Subprocessors
Lyra uses a small number of third-party services to operate our product. These services — our “subprocessors” — process customer data on our behalf, under contractual restrictions that require them to handle that data with the same care we do.
This page lists every subprocessor that processes Lyra customer data. We update it whenever this list changes.
Last updated: June 19, 2026
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services | Application hosting, transactional email delivery, file storage | All customer data, encrypted at rest | United States |
| Anthropic | AI text generation (Vega) | Collection metadata and aggregated circulation statistics. See data handling page. | United States |
| Cloudflare | Marketing and support site hosting and DNS | Marketing and support site traffic only. No customer application data. | Global edge network |
| ISBNdb | Bibliographic metadata lookups (cover images, author info, publisher data) | ISBNs and titles only. No customer or patron data is sent. | United States |
| Neon | PostgreSQL database hosting | All customer data, encrypted at rest | United States |
| OpenAI | Embeddings for semantic catalog search | Catalog item text and search queries. See data handling page. | United States |
| Sentry | Error monitoring and diagnostics | Browser session data including school, library, and user identifiers. | United States |
| Stripe | Payment processing | Billing contact information and payment method metadata. No patron data. | United States |
Notifications of changes
When we add or change a subprocessor, we notify customers by email at least 30 days before the change takes effect, unless the change is required for security or compliance reasons. Customers who object to a new subprocessor may terminate their subscription as described in their service agreement.
Questions
Contact support@lyralibrary.com.