Sub-processors
Last updated: 18 July 2026.
The service providers below help us run Symply. We keep the list short on purpose, vet each provider for security and data protection, and publish it here so you can audit it at any time.
| Provider | Status | Purpose | Region | Data |
|---|---|---|---|---|
| Cloudflare, Inc. | Active | Web serving, edge compute (server-side rendering), CDN, DDoS mitigation | Global edge (EU-first routing) | Request metadata, IP addresses, TLS termination |
| Supabase (Supabase Inc.) | Active | Database, authentication, object storage, and transactional email delivery via Supabase's built-in mail provider (sign-in confirmations, share notifications) | European Union (Ireland) | All application data at rest — profiles, health records, files; email address and message body for transactional emails |
| Lovable AI Gateway | Active | Routes AI transcription requests when you opt in to transcription Only receives audio when you enable transcription on a voice note. | European Union / United States | Voice audio you choose to transcribe |
| OpenAI, L.L.C. (via Lovable AI Gateway) | Active | Speech-to-text model (gpt-4o-transcribe) used for transcription | United States | Voice audio you choose to transcribe. Not used to train models. |
| Sentry (Functional Software, Inc.) | Optional / not enabled | Error monitoring; only enabled when a Sentry DSN is configured Not currently enabled in production. We will update this page before turning it on. | European Union | Error stack traces and request URLs, scrubbed of health content |
Active means we are currently sending data to that provider in the production deployment. Optional / not enabled means the integration exists in the codebase but is switched off by default; we will update this page before turning it on.
We will give reasonable prior notice — through this page and in-app notice for signed-in users — before adding a new sub-processor that will process personal data.