Service providers & other recipients.
Updated July 21, 2026

Quick answer: LeanLens uses OpenAI and Google as third-party AI providers. Supabase and Vercel support accounts, storage, hosting, and files; RevenueCat supports mobile entitlements; and analytics, diagnostics, or queue providers apply only as described below.

This page identifies verified production-capable providers that may receive personal information to operate LeanLens. It separates current paths from conditional integrations and does not treat every software package or development tool as a subprocessor.

How providers are classified

Current means LeanLens has an implemented production-capable path to the provider. It does not mean every supported feature or platform is launched. Conditional means the integration receives data only when the named feature is enabled and configured.

“Provider” is used because a service can act as a processor for one activity and as an independent controller for another. The providers listed receive information for the stated operational purpose. Mobile storefronts and some analytics or platform providers handle their own account, billing, security, or legal processing under their own terms.

Analysis and AI

OpenAI

AI analysis

Status: Current

Data categories: Photos selected for analysis, optional profile inputs, instructions and analysis context, and generated outputs.

This provider may also process training or voice-feature content if those separately controlled features are made available.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

Google

AI analysis and illustrative Future Physique images

Status: Current

Data categories: Photos selected for analysis or the normalized source frame used for Future Physique, optional profile inputs, instructions and analysis context, and generated outputs.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

Accounts, storage and delivery

Supabase

Accounts and application data

Status: Current

Data categories: Account identifiers, email, profile and preference data, saved analyses, progress data, saved progress photos, subscription state, and service records.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

Vercel

Hosting and file delivery

Status: Current

Data categories: Requests, network and device metadata, operational logs, uploaded analysis files, shared-result media, and other files handled by hosted LeanLens features.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

QStash by Upstash

Analysis job delivery

Status: Conditional

Data categories: Analysis job identifiers and the processing instructions needed to deliver queued analysis work.

Used only when the production analysis queue is enabled and configured.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

Subscriptions, analytics and diagnostics

RevenueCat

Mobile subscription management

Status: Current

Data categories: App user identifiers, product identifiers, purchase and entitlement status, transaction context, and storefront receipt metadata.

Applies when mobile subscriptions are offered through a launched storefront.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

Google Analytics

Web and native-app usage analytics

Status: Current

Data categories: Page or screen views, low-cardinality interaction events, pseudonymous app-instance identifiers, and browser, device, or runtime context. LeanLens filters raw analysis identifiers, account identifiers, free text, photos, and body- or fitness-derived result values from these events.

Loaded on configured production web hosts only after the browser stores an affirmative analytics choice. Firebase Analytics is enabled in production iOS and Android apps with advertising identifiers, personalized-ad signals, automatic native screen reporting, and tracking disabled.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

Sentry

Reliability diagnostics

Status: Conditional

Data categories: Error and performance data, runtime and device context, masked interaction context, and diagnostic breadcrumbs.

Used only when diagnostics are configured. Web session replay is disabled.

Role, location and transfer context: Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.

Storefronts and other recipients

  • Apple App Store and Google Play — mobile storefronts can process store-account, payment, purchase, refund, and subscription information under their own terms. They may be independent controllers rather than LeanLens subprocessors. Only a storefront offer actually available in the app is treated as launched. Storefront purchases must be managed through the applicable Apple App Store or Google Play process shown with the purchase, without limiting statutory withdrawal, conformity, refund, or chargeback rights that cannot lawfully be excluded.
  • User-directed share recipients — people who receive a share link are recipients chosen by the user, not LeanLens subprocessors.
  • Authorities and transaction counterparties — disclosures required by law or made in connection with a corporate transaction do not automatically make the recipient a subprocessor.

Provider safeguards and change control

  • LeanLens does not use uploaded photos to train its own general-purpose model. It sends selected photos to the AI provider used for the requested analysis. Provider-side retention and model-improvement practices depend on the provider service and terms in use, so LeanLens does not promise zero provider retention or training without provider-specific confirmation.
  • The providers listed receive information for the stated operational purpose. Mobile storefronts and some analytics or platform providers handle their own account, billing, security, or legal processing under their own terms.
  • Some providers may process information outside Portugal or the EEA. The destination and transfer safeguard depend on the provider and service configuration in use. Contact support@leanlens.ai for the current information available for a particular provider.
  • Categorized support-contact messages are stored with LeanLens application data and are not sent to the generic feedback destination.
  • Other feedback categories may use an additional configured delivery service. LeanLens can identify the current recipient for a specific request on request.
  • Conditional providers receive data only when the named integration is enabled. Sentry session replay is disabled, and non-essential analytics requires an affirmative choice.

Provider changes that materially affect personal-information handling should be reflected on this page and in the Privacy Policy before or when the change takes effect, as applicable.