Ophie relies on a small set of vetted service providers to deliver voice sessions, store memories, and keep the service safe. This page lists every one of them, what they receive, and where they process it.
Last updated April 26, 2026
Every provider is bound by a data-processing agreement requiring breach notification, security controls, and subprocessor flow-downs.
Where a provider trains models, we contractually prohibit them from training on data we send.
We give at least 30 days' advance notice before adding a new subprocessor that handles consumer health data.
Postgres database, authentication, and auth-flow email (account confirmation, password reset)
WebRTC voice transport and agent orchestration
Speech-to-text transcription
Text-to-speech voice synthesis (default provider)
Text-to-speech voice synthesis (alternate provider, configurable per session)
Text-to-speech voice synthesis with emotion adapter (alternate provider, configurable per session)
Primary conversational LLM inference (Qwen 3.5-397B via Gradient AI / vLLM)
Background LLM, RAG summarization, and safety-classifier inference (GPT-OSS-20B, Llama-3.1-8B, GPT-OSS Safeguard-20B)
Fallback LLM, embeddings, sentiment / summary / memory-trigger helpers, supplementary safety classification
Image OCR / 'read this' tool inference (Claude Haiku via OpenRouter)
PDF reading tool inference (Gemini 2.5 Flash via OpenRouter)
Routing intermediary for tool-level LLM calls (Anthropic, Google AI, supplementary models)
Embedding and reranking models for semantic memory
Vector database (retrieval-augmented memory)
Payment processing and subscription billing
Frontend application hosting and CDN
Backend API hosting
Error monitoring and performance tracing (PII scrubbed)
Product analytics (opt-in only)
Bot and abuse prevention on signup and waitlist forms
IP-based geolocation for regional access controls (IL / TX / EU / EEA / UK block)
Secrets management (internal infrastructure only)
Transactional email delivery (notifications, reminders, verifications)
Gift-card fulfillment for promotional rewards
We do not transfer personal information outside the United States. All providers above process data in U.S. data centers under U.S. legal frameworks. EU, EEA, and UK access to the service is currently region-gated. If we ever change this, we will update this page and provide advance notice to affected users where required by law.
To request advance notice when we add or change a subprocessor that handles consumer health data, email us with the subject line "Subprocessor notifications."
team@ophie.app