● Trust

Subprocessors

The third-party services that process data on our behalf. Services marked as handling health information are only used where the data needs them. Some are connected only when a business chooses to link its own account (for example its own calendar, phone number or store).

ServiceWhat it's used forHealth data
Acuity SchedulingBring-your-own calendar (customer connects their own Acuity account) — two-way via opaque blocksNo
AnthropicLLM (answering, drafting, extraction)Yes
CalendlyBring-your-own calendar (customer connects their own Calendly account) — read-only availabilityNo
FlittCard payments (no PHI)No
GoogleRealtime voice (Gemini Live — default patient/onboarding voice)Yes
Google CalendarBring-your-own calendar (customer connects their own Google account via OAuth) — two-way appointment syncYes
HubSpotBring-your-own CRM (sales vertical) — read-only contact → lead sync, activity loggingNo
Open DentalBring-your-own practice management system (customer connects their own Open Dental) — patient + appointment sync, appointment write-backYes
OpenAIRealtime voice + speech-to-text (patient/onboarding voice, fallback)Yes
PipedriveBring-your-own CRM (sales vertical) — read-only contact → lead sync, activity loggingNo
ResendTransactional email + patient email replies (email answering routes patient message bodies through Resend once email_answering_live flips)Yes
ShopifyBring-your-own commerce (customer connects their own store) — read-only order lookupNo
SupabaseDatabase + storage (PHI at rest)Yes
TelnyxBring-your-own telephony (customer connects their own Telnyx account) — SMS + voice from their numberYes
TwilioSMS transportYes
VercelHosting (no PHI persisted)No

See also Trust & Security.