Legal transparency
Sub-processors
Kitrus uses infrastructure, AI, billing, analytics, and optional integration providers to operate the service. This page lists providers that may process personal data for Kitrus and the boundaries we apply to each one.
Last updated: May 19, 2026
Core service providers
| Provider | Role | Data processed | Boundary |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | Account data, user-entered health data, uploads, chat records, causal maps, and audit records | Durable system of record. Row-level security and server-side ownership checks protect user data. |
| OpenAI | AI analysis, extraction, transcription, report narration, and service-quality analysis | Selected health context, chat messages, uploaded document content, and generated health-analysis outputs | Used through commercial APIs. Data retention posture is governed by the signed account terms. |
| Vercel | Application hosting, serverless runtime, cron, logs, and performance analytics | Requests in transit, coarse runtime metadata, and redacted operational logs | Kitrus policy forbids PHI in logs and gates production-only vendor fanout in code. |
| Customer.io | Transactional and lifecycle email | Email address, account identifiers, and coarse lifecycle events | Health details must not be sent in lifecycle or marketing payloads. |
| Sentry | Error and performance monitoring | Redacted error context, stack traces, route categories, and user ids where needed for debugging | PHI scrubbers run across client, server, and edge telemetry. |
Billing and app-store providers
| Provider | Role | Data processed | Boundary |
|---|---|---|---|
| RevenueCat | Native iOS and Android subscription adapter | App user identifiers, receipts, product ids, and subscription state | No health data is intentionally sent. |
| Whop | Web checkout and web subscription lifecycle | Billing identity, email, plan id, membership, payment, refund, and cancellation state | No health data is intentionally sent. DPA status remains under legal review. |
| Apple and Google | App distribution, app-store billing, Sign in with Apple/Google, HealthKit or Health Connect where authorized | Store account, receipt, sign-in, device, and user-authorized health-source data depending on the feature used | Health-source access is controlled by the user through the operating system permissions screen. |
Analytics and attribution providers
| Provider | Role | Data processed | Boundary |
|---|---|---|---|
| Google Analytics / GA4 | Site and campaign measurement | Coarse page, conversion, and device-event metadata | No biomarkers, medications, symptoms, lab values, uploads, or chat content. |
| TikTok | Ad attribution and conversion measurement | Coarse conversion events and click identifiers when enabled | Marketing payloads must not include health data. |
| Ad attribution and conversion measurement | Coarse conversion events and click identifiers when enabled | Marketing payloads must not include health data. | |
| PropellerAds | Telegram Mini App campaign attribution where enabled | Coarse attribution and conversion metadata | Marketing payloads must not include health data. |
Optional integrations and inactive fallback providers
- Oura
- WHOOP
- Fitbit
- Withings
- Telegram
- PayPal
Optional integrations process data only when you connect or use that feature. Inactive fallback providers do not receive production data unless Kitrus deliberately re-enables that path.
Change notices
Sub-processor change notices
Signed-in users can subscribe to email notices before Kitrus adds a new sub-processor that materially changes how personal data is processed.
Checking your preference...
Questions or objections
Contact hello@kitrus.ai for privacy questions. See the Privacy Policy for the full description of data rights, retention, international transfers, and user controls.