Skip to main content

Legal transparency

Sub-processors

Kitrus uses infrastructure, AI, billing, analytics, and optional integration providers to operate the service. This page lists providers that may process personal data for Kitrus and the boundaries we apply to each one.

Last updated: May 19, 2026

Kitrus does not sell personal data. Marketing and analytics providers must not receive health details such as lab values, medications, symptoms, diagnoses, uploads, or chat content.

Core service providers

ProviderRoleData processedBoundary
SupabaseDatabase, authentication, and file storageAccount data, user-entered health data, uploads, chat records, causal maps, and audit recordsDurable system of record. Row-level security and server-side ownership checks protect user data.
OpenAIAI analysis, extraction, transcription, report narration, and service-quality analysisSelected health context, chat messages, uploaded document content, and generated health-analysis outputsUsed through commercial APIs. Data retention posture is governed by the signed account terms.
VercelApplication hosting, serverless runtime, cron, logs, and performance analyticsRequests in transit, coarse runtime metadata, and redacted operational logsKitrus policy forbids PHI in logs and gates production-only vendor fanout in code.
Customer.ioTransactional and lifecycle emailEmail address, account identifiers, and coarse lifecycle eventsHealth details must not be sent in lifecycle or marketing payloads.
SentryError and performance monitoringRedacted error context, stack traces, route categories, and user ids where needed for debuggingPHI scrubbers run across client, server, and edge telemetry.

Billing and app-store providers

ProviderRoleData processedBoundary
RevenueCatNative iOS and Android subscription adapterApp user identifiers, receipts, product ids, and subscription stateNo health data is intentionally sent.
WhopWeb checkout and web subscription lifecycleBilling identity, email, plan id, membership, payment, refund, and cancellation stateNo health data is intentionally sent. DPA status remains under legal review.
Apple and GoogleApp distribution, app-store billing, Sign in with Apple/Google, HealthKit or Health Connect where authorizedStore account, receipt, sign-in, device, and user-authorized health-source data depending on the feature usedHealth-source access is controlled by the user through the operating system permissions screen.

Analytics and attribution providers

ProviderRoleData processedBoundary
Google Analytics / GA4Site and campaign measurementCoarse page, conversion, and device-event metadataNo biomarkers, medications, symptoms, lab values, uploads, or chat content.
TikTokAd attribution and conversion measurementCoarse conversion events and click identifiers when enabledMarketing payloads must not include health data.
PinterestAd attribution and conversion measurementCoarse conversion events and click identifiers when enabledMarketing payloads must not include health data.
PropellerAdsTelegram Mini App campaign attribution where enabledCoarse attribution and conversion metadataMarketing payloads must not include health data.

Optional integrations and inactive fallback providers

  • Oura
  • WHOOP
  • Fitbit
  • Withings
  • Telegram
  • PayPal

Optional integrations process data only when you connect or use that feature. Inactive fallback providers do not receive production data unless Kitrus deliberately re-enables that path.

Change notices

Sub-processor change notices

Signed-in users can subscribe to email notices before Kitrus adds a new sub-processor that materially changes how personal data is processed.

Checking your preference...

Questions or objections

Contact hello@kitrus.ai for privacy questions. See the Privacy Policy for the full description of data rights, retention, international transfers, and user controls.

Sub-processors | Kitrus