1.What a "subprocessor" is
A subprocessor is a third-party company we use to help deliver Amaina — for example, to store your account, transcribe your voice, look up the weather, or manage your in-app subscription. When a subprocessor handles your personal data, it does so only on our instructions and only for the purpose listed below, under a written contract (a Data Processing Agreement, or DPA, where applicable).
We keep this list current and give advance notice before we add a new subprocessor (see section 5).
Two things we want to be clear about up front:
- We never send your health data — your migraine logs, the details you record, data read from Apple Health / Google Health Connect, or any AI-generated summary — to advertising or analytics ad-platforms, and we never use it to build advertising audiences.
- We never sell your personal data.
2.Subprocessor list
The table below covers the Amaina app (iOS; Android / Health Connect is a planned later release) and the amaina.health website. The app itself uses two in-product measurement providers — Amplitude (usage analytics) and Google Firebase Crashlytics (crash diagnostics), both described below. Separately, providers marked "web only" apply to the website and the web questionnaire, not to the app. That group is no longer only advertising pixels: the web questionnaire is built and hosted by a third party, and the web subscription is charged through Stripe, so those providers are listed alongside the pixels.
On a future Android release, your device's operating system (Google) would play the same role Apple plays on iOS: it would perform speech-to-text on your device and mediate access to Google Health Connect (the Android equivalent of Apple Health). As on iOS, your audio would never reach us or Anthropic — we would receive only the resulting text — and raw Health Connect readings would be processed on your device. The OS-level safeguards described in the Apple row would apply the same way on Android. Amaina v1 ships on iOS only.
| Provider | Data it receives | Purpose | Location | Safeguard |
|---|---|---|---|---|
| Anthropic (Claude) | The text of your log and summary prompts. No name, email, or date of birth; no audio; no raw HealthKit / Health Connect readings; no health identifiers in field names. | Two things: (1) AI structuring of your logged text into fields (time, intensity, duration, symptoms, aura, medication, triggers); and (2) drafting the descriptive doctor-visit summary narrative from the prompt built from your logs. Both are gated on your AI consent; the doctor summary also has a static, no-AI fallback. | United States | DPA (with SCCs) in force; no training on our data; inputs/outputs auto-deleted within 30 days, kept longer only if content is flagged for a safety/policy review; ZDR requested but NOT available to us (enterprise-only, declined 2026-07-07) — we rely on the 30-day default + DPA + our own minimization; standard (non-Covered) model; backend-only calls. |
| OpenWeatherMap | Approximate coordinates only — reduced accuracy, when-in-use (when you enable weather features). | Reads local barometric pressure and a 5-day forecast; on a forecast fall of about 6 hPa or more over ~24 hours Amaina shows a "Pressure dropping today" note, and the weather view charts pressure coloured by how fast it is forecast to fall (Steady / Falling / Falling fast). Humidity and temperature are shown without colour coding. This is a general environmental signal on a fixed threshold — not personalized to your health history and not a prediction of personal risk. | US / EU | We send only approximate coordinates and do not store them on our side; the lookup is transient (used only to return the weather/pressure for that request). We do not use location for tracking or advertising. |
| Google (Firebase Auth + Firestore) | Account data (first name, email, date of birth, and an optional Sex field) and your attack logs (including recorded barometric pressure). | Sign-in/authentication and secure storage of your account and logs. | United States | DPA with SCCs; encryption in transit and at rest. |
| Apple (Speech / HealthKit / App Store / In-App Purchase) | Audio for on-device or Apple Speech transcription (never reaches us); HealthKit data stays on your device (we read/write only with your granular permission); App Store handles app distribution; In-App Purchase processes your subscription payment and card details directly — we never see or store your card. | Voice transcription (on-device or on Apple's servers), Health integration, app distribution, and in-app subscription purchase/billing. | United States | Apple's terms and Apple Speech / HealthKit rules; HealthKit data is never used for advertising, marketing, or data-mining and is never shared for those purposes; Apple handles all payment and card data under its own terms — we never receive card data. |
| Adapty Tech Inc. — entitlements in the iOS app (replaced RevenueCat in build 58) | Your purchase receipt (App Store) or subscription record (web), an app-assigned user identifier (customerUserId = your Firebase uid), and your subscription / entitlement status. Additionally, on a web-originated purchase, Adapty's deferred attribution channel (ios_deferred_data) carries the FunnelFox user id and your email so the purchase can be reconciled to your account on first sign-in. No card data; no health data. | Validate your subscription — bought in the app through Apple or on the web through Stripe — and unlock paid features; resolve where to manage or cancel. | United States | DPA. Receives no card data and no health data. The SDK's own bundled privacy manifest declares no tracking, no tracking domains, and collection limited to purchase history for app functionality. |
| Adapty Tech Inc. — FunnelFox web questionnaire (web only) | Your questionnaire answers (including health answers and, on the female branch, whether attacks follow your menstrual cycle) and your email. | Builds, hosts and serves the web questionnaire and the checkout page that follows it. | United States | DPA in force (FF 202814, signed 2026-08-26); SOC 2 report reviewed 2026-08-25. Health answers are never sent to advertising platforms. Retention: under our data processing agreement, all personally identifiable information within questionnaire responses — including email address, device identifiers and IP address — is automatically anonymised or pseudonymised within one (1) hour of receipt, and longer retention requires our written request. Onward transfer of health-related responses is restricted to Amazon Web Services, Inc. and OVH US, LLC for hosting. On our written request, all personal data is deleted, destroyed or returned. |
| Stripe (web only) | Your card and billing details, entered directly with Stripe, and your email. No health answers. | Processes the web subscription payment and hosts the billing page where you manage or cancel it. | United States | Stripe's DPA under the Stripe Services Agreement. We never see or store your card details. Stripe is not merchant of record — we are the seller of record for web subscriptions. |
| Resend (web only) | Your email address, and the content of the transactional emails we send to it — for example, confirmation that you cancelled a web subscription and the date your access runs to. No health answers, no card data. | Sends transactional emails about your web subscription. | United States | Operated by Plus Five Five, Inc. (San Francisco, CA). DPA in force under Resend's Data Processing Addendum, which is incorporated into its Terms of Service and becomes binding on account creation; it includes the EU Standard Contractual Clauses (Module Two, controller-to-processor), the UK Addendum and the Swiss equivalent. Resend's own subprocessor list is published at resend.com/legal/subprocessors; delivery runs on Amazon Web Services. Our transactional emails contain no health data. |
| Amplitude | Anonymous product-usage/behaviour events — onboarding and funnel steps, attack-logging events, voice-transcription quality, use of the pain head-map (a flag only — no location value), report generated/shared, paywall viewed, and an elevated-weather-risk banner shown. Health-adjacent facts appear only as privacy-safe proxies: severity as a coarse bucket (low/mod/high), medication as a yes/no, triggers as a count, pain-map use as a flag — never raw or derived health data, no medication/trigger names, no dates, no pain-location values, no log content or AI output. (Full event list: the app's ANALYTICS_EVENTS.md.) Identified only by an anonymous internal user id (your Firebase UID), never your name or email. Separately, subscription-lifecycle events forwarded from Adapty (e.g. trial started, subscription purchased/renewed/canceled), keyed to the same anonymous Firebase UID. No card data, no health data. | Product and subscription analytics. Behaviour/usage events are collected only when you turn on "Usage analytics" (off by default). Separately, subscription-lifecycle events are sent to Amplitude via a server-side Adapty→Amplitude integration on a contractual/billing basis — these are NOT controlled by the "Usage analytics" toggle. | United States | DPA. No Session Replay; no advertising or cross-app tracking (no IDFA / no ATT); never used to build advertising audiences. IP address, geo (country/region/city/DMA/lat-lng), carrier, and advertising id capture are disabled in the Amplitude SDK (TrackingOptions), build 18 — so no IP or location is collected and "Tracking = No" does not depend on a console setting. Revenue events carry no card data and no health data. |
| Google — Firebase Crashlytics | Anonymous crash reports (stack traces, device/OS) to fix bugs — never health data, and not linked to your identity. | Crash diagnostics. On by default; turn it off under "Crash diagnostics" in Settings → Privacy & consent. | United States | DPA. Reports are anonymous and not linked to you; no health data in crash keys. |
| HubSpot (web only) | First name and email. | Website email / CRM (launch and product updates you opt into). | United States | DPA. Scope: receives submissions from the website contact form only. The web questionnaire does not send anything to HubSpot, and no longer collects a name. |
| Upstash (web only) | Visitors' IP address only. | Rate-limiting our serverless functions, to protect them from abuse. | Being confirmed | IP address only — no health data, no email, no account data. Processing region and agreement reference are being confirmed and will be stated here. |
| Google / Meta ad + analytics pixels (web only) | Web usage and cookie data. | Aggregate ad-conversion measurement only — no health data. | United States | Consent-gated; health data, HealthKit data, structured logs, and AI outputs are never sent to ad platforms and never used to build custom, lookalike, or health-interest audiences. |
| Vercel (web only) | Visitors' IP address, user agent, request path and query-string parameters, plus whatever our own serverless functions write to their logs. Hosts amaina.health as static pages and runs the functions in api/ — including the AI endpoint the mobile app calls, so log text transits Vercel en route to Anthropic. | Website hosting and our serverless backend. | United States (primary); Vercel reserves transfers to wherever it or its subprocessors operate. | DPA in force under Vercel's Data Processing Addendum, which includes Standard Contractual Clauses. Vercel's own subprocessor list is published at security.vercel.com. Runtime logs retain request metadata only — request bodies are never written to logs — and are kept for a short window. |
Where web-questionnaire data rests. If you fill in the questionnaire on our website, your answers are held by our funnel provider (Adapty Tech Inc.) and are not copied into our own systems. If you go on to subscribe, the only thing that reaches us is your email address, which lands in our own account store (Google Firebase). To have your questionnaire answers deleted, email us — we instruct the provider.
What our own serverless functions do. amaina.health is served as static pages by Vercel, and a small set of Vercel functions sit behind it: one is the backend that relays your logged text to Anthropic for the AI features (never directly from your browser), one posts website contact-form submissions to HubSpot, and three handle subscription billing with Stripe and Adapty. Vercel therefore processes your IP address and request metadata, and our AI requests pass through it. Request bodies are not written to logs.
3.How to read this list (a few notes)
- Your audio never leaves your phone for us. Apple performs speech-to-text either on your device or on Apple's servers depending on your device, language, and settings. Either way, we and Anthropic receive only the resulting text — never the audio. A tap / manual-entry option is always available and works without any AI.
- Anthropic (Claude) — what it does and doesn't get. There are exactly two places Amaina calls Anthropic, both gated on your AI consent: (1) to structure your voice/typed log into fields, and (2) to draft the descriptive doctor-visit summary narrative (the doctor summary also has a static, no-AI fallback). In both cases we send Anthropic only the text — the log to be structured, or the prompt built from your logs for the summary. We do not send your name, email, date of birth, audio, or raw HealthKit / Health Connect readings, and we do not put any health identifiers in the AI's field names. Anthropic acts as a subprocessor under a DPA (with SCCs) and does not train on our data, and it automatically deletes the text of AI requests within 30 days — keeping it longer only if content is flagged for a safety/policy review. (We asked Anthropic for Zero Data Retention, which would remove even that short window, but it is currently offered only to large enterprise accounts, so we rely on this standard 30-day-deletion policy together with our data-processing agreement and our own data minimization — only text, never your name, email, date of birth, audio, or raw health-app readings.) The AI is called only from our own backend server — never directly from your browser.
- In-app Insights are computed on your device/app, not by AI. The FREQUENCY, SLEEP, CYCLE, ACTIVITY, and PROFILE cards are produced by rule-based logic inside the app — they do not go to Anthropic and are descriptive only.
- Health integrations stay local. Raw readings from Apple Health / Google Health Connect (sleep, cycle, workouts) are processed on your device and are not retained by us beyond what's needed; your attack log (including recorded barometric pressure) is saved to your account in Firestore.
- There are now two ways to subscribe, and they work differently.
In the app, through Apple. Amaina sells an auto-renewable subscription via Apple In-App Purchase (StoreKit), with entitlements managed by Adapty. Apple processes the payment and your card — we never see or store card data; Adapty receives only the purchase receipt, an app-assigned user id, and your subscription/entitlement status. The subscription renews automatically at the then-current price unless auto-renew is turned off at least 24 hours before the end of the current period; payment is charged to your Apple ID at confirmation of purchase. Manage or cancel anytime in Settings → your Apple ID → Subscriptions; refunds for App Store purchases are handled by Apple (Report a Problem / Apple Support).
On the web, through Stripe. If you subscribe at the end of the web questionnaire, we are the seller of record — not Apple. Stripe collects your card details directly and processes the payment; we never see or store them. You manage or cancel the subscription on your billing page, the link to which is included in the subscription emails Stripe sends you and published on amaina.health; cancelling there takes effect at the end of the period you have already paid for. Refunds for web subscriptions are handled by us, not Apple — email legal@smart-it.io. Apple's "Report a Problem" route does not apply to web subscriptions.
In both cases, deleting your Amaina account does not cancel your subscription — cancel it in your Apple subscription settings (App Store purchase) or on your billing page (web purchase).
Correction to an earlier version of this page. A previous version stated that "amaina.health is a marketing and legal-information site only; it does not host checkout or process payments." That is no longer accurate — the web questionnaire ends in a Stripe checkout, and this page has been updated accordingly.
4.What we never do with these providers
To keep Amaina squarely a wellness tracker — not a medical device, and not an advertising product built on your health data — we hold these providers to hard limits:
- We never send your health data, HealthKit data, structured logs, or AI outputs to Meta, Google's ad products, or any advertising platform.
- We never use your health data to build custom, lookalike, or health-interest audiences.
- We never sell your personal data.
- HealthKit data is never used for advertising, marketing, or data-mining, and never shared with third parties for those purposes.
- Our in-app measurement is not advertising. Amplitude receives anonymous behaviour events only (severity as a coarse bucket, medication as a yes/no, triggers as a count) — never raw or derived health data, log content, or AI output — and there is no IDFA and no cross-app tracking (no ATT prompt). Behaviour/usage analytics is opt-in and off by default. Separately, subscription-lifecycle/billing events flow to Amplitude via a server-side Adapty integration on a contractual/billing basis and are NOT governed by the Usage-analytics toggle; these carry no card data and no health data. Crash diagnostics (Firebase Crashlytics) is anonymous and can be turned off in Settings → Privacy & consent.
5.Notice before we add a subprocessor
Before we engage a new subprocessor that will process your personal data, we will update this page and provide reasonable advance notice — for example, by updating the "Last updated" date above and, for material changes, by notice in the app or by email. You may review the change and, where applicable law gives you the right, object or exercise your privacy choices (see the Privacy Policy for how). The current version of this list is always available at amaina.health/subprocessors.
Your US rights over this data. US residents — including in Washington and California — have specific rights over health-related data, including consent controls on sharing consumer health data (Washington My Health My Data Act) and, in California, a right to limit the use of sensitive personal information and to have the Global Privacy Control (GPC) honored. We do not share your health data for advertising with any provider on this list. For how to exercise these rights, see the Privacy Policy, Section 8 (Your US privacy rights).
If a provider suffers a breach. If a subprocessor on this list suffers a data breach affecting your data, we notify you as described in the Privacy Policy, Section 12 (Security and breach notification) — consistent with the FTC Health Breach Notification Rule.
6.Note for EEA / UK users (secondary)
We do not currently target the EEA or UK at launch (Amaina is US-only). We include this note only in case that changes.
If we begin offering Amaina in the EEA or UK, the providers above would act as processors or sub-processors under Article 28 GDPR, with international transfers outside the EEA/UK covered by Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or each provider's equivalent safeguard. Health data would be treated as special-category data (Article 9), processed on the basis of your explicit consent. Copies of transfer safeguards are available on request at legal@smart-it.io.
7.Contact
Questions about this list or any provider on it:
Email: legal@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
This page is written in plain English. If anything is unclear, email legal@smart-it.io — we'll explain.