← Privacy Policy

Subprocessors

Working draft · pending attorney review · Last updated for pilot alignment

Last Updated: 2026-09-02

Third parties that may process account or health-related data on behalf of prismaIQ. prismaIQ is HIPAA compliant, with BAAs in place from our associated vendors — including an executed Xata BAA for core database hosting and an executed OpenAI BAA for the optional AI Assistant. See the Privacy Policy for detail.

VendorPurposeNotes
Xata / PostgresPrimary databaseExecuted BAA for core database hosting
VercelApp hostingRequest traffic / deployment; Blob used for private vault files
Vercel BlobHealth vault file storagePrivate object storage; product gates may apply to real uploads
GoogleOAuth sign-inIdentity only
StripeBillingPayment data; PCI; no full card storage by prismaIQ
OpenAIAI Assistant onlyExecuted BAA; HIPAA compliant
AnthropicAI Assistant fallback (optional)Optional Assistant fallback under the same HIPAA-compliant protections
SentryError monitoringPII scrubbed / sendDefaultPii disabled
ResendTransactional emailEmail + content you submit
InstacartGrocery cart handoffFood names / search terms only — not biomarkers
WHOOP / GarminWearables (user-authorized)Tokens encrypted AES-256-GCM at rest in app

Questions: info@prismaiq.io