About this list
These are the companies that process data on our behalf, what each one receives, and where it is processed.
We publish this rather than supplying it on request, because a list you have to ask for is one you cannot check before you sign up.
A provider appears here if any personal data reaches it, including a provider that only ever sees an email address. Four of the 7 can hold clinical content, and those are marked.
Every provider operates under its standard data-processing terms. No provider-specific agreement has been negotiated, and no business associate agreement exists with any of them — which is why our terms of service refuse HIPAA-regulated use.
1
Providers
- Convex — Application database, realtime queries, scheduled jobs, and server-side functions. Data: account data, workspace content, clinical records, audit events, billing records. Processing: United States. Can access clinical content. Provider data-processing terms. Holds the canonical copy of every Personal Cloud report. local reports stay in the browser and reach Convex only when the user copies or moves one to Personal Cloud.
- Cloudflare — Application hosting (Workers), file storage (R2), realtime collaboration rooms (Durable Objects), and bot protection (Turnstile, through Clerk). Data: uploaded files, report source documents, collaboration state, technical data. Processing: Global edge network, United States. Can access clinical content. Provider data-processing terms. Files are stored under opaque keys and served only through an authorized proxy.
- Clerk — Account identity, sessions, and the email-only waitlist, including the invitation emails it sends on our behalf. Data: account data, email address, authentication events. Processing: United States. No clinical content. Provider data-processing terms.
- Paystack — Subscription checkout, card and Mobile Money payment processing, and renewal webhooks. Data: billing data, email address, transaction references. Processing: Ghana, Nigeria, South Africa. No clinical content. Provider data-processing terms. Nonu never receives full card numbers.
- Resend — Transactional email: workspace notifications, the daily digest, and secure patient report links. Data: email address, notification metadata, delivery events. Processing: United States. No clinical content. Provider data-processing terms. Subjects and bodies carry no report content and no patient identifiers.
- OpenAI — Cloud AI assistance and cloud dictation transcription, when a user requests them. Data: selected report context, instructions, dictation audio. Processing: United States. Can access clinical content. Provider data-processing terms. Only reached for a feature the user explicitly invokes. Offline dictation never leaves the device. For a local report, each request first needs a purpose-specific permission, and Nonu stores neither the request nor the response.
- Anthropic — Alternative cloud AI provider for report assistance and review, when configured. Data: selected report context, instructions. Processing: United States. Can access clinical content. Provider data-processing terms.
2
Which ones can see clinical content
Marked above: Convex, Cloudflare, OpenAI and Anthropic.
Convex holds the canonical copy of every report, because it is the database. Cloudflare R2 holds uploaded files and imported source documents, because it is the object store.
A cloud AI provider receives selected report context, instructions, or dictation audio — but only when you invoke a cloud AI or cloud dictation feature, never in the background. Offline dictation never leaves your device.
Grammar, spelling and style proofing runs entirely in your browser. Report text is not sent anywhere to be checked.
3
International transfers
Nonu is operated from Ghana, and most providers above process outside it. Where a transfer requires a safeguard, we rely on the mechanism in each provider's data-processing terms.
We do not pin a processing region today. If your deployment requires one, ask before you start — the answer is a change to our infrastructure, not a setting.
4
Changes to this list
Adding a provider is a change to this page and to the register it is built from, made in the same commit. Material changes are announced the same way a privacy policy change is.
Questions about a provider on this list go to support@usenonu.com. Do not include patient information in email.