1.What a "subprocessor" is

A subprocessor is a third-party company we use to help deliver Amaina — for example, to store your account, transcribe your voice, look up the weather, or manage your in-app subscription. When a subprocessor handles your personal data, it does so only on our instructions and only for the purpose listed below, under a written contract (a Data Processing Agreement, or DPA, where applicable).

We keep this list current and give advance notice before we add a new subprocessor (see section 5).

Two things we want to be clear about up front:

2.Subprocessor list

The table below covers the Amaina app (iOS; Android / Health Connect is a planned later release) and the amaina.health website. The app itself uses two in-product measurement providers — Amplitude (usage analytics) and Google Firebase Crashlytics (crash diagnostics), both described below. Separately, the last group (marked "web only") applies only to the website funnel, not to the app — those are advertising/analytics pixels on the marketing site, distinct from the in-app measurement providers.

On a future Android release, your device's operating system (Google) would play the same role Apple plays on iOS: it would perform speech-to-text on your device and mediate access to Google Health Connect (the Android equivalent of Apple Health). As on iOS, your audio would never reach us or Anthropic — we would receive only the resulting text — and raw Health Connect readings would be processed on your device. The OS-level safeguards described in the Apple row would apply the same way on Android. Amaina v1 ships on iOS only.

ProviderData it receivesPurposeLocationSafeguard
Anthropic (Claude)The text of your log and summary prompts. No name, email, or date of birth; no audio; no raw HealthKit / Health Connect readings; no health identifiers in field names.Two things: (1) AI structuring of your logged text into fields (time, intensity, duration, symptoms, aura, medication, triggers); and (2) drafting the descriptive doctor-visit summary narrative from the prompt built from your logs. Both are gated on your AI consent; the doctor summary also has a static, no-AI fallback.United StatesDPA (with SCCs) in force; no training on our data; inputs/outputs auto-deleted within 30 days, kept longer only if content is flagged for a safety/policy review; ZDR requested but NOT available to us (enterprise-only, declined 2026-07-07) — we rely on the 30-day default + DPA + our own minimization; standard (non-Covered) model; backend-only calls.
OpenWeatherMapApproximate coordinates only — reduced accuracy, when-in-use (when you enable weather features).Reads local barometric pressure and a short (~24-hour) forecast; when a drop of about 6 hPa or more is forecast, Amaina shows a general colour-coded heads-up (green / amber). This is a general environmental signal — not personalized to your health history and not a medical prediction.US / EUWe send only approximate coordinates and do not store them on our side; the lookup is transient (used only to return the weather/pressure for that request). We do not use location for tracking or advertising.
Google (Firebase Auth + Firestore)Account data (first name, email, date of birth, and an optional Sex field) and your attack logs (including recorded barometric pressure).Sign-in/authentication and secure storage of your account and logs.United StatesDPA with SCCs; encryption in transit and at rest.
Apple (Speech / HealthKit / App Store / In-App Purchase)Audio for on-device or Apple Speech transcription (never reaches us); HealthKit data stays on your device (we read/write only with your granular permission); App Store handles app distribution; In-App Purchase processes your subscription payment and card details directly — we never see or store your card.Voice transcription (on-device or on Apple's servers), Health integration, app distribution, and in-app subscription purchase/billing.United StatesApple's terms and Apple Speech / HealthKit rules; HealthKit data is never used for advertising, marketing, or data-mining and is never shared for those purposes; Apple handles all payment and card data under its own terms — we never receive card data.
RevenueCatYour App Store purchase receipt, an app-assigned user identifier, and your subscription / entitlement status. No card data; no health data.Validate your App Store subscription and unlock paid features (subscription / entitlement management), and forward subscription-lifecycle events to our analytics provider (Amplitude) via a server-side integration.United StatesDPA. Receives no card data (Apple handles the payment) and no health data; used to validate purchases, manage entitlements, and — via a server-side RevenueCat→Amplitude integration — forward subscription-lifecycle events (trial start, purchase, renewal, cancellation) to Amplitude, keyed to the same anonymous Firebase UID and carrying no card data and no health data.
AmplitudeAnonymous product-usage/behaviour events — onboarding and funnel steps, attack-logging events, voice-transcription quality, use of the pain head-map (a flag only — no location value), report generated/shared, paywall viewed, and an elevated-weather-risk banner shown. Health-adjacent facts appear only as privacy-safe proxies: severity as a coarse bucket (low/mod/high), medication as a yes/no, triggers as a count, pain-map use as a flag — never raw or derived health data, no medication/trigger names, no dates, no pain-location values, no log content or AI output. (Full event list: the app's ANALYTICS_EVENTS.md.) Identified only by an anonymous internal user id (your Firebase UID), never your name or email. Separately, subscription-lifecycle events forwarded from RevenueCat (e.g. trial started, subscription purchased/renewed/canceled), keyed to the same anonymous Firebase UID. No card data, no health data.Product and subscription analytics. Behaviour/usage events are collected only when you turn on "Usage analytics" (off by default). Separately, subscription-lifecycle events (rc_*) are sent to Amplitude via a server-side RevenueCat→Amplitude integration on a contractual/billing basis — these are NOT controlled by the "Usage analytics" toggle.United StatesDPA. No Session Replay; no advertising or cross-app tracking (no IDFA / no ATT); never used to build advertising audiences. IP address, geo (country/region/city/DMA/lat-lng), carrier, and advertising id capture are disabled in the Amplitude SDK (TrackingOptions), build 18 — so no IP or location is collected and "Tracking = No" does not depend on a console setting. Revenue events carry no card data and no health data.
Google — Firebase CrashlyticsAnonymous crash reports (stack traces, device/OS) to fix bugs — never health data, and not linked to your identity.Crash diagnostics. On by default; turn it off under "Crash diagnostics" in Settings → Privacy & consent.United StatesDPA. Reports are anonymous and not linked to you; no health data in crash keys.
HubSpot (web only)First name and email.Website email / CRM (launch and product updates you opt into).United StatesDPA.
Google / Meta ad + analytics pixels (web only)Web usage and cookie data.Aggregate ad-conversion measurement only — no health data.United StatesConsent-gated; health data, HealthKit data, structured logs, and AI outputs are never sent to ad platforms and never used to build custom, lookalike, or health-interest audiences.

3.How to read this list (a few notes)

4.What we never do with these providers

To keep Amaina squarely a wellness tracker — not a medical device, and not an advertising product built on your health data — we hold these providers to hard limits:

5.Notice before we add a subprocessor

Before we engage a new subprocessor that will process your personal data, we will update this page and provide reasonable advance notice — for example, by updating the "Last updated" date above and, for material changes, by notice in the app or by email. You may review the change and, where applicable law gives you the right, object or exercise your privacy choices (see the Privacy Policy for how). The current version of this list is always available at amaina.health/subprocessors.

Your US rights over this data. US residents — including in Washington and California — have specific rights over health-related data, including consent controls on sharing consumer health data (Washington My Health My Data Act) and, in California, a right to limit the use of sensitive personal information and to have the Global Privacy Control (GPC) honored. We do not share your health data for advertising with any provider on this list. For how to exercise these rights, see the Privacy Policy, Section 8 (Your US privacy rights).

If a provider suffers a breach. If a subprocessor on this list suffers a data breach affecting your data, we notify you as described in the Privacy Policy, Section 12 (Security and breach notification) — consistent with the FTC Health Breach Notification Rule.

6.Note for EEA / UK users (secondary)

We do not currently target the EEA or UK at launch (Amaina is US-only). We include this note only in case that changes.

If we begin offering Amaina in the EEA or UK, the providers above would act as processors or sub-processors under Article 28 GDPR, with international transfers outside the EEA/UK covered by Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or each provider's equivalent safeguard. Health data would be treated as special-category data (Article 9), processed on the basis of your explicit consent. Copies of transfer safeguards are available on request at legal@smart-it.io.

7.Contact

Questions about this list or any provider on it:

Email: legal@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA

This page is written in plain English. If anything is unclear, email legal@smart-it.io — we'll explain.

<!-- INTERNAL — NOT FOR PUBLICATION. Remove this block before the page goes live.

Pre-publication checklist / open items for the health-tech lawyer + CTO:

  1. PLATFORM SCOPE (lawyer). This doc — and the whole Amaina doc family — assumes iOS + Android (Google Health Connect, Android Settings paths; see healthkit_data_use.md, privacy_policy.md, account_and_data_deletion.md). The current PL-025 task brief says "Native iOS app + web," US-only. Confirm the launch platform set. If iOS-only at launch: strip Health Connect / Android references across ALL docs together (not just this one) so nothing contradicts. Left as iOS + Android here to stay consistent with the sibling docs.
  1. CLAUDE-CALLING FEATURES (CTO). CONFIRMED for build 1.0.0(22): there are exactly TWO AI (Anthropic / Claude) call sites, both LIVE and both gated on AI consent — (1) structuring your voice/typed log into fields, and (2) drafting the doctor-visit summary narrative (the report also has a static, no-AI fallback). The tap/manual path never uses AI. Wording in the table and section 3 reflects this; no open item remaining here.
  1. OPENWEATHERMAP DPA. OWM is the only subprocessor with no DPA listed. The safeguard cell now states only what Amaina controls (we don't store coordinates; transient lookup). If a DPA or OWM's published retention terms support a stronger statement, cite that basis; otherwise leave as-is. Self-assessed acceptable for MVP (Anton, 2026-07-24) — coarse/transient/not-stored; not routed to counsel (revisit post-MVP).
  1. LINK PLACEHOLDERS (site build). Replace every "Privacy Policy" bracket (and any "AI Processing Notice"-style bracket used across the doc family) with the real amaina.health URL. Confirm no bracketed link placeholders remain in any public-facing doc before submission. Confirm the Privacy Policy still carries: MHMDA separate-consent-to-share, CPRA right-to-limit + GPC (Section 8), and the FTC HBNR breach commitment (Section 12) that this page points to.

-->