Sub-processors
Last updated: August 31, 2026
This is a working draft to be reviewed and finalized with legal counsel before public launch. Bracketed items (e.g. [Legal entity]) are placeholders.
Who processes your data
Vextara uses the third-party providers below to run the service. Each acts as a processor on our behalf, under a data-processing agreement (DPA) and instructed to use personal data only to provide their service to us. We do not sell personal data.
Bracketed items are placeholders to be confirmed with counsel before public launch. If you are a business customer and need a signed DPA (or, where applicable, a HIPAA Business Associate Agreement), contact [privacy@vextara.example].
Current sub-processors
| Provider | Purpose | Data | Location | Agreement |
|---|---|---|---|---|
| Supabase | Database, authentication, and file storage | Account, intake, assessment, and care data; uploaded files | [Region — e.g. AWS us-east-1] | DPA in place; HIPAA BAA on eligible plans |
| OpenAI | AI copilot (Ollie) and content matching | Parent messages and limited child context (first name, age, subtype) | United States | BAA / Zero-Data-Retention — [pending] |
| Vercel | Application hosting and content delivery | Request metadata and operational logs (no health data in logs) | United States / global edge | DPA in place |
| Resend | Transactional and lifecycle email (when enabled) | Email address and message content (no PHI in email bodies) | United States | DPA in place |
| Stripe | Payment processing (production only — the demo checkout does not use it) | Payment card data, handled entirely by Stripe | United States | DPA in place; PCI-DSS Level 1 |
Changes
We’ll update this page when we add or remove a sub-processor. Material changes affecting how personal data is processed will be reflected in the Privacy Policy and, where required, notified to you.