● Trust
Subprocessors
The third-party services that process data on our behalf. Services marked as handling health information are only used where the data needs them. Some are connected only when a business chooses to link its own account (for example its own calendar, phone number or store).
| Service | What it's used for | Health data |
|---|---|---|
| Acuity Scheduling | Bring-your-own calendar (customer connects their own Acuity account) — two-way via opaque blocks | No |
| Anthropic | LLM (answering, drafting, extraction) | Yes |
| Calendly | Bring-your-own calendar (customer connects their own Calendly account) — read-only availability | No |
| Flitt | Card payments (no PHI) | No |
| Realtime voice (Gemini Live — default patient/onboarding voice) | Yes | |
| Google Calendar | Bring-your-own calendar (customer connects their own Google account via OAuth) — two-way appointment sync | Yes |
| HubSpot | Bring-your-own CRM (sales vertical) — read-only contact → lead sync, activity logging | No |
| Open Dental | Bring-your-own practice management system (customer connects their own Open Dental) — patient + appointment sync, appointment write-back | Yes |
| OpenAI | Realtime voice + speech-to-text (patient/onboarding voice, fallback) | Yes |
| Pipedrive | Bring-your-own CRM (sales vertical) — read-only contact → lead sync, activity logging | No |
| Resend | Transactional email + patient email replies (email answering routes patient message bodies through Resend once email_answering_live flips) | Yes |
| Shopify | Bring-your-own commerce (customer connects their own store) — read-only order lookup | No |
| Supabase | Database + storage (PHI at rest) | Yes |
| Telnyx | Bring-your-own telephony (customer connects their own Telnyx account) — SMS + voice from their number | Yes |
| Twilio | SMS transport | Yes |
| Vercel | Hosting (no PHI persisted) | No |
See also Trust & Security.