Sub-processors
These are the providers that process data on our behalf. Each row says what actually reaches that provider rather than describing it as "your data". We do not sell personal data to anyone on this list or off it.
| Provider | Purpose | What reaches them | Location | Terms | PHI path |
|---|---|---|---|---|---|
| Google Cloud Platform | Infrastructure, compute, and storage | Account data, work data, audit records | United States | DPA. BAA available for HIPAA-eligible services. | BAA required |
| Anthropic | Model provider for agent execution | The task context sent to the model: prompts, code, and documents in scope for that task | United States | Commercial API terms. No training on submitted data. BAA on first-party API and Enterprise plans only. | BAA required |
| Stytch | Authentication and identity | Email address, organization, session records | United States | DPA | Never |
| Umami | Website analytics | Aggregate page views. No cookies and no personal data. | European Union and United States | DPA | Never |
| PostHog | Product analytics | Usage events within the product | United States and European Union | DPA | Never |
| AWS SES | Transactional email | Email address and message content | United States | DPA | Never |
How this list is used
- PHI path. "BAA required" means the provider may handle protected health information only once a Business Associate Agreement is executed with them. "Never" means no PHI is routed there at all, by design rather than by policy.
- Model access. Our default execution path runs on a subscription plan that is not covered by a BAA, so it is never used for PHI. Work in scope for PHI runs on first-party API or Enterprise plans under a signed BAA.
- Changes. We tell customers before adding or replacing a sub-processor, and you can object. Ask privacy@lucitra.ai to be notified of changes to this page.
- Contractual basis. Every provider here is under a data processing agreement. The obligations we take on toward you are in our DPA.