Subprocessor annex
Last updated 14 September 2026. Available on request, and published here so nobody has to ask.
Every third party involved in running Paperbark, what each one holds, and where it sits.
Who touches what
The providers below support Paperbark. Original records stay local; cloud providers process optional messages and reviewed case summaries you choose to send. This annex is the detail behind the privacy policy, for practitioners who need it for their own compliance file.
Google Firebase Authentication and migration archive
Holds: sign-in identity and authentication information. A temporary read-only Firestore copy of pre-migration account data is retained for recovery.
Where: the Firestore archive is in australia-southeast1, Sydney. Firebase Authentication is separately managed and not restricted to that region. Google LLC operates these services and may provide support from outside Australia.
Purpose: account sign-in and migration recovery. Current account and message writes use Paperbark-operated servers.
Cloudflare
Holds: network traffic to paperbark.app and to the intake relay, including IP addresses in transit logs.
Where: global edge network; the origin is in Australia.
Purpose: serving this site and protecting the relay.
Cannot see: anything inside the encrypted payloads it carries.
Cloud messaging and subscriptions
During beta and development, Paperbark-operated servers in Australia store account settings, device rosters, practitioner profiles, invitations, messages, reviewed case summaries, timestamps, reports and subscription entitlements. Chart templates are encrypted in storage, but the service also holds the account key used by authenticated devices; this is not end-to-end encryption. Messages are protected in transit and by account access controls, and are not end-to-end encrypted. Cloudflare carries HTTPS traffic to the service. The subscription verifier contacts Apple or Google Play; those providers handle purchases and payment. Original client records and attachments are not uploaded by messaging.
The intake relay (Koda Software)
Holds: a blank intake form, a client's first name, your practitioner name, a public key, and, once submitted, the client's encrypted answers.
Where: hardware we operate in Australia.
Purpose: passing an intake form to a client and their answers back to you.
Cannot see: the answers, which are encrypted in the client's browser to a key only your device holds, and which are deleted as soon as your app confirms it has them.
Your cloud drive, if you connect one
Holds: the encrypted archives you choose to put there.
Where: wherever that provider keeps your account.
Purpose: your own backups.
Cannot see: anything inside them. This is your account and your agreement with Google, Apple, Microsoft or Dropbox; we are not a party to it and we have no access to it.
Apple and Google sign-in
Used only if you choose them, and only to establish who you are. They learn that you use Paperbark; they learn nothing about your clients.
Questions
Email takamundy@gmail.com and you will get a written answer from a person.