Working draft · pending attorney review · Last updated for pilot alignment
Last Updated: 2026-09-02
Third parties that may process account or health-related data on behalf of prismaIQ. prismaIQ is HIPAA compliant, with BAAs in place from our associated vendors — including an executed Xata BAA for core database hosting and an executed OpenAI BAA for the optional AI Assistant. See the Privacy Policy for detail.
| Vendor | Purpose | Notes |
|---|---|---|
| Xata / Postgres | Primary database | Executed BAA for core database hosting |
| Vercel | App hosting | Request traffic / deployment; Blob used for private vault files |
| Vercel Blob | Health vault file storage | Private object storage; product gates may apply to real uploads |
| OAuth sign-in | Identity only | |
| Stripe | Billing | Payment data; PCI; no full card storage by prismaIQ |
| OpenAI | AI Assistant only | Executed BAA; HIPAA compliant |
| Anthropic | AI Assistant fallback (optional) | Optional Assistant fallback under the same HIPAA-compliant protections |
| Sentry | Error monitoring | PII scrubbed / sendDefaultPii disabled |
| Resend | Transactional email | Email + content you submit |
| Instacart | Grocery cart handoff | Food names / search terms only — not biomarkers |
| WHOOP / Garmin | Wearables (user-authorized) | Tokens encrypted AES-256-GCM at rest in app |
Questions: info@prismaiq.io