1. The list
Supabase
Purpose: Database, authentication, and file storage. Supabase holds all Customer Data at rest — evaluation events, coaching records, account details, and verbatim prompt content for the length of the retention window the customer configures.
Processing location: United States by default; an EU region is available per contract.
Cloudflare
Purpose: Network edge and access control. Every request to coapro.org, app.coapro.org and api.coapro.org reaches us through Cloudflare, which terminates TLS. That includes prompt text on its way to the evaluation API, so Cloudflare is in the path of the most sensitive data we handle, in transit. Cloudflare also enforces sign-in on the administrator console.
Processing location: Global edge network; the request is served by the location nearest the user.
Ollama Cloud
Purpose: Runtime text generation only. To draft coaching feedback and skill assessments at runtime, redacted (non-verbatim) context is sent to this provider. Per its published terms, it does not train on API inputs.
What it is not used for: model training. Coapro trains its own models on its own infrastructure — customer prompt content is never sent anywhere for training. See Model Training.
Processing location: United States.
Resend
Purpose: Transactional email — coaching digests and administrator alerts. Receives recipient email addresses and the contents of the message. Mail is sent from coapro.org, authenticated with DKIM, with SPF published on the send.coapro.org return path.
Processing location: United States. Resend delivers through Amazon Simple Email Service (us-east-1), so Amazon Web Services is a further sub-processor for mail in transit.
Status: Configured and the sending domain is verified. Email is sent only for features a customer turns on — coaching digests and administrator alerts — and to the addresses that customer has enrolled.
2. What is not on this list
We use no advertising, analytics, or session-replay services. The marketing site sets no cookies and loads no third-party trackers. We do not sell personal information and we do not share it for advertising. And there are no model-training vendors: training is ours — see the next section.
3. Model training, stated plainly
Coapro trains its own models on its own infrastructure. Customer prompts are never sent anywhere for training — there is no third-party training run to send them to. Verbatim prompt text is never a training input under any configuration: verbatim content is short-retention by design, and a trained model would be a retention window that never forgets, so we do not build one.
Our ranking models train on synthetic journeys generated from our published coaching corpus and, contract-gated, on de-identified aggregate feature statistics (outcome-class counts, band histories — never text, never re-identifiable). A customer can exclude even that with the Training Exclusion option in their order form, and the product loses no functionality. The full account is on the Model Training page.
A customer who cannot accept the default aggregate use today can disable it by contract — and coaching generation, the only feature that sends any prompt-adjacent context off our systems, can be turned off independently. Policy evaluation, event logging, and the retention controls do not use any model provider.
4. Changes to this list
We will notify customer administrators by email at least thirty days before a new sub-processor begins processing Customer Data, and will update the effective date on this page. A customer who objects on reasonable data-protection grounds within that window may raise it with us before the change takes effect.
An emergency replacement — where a provider fails and continuing the service requires a substitute sooner — will be notified as soon as it is made rather than in advance, with the reason.
5. Questions
Security questionnaires and sub-processor objections: privacy@coapro.org. Related reading: our Privacy Policy and Trust pages.