Subprocessors
Draft, not yet reviewed by counsel.
Active
| Processor | What it does for us | Data it sees | Location | Contract |
|---|---|---|---|---|
| Google Cloud — Cloud Run, Cloud SQL, Cloud Storage, Secret Manager, Cloud KMS, Cloud Logging, Cloud Build, Artifact Registry | Hosting, database, file storage, key management, logs | All account and health data at rest | southamerica-east1 (São Paulo) | Google's Cloud Data Processing Addendum, incorporated into the Google Cloud terms the account runs under, with the EU standard contractual clauses it carries for transfers |
| Google Cloud — Speech-to-Text v2 (Chirp) | Converts recorded audio into text | Audio recordings and the resulting text | eu multi-region | Same DPA; transfer covered by the highlighted consent in 03 |
| Google Cloud — Vertex AI (Gemini) | Summaries, extracted terms, Ask answers, suggested questions, de-identification pass; for the opt-in live-notes feature, live listening notes and verdicts on whether prepared questions were answered | Transcript text and derived text; for the opt-in live-notes feature, the recording's audio while the visit is in progress, sent inline per window, together with the visit's note board and open questions | southamerica-east1 | Same DPA; under Google Cloud's data-governance terms as they stand today, our data is not used to train Google's models |
| Google BigQuery | Destination for opt-in usage events (ships with 0.13.0, activated at deployment: the real adapter, the dataset and the purge job are all in this release, and the environment's fake-sink flag is off in Terraform — the first event lands when 0.13.0 is applied and deployed, not before) | Pseudonymous events only: event name, timestamp, random analytics_id, coarse client metadata. Not the content of a recording, a transcript, a summary or a note | southamerica-east1 (per-region dataset) | Same Google Cloud DPA; retention 24 months per ../retention.json, enforced as the events table's partition expiry; delete-by-id purge ≤ 30 days |
| Google Firebase Hosting | Serves the published legal site https://scribe.dehaze.de/inapp: the privacy policy, the terms, the deletion page, the imprint and the notices, including the /inapp/* pages the app itself opens in its in-app browser | Web-request metadata of anyone who opens one of those pages: IP address, user agent, requested URL, timestamp, in Google's request logs. No account data, no health data, and no sign-in is involved — reading a legal page is deliberately possible without an account | Google's global CDN edge, so a reader is served from the edge nearest them; the origin content is static | Firebase Data Processing and Security Terms (same contracting relationship as the Cloud row) |
| Google Firebase Crashlytics (live as of 0.13.0, ruling D14) | Crash reporting for the app | Content-free crash reports: stack trace, device model, OS and app version. No health data, no content, no email, no user identifier, no IDFA; dev and prod streams separated by the per-identity Firebase projects | Google infrastructure | Firebase Data Processing and Security Terms; retention 90 days — Crashlytics' own fixed retention, recorded in ../retention.json |
| Google Firebase Cloud Messaging | Delivers push notifications to devices | Device push token, neutral notification text | Google infrastructure | Firebase Data Processing and Security Terms |
| Apple Push Notification service | Delivers those notifications on iPhones | Device token, neutral text | Apple infrastructure | Apple Developer Program terms |
| Apple Maps (MapKit) | Draws the map for a visit's saved location on iPhones | The coordinates being shown, while the map is on screen. No account data, no health data, nothing about the visit itself | Apple infrastructure | Apple Developer Program terms (platform service under Apple's own terms, not an Art. 28 processor) |
| Google Maps Platform (Android) | Draws the map for a visit's saved location on Android | The coordinates being shown, while the map is on screen. No account data, no health data, nothing about the visit itself | Google infrastructure | Google Maps Platform terms (platform service under Google's own terms, not an Art. 28 processor) |
| Mailjet | Sends sign-in codes, deletion confirmations | Email address, message content | EU | Mailjet's data-processing terms, part of its standard terms of service |
Planned — must be added here before they go live
| Processor | Purpose | Blocker |
|---|---|---|
| Google Cloud — separate training project | Segregated de-identified training corpus | Live only for opted-in users; confirm it is contractually inside the same DPA scope |
Formerly planned and now settled: both map services moved to the active table (0.13.0 — the Android map now renders through the Google Maps SDK rather than a placeholder, so the row is no longer conditional on C9); BigQuery moved to the active table (0.13.0, Q-08 closed); Sentry did not ship — crash reporting is Firebase Crashlytics in the app (ruling D14, superseding the spec's earlier Sentry posture), and backend errors surface through Google Cloud Error Reporting derived from the existing structured logs (no new backend SDK, inside the Google Cloud row above).
Not processors
- Apple and Google as app stores are independent controllers for what they collect about downloads, payments and reviews. We do not receive user-level store data.
- WhatsApp and any other app you share a summary into — sharing is initiated by the user from their device; the content leaves our control entirely and we have no relationship with the recipient app.
- The maps app you open a visit's location in — "Open in maps" is the user's own action and hands the coordinates to whichever app they pick. Distinct from the Apple Maps and Google Maps rows above, which are the in-app map being drawn.