Vendor Register

Last updated: May 11, 2026

This page lists every third party that may receive data from Pearl, what data they receive, why, and how long they retain it. It complements the Privacy Policy and Consumer Health Data Privacy Policy.

VendorPurposeData sentTraining on our data?Retention
Anthropic (Claude) AI inference for chat, summaries, triage. Messages (after PHI fence), system prompt, model selection. No (API tier). ~30 days abuse monitoring.
OpenAI (GPT) Alternate AI inference (user-selectable). Messages (after PHI fence), system prompt, model selection. No (API tier). ~30 days abuse monitoring.
Google (Gemini) Alternate AI inference (user-selectable). Messages (after PHI fence), system prompt, model selection. No (paid/API tier). Per Google AI API terms.
Netlify Hosting + serverless functions. HTTP requests to app domain, including function payload transport. Health conversations are not stored in Netlify cloud storage. N/A ~30 day access logs.
SendGrid (Twilio) Transactional email to Pearl operators for beta signup, feedback/privacy requests, and public-story review drafts. Only the form content you intentionally submit in those screens, plus minimal request metadata. N/A Per SendGrid mail-send activity retention.
Mixpanel Pseudonymous analytics, only with consent. Event name, screen, feature flags. Never chat content. N/A Default Mixpanel retention (under review).

What we never do:

Subprocessors

The internal-facing version of this register lives at docs/vendor-register.md in our source tree. Material updates are reflected here within 7 days.