AINuma

Subprocessors

AINuma uses infrastructure and service providers to operate the Practice OS. The table lists providers identified from our application and API configuration. Processing regions must be confirmed in each provider account and DPA—we do not invent residency claims here.

Current providers

Engineering inventory last reviewed: 2026-08-11. Confirm production enablement and regions before relying on this list for a formal DPIA.

ProviderPurposeData categoryProcessing regionStatus
Supabase (PostgreSQL)Primary application databaseAccount, practice, patient, clinical, and operational recordsEuropeCore
RenderAPI / backend application hostingApplication processing of practice and patient data in transit and at rest on host volumes as configuredEuropeCore
Amazon Web Services (S3)Object storage (e.g. uploads, audio/media, profile assets)Stored files and related object metadataEuropeCore
StripeAINuma SaaS subscriptions and practice patient payments (Connect)Billing identifiers, payment metadata; card data handled by Stripe (not stored by AINuma)See Stripe DPA / Stripe infrastructureCore
Twilio SendGridTransactional email (invites, magic links, payment requests, notifications)Email addresses and message content required to send the emailSee Twilio SendGrid DPACore
SMTP provider (fallback)Email delivery when SendGrid is not configured (code default host can be Gmail SMTP)Email addresses and message contentConfirm whether used in production; otherwise N/AConditional
GoogleSign-in / OAuth for psychologists and companion; optional Google Calendar syncIdentity tokens, profile basics; calendar event data if Calendar is connectedSee Google Cloud / Workspace DPAs for connected productsCore
Google Analytics / Google Tag ManagerMarketing site analyticsUsage and device/analytics signals on marketing pages (consent-gated where required)See Google Analytics DPACore
AppleSign in with Apple for Patient CompanionIdentity tokens / Apple Sign In audience dataSee Apple privacy termsCore
Keycloak (auth.ainuma.com)Optional identity / SSO token issuer for staff authenticationAuthentication tokens and identity claimsConfirm hosting region for auth.ainuma.comConditional
LiveKitAINuma Meet real-time video/audio and related session media transportReal-time audio/video streams and session connection metadataEuropeCore
OpenAISpeech-to-text transcription (Whisper) for session audioTemporary audio / transcript content for speech-to-textSee OpenAI DPACore
AnthropicLLM drafting for clinical documentation assistanceText prompts and model outputs for documentation draftsSee Anthropic DPACore
  • Core: Used for standard platform operation when the related feature is enabled.
  • Conditional: Used only when configured (e.g. analytics IDs, Keycloak SSO, Anthropic key, companion Apple Sign In, or SMTP fallback).

How to read this list

Core providers support hosting, database, payments, email, identity, telehealth, and AI transcription/documentation. Conditional providers appear only when the corresponding environment configuration is active. Card payment data is processed by Stripe; AINuma does not store full card numbers.

Enterprise requests

Clinic and enterprise buyers can request a dated PDF, DPA pack, and notification process for material subprocessor changes as part of contract review. Contact support@ainuma.com or use the Trust Center contact path.