Supabase
A potential core provider for authentication, workspace database and private file storage. Real clinical data is not activated until project region, backup scope, processing agreement and transfer mechanism are verified.
Provider transparency
The names below are providers the product can support. Inclusion does not mean a provider is active for every workspace.
A potential core provider for authentication, workspace database and private file storage. Real clinical data is not activated until project region, backup scope, processing agreement and transfer mechanism are verified.
A potential core provider for the web application, server functions, security and performance delivery. Execution region and contract are verified. Optional measurement runs only with consent and on public pages.
Used as an identity provider only when a user chooses Google sign-in, for account identifier, email and basic profile details. Google sign-in is optional and does not receive clinic patient files.
If the public question form is enabled, it processes client IP address, TLS fingerprint, User-Agent, sitekey and origin plus browser-security signals to distinguish bots and abuse; it does not receive question-form fields. The form stays off until the provider contract, region and applicable transfer safeguard are verified.
May deliver the single-use public-question verification email and, for clinic features, only a separately enabled email channel. The recipient and message are sent to Resend. The verified stokontrol.com sender routes and sends email from Tokyo (ap-northeast-1); this choice does not change data residency, and account metadata, logs and API records are stored in the United States. Live delivery stays off until the contract, the applicable transfer safeguard under Article 9 of Türkiye's Personal Data Protection Law, retention, production-account ownership and sender domain are evidenced.
May deliver SMS or WhatsApp only after the clinic connects and verifies that channel. The recipient and message may be sent to that provider. Live delivery stays off until channel, patient preference, template, contract and region are verified.
If the server-side Stoko AI feature is separately enabled, text submitted to that feature may be processed. Users must not enter unnecessary patient identity or health text. The feature is off by default and clinical content is not enabled until model, region, retention and processing terms are verified.
Iyzico or another verified regional payment provider is used only after payment activation; card data is processed on its hosted checkout. A Marketplace fulfilment party and its role are disclosed before order approval. Patient health data is not sent to these parties.
If Academy live or single-view replay is enabled, the actual provider may process IP address, device/browser signals, media requests and opaque stream identifiers for short-lived signed playback, device/network limits, recording processing and delivery. Its name, account, region, subprocessors, retention/download settings, transfer safeguard and recording rights are verified and published before programme sale. Code support for Cloudflare Stream, Mux or another candidate does not mean it is active; Academy checkout and playback remain closed without that evidence.
Adding or replacing an active subprocessor, or changing its region, creates a new notice version. Workspace administrators receive applicable notice and objection time; if an objection cannot be resolved, the affected feature is disabled or a contractual exit is offered.