OpnFit
Back to app

Subprocessors

Last updated: August 3, 2026

In the spirit of transparency, this page lists every third-party service provider ("subprocessor") that can touch data while you use OpnFit, what each one does, and how long it keeps anything.

The short version: OpnFit itself stores nothing — it has no database, and your health data is never written to our servers. The services below process data in transit only, and the AI provider we use is contractually committed to zero data retention.


Infrastructure

SubprocessorPurposeLocationRetention
Vercel Inc.Application hosting and serverless compute — runs the OpnFit app and proxies your requests to Google and the AI providerUSA (global edge)In transit only. OpnFit is stateless: no database, and no health data is written to logs. Standard operational request logs (URLs, status codes — never health payloads) are kept briefly by the platform.
Cloudflare, Inc.DNS, TLS termination, and CDN in front of the appGlobal edge networkIn transit only. Transient request metadata for security and performance; no health payloads are cached or stored.

AI coach

SubprocessorPurposeLocationRetention
Ollama, Inc. (Ollama Cloud)Runs the AI model that powers the coach. Receives your chat messages and the health metrics needed to answer themUSAZero retention. Per Ollama's cloud policy, "prompt or response data is never logged or trained on," and its hosting partners are required to operate with no logging, no training, and zero data retention.

The coach is the only feature that sends your health data to an AI provider, and it only sends the metrics relevant to your question. The dashboard works fully without it.

Data source (not a subprocessor)

ServiceRole
Google LLC (sign-in & Google Health API)Google is where your health data already lives — it acts as an independent service you authorize, not as our subprocessor. OpnFit reads your data from Google with the read-only permissions you grant, under the Google Privacy Policy.

Changes to this list

If we add, remove, or replace a subprocessor, we will update this page (and the "last updated" date) before the change takes effect. Adding any subprocessor that would store health data — today there are none — would also require updating the Privacy Policy and asking for your consent again where required.

Contact

Questions about a subprocessor? Email [email protected].