Subprocessors
Version: 2026-07-04 · Effective: July 4, 2026
These third parties process data on our behalf to operate CiteLyra. What each receives depends on your activity (e.g. AI providers receive your topic and draft content during generation).
| Subprocessor | Purpose | Data it may receive | Region |
|---|---|---|---|
| Lemon Squeezy (Merchant of Record) | Payments, checkout, tax, billing | Name, email, payment details (handled by them), purchase events | US/EU |
| AI provider — Google (Gemini) / DeepSeek / OpenAI / Anthropic, per configuration | Draft generation | Your topic and generated/intermediate text | per provider |
| Search / citation providers — e.g. Serper / DataForSEO, academic APIs (Crossref, OpenAlex, Semantic Scholar) | Source discovery & citation lookup | Search queries derived from your topic | per provider |
| DigitalOcean (application host) | Application hosting / compute | All processed data transits the servers | EU |
| Cloudflare R2 (or chosen object storage) | Storage of generated artifacts | Generated documents and intermediate files | Global |
| Email provider (SMTP) | Verification, password-reset, transactional email | Email address, message content | Global |
| Sentry (if enabled) | Error monitoring | Error metadata, correlation IDs (draft content excluded/redacted) | Global |
Notes
- Confirm retention/training terms: for each AI provider, confirm in writing whether submitted content may be retained or used for training, and prefer no-training/zero-retention tiers where available.
- Transfers: where a provider processes data outside the EEA, ensure an appropriate transfer mechanism (e.g. EU SCCs) is in place.
- We will update this list and notify customers before adding a subprocessor that materially changes how data is processed.
Contact: support@citelyra.com.