Ophie relies on a small set of vetted service providers to deliver voice sessions, store memories, and keep the service safe. This page lists every one of them, what they receive, and where they process it.
Last updated September 1, 2026
Most providers below are bound by a written DPA covering security, breach notification, and subprocessor flow-downs. Where a provider does not offer one, or where ours is not yet executed, the provider's card says so.
Ophie does not train models on your data. Provider protections vary: some are contractually barred, while others require an opt-out or do not state a rule. Those differences and unresolved controls are flagged below.
We give at least 30 days' advance notice before adding a new subprocessor that handles consumer health data.
Active providers receive data under our current configuration. Failover only providers receive data solely when the primary provider errors out. Not currently used providers are integrated and listed for completeness, but no data reaches them under the running configuration. Providers marked Health data can receive consumer health data and are also named in our Consumer Health Data Privacy Notice. Runtime selection and the active-recipient list were last reconciled on 2026-09-01. Vendor legal-page review dates vary; contract and evidence status is tracked separately and remains subject to final legal review.
These providers use what we send for model improvement unless we opt out. We disclose them rather than describe our stack as uniformly no-training: AssemblyAI, Inc.; Deepgram, Inc.; Cartesia AI, Inc.; Together Computer, Inc. (Together AI); Voyage AI Innovations, Inc. (a MongoDB, Inc. company); PostHog, Inc..
Managed Postgres database, authentication, file storage, and auth-flow email (account confirmation, password reset)
Real-time WebRTC voice transport and LiveKit Cloud hosting of our voice agent runtime
Primary text-to-speech voice synthesis (the Simba 3.2 streaming model) — speaks Ophie's replies aloud
Streaming speech-to-text transcription of your voice during sessions (Universal-3.5 Realtime Pro), plus batch transcription of session audio
Last-resort text-to-speech fallback when the primary voice provider fails to initialize; formerly also the streaming speech-to-text provider (not selected while the AssemblyAI override is set)
Text-to-speech voice synthesis (Octave 2) — selectable alternate; not selected under the current configuration
Text-to-speech voice synthesis (selectable alternate; not selected under the current configuration)
Text-to-speech and speech-to-text (selectable alternate; not selected in production)
Primary inference provider for our conversational LLM (GPT-5.6) — generates the AI response. An optional batch speech-to-text path (Whisper) exists but is not enabled.
First automatic failover leg for the conversational LLM when the primary provider fails (an open-weight Qwen model); also inference for our crisis-detection safety classifier (the open-weight GPT-OSS-Safeguard 20B model), background reasoning models, and RAG summarization
Former primary inference provider for the conversational LLM (an open-weight Tencent Hy3 model); the integration and credentials remain but no production code path selects it
Former last-resort failover inference provider for the conversational LLM; the integration and credentials remain but no production code path selects it
Former primary inference provider for the conversational LLM (an open-weight Qwen 3 model); the integration and credentials remain but no production code path selects it
Inference for voice-session subconscious intuition and Guardian reasoning loops
Text-embedding and reranking models used for memory retrieval
Former managed vector database retained as a disabled rollback integration while Supabase pgvector is active
Key management for our application-layer envelope encryption
Backend API hosting
Frontend application hosting and CDN
Error monitoring and performance telemetry (backend and client apps)
Product analytics — only if you opt in; the default is off
Payment processing and subscription billing (not enabled during beta)
Transactional email delivery (verification codes, receipts, policy notices)
Coarse IP-based geolocation used at signup to enforce regional eligibility rules
Delivery of mobile push notifications, abstracting Apple Push Notification service and Firebase Cloud Messaging
Optional third-party authentication (mobile app only; not yet enabled on web)
Optional third-party authentication (mobile app only; not yet enabled on web)
Secrets management (internal infrastructure only)
Gift-card fulfillment for waitlist referral rewards (no API key configured in production; rewards are issued manually)
We select United States endpoints where providers offer them and the selection is evidenced. Together AI describes its hosting only as North America, and its exact production endpoint region is not evidenced. Several providers' agreements also reserve the right to process in other countries where they or their subprocessors operate; those limitations are noted under "Residency" above. EU, EEA, and UK access to the service is region-gated. If we ever change this, we will update this page and provide advance notice to affected users where required by law.
To request advance notice when we add or change a subprocessor that handles consumer health data, email us with the subject line "Subprocessor notifications."
support@ophie.app