Subprocessors
Subprocessors
This page lists subprocessors Leara may use to provide the website, app, API, SDK support, analytics, billing, and model-backed composition features.
Last updated August 31, 2026
1. How We Use Subprocessors
Leara uses subprocessors to host the application, store product data, authenticate users, process payments, measure public website traffic after consent, and call model providers when composition features are used. A provider only processes the data needed for the relevant feature.
2. Current Subprocessors
| Subprocessor | Purpose | Data categories | Location and terms |
|---|---|---|---|
| Render | Cloud hosting, application runtime, deployment, networking, and infrastructure logs. | Account, workspace, prompt, output, request, usage, security, and log data processed by the hosted app. | Regions depend on deployment configuration. Current app configuration targets Frankfurt. Render DPA |
| MongoDB | Database hosting and persistence for accounts, workspaces, projects, API key hashes, usage, requests, traces, and settings. | Account data, workspace data, product configuration, API key metadata and hashes, usage records, trace records, and product data submitted to the app. | Region depends on the configured MongoDB deployment. MongoDB DPA and MongoDB subprocessors |
| Google sign-in and Google Analytics for public website measurement after consent. | Authentication profile data such as name, email, and profile image; analytics identifiers and event metadata when optional cookies are accepted. | Processing locations depend on Google services used. Google Analytics data processing terms and Google subprocessors | |
| Stripe | Payment processing, subscription management, checkout, customer portal, invoices, tax and billing status. | Billing contact data, subscription status, invoice metadata, payment status, tax metadata, and Stripe customer identifiers. Leara does not store full card numbers. | Processing locations depend on Stripe services used. Stripe DPA and Stripe service providers |
| OpenAI | Model-backed composition, structured output, repair, and evaluation when OpenAI-powered features are configured or used. | Prompts, selected context, tool results, generated interface output, model metadata, error metadata, and usage metadata needed for composition. | Processing locations depend on OpenAI services used. OpenAI DPA and OpenAI subprocessor list |
3. Service-Specific Use
- Google Analytics is loaded only after optional cookie consent on public pages.
- Stripe receives billing data only when checkout, subscriptions, invoices, or billing portal features are used.
- OpenAI receives prompt and context data only when model-backed composition features are configured or used.
- MongoDB is used when database persistence is configured; local development may use in-memory storage.
4. Changes and Objections
Leara may add or replace subprocessors as the service changes. We will update this page when making material changes. Customers may object on reasonable data protection grounds by contacting privacy@leara.dev. If we cannot reasonably resolve an objection, either party may terminate the affected service according to the Agreement.