Subprocessors
Last reviewed: August 14, 2026
Curio uses a small number of third-party providers to run its service. This page lists every one of them, what they do, and what information they can access. It is the same list we maintain internally — we publish it so you can check it against your own privacy obligations.
Everything we store is stored in Canada, and every provider below is bound by a written data-protection agreement. One provider is different and we want to be clear about it: Cloudflare sits in front of our application and unlocks each request as it arrives, at whichever of its locations is closest to the person making it. For someone in Canada that is normally a Canadian location, but it depends on how the internet routes them and we cannot promise it always will be. Nothing is stored there.
We will give therapists at least 30 days' notice before adding or replacing any provider that handles health information, so you have time to review the change or object.
Providers that handle health information
These providers can access the information therapists and their clients entrust to Curio.
| Provider | What they do for us | What they can access | Where |
|---|---|---|---|
| Google Cloud Platform | Hosting, database, and encryption-key management | Encrypted message content and account records, stored at rest | Canada (Montréal) |
| Amazon Web Services | Outbound email gateway — delivers your messages | Message content while it is in transit, for as long as delivery takes | Canada (Montréal) |
| Cloudflare | Security and content delivery in front of the Curio application, and DNS | Unlocks each request to read and protect it as it passes through, then forwards it. Does not store anything | The location closest to the person making the request, normally Canadian for Canadian users but not guaranteed |
Providers that do not handle health information
These providers support the service but never receive health information.
| Provider | What they do for us | What they can access | Where |
|---|---|---|---|
| Upstash | Background job processing and caching | Technical job data and internal identifiers — no message content | Canada |
| Resend | Service notification emails | A recipient address and a secure link — no message content, no health information | Not published by vendor |
| Stripe | Payment processing | Billing details only — no health information | Not published by vendor |
| UptimeRobot | Checks that the service is reachable and alerts us when it is not | Whether a page responds, and how quickly — no message content, no health information | Slovak Republic, EU |
| Google Analytics | Marketing-website analytics, only if you consent | Anonymized website usage — no health information | Not published by vendor |
Not a subprocessor: your own Google Workspace
If you route outbound mail through Curio from your own Google Workspace, that Workspace is yours, not ours. Mail flows from your tenant to Curio. Curio never pushes your information into a Google Workspace it controls. Google is therefore not a Curio subprocessor for this feature, and your Workspace relationship remains your own responsibility as custodian.
We list it here only because therapists reasonably ask where Google fits.
Changes to this list
We review this list every quarter and whenever a provider changes.
Before any new provider that handles health information goes live, we notify the primary contact on every affected account at least 30 days in advance. If you object to a change, contact us at support@curio.health — your rights on objection are set out in the Electronic Service Provider Agreement you accepted at sign-up.
Last reviewed: August 14, 2026 · Questions: support@curio.health