The third parties Care Tales uses to run the service, what each one does and what data it touches.
Care Tales uses a small number of third parties to run the platform. This page lists every one of them that can touch customer or patient data, what it does and what it receives. It is the list referred to by the data processing addendum and the business associate agreement.
| Subprocessor | What it does | What data it touches | Location |
|---|---|---|---|
| Google Cloud and Firebase (Google LLC) | Core hosting. Firebase Authentication, Firestore, Cloud Storage, Cloud Functions and App Hosting, in project caretales-a6bf7 | All platform data: accounts, profiles, module progress, visits, module sessions, survey answers, ratings, chatbot transcripts, uploaded files | United States. Firestore in the nam5 multi-region, Cloud Storage, App Hosting and functions in us-central1, backups in the US multi-region |
| Google Gemini on Vertex AI (Google LLC) | Patient chat answers, embeddings of patient questions and topic classification | Patient chat messages and recent conversation turns, the organization's approved knowledge base extracts, the organization's system prompt, a derived city and region line and, for the embeddable widget, up to 3000 characters of scraped host page text | us-central1, United States |
| Google Gemini API (Google LLC) | Module generation, translation, narration, image and video generation, and indexing an organization's uploaded documents | Module content and documents an organization uploads. No patient data | Google infrastructure, not restricted to one region |
| Google Cloud Text-to-Speech (Google LLC) | Spoken audio for module text | Module text submitted for narration | United States |
| Google Cloud Translate (Google LLC) | Translation support across the six supported languages | Text submitted for translation | United States |
| ip-api.com | Coarse geolocation lookup during chat, used to give the model a city and region line | A truncated IP address only. No message text, no account data | Operated outside Google Cloud. Location not contractually established by Care Tales |
| Gmail SMTP (Google LLC) | Outgoing transactional email | Recipient email address and message content | United States |
| Twilio Inc. | Outgoing SMS, used to send a module link | Recipient phone number, message content and the associated consent record | United States |
| Apple Inc. | Sign in with Apple, an optional identity provider | Authentication identifiers for users who choose it | United States |
| Google LLC (Google Sign-In) | Google sign in, an optional identity provider | Authentication identifiers for users who choose it | United States |
| Microsoft Corporation | Microsoft sign in, an optional identity provider | Authentication identifiers for users who choose it | United States |
| Google Analytics 4 (Google LLC) | Marketing site analytics only | Marketing site page views and analytics cookies. It is not loaded on module pages or organization pages and receives no patient module or chat data | United States |
The widget receives more than the hosted chat. The main site chatbot uses an IP address for a geolocation lookup and does not store it. The embeddable WordPress widget stores the full untruncated IP address along with country, city, region, coordinates, browser, operating system, device type, language, timezone, screen size and referrer. Customers deploying the widget should account for that.
ip-api.com sits outside our Google agreements. It is the only non Google party that receives any network identifier. It receives a truncated IP address and nothing else. Customers who do not want this call made should tell us, since the result is only used to give the model a coarse location line.
Google Analytics is confined to the marketing site. It does not run where patients read modules or use an organization page.
To close off the usual questionnaire items: Care Tales does not use Sentry, Stripe, Plaid, Vercel, PostHog, Mixpanel, Segment, Datadog, Amplitude, Hotjar, Intercom, Firebase Crashlytics, OpenAI or Anthropic anywhere in the product. The mobile app contains no analytics and no crash reporting SDK and sends no push tokens because reminders are scheduled locally on the device.
Care Tales does not send customer or patient data to any model provider for the purpose of training that provider's models, and does not train its own models on customer or patient data. Patient data goes to Gemini only through Google Cloud Vertex AI, whose terms do not permit Google to train on it. Content work uses the Gemini API on Care Tales' paid account. An organization's own model key, where supplied, only indexes that organization's documents. See the AI disclosure for detail.
To be added to the notification list, or to ask about a specific subprocessor, write to support@caretales.com.
This page is the authoritative list. It is updated on each change with a new effective date, and notice is given as described above.