Subprocessors
The list
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Google — Firebase Authentication | Sign-in and session management | Email address, authentication credentials and tokens |
| Google — Firebase / Firestore | Account, entitlement, organisation and support records | Account profile, licensing status, templates, enquiries |
| Google — Gemini | The AI features | Only when a clinician runs one: a redacted summary of structured clinical findings |
| Google — Firebase Analytics (GA4) | Aggregate product analytics | Only after opt-in: closed-catalogue events with no account identifier |
| Stripe | Payment processing, subscriptions, billing portal | Payment and billing details, handled by Stripe directly |
| Postmark | Transactional email | Recipient address and message content |
| Coolify-managed UK hosting | Application hosting | Application traffic |
What each one does not receive
Google Gemini receives only what a clinician explicitly submits by running an AI feature, after redaction on both client and server. It is not given account identifiers, and neither the prompt nor the response is retained by us.
Google Analytics never receives an account identifier. Advertising features, Google Signals and ad personalisation are disabled, and IP is anonymised. Where a user has not opted in, the analytics code is never loaded into the app at all.
Stripe handles card data directly. We never see or store card details; we receive subscription status by signed webhook.
Postmark carries transactional email. Outbound messages pass an automated guard that blocks anything matching the shape of clinical content — formatted observation lines, scored GCS, vitals with units, report section lines — so clinical data cannot leave by email even accidentally. Open and click tracking are disabled, deliberately: neither is needed, and both would create records of whether a clinician read their email.
International transfers
Google and Stripe operate global infrastructure and may process data outside the UK and EEA, under their respective data protection commitments and transfer mechanisms.
Our own application hosting is UK-based.
What clinical data reaches a subprocessor
Only one path: Google Gemini, only when a clinician runs an AI feature, and only as a redacted structured summary in which the patient is referred to as "Pt".
There is no other route by which clinical content reaches any subprocessor, because there is no other route by which it leaves the device — with the two narrow exceptions of a user-initiated device transfer, which is held in memory on our own infrastructure for at most 10 minutes, and a saved template, which a user creates deliberately.
Changes
We will keep this page current. If your organisation requires advance notice of subprocessor changes as a contractual term, raise it at hello@swyftscale.com.