Purpose and scope
This Subprocessor List identifies public service providers that may process personal information for Pocket Genes infrastructure, authentication, database, backend, hosting, operations, diagnostics, support, or scheduling workflows.
The list reflects public providers used by current Pocket Genes surfaces and is updated when a provider is added, replaced, removed, or starts processing a new category of personal information.
Who this page applies to
- Pocket Genes users, invited users, caregivers, and community participants.
- Integrators, providers, and Trusted Organizations evaluating Pocket Genes data handling.
- People who submit support, booking, incident, accessibility, or trusted-organization requests.
Definitions
Subprocessor
A service provider that processes personal information for Pocket Genes according to Pocket Genes instructions or configuration.
Infrastructure provider
A cloud or platform provider that hosts, stores, authenticates, transmits, logs, or supports Pocket Genes technical components.
International processing
Processing, storage, support, or access that may occur outside the user country depending on provider architecture and support operations.
Provider public information
Public privacy, security, data-processing, or service information published by the provider.
Public register
Each provider entry identifies the legal entity, service, purpose, information categories, processing role, transfer context, public reference, and review date.
Amazon Web Services
- Legal provider entity: Amazon Web Services, Inc. or applicable AWS contracting affiliate.
- Product or service used: Cloud infrastructure and backend services used by Pocket Genes components.
- Purpose: Hosting, compute, storage, network, operational reliability, security, and backend service operation.
- Categories of information: Application, operational, logging, integration, support, and limited account information depending on hosted component.
- Processing role: Hosts, stores, transmits, and supports infrastructure under Pocket Genes configuration.
- Jurisdictions or transfers: International processing may apply depending on AWS region, support, and service configuration.
- Public reference: AWS privacy, data processing, security, and compliance information.
- Added or reviewed: August 2026.
Google Firebase
- Legal provider entity: Google LLC or applicable Google contracting affiliate.
- Product or service used: Firebase Authentication, Firebase or Google Cloud database and application infrastructure where configured.
- Purpose: Authentication, account identity, database, application operations, security events, and app infrastructure.
- Categories of information: Account identifiers, authentication data, login records, profile/application data, integration references, technical logs, and diagnostic information depending on feature.
- Processing role: Authenticates, hosts, stores, transmits, and supports application infrastructure.
- Jurisdictions or transfers: International processing may apply under Google and Firebase service terms and infrastructure.
- Public reference: Google Cloud, Firebase, privacy, data processing, and security information.
- Added or reviewed: August 2026.
Provider selection
Pocket Genes assesses service providers according to the service purpose, information categories involved, security controls, privacy terms, contractual terms, reliability, support model, and whether the provider is necessary for the relevant feature.
Changes and notice
Material additions, replacements, removals, or new processing purposes are reflected in this list. Pocket Genes may notify users, integrators, or organizations separately when a change materially affects their information, contract, integration, or legal rights.
A provider used only for a different Golden Crow Venture Studio product is not treated as a Pocket Genes subprocessor unless it processes Pocket Genes information.
Provider handling model
- The provider register identifies services used for Pocket Genes surfaces.
- Data sent to each provider is limited to the purpose of the integration.
- Provider security and privacy information is reviewed before material use.
- Users or partners are updated when a material provider change requires notice.
User, integrator, and organization responsibilities
- Users should use privacy request channels for questions about provider processing.
- Integrators should not assume their own vendors are covered by this Pocket Genes list.
- Organizations should disclose their own external tools when they send users away from Pocket Genes or collect information independently.
Exceptions and limitations
- Provider legal entities and product names can vary by contract and region.
- Emergency support, legal requests, fraud investigations, and provider outages may involve additional processors or disclosures where permitted.
- This list does not cover independent providers that control their own reports, websites, clinical services, events, or resources.
How to make a request or report a problem
Privacy, account, deletion, accessibility, safety, trusted-organization, and security requests can be sent to support@goldencrowvs.com. Use a subject line that identifies the issue, the affected Pocket Genes account or workflow, and whether the request is urgent.
Pocket Genes may need to verify the requester before changing or disclosing account information. Verification is handled proportionally to the request, the sensitivity of the information, and the risk of giving account access or private information to the wrong person.
Effective date, version, and review history
| Item | Value |
|---|---|
| Effective date | August 14, 2026 |
| Version | 1.1 |
| Last reviewed | August 2026 |
| Material changes | Expanded Trust Center format, operator identity, data-map boundaries, request paths, and responsibility sections. |
| Previous version | July 2026 Trust Center overview copy. |