1.What a "subprocessor" is
A subprocessor is a third-party company we use to help deliver Amaina — for example, to store your account, transcribe your voice, look up the weather, or manage your in-app subscription. When a subprocessor handles your personal data, it does so only on our instructions and only for the purpose listed below, under a written contract (a Data Processing Agreement, or DPA, where applicable).
We keep this list current and give advance notice before we add a new subprocessor (see section 5).
Two things we want to be clear about up front:
- We never send your health data — your migraine logs, the details you record, data read from Apple Health / Google Health Connect, or any AI-generated summary — to advertising or analytics ad-platforms, and we never use it to build advertising audiences.
- We never sell your personal data.
2.Subprocessor list
The table below covers the Amaina app (iOS; Android / Health Connect is a planned later release) and the amaina.health website. The app itself uses two in-product measurement providers — Amplitude (usage analytics) and Google Firebase Crashlytics (crash diagnostics), both described below. Separately, the last group (marked "web only") applies only to the website funnel, not to the app — those are advertising/analytics pixels on the marketing site, distinct from the in-app measurement providers.
On a future Android release, your device's operating system (Google) would play the same role Apple plays on iOS: it would perform speech-to-text on your device and mediate access to Google Health Connect (the Android equivalent of Apple Health). As on iOS, your audio would never reach us or Anthropic — we would receive only the resulting text — and raw Health Connect readings would be processed on your device. The OS-level safeguards described in the Apple row would apply the same way on Android. Amaina v1 ships on iOS only.
| Provider | Data it receives | Purpose | Location | Safeguard |
|---|---|---|---|---|
| Anthropic (Claude) | The text of your log and summary prompts. No name, email, or date of birth; no audio; no raw HealthKit / Health Connect readings; no health identifiers in field names. | Two things: (1) AI structuring of your logged text into fields (time, intensity, duration, symptoms, aura, medication, triggers); and (2) drafting the descriptive doctor-visit summary narrative from the prompt built from your logs. Both are gated on your AI consent; the doctor summary also has a static, no-AI fallback. | United States | DPA (with SCCs) in force; no training on our data; inputs/outputs auto-deleted within 30 days, kept longer only if content is flagged for a safety/policy review; ZDR requested but NOT available to us (enterprise-only, declined 2026-07-07) — we rely on the 30-day default + DPA + our own minimization; standard (non-Covered) model; backend-only calls. |
| OpenWeatherMap | Approximate coordinates only — reduced accuracy, when-in-use (when you enable weather features). | Reads local barometric pressure and a short (~24-hour) forecast; when a drop of about 6 hPa or more is forecast, Amaina shows a general colour-coded heads-up (green / amber). This is a general environmental signal — not personalized to your health history and not a medical prediction. | US / EU | We send only approximate coordinates and do not store them on our side; the lookup is transient (used only to return the weather/pressure for that request). We do not use location for tracking or advertising. |
| Google (Firebase Auth + Firestore) | Account data (first name, email, date of birth, and an optional Sex field) and your attack logs (including recorded barometric pressure). | Sign-in/authentication and secure storage of your account and logs. | United States | DPA with SCCs; encryption in transit and at rest. |
| Apple (Speech / HealthKit / App Store / In-App Purchase) | Audio for on-device or Apple Speech transcription (never reaches us); HealthKit data stays on your device (we read/write only with your granular permission); App Store handles app distribution; In-App Purchase processes your subscription payment and card details directly — we never see or store your card. | Voice transcription (on-device or on Apple's servers), Health integration, app distribution, and in-app subscription purchase/billing. | United States | Apple's terms and Apple Speech / HealthKit rules; HealthKit data is never used for advertising, marketing, or data-mining and is never shared for those purposes; Apple handles all payment and card data under its own terms — we never receive card data. |
| RevenueCat | Your App Store purchase receipt, an app-assigned user identifier, and your subscription / entitlement status. No card data; no health data. | Validate your App Store subscription and unlock paid features (subscription / entitlement management), and forward subscription-lifecycle events to our analytics provider (Amplitude) via a server-side integration. | United States | DPA. Receives no card data (Apple handles the payment) and no health data; used to validate purchases, manage entitlements, and — via a server-side RevenueCat→Amplitude integration — forward subscription-lifecycle events (trial start, purchase, renewal, cancellation) to Amplitude, keyed to the same anonymous Firebase UID and carrying no card data and no health data. |
| Amplitude | Anonymous product-usage/behaviour events — onboarding and funnel steps, attack-logging events, voice-transcription quality, use of the pain head-map (a flag only — no location value), report generated/shared, paywall viewed, and an elevated-weather-risk banner shown. Health-adjacent facts appear only as privacy-safe proxies: severity as a coarse bucket (low/mod/high), medication as a yes/no, triggers as a count, pain-map use as a flag — never raw or derived health data, no medication/trigger names, no dates, no pain-location values, no log content or AI output. (Full event list: the app's ANALYTICS_EVENTS.md.) Identified only by an anonymous internal user id (your Firebase UID), never your name or email. Separately, subscription-lifecycle events forwarded from RevenueCat (e.g. trial started, subscription purchased/renewed/canceled), keyed to the same anonymous Firebase UID. No card data, no health data. | Product and subscription analytics. Behaviour/usage events are collected only when you turn on "Usage analytics" (off by default). Separately, subscription-lifecycle events (rc_*) are sent to Amplitude via a server-side RevenueCat→Amplitude integration on a contractual/billing basis — these are NOT controlled by the "Usage analytics" toggle. | United States | DPA. No Session Replay; no advertising or cross-app tracking (no IDFA / no ATT); never used to build advertising audiences. IP address, geo (country/region/city/DMA/lat-lng), carrier, and advertising id capture are disabled in the Amplitude SDK (TrackingOptions), build 18 — so no IP or location is collected and "Tracking = No" does not depend on a console setting. Revenue events carry no card data and no health data. |
| Google — Firebase Crashlytics | Anonymous crash reports (stack traces, device/OS) to fix bugs — never health data, and not linked to your identity. | Crash diagnostics. On by default; turn it off under "Crash diagnostics" in Settings → Privacy & consent. | United States | DPA. Reports are anonymous and not linked to you; no health data in crash keys. |
| HubSpot (web only) | First name and email. | Website email / CRM (launch and product updates you opt into). | United States | DPA. |
| Google / Meta ad + analytics pixels (web only) | Web usage and cookie data. | Aggregate ad-conversion measurement only — no health data. | United States | Consent-gated; health data, HealthKit data, structured logs, and AI outputs are never sent to ad platforms and never used to build custom, lookalike, or health-interest audiences. |
3.How to read this list (a few notes)
- Your audio never leaves your phone for us. Apple performs speech-to-text either on your device or on Apple's servers depending on your device, language, and settings. Either way, we and Anthropic receive only the resulting text — never the audio. A tap / manual-entry option is always available and works without any AI.
- Anthropic (Claude) — what it does and doesn't get. There are exactly two places Amaina calls Anthropic, both gated on your AI consent: (1) to structure your voice/typed log into fields, and (2) to draft the descriptive doctor-visit summary narrative (the doctor summary also has a static, no-AI fallback). In both cases we send Anthropic only the text — the log to be structured, or the prompt built from your logs for the summary. We do not send your name, email, date of birth, audio, or raw HealthKit / Health Connect readings, and we do not put any health identifiers in the AI's field names. Anthropic acts as a subprocessor under a DPA (with SCCs) and does not train on our data, and it automatically deletes the text of AI requests within 30 days — keeping it longer only if content is flagged for a safety/policy review. (We asked Anthropic for Zero Data Retention, which would remove even that short window, but it is currently offered only to large enterprise accounts, so we rely on this standard 30-day-deletion policy together with our data-processing agreement and our own data minimization — only text, never your name, email, date of birth, audio, or raw health-app readings.) The AI is called only from our own backend server — never directly from your browser.
- In-app Insights are computed on your device/app, not by AI. The FREQUENCY, SLEEP, CYCLE, ACTIVITY, and PROFILE cards are produced by rule-based logic inside the app — they do not go to Anthropic and are descriptive only.
- Health integrations stay local. Raw readings from Apple Health / Google Health Connect (sleep, cycle, workouts) are processed on your device and are not retained by us beyond what's needed; your attack log (including recorded barometric pressure) is saved to your account in Firestore.
- You subscribe inside the app, through Apple. Amaina sells an auto-renewable subscription via Apple In-App Purchase (StoreKit), managed with RevenueCat. Apple processes the payment and your card — we never see or store card data; RevenueCat receives only the purchase receipt, an app-assigned user id, and your subscription/entitlement status to unlock paid features. The subscription automatically renews at the then-current price unless auto-renew is turned off at least 24 hours before the end of the current period; payment is charged to your Apple ID at confirmation of purchase. Manage or cancel anytime in Settings → your Apple ID → Subscriptions; refunds are handled by Apple (Report a Problem / Apple Support). Deleting your Amaina account does not cancel your App Store subscription — you must cancel it in your Apple subscription settings. amaina.health is a marketing and legal-information site only; it does not host checkout or process payments.
4.What we never do with these providers
To keep Amaina squarely a wellness tracker — not a medical device, and not an advertising product built on your health data — we hold these providers to hard limits:
- We never send your health data, HealthKit data, structured logs, or AI outputs to Meta, Google's ad products, or any advertising platform.
- We never use your health data to build custom, lookalike, or health-interest audiences.
- We never sell your personal data.
- HealthKit data is never used for advertising, marketing, or data-mining, and never shared with third parties for those purposes.
- Our in-app measurement is not advertising. Amplitude receives anonymous behaviour events only (severity as a coarse bucket, medication as a yes/no, triggers as a count) — never raw or derived health data, log content, or AI output — and there is no IDFA and no cross-app tracking (no ATT prompt). Behaviour/usage analytics is opt-in and off by default. Separately, subscription-lifecycle/billing events flow to Amplitude via a server-side RevenueCat integration on a contractual/billing basis and are NOT governed by the Usage-analytics toggle; these carry no card data and no health data. Crash diagnostics (Firebase Crashlytics) is anonymous and can be turned off in Settings → Privacy & consent.
5.Notice before we add a subprocessor
Before we engage a new subprocessor that will process your personal data, we will update this page and provide reasonable advance notice — for example, by updating the "Last updated" date above and, for material changes, by notice in the app or by email. You may review the change and, where applicable law gives you the right, object or exercise your privacy choices (see the Privacy Policy for how). The current version of this list is always available at amaina.health/subprocessors.
Your US rights over this data. US residents — including in Washington and California — have specific rights over health-related data, including consent controls on sharing consumer health data (Washington My Health My Data Act) and, in California, a right to limit the use of sensitive personal information and to have the Global Privacy Control (GPC) honored. We do not share your health data for advertising with any provider on this list. For how to exercise these rights, see the Privacy Policy, Section 8 (Your US privacy rights).
If a provider suffers a breach. If a subprocessor on this list suffers a data breach affecting your data, we notify you as described in the Privacy Policy, Section 12 (Security and breach notification) — consistent with the FTC Health Breach Notification Rule.
6.Note for EEA / UK users (secondary)
We do not currently target the EEA or UK at launch (Amaina is US-only). We include this note only in case that changes.
If we begin offering Amaina in the EEA or UK, the providers above would act as processors or sub-processors under Article 28 GDPR, with international transfers outside the EEA/UK covered by Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or each provider's equivalent safeguard. Health data would be treated as special-category data (Article 9), processed on the basis of your explicit consent. Copies of transfer safeguards are available on request at legal@smart-it.io.
7.Contact
Questions about this list or any provider on it:
Email: legal@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
This page is written in plain English. If anything is unclear, email legal@smart-it.io — we'll explain.
<!-- INTERNAL — NOT FOR PUBLICATION. Remove this block before the page goes live.
Pre-publication checklist / open items for the health-tech lawyer + CTO:
- PLATFORM SCOPE (lawyer). This doc — and the whole Amaina doc family — assumes iOS + Android (Google Health Connect, Android Settings paths; see healthkit_data_use.md, privacy_policy.md, account_and_data_deletion.md). The current PL-025 task brief says "Native iOS app + web," US-only. Confirm the launch platform set. If iOS-only at launch: strip Health Connect / Android references across ALL docs together (not just this one) so nothing contradicts. Left as iOS + Android here to stay consistent with the sibling docs.
- CLAUDE-CALLING FEATURES (CTO). CONFIRMED for build 1.0.0(22): there are exactly TWO AI (Anthropic / Claude) call sites, both LIVE and both gated on AI consent — (1) structuring your voice/typed log into fields, and (2) drafting the doctor-visit summary narrative (the report also has a static, no-AI fallback). The tap/manual path never uses AI. Wording in the table and section 3 reflects this; no open item remaining here.
- OPENWEATHERMAP DPA. OWM is the only subprocessor with no DPA listed. The safeguard cell now states only what Amaina controls (we don't store coordinates; transient lookup). If a DPA or OWM's published retention terms support a stronger statement, cite that basis; otherwise leave as-is. Self-assessed acceptable for MVP (Anton, 2026-07-24) — coarse/transient/not-stored; not routed to counsel (revisit post-MVP).
- LINK PLACEHOLDERS (site build). Replace every "Privacy Policy" bracket (and any "AI Processing Notice"-style bracket used across the doc family) with the real amaina.health URL. Confirm no bracketed link placeholders remain in any public-facing doc before submission. Confirm the Privacy Policy still carries: MHMDA separate-consent-to-share, CPRA right-to-limit + GPC (Section 8), and the FTC HBNR breach commitment (Section 12) that this page points to.
-->