Data-flow sub-processors
These third parties process personal data on Lonia's behalf to operate Aletheia. Each is limited to the purpose listed. Because Aletheia processes user documents in the user's own browser and stores them in a local library on the user's device, no sub-processor below receives user documents. The one piece of user content that reaches a sub-processor is a single image, and only when a Personal or Family user opts into Enhanced AI: that image goes to OpenRouter for the description and is discarded once the description is returned. The Lonia-mediated Enhanced AI transfer to OpenRouter is covered by the scoped Standard Contractual Clauses at /legal/sccs.
| Service Name | Purpose | Region(s) | Data Categories Processed | Contract Instrument |
|---|---|---|---|---|
| Supabase | Managed PostgreSQL database, OAuth session management, and account storage. | United States (single region). | Account identity (name, email address), plan and billing status, usage counts, and append-only audit records. No user documents. | Data Processing Addendum; Standard Contractual Clauses where applicable. |
| Cloudflare | Static site hosting (Pages), serverless compute (Workers), and bot protection (Turnstile). | Global edge network, United States account. | Network-level metadata (IP address, request headers) processed at the edge to route and protect traffic. No user documents. | Data Processing Addendum; Standard Contractual Clauses where applicable. |
| OAuth sign-in for Google Workspace accounts. Identity assertion only. | United States. | Sign-in identity (name, email address) asserted at authentication. Google does not receive user content. | Google Workspace and Cloud Data Processing Addendum; Standard Contractual Clauses where applicable. | |
| Microsoft | OAuth sign-in for Microsoft 365 accounts. Identity assertion only. | United States. | Sign-in identity (name, email address) asserted at authentication. Microsoft does not receive user content. | Microsoft Products and Services Data Protection Addendum; Standard Contractual Clauses where applicable. |
| Stripe | Payment processing and subscription billing for consumer and institutional plans. | United States. | Billing contact details, payment method data (card details for consumer plans and bank account details for ACH institutional billing, all handled by Stripe; Lonia never receives full card or account numbers), subscription status, and a payment fingerprint used for abuse prevention. | Stripe Data Processing Agreement; Standard Contractual Clauses where applicable. |
| OpenRouter (Enhanced AI on Personal and Family tiers) | AI model routing for the opt-in Enhanced AI image description path on the Personal and Family consumer tiers only. Lonia operates its own OpenRouter account, pays for this usage, and mediates the request on the user's behalf, which is why OpenRouter is a Lonia sub-processor for this path. | United States. | A single image the user chooses to describe and a short instruction, sent in one request and discarded once the description is returned. The image is not logged, retained, or used for training. No user documents and no account identity beyond the authenticated request. | Scoped Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2), scoped to this transit. See /legal/sccs. |
| AI provider for Enterprise bring-your-own-key (institution-selected: Anthropic, OpenAI, or OpenRouter) | AI model access for the Enterprise institution-managed bring-your-own-key Enhanced AI path only. The institution administrator enrolls one API key with Lonia's Enterprise Worker; the Worker holds it envelope-encrypted at rest and decrypts it in memory at request time to call the institution-selected provider on the institution's behalf. Because Lonia's Worker invokes the provider, the provider is a Lonia sub-processor for this path. | User-selectable per institutional enrollment. | User-selectable per institutional enrollment. A single image the user chooses to describe and a short instruction, relayed in one request and discarded once the description is returned. The image is not persisted server-side beyond the synchronous request and response. No user documents. | Transit through Lonia's Cloudflare and Supabase infrastructure, covered by the Standard Contractual Clauses referenced in the DPA at /legal/dpa. Provider engagement disclosed here under the update-on-change policy. |
Professional bring-your-own-key AI providers (user-invoked, not sub-processors)
| Provider Name | User-Direct Endpoint | Purpose |
|---|---|---|
| Anthropic (Claude models) | api.anthropic.com | Cloud image description and content assistance, called with the user's own Anthropic API key. |
| OpenAI (GPT models) | api.openai.com | Cloud image description and content assistance, called with the user's own OpenAI API key. |
| OpenRouter (multi-provider proxy) | openrouter.ai/api | Cloud image description and content assistance routed to a user-selected model, called with the user's own OpenRouter API key. |
Update-on-change policy
- Publication commitment. Aletheia updates this page within 30 days of any material change to its sub-processors.
- Advance notification. Aletheia will notify institutional Customers by email at least 30 days in advance of adding a new sub-processor that processes personal data.
- Right to object. A Customer may object to a new sub-processor on reasonable data protection grounds under the terms of the Data Processing Agreement. The parties will work in good faith to resolve the objection. If it cannot be resolved, the Customer may terminate the affected service.
Change history
| Date | Version | Change |
|---|---|---|
| August 9, 2026 | 1.2 | Corrected the bring-your-own-key classification to distinguish the two tiers. Professional bring-your-own-key remains browser-direct, and the provider is not a Lonia sub-processor. Enterprise bring-your-own-key is institution-managed and server-side: the institution's key is enrolled with Lonia's Enterprise Worker, which relays Enhanced AI requests to the institution-selected provider on the institution's behalf, so for that path the provider is a Lonia sub-processor. Added the Enterprise bring-your-own-key AI provider to the data-flow sub-processor table. |
| July 16, 2026 | 1.1 | Added OpenRouter as a data-flow sub-processor for the Lonia-mediated Enhanced AI image path on the Personal and Family tiers, covered by the scoped SCCs. Clarified that OpenRouter holds a dual role: a Lonia sub-processor on the Lonia-mediated Enhanced AI path, and a user-invoked provider (not a Lonia sub-processor) on the bring-your-own-key path. |
| July 14, 2026 | 1.0 | Initial publication of the authoritative sub-processor list. |
Future additions, removals, and material changes will be recorded as dated entries in the table above.
Contact
For sub-processor inquiries, including a request to be notified in advance of sub-processor changes, contact legal@lonia.ai.