Notice

Subprocessors

The third parties Care Tales uses to run the service, what each one does and what data it touches.

Effective September 22, 2026, version 1

Subprocessors

Care Tales uses a small number of third parties to run the platform. This page lists every one of them that can touch customer or patient data, what it does and what it receives. It is the list referred to by the data processing addendum and the business associate agreement.

Current subprocessors

SubprocessorWhat it doesWhat data it touchesLocation
Google Cloud and Firebase (Google LLC)Core hosting. Firebase Authentication, Firestore, Cloud Storage, Cloud Functions and App Hosting, in project caretales-a6bf7All platform data: accounts, profiles, module progress, visits, module sessions, survey answers, ratings, chatbot transcripts, uploaded filesUnited States. Firestore in the nam5 multi-region, Cloud Storage, App Hosting and functions in us-central1, backups in the US multi-region
Google Gemini on Vertex AI (Google LLC)Patient chat answers, embeddings of patient questions and topic classificationPatient chat messages and recent conversation turns, the organization's approved knowledge base extracts, the organization's system prompt, a derived city and region line and, for the embeddable widget, up to 3000 characters of scraped host page textus-central1, United States
Google Gemini API (Google LLC)Module generation, translation, narration, image and video generation, and indexing an organization's uploaded documentsModule content and documents an organization uploads. No patient dataGoogle infrastructure, not restricted to one region
Google Cloud Text-to-Speech (Google LLC)Spoken audio for module textModule text submitted for narrationUnited States
Google Cloud Translate (Google LLC)Translation support across the six supported languagesText submitted for translationUnited States
ip-api.comCoarse geolocation lookup during chat, used to give the model a city and region lineA truncated IP address only. No message text, no account dataOperated outside Google Cloud. Location not contractually established by Care Tales
Gmail SMTP (Google LLC)Outgoing transactional emailRecipient email address and message contentUnited States
Twilio Inc.Outgoing SMS, used to send a module linkRecipient phone number, message content and the associated consent recordUnited States
Apple Inc.Sign in with Apple, an optional identity providerAuthentication identifiers for users who choose itUnited States
Google LLC (Google Sign-In)Google sign in, an optional identity providerAuthentication identifiers for users who choose itUnited States
Microsoft CorporationMicrosoft sign in, an optional identity providerAuthentication identifiers for users who choose itUnited States
Google Analytics 4 (Google LLC)Marketing site analytics onlyMarketing site page views and analytics cookies. It is not loaded on module pages or organization pages and receives no patient module or chat dataUnited States

Notes on this list

The widget receives more than the hosted chat. The main site chatbot uses an IP address for a geolocation lookup and does not store it. The embeddable WordPress widget stores the full untruncated IP address along with country, city, region, coordinates, browser, operating system, device type, language, timezone, screen size and referrer. Customers deploying the widget should account for that.

ip-api.com sits outside our Google agreements. It is the only non Google party that receives any network identifier. It receives a truncated IP address and nothing else. Customers who do not want this call made should tell us, since the result is only used to give the model a coarse location line.

Google Analytics is confined to the marketing site. It does not run where patients read modules or use an organization page.

Parties we do not use

To close off the usual questionnaire items: Care Tales does not use Sentry, Stripe, Plaid, Vercel, PostHog, Mixpanel, Segment, Datadog, Amplitude, Hotjar, Intercom, Firebase Crashlytics, OpenAI or Anthropic anywhere in the product. The mobile app contains no analytics and no crash reporting SDK and sends no push tokens because reminders are scheduled locally on the device.

Model training

Care Tales does not send customer or patient data to any model provider for the purpose of training that provider's models, and does not train its own models on customer or patient data. Patient data goes to Gemini only through Google Cloud Vertex AI, whose terms do not permit Google to train on it. Content work uses the Gemini API on Care Tales' paid account. An organization's own model key, where supplied, only indexes that organization's documents. See the AI disclosure for detail.

How we tell you about changes

  1. New or replacement subprocessors are added to this page before they begin processing customer data in production.
  2. We give at least 30 days notice by email to the administrative contact for each customer organization before a new subprocessor starts processing, except where a subprocessor must be engaged sooner to prevent or resolve a security or availability incident, in which case we notify as soon as practicable.
  3. A customer with an active data processing addendum may object on reasonable data protection grounds within the notice period. We will work with the customer to find an alternative. If none is available, the customer may terminate the affected part of the service without penalty for the remainder of the paid term.
  4. Removing a subprocessor does not require notice, but the change is reflected here.

To be added to the notification list, or to ask about a specific subprocessor, write to support@caretales.com.

Contact

support@caretales.com

Changes to this document

This page is the authoritative list. It is updated on each change with a new effective date, and notice is given as described above.

Questions about this document
Write to support@caretales.com and we will answer.
All legal documents