Sub-processors

Last updated September 12, 2026

To run Luminous Social we rely on a small number of third-party services. This page lists them and what each one handles, because a firm deciding whether to put privileged client information into software should be able to see who else touches it without having to ask.

This page is a factual disclosure, not a contract. It is not a data-processing agreement, and nothing here asserts a certification or audit on our part or theirs. Read it alongside our Privacy Policy.

1. Current Sub-processors

ServiceWhat it doesWhat it handles
SupabaseDatabase, authentication, and file storageHosted in the region selected for this deployment.Everything you enter: matters, clients, contacts, deadlines, documents, notes, time and billing records, and your account credentials.
VercelApplication hosting and content deliveryGlobal edge network.Serves the application and processes requests in transit. Request logs may include IP address and page paths. Vercel does not receive a copy of your matter data at rest.
ResendTransactional email deliveryDetermined by Resend.The content of emails the Service sends on your instruction — sign-in codes, password resets, deadline digests, and any client email or status update you choose to send — together with the recipient address.
StripeSubscription billing for your firm’s own Luminous Social planDetermined by Stripe.Your firm’s billing contact and payment details. Stripe handles card data directly; we never receive or store card numbers. No client or matter information is sent to Stripe.
OpenAIOptional “Review from your data” on the Performance pageDetermined by OpenAI.Only aggregate counts and dollar totals — open matter count, deadlines met and missed, overdue task count, billable and invoiced totals, and the number of trust ledgers showing a negative balance. No client names, no matter names, no notes, no documents, and no free text you have entered. Runs only when you press the button, and only if the deployment is configured for it.

2. What We Do Not Use

We do not use analytics, advertising, retargeting, or session-recording services, and there are no third-party scripts, embeds, or tracking pixels in the Service. Fonts are served from our own deployment rather than a font CDN, so loading a page does not contact a third party for them.

3. Your Clients’ Information

Where you use Luminous Social to hold information about your own clients, you are the one deciding what is collected and why; we hold and process it to provide the Service to you. If your professional obligations or your own client agreements require a data-processing agreement, or a restriction on where data is stored, contact us before entering client information rather than after.

4. Changes

If we add or replace a sub-processor that handles information you have entered, we will update this page. If a change materially affects how that information is handled, we will also tell account owners by email rather than relying on you to re-read this page.

5. Questions

Questions about this list, or a request for the documentation your firm needs before adopting the Service, can go to our Privacy Officer using the contact details in the Privacy Policy.