1. The commitment
Before any new subprocessor processes Customer Data, this register is updated and customer account contacts are notified at least 30 days in advance, with an objection right — the mechanics are in DPA §7. Every subprocessor is bound by a written contract imposing data-protection obligations at least as protective as the DPA’s, and Lucubra remains fully responsible for each one’s performance.
2. Current subprocessors
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Render (render.com) | Cloud hosting — the platform’s API and ingestion services and its managed database, the primary datastore | All Customer Data classes, encrypted in transit and at rest | United States (Oregon) |
| Cloudflare, Inc. | Content delivery and DNS in front of the platform; object storage for build artifacts, symbol files, and diagnostic payloads; serving of install pages and short links | Build artifacts and symbols (customer IP), diagnostic payloads (bounded at 30 days), delivery-layer request logs | United States, with a global edge network |
| Apple Inc. | Relay for notifications the Service delivers to End-User devices on Apple platforms — engaged only for Apps whose owner configures delivery credentials; until you do, nothing reaches Apple | Device notification-delivery tokens and notification payload content, in transit for delivery | United States |
| Google LLC | Relay for notifications the Service delivers to End-User devices via Google’s delivery network — engaged only for Apps whose owner configures delivery credentials; until you do, nothing reaches Google | Device notification-delivery tokens and notification payload content, in transit for delivery | United States |
No other vendor processes Customer Data. Apple and Google receive data only for Apps whose owner has configured delivery credentials — listing them here is what makes the Section 1 promise keepable the moment you do. Any further addition arrives through that process first: register update, 30 days’ notice, objection right.
3. Providers for account data
Separate from Customer Data, the vendors that process customer account data (the identity and operational data of the people operating a Pharen account) are described in the Privacy Notice: Render and Cloudflare above, plus GitHub, Inc. as the sign-in identity provider for the console and CLI (United States).
Data sources are not subprocessors. Where you connect your own app-store credential, the Service retrieves data from Apple at your instruction — your reviews, sales, and performance data, plus public listing information. In that flow Apple processes data as Apple, under your agreement with it, and nothing is disclosed to Apple by us; Apple appears in Section 2 only for the delivery-relay role.
4. Changes & notifications
This page is the system of record; its version history below records every change. To receive change notices by email in addition to the DPA’s account-contact notice, email hello@pharen.ai with the subject “Subscribe: subprocessor notices.”
Version history
- 1.0 — September 2, 2026 — initial register: Render, Cloudflare.
The Pharen platform is operated by Lucubra LLC, a Washington (USA) limited liability company, operating the Pharen platform. 522 W Riverside Ave, Ste N, Spokane, WA 99201-0581, USA · hello@pharen.ai