Lucent product available at app.lucenthq.com (the "Services"). These vendors process personal data on our behalf when we deliver the Services to our business customers.
This list covers the Lucent product only. It does not cover the lucenthq.com marketing website or other properties.
We may update this list from time to time as we add or remove subprocessors. Material changes will be reflected on this page with an updated "Last updated" date.
Capitalized terms not defined on this page have the meanings given in our Privacy Notice or applicable agreement with our customers.
Data Subjects
The personal data processed by these subprocessors may relate to:
- Customers — Lucent account users (for example, name, email, organization, and billing information)
- End-users — users of our customers' applications whose sessions Lucent records and analyzes
Subprocessors
| Legal name | Purpose | Data types processed | Location | Always / conditional |
|---|---|---|---|---|
| Supabase, Inc. | Primary database (PostgreSQL), authentication, and object storage for session replays, videos, thumbnails, and screenshots | Customers: name, email, organization/profile, auth credentials/OAuth tokens (encrypted at rest). End-users: session IDs, anonymous IDs, user IDs/emails/names when identified via SDK, rrweb replay events (DOM, clicks, console, network metadata), IP address, user agent, page URLs, session videos | United States (project region configurable) | Always |
| Vercel Inc. | Hosts the Lucent web application (app.lucenthq.com) and API routes | Customer account data in HTTP requests/responses, auth cookies, server logs | United States | Always |
| Render Services, Inc. | Hosts backend API, SDK ingest, and background workers | End-user session replay payloads via SDK; customer/org metadata in API calls; job orchestration payloads | United States | Always |
| Modal Labs, Inc. | Serverless compute for session video rendering (Playwright + rrweb to MP4) | End-user session replay JSON, generated session videos, derived event timelines | United States | Always (when session video processing runs) |
| Google LLC (Google Cloud Platform / Vertex AI) | Primary AI/LLM provider for session analysis; temporary media storage (GCS) for video upload to Gemini | End-user session videos, behavioral event summaries, URLs, issue-detection prompts; may include on-screen PII visible in recordings | United States (region configurable) | Always (default AI route) |
| Google LLC (Gemini API / AI Studio) | Alternate AI/LLM route | Same as Vertex AI | United States | Conditional (when AI Studio mode is enabled) |
| Anthropic, PBC | LLM for session insights, investigation synthesis, and Slack bot replies | Redacted session timelines/metadata, investigation context, issue descriptions; Slack message content when customers mention the Lucent bot | United States | Conditional (when Anthropic is configured) |
| Inngest, Inc. | Async workflow orchestration (session processing, notifications, scheduled jobs) | Session IDs, org IDs, job metadata, notification payloads | United States | Always |
| Resend, Inc. (Plus Five Five, Inc.) | Transactional email delivery | Customer email addresses, names, org names, issue titles/descriptions/previews, invitation and onboarding content | United States | Always |
| Loops | Marketing and onboarding email automation | Customer email, first/last name, company, org role, plan, product-usage flags | United States | Always |
| Stripe, Inc. | Subscription billing and payment processing | Customer name, email, billing address, payment method metadata, subscription/plan status | United States and global processing per Stripe | Always for billing flows; conditional for orgs that never enter checkout/billing |
| Functional Software, Inc. (Sentry) | Error monitoring and application observability | Error/stack traces, user IDs, emails, request context | United States | Always in production |
| Upstash, Inc. | Redis rate limiting (SDK ingest, OAuth client registration) | Hashed/rate-limit identifiers, IP addresses (OAuth DCR), API key identifiers | United States | Always in production |
| PostHog, Inc. | Lucent's own product analytics on the dashboard (not customer PostHog projects) | Lucent customer user ID, email, name, org ID, in-app product usage events | United States | Always in production dashboard |
| Productlane | In-app feedback and support widget | Lucent customer email (via signed JWT), feedback/support submissions | United States | Always (widget loaded on dashboard) |
| Slack Technologies, LLC (Salesforce) | Lucent internal operational Slack workspace only (signups, upgrades, onboarding traces) | Customer org name, owner name/email, org ID, upgrade activity | United States | Always |
| Google LLC | OAuth sign-in provider (via Supabase Auth) | Customer email, name, Google account identifier when "Sign in with Google" is used | United States | Conditional (only when customer chooses Google login) |
Notes on Subprocessors
- PII redaction: Text sent to Anthropic for insights and investigations is redacted before transmission. Primary session analysis sends video and event summaries to Gemini and may include visible on-screen end-user content from recordings.
- GitHub, Inc.: Used only to clone Lucent's own repository inside Modal sandboxes. It does not process customer or end-user personal data and is not listed above.
Customer-Controlled Integrations
The integrations below are not Lucent subprocessors. They are optional integrations that a customer connects to their own accounts. Lucent accesses data the customer authorizes; the vendor relationship is primarily between the customer and the provider. When Lucent pulls or pushes data through these connections, Lucent acts as the customer's processor.
| Integration | Purpose | Data types (when connected) | Location | Enabled by |
|---|---|---|---|---|
| PostHog, Inc. | Import session replays from customer's PostHog project | End-user session replays, person properties (email, name when present), feature-flag metadata | Customer's PostHog region (US/EU cloud or self-hosted) | Customer |
| Slack Technologies, LLC | Issue notifications, ticket creation, bot interactions in customer's workspace | Issue titles/descriptions, session links, Slack user IDs, channel metadata | Customer's Slack workspace region | Customer |
| Linear Orbit, Inc. | Create/link tickets in customer's Linear workspace | Issue details, assignee/team metadata, Lucent user who triggered action | Customer's Linear region | Customer |
| Atlassian Pty Ltd (Jira) | Create/link tickets in customer's Jira | Issue details, project metadata | Customer's Atlassian cloud region | Customer |
| Asana, Inc. | Create/link tasks in customer's Asana workspace | Issue details, project/workspace metadata | Customer's Asana region | Customer |
| Intercom, Inc. | Correlate sessions with customer's Intercom contacts | End-user contact ID, email, name, conversation metadata | Customer's Intercom region | Customer |
| Datadog, Inc. | Import session replays from customer's Datadog RUM | End-user session replays, RUM metadata | Customer's Datadog site (for example, datadoghq.com or datadoghq.eu) | Customer |
| Amplitude, Inc. | Import session replays from customer's Amplitude project | End-user session replays, user/device metadata, feature-flag exposures | Customer-selected region | Customer |
| Functional Software, Inc. (Sentry) | Import session replays from customer's Sentry project | End-user session replays, error/replay metadata | Customer's Sentry region | Customer |
Contact
Questions about this list or our data processing practices may be directed to privacy@lucenthq.com.