Overview
Each sub-processor is engaged under that vendor’s written terms, which limit use to the service we buy, require confidentiality, and impose security obligations. Sub-processors that process EU/UK personal data are bound by Standard Contractual Clauses or another approved transfer mechanism.
On Business Associate Agreements. Aler executes a BAA with clinical practices and covered entities that send us data. Vendor-side BAA paperwork with our own sub-processors is on our pre-launch list and is not complete today. We say so here rather than imply coverage we do not yet have. Section 3 describes what that means for model inference specifically.
Current sub-processors
| Sub-processor | Function | Data processed | Region | Safeguards |
|---|---|---|---|---|
| Anthropic, PBC | Model inference for chat, insights, and document understanding (Claude models) | Prompts and completions. A prompt carries the context the answer needs, which can include your profile, medications, conditions, lab values, recent metrics, and your question | US | Commercial API terms prohibit training on prompts or completions. See Section 4 for the BAA position |
| OpenAI, L.L.C. | Image generation for decorative scene imagery only | A city name and a scene description. No health data, no account identifiers, no free text you wrote | US | API terms prohibit training on inputs or outputs; results are cached per city and reused |
| Google LLC (Cloud Text-to-Speech) | Spoken playback of a reply, when you use voice | The text of the reply, which can contain health information | US | Speech recognition runs on your device. Recorded audio is never uploaded, to this vendor or to us |
| Google LLC (Firebase Cloud Messaging) | Push notification delivery on Android and iOS | Device push tokens, notification title and body, deep-link target | US | Payloads avoid clinical detail; content renders after the app opens |
| Apple Inc. (APNs, Sign in with Apple, TestFlight) | iOS push transport, sign-in, and beta build distribution | Device push tokens; the account identifier returned at sign-in; tester email and device identifiers during the beta | US | Platform transport under Apple’s developer terms |
| Google LLC (Google Sign-In, Firebase App Distribution) | Sign-in, optional profile prefill, and Android beta distribution | Email address and account identifier at sign-in; name, sex, and gender if you choose profile prefill; tester email and device identifiers during the beta | US | Prefill is optional and shown to you before it is saved; beta distribution ends with the beta |
| Resend, Inc. | Transactional email (sign-in links, security notices, invitations, reminders) | Email address, name, message content | US | Message content is kept to links and notices; clinical detail stays in the app. Delivery infrastructure runs on Amazon SES |
| Cloudflare, Inc. | Network edge: DNS, TLS termination, tunnel, and DDoS protection in front of Aler-managed infrastructure | All traffic between you and Aler while it is in transit, including health data | US (global edge) | Transit only. Application data is stored on Aler-managed infrastructure, not at the edge |
| Formspree, Inc. | Waitlist and contact forms on the marketing website | Email address, name, the interests you select, and a timestamp | US | Marketing website only. No health data and no account data reach this vendor |
Hosting. The application, the primary database, the job queue and cache, and uploaded files all run on Aler-managed infrastructure in the United States and are not sub-processed. Cloudflare sits in front of it as described above.
Browser push. If you enable web push, the push service operated by your browser vendor (Google, Mozilla, or Apple depending on the browser) carries the encrypted notification to your device. We do not contract with them; they are a transport path your browser chooses.
Categories we do not engage
Vendor lists on privacy pages tend to describe an intended architecture. This one describes the running one. As of the effective date above, Aler engages no vendor in any of the following categories, and nothing is sent to one:
- Product analytics, session recording, or behavioral tracking. There is no analytics SDK in the app or on the website.
- Third-party crash or error reporting. Client errors post to an Aler-operated endpoint on our own infrastructure. No error-reporting vendor receives anything.
- Advertising, attribution, or marketing-automation vendors.
- Payment processing. Paid plans are not enabled. When they launch we expect to engage a PCI-DSS Level 1 processor, full card numbers will never touch Aler systems, and this page will be updated under the notice process in Section 8 before any payment data is collected.
- SMS delivery. No text messages are sent.
- Identity-verification vendors. We do not collect government-issued identity documents.
- Customer-support helpdesk software. Support runs over email.
- SIEM, DLP, or managed security-monitoring vendors.
If any of these changes, the vendor appears in Section 2 and subscribed users are notified under Section 8.
Model inference providers
Aler routes prompts to Anthropic’s Claude models for chat, insight generation, and document understanding. A prompt contains the context the answer needs. In practice that means identifiable health information leaves our infrastructure for the duration of the call.
What is contractually true today. Anthropic’s commercial API terms prohibit the provider from using prompts or completions to train its models, and limit retention to a short window kept for abuse monitoring rather than for model development. Those terms apply to every call we make.
What is not true yet. We do not have a Business Associate Agreement in place with an inference provider, and we are not currently routing through a BAA-eligible, tenant-isolated hosting arrangement. Both are on our pre-launch list, and the intended end state is inference under a BAA in a dedicated region. Until that is signed and switched on, this page says so plainly rather than implying coverage that does not exist. If you would rather not have your record used this way, the assistant features are optional and can be left unused; the rest of the App works without them.
Aler does not send your record to any other generative-model provider. The image provider named in Section 2 receives a city name and nothing else.
Reference and location lookups
Some features answer a question by asking a public data source. These providers are not sub-processors in the ordinary sense, because they do not hold data on our behalf, but they do see a request, and some of those requests carry information about you. We list them for completeness.
Providers that can receive approximate coordinates or a place query, when you use environment, travel, or place features: Google Maps Platform (Places and Pollen), the U.S. National Weather Service, currentUVindex, the U.S. Geological Survey elevation service, the U.S. Environmental Protection Agency drinking-water service together with the FCC geocoder, OpenStreetMap Nominatim, and Geoapify. Each request carries a location and identifies Aler as the caller. None carries your name, your account identifier, or your health record.
Providers we read reference data from, with no data about you: openFDA, RxNorm and RxNav, RxClass, DailyMed, PubChem, the NIH Dietary Supplement Label Database, USDA FoodData Central, the NLM Clinical Tables service, Open Targets, and the CMS NPPES registry. These are read into a shared reference table and served from that cache, so a question you ask does not become a live call carrying your data.
Assets your browser loads
The website and the app load a small number of files from third-party origins. Loading a file discloses your IP address and user-agent string to whoever serves it. No health data is involved, and none of these set advertising cookies for us.
- Typefaces served from rsms.me and from Google Fonts.
- Sign-in widgets served from accounts.google.com and appleid.cdn-apple.com, loaded only on screens that offer those sign-in options.
- App-store badge icons served from Google’s content network on the marketing website.
Connected sources and affiliate links
Connected sources are not sub-processors. Wearable, phone-platform, calendar, and health-record services you choose to connect (for example Whoop, Oura, Withings, Polar, Wahoo, Google Health, Android Health Connect, Apple Health, and Google Calendar) act under your own authorization as sources of data. They send to us; we do not send your record to them. Their own privacy notices govern what they collect from you.
Affiliate links. Some product suggestions link to Amazon through the Amazon Associates program. Aler makes no server call to Amazon and sends nothing about you. If you click one of those links, Amazon receives the ordinary information any referred visit carries, including that you arrived from Aler and which product you opened. Do not click if you would rather Amazon not have that.
How we manage changes
- Adding or replacing a sub-processor that materially expands data categories outside the U.S. requires at least thirty (30) days’ advance notice to subscribed users.
- Adding a sub-processor that processes the same categories already disclosed here, in the same regions already disclosed, may be made on shorter notice.
- Adding a sub-processor in one of the categories listed in Section 3 as not engaged is treated as a material change and gets the full thirty (30) days’ notice.
- If you reasonably object to a new sub-processor on data-protection grounds, you may terminate the affected Services without further obligation; the procedure is described in the App Terms of Service.
Subscribe to changes
Email [email protected] with the subject line “Sub-processor notifications” to be added to the change-notification list.
