Ophie relies on a small set of vetted service providers to deliver voice sessions, store memories, and keep the service safe. This page lists every one of them, what they receive, and where they process it.
Last updated July 26, 2026
Most providers below are bound by a written DPA covering security, breach notification, and subprocessor flow-downs. Where a provider does not offer one, or where ours is not yet executed, the provider's card says so.
We never train on your data. Most providers are contractually barred from training on what we send; a few use inputs for model improvement unless we opt out, and those are flagged in red below.
We give at least 30 days' advance notice before adding a new subprocessor that handles consumer health data.
Active providers receive data under our current configuration. Failover only providers receive data solely when the primary provider errors out. Not currently used providers are integrated and listed for completeness, but no data reaches them under the running configuration. Providers marked Health data can receive consumer health data and are also named in our Consumer Health Data Privacy Notice. Every entry was checked against the provider's own legal pages on 2026-07-29.
These providers use what we send for model improvement unless we opt out. We disclose them rather than describe our stack as uniformly no-training: Deepgram, Inc.; Cartesia AI, Inc.; Voyage AI Innovations, Inc. (a MongoDB, Inc. company); PostHog, Inc.; Intuition Machines, Inc. (hCaptcha).
Managed Postgres database, authentication, file storage, and auth-flow email (account confirmation, password reset)
Real-time WebRTC voice transport and LiveKit Cloud hosting of our voice agent runtime
Speech-to-text transcription; last-resort text-to-speech fallback
Text-to-speech voice synthesis (Octave 2) — the default voice
Text-to-speech voice synthesis (fallback when the default provider fails)
Text-to-speech and speech-to-text (selectable alternate; not selected in production)
Primary inference provider for our conversational LLM (an open-weight Tencent Hy3 model) — generates the AI response
Last-resort failover inference provider for the conversational LLM — serves the same model as the primary, and receives data only when both the primary and the first failover provider fail
Former primary inference provider for the conversational LLM (an open-weight Qwen 3 model); the integration and credentials remain but no production code path selects it
Former failover inference provider for the conversational LLM; the integration and credentials remain but no production code path selects it
Inference for our crisis-detection safety classifier (the open-weight GPT-OSS-Safeguard 20B model), for background reasoning and sentiment models, and — as the first failover leg — for the conversational LLM itself when the primary provider fails
Legacy/failover conversational-LLM path and optional batch speech-to-text (Whisper); neither is enabled in production
Text-embedding and reranking models used for memory retrieval
Managed vector database for memory retrieval (RAG)
Key management for our application-layer envelope encryption
Backend API hosting
Frontend application hosting and CDN
Error monitoring and performance telemetry (backend and client apps)
Product analytics — only if you opt in; the default is off
Payment processing and subscription billing (not enabled during beta)
Transactional email delivery (verification codes, receipts, policy notices)
Bot and abuse prevention on the waitlist
Coarse IP-based geolocation used at signup to enforce regional eligibility rules
Delivery of mobile push notifications, abstracting Apple Push Notification service and Firebase Cloud Messaging
Optional third-party authentication (mobile app only; not yet enabled on web)
Optional third-party authentication (mobile app only; not yet enabled on web)
Secrets management (internal infrastructure only)
Gift-card fulfillment for waitlist referral rewards (no API key configured in production; rewards are issued manually)
We direct all processing to United States endpoints and regions, and we do not instruct any provider to process your data elsewhere. Several providers' own agreements nonetheless reserve the right to process in other countries where they or their subprocessors operate; where that is so, it is noted under "Residency" on that provider's entry above. EU, EEA, and UK access to the service is region-gated. If we ever change this, we will update this page and provide advance notice to affected users where required by law.
To request advance notice when we add or change a subprocessor that handles consumer health data, email us with the subject line "Subprocessor notifications."
team@ophie.app