Subprocessors
Effective date: September 1, 2026Last updated: September 1, 2026
BenAsk shares information with the categories of subprocessors below so we can host the Service, authenticate you, run AI features you opt into, and autocomplete drug names. We keep this list accurate for the production deployment; if we add a material new subprocessor, we will provide at least 30 days' notice by email and an in-product banner before it begins processing consumer health data.
| Subprocessor | Purpose | Data categories | Location | Retention | DPA / BAA |
|---|---|---|---|---|---|
| Clerk | Authentication, organization (“family”) management, invitations, session security. | Email, legal name where provided, Clerk user ID, org membership, MFA/session signals. | United States (Clerk data region for this deployment). | Until you delete your Clerk-connected account plus vendor rotation—see Clerk's privacy documentation. | Standard DPA available for business customers. |
| OpenAI | LLM chat completions, optional revision passes, document summarization/OCR-assisted workflows grounded in uploads. | Document text, onboarding/wizard-derived context, voluntary drug-name strings surfaced in concierge flows, chat messages, sanitized carrier-page excerpts you trigger. | United States API regions tied to BenAsk workspace configuration. | ~30 days on standard tiers for misuse monitoring unless different enterprise terms apply directly between you and OpenAI. | No HIPAA BAA executed with BenAsk today. |
| Vercel | Application hosting, edge routing, serverless execution, private Blob object storage for uploads/exports. | All application traffic and stored objects needed to run BenAsk, including uploaded documents. | United States—Blob and primary compute in Vercel IAD1 region unless we publish a change. | Until you delete user-owned objects or complete account erasure, subject to log rotation described in the Privacy Policy. | Data Processing Agreement available from Vercel. |
| Supabase | Managed PostgreSQL for application data (onboarding, documents metadata, chat, claims, consent ledgers). | Org-scoped application records; encrypted PII maps where configured; no browser Supabase client. | United States (project region configured for this deployment). | Until account erasure or scheduled deletion completes, subject to backup rotation. | Data Processing Addendum available from Supabase. |
| Resend | Transactional email (support form delivery) and optional inbound email document forwarding when enabled. | Support message metadata and content; inbound email attachments may be seen raw before BenAsk redaction when forwarding is enabled. | United States. | Per Resend retention for message delivery logs; BenAsk stores processed documents per Privacy Policy. | Data Processing Addendum available from Resend. |
| Telegram | Optional inbound document channel when a family links the BenAsk bot. | Chat identifiers and file attachments forwarded to BenAsk before redaction/analysis. | Telegram infrastructure (global); BenAsk stores processed artifacts in U.S. hosting. | Per Telegram policies for messenger content; BenAsk stores processed documents per Privacy Policy. | N/A—consumer messenger; enable only if you accept Telegram as a channel for your documents. |
| Google Analytics | Product analytics on marketing and app surfaces in production (not gated by the cookie banner). | Pseudonymous usage events; some funnel events may include Clerk user IDs. Not chat bodies or document contents. | United States / Google global infrastructure. | Per Google Analytics property settings and Google’s policies. | Google Ads Data Processing Terms where applicable; not a HIPAA BAA for BenAsk. |
| Better Stack / Sentry-compatible error tracking | Operational logs and error reports when configured via environment tokens. | Request metadata and stack traces configured to avoid unnecessary PII/PHI in message bodies. | Vendor regions for the configured Better Stack / Sentry project. | Per vendor log retention for the source. | Vendor DPA available; not a HIPAA BAA for BenAsk. |
| NLM RxTerms (NIH) | Drug-name autocomplete only (public reference API). | Partial drug-name query strings; no BenAsk account identifiers are intentionally attached to NIH calls. | United States (U.S. government infrastructure). | Per NIH/NLM policies; BenAsk does not maintain a separate RxTerms query archive beyond short-lived server logs. | N/A—no PII contractually required for public reference lookups. |
Full privacy context lives in the Privacy Policy and AI-specific controls live under Settings → Privacy & AI.