Subprocessors
Effective Date: 2026-05-08 · Last Updated: 2026-05-08
This page lists the third-party service providers ("subprocessors") that Lucid North LLCuses to operate the Song Zero application and related services (the "Service"). Each subprocessor processes information only to provide a specific function on our behalf, under contractual confidentiality and security obligations.
This page is referenced in §7 of our Privacy Policy and is updated when subprocessors are added, removed, or materially changed.
Current Subprocessors
| Subprocessor | Function | Data Processed | Processing Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing, subscription management, Print Product checkout, refunds, tax | Email, name, payment method (card brand + last 4), billing address, Stripe customer ID, subscription status | United States |
| Supabase, Inc. | Primary database, authentication, file storage, Row Level Security | Account data, User Inputs, Generations, Run telemetry, audit log entries | United States (AWS us-east-1) |
| Vercel, Inc. | Application hosting, edge delivery, serverless functions, deployment logs | Application traffic, request logs, IP address, deployment artifacts | United States and global edge network |
| Inngest, Inc. | Background job orchestration for the Run pipeline | Run metadata, event payloads, job state | United States |
| Anthropic, PBC | LLM inference (Claude models) for blurb generation and editorial commentary | User Inputs, intermediate prompts, model outputs | United States |
| Google LLC (Gemini API) | LLM inference for fact-checking and validation stages | Intermediate prompts | United States |
| Google LLC (OAuth) | "Sign in with Google" authentication | OAuth tokens, Google account ID, email, name | United States |
| Google LLC (Google Analytics 4) | Aggregate usage analytics | IP address (truncated), device data, page views, event properties | United States |
| Spotify AB | Track metadata lookup via the Spotify Web API; embedded playlist player delivery to end users | Track titles, artist names, album metadata; no personal Spotify data is accessed | United States and European Union |
| Resend, Inc. | Transactional email delivery (magic-link sign-in, receipts, account notices) | Email address, message content, delivery telemetry | United States |
| Print-on-Demand Provider (to be named at launch — e.g., Printful, Printify, or Gelato) | Print Product fulfillment, printing, packaging, and shipping | Customer name, shipping address, contact information, design files | Provider-dependent (typically United States and European Union) |
How We Manage Subprocessors
- Selection. We select subprocessors based on their security posture, contractual data-protection commitments, and fitness for the specific function.
- Contracts. Each subprocessor is engaged under a written agreement that includes confidentiality obligations and data-handling commitments. Where applicable (Stripe, Supabase, Vercel, Resend, Anthropic, Google), agreements include a Data Processing Addendum (DPA) covering U.S. state privacy laws.
- No training on your data. Our agreements with Anthropic and Google (Gemini) prohibit the use of your User Inputs or any pipeline content to train their foundation models.
- No sale of personal information. None of our subprocessors are authorized to sell or share your personal information for cross-context behavioral advertising.
- Security. Subprocessors apply industry-standard security controls (encryption in transit and at rest, access logging, role-based access). We layer our own controls on top, including Supabase Row Level Security, scoped service-role access, Stripe webhook signature verification, and audit logging of administrative actions.
Notice of Changes
We will update this page when we add, remove, or materially change a subprocessor. For material changes that affect how your information is processed, we will provide notice by email or in-app notification at least 14 days before the change takes effect, consistent with §15 of our Privacy Policy.
If you would like to be notified of subprocessor changes by email, you can subscribe to update notices by emailing support@song-zero.app with the subject line Subprocessor Updates.
Questions
For questions about this list, our DPAs, or to request additional information about a specific subprocessor's data-handling practices, contact:
Lucid North LLC — Privacy
6 Honeysuckle Ct., Brick, NJ 08724, United States
Email: support@song-zero.app