Legal

Subprocessors

Last updated: May 15, 2026

These are every third party we use to deliver Dia AI. We BAA (Business Associate Agreement) with every vendor that processes Protected Health Information. We will update this page at least 30 days before adding or replacing any subprocessor that handles PHI, and we will email Pro-tier customers when we do.

VendorPurposeData processedRegionBAA / status
AnthropicClaude Sonnet Vision — meal photo analysisMeal photos (24h TTL), prompt + responseUSYes
AWSPrimary application hosting + databaseUser account, log data, encrypted health recordsUS-East-1 (default) / Frankfurt (EU)Yes (BAA available)
Cloudflare R2Meal photo object storage (24h TTL)Meal photos (encrypted at rest)Global edge / EU on requestYes (BAA available)
AppleSign in with Apple, App Store subscriptions, APNSApple ID, subscription state, push tokensUSN/A
RevenueCatStoreKit wrapper, entitlement management, paywall A/BApple ID, subscription events. No PHI.USN/A
SuperwallOnboarding paywall experimentsAnonymous device ID, paywall events. No PHI.USN/A
SentryCrash reporting + performance monitoringStack traces, device metadata. PHI scrubbed pre-send.USYes (BAA available)
PostHogProduct analytics + feature flags (self-hosted EU)Anonymous device ID, feature events. No PHI.EU (self-hosted)Self-hosted
PostmarkTransactional email — waitlist welcome, accountEmail address, message bodyUSYes (BAA available)

What "BAA" means

A Business Associate Agreement is the contract HIPAA requires between a covered entity (or a HIPAA-aligned company like us) and any vendor that processes Protected Health Information. If a vendor here is marked Yes, we have a BAA in place. BAA available means the vendor offers a BAA on the plan we're on, and we will sign it before processing any PHI through them in production.

Cross-border transfers

For EU users, we host production data in AWS Frankfurt and use Cloudflare R2's EU region for image storage. Where data must cross borders (e.g. for AI inference at Anthropic), we rely on Standard Contractual Clauses and equivalent transfer mechanisms.

Why we publish this

Diabetes data is some of the most sensitive personal health information a person carries. You deserve to know exactly which companies touch it, what they do with it, and where it lives. Transparency is a feature.