Current providers
Engineering inventory last reviewed: 2026-08-11. Confirm production enablement and regions before relying on this list for a formal DPIA.
| Provider | Purpose | Data category | Processing region | Status |
|---|---|---|---|---|
| Supabase (PostgreSQL) | Primary application database | Account, practice, patient, clinical, and operational records | Europe | Core |
| Render | API / backend application hosting | Application processing of practice and patient data in transit and at rest on host volumes as configured | Europe | Core |
| Amazon Web Services (S3) | Object storage (e.g. uploads, audio/media, profile assets) | Stored files and related object metadata | Europe | Core |
| Stripe | AINuma SaaS subscriptions and practice patient payments (Connect) | Billing identifiers, payment metadata; card data handled by Stripe (not stored by AINuma) | See Stripe DPA / Stripe infrastructure | Core |
| Twilio SendGrid | Transactional email (invites, magic links, payment requests, notifications) | Email addresses and message content required to send the email | See Twilio SendGrid DPA | Core |
| SMTP provider (fallback) | Email delivery when SendGrid is not configured (code default host can be Gmail SMTP) | Email addresses and message content | Confirm whether used in production; otherwise N/A | Conditional |
| Sign-in / OAuth for psychologists and companion; optional Google Calendar sync | Identity tokens, profile basics; calendar event data if Calendar is connected | See Google Cloud / Workspace DPAs for connected products | Core | |
| Google Analytics / Google Tag Manager | Marketing site analytics | Usage and device/analytics signals on marketing pages (consent-gated where required) | See Google Analytics DPA | Core |
| Apple | Sign in with Apple for Patient Companion | Identity tokens / Apple Sign In audience data | See Apple privacy terms | Core |
| Keycloak (auth.ainuma.com) | Optional identity / SSO token issuer for staff authentication | Authentication tokens and identity claims | Confirm hosting region for auth.ainuma.com | Conditional |
| LiveKit | AINuma Meet real-time video/audio and related session media transport | Real-time audio/video streams and session connection metadata | Europe | Core |
| OpenAI | Speech-to-text transcription (Whisper) for session audio | Temporary audio / transcript content for speech-to-text | See OpenAI DPA | Core |
| Anthropic | LLM drafting for clinical documentation assistance | Text prompts and model outputs for documentation drafts | See Anthropic DPA | Core |
- Core: Used for standard platform operation when the related feature is enabled.
- Conditional: Used only when configured (e.g. analytics IDs, Keycloak SSO, Anthropic key, companion Apple Sign In, or SMTP fallback).
How to read this list
Core providers support hosting, database, payments, email, identity, telehealth, and AI transcription/documentation. Conditional providers appear only when the corresponding environment configuration is active. Card payment data is processed by Stripe; AINuma does not store full card numbers.
Enterprise requests
Clinic and enterprise buyers can request a dated PDF, DPA pack, and notification process for material subprocessor changes as part of contract review. Contact support@ainuma.com or use the Trust Center contact path.
