Legal
Subprocessors
Last updated: August 17, 2026
These are the 27 third parties that process data on behalf of LaunchSite OS, LLC, what each one does, and which categories of data it can see. This page is generated from the register the application itself uses, so it cannot quietly fall behind the software.
How to read this
- "Handles client data" means the provider can access client health-related information - check-ins, labs, photos, programming, or the AI prompts built from them. Providers without that marker see only account, billing, messaging, or diagnostic data.
- We enter into data-processing terms with each provider. None is permitted to use the data for its own purposes, to sell it, or to train AI models on it.
- Providers marked as connection-dependent are not in the path at all unless a coach or client chooses to connect them. Disconnecting stops the flow.
- We are not a HIPAA business associate and these are not BAAs; they are standard DPAs. See the Privacy Policy.
Always active
These providers are part of running the platform for every account.
Supabase · handles client data
Primary database, authentication, and file storage (lab files, progress photos).
- Data it can see: Account and profile information; Client wellness and health-related records; Lab files and extracted markers; Progress photos and movement video; Connected device and wearable metrics; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; Campaign and engagement records; AI prompts, outputs, and workspace memory; Usage, device, and diagnostic data
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: https://supabase.com/legal/dpa
Stores the bulk of client data. Encrypted in transit and at rest; access scoped by row-level security.
Microsoft Azure (Container Apps, Blob Storage, Application Insights, Log Analytics) · handles client data
Application hosting, large-file storage, performance monitoring, and error logging.
- Data it can see: Account and profile information; Client wellness and health-related records; Lab files and extracted markers; Progress photos and movement video; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; AI prompts, outputs, and workspace memory; Usage, device, and diagnostic data
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: Microsoft Products and Services Data Protection Addendum (DPA).
Application Insights receives timing and diagnostic traces only — never prompt, reply, or document text. The Log Analytics workspace additionally holds 30 days of request failure records, which include the requesting IP address and user-agent, but no request or response bodies.
Sentry
Application error monitoring.
- Data it can see: Usage, device, and diagnostic data
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: https://sentry.io/legal/dpa/
Configured to exclude request bodies, cookies, and personal data from error events.
Microsoft Azure OpenAI Service · handles client data
AI-assisted drafting, embeddings, image generation, audio transcription, and retrieval-only context generation for coach documents.
- Data it can see: Client wellness and health-related records; Lab files and extracted markers; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; AI prompts, outputs, and workspace memory
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: Microsoft Products and Services Data Protection Addendum (DPA).
Contractually prohibited from using customer data to train or improve its models. Context generation sends a coach document to the same Azure-operated endpoint and stores its output separately from the clean source passage; generated context is used only to retrieve, and is never shown or cited as evidence.
Anthropic · handles client data
AI-assisted drafting and analysis.
- Data it can see: Client wellness and health-related records; Lab files and extracted markers; Messages and conversation content; Prospect, lead, and CRM contact information; AI prompts, outputs, and workspace memory
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: https://www.anthropic.com/legal/commercial-terms
Commercial API terms: inputs and outputs are not used to train models. Reached only through the Azure-hosted Foundry endpoint.
Resend
Transactional and campaign email delivery, and delivery/bounce/complaint webhooks.
- Data it can see: Account and profile information; Messages and conversation content; Campaign and engagement records; Prospect, lead, and CRM contact information
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: https://resend.com/legal/dpa
Amazon Web Services (Simple Email Service)
Alternate transactional email delivery path.
- Data it can see: Account and profile information; Messages and conversation content; Campaign and engagement records
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: https://aws.amazon.com/service-terms/
Stripe
Subscription billing, payment processing, marketplace payouts to coaches (Stripe Connect), and payment for consultations booked on a coach’s public booking page.
- Data it can see: Account and profile information; Subscription and payment information; Prospect, lead, and CRM contact information
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: https://stripe.com/legal/dpa
Processes billing data (name, email, card) only - no client health data. Coaches who sell through the marketplace complete Stripe Connect onboarding directly with Stripe, which collects the identity and bank details required by financial regulation. When a coach charges for a call on their public booking page, the charge is taken DIRECTLY on that coach’s own connected account with no platform fee - the coach is the merchant of record and the funds never enter a LaunchSite balance. Card details are entered on Stripe’s own hosted checkout and are never seen or stored by LaunchSite; we keep only the amount, the currency, whether it was paid, and Stripe’s session identifiers.
n8n
Internal workflow automation for our own outbound marketing operations.
- Data it can see: Prospect, lead, and CRM contact information
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: Available on request.
Used by LaunchSite OS for our own prospect outreach. It is not part of a coach’s workspace and sees no client data.
Namespace Labs
CI runners that build and test the application.
- Data it can see: Account and profile information
- Processing region: United States (Namespace Labs Inc., California law; processing region not specified in the terms)
- When it is in the path: Always active
- Data-processing terms: https://namespace.so/terms
Executes CI jobs and therefore holds every secret exposed to those jobs. Unlike Ubicloud (ToS 4.10) and Blacksmith (ToS 1.14/3), the Namespace terms read 2026-08-18 contain no clause prohibiting protected health information or GDPR Article 9 data — but no BAA is offered either, and the terms do not state where processing occurs. Runners carry a persistent cache volume (the -with-cache label suffix) holding npm, git and Docker layer data between runs, so build artefacts outlive a single job.
GitHub (Microsoft) · handles client data
Source control, automated provisioning of coach site repositories, and the CI runners that build, test, and deploy the application.
- Data it can see: Account and profile information; Client wellness and health-related records; Lab files and extracted markers; Progress photos and movement video; Connected device and wearable metrics; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; Campaign and engagement records; AI prompts, outputs, and workspace memory; Usage, device, and diagnostic data
- Processing region: United States
- When it is in the path: Always active
- Data-processing terms: https://github.com/customer-terms/github-data-protection-agreement
Engineering infrastructure. The nightly production database backup is produced on a GitHub-hosted runner, so the database contents transit that runner before being written to Azure Blob and shredded; file contents in Supabase Storage (lab documents, progress photos) are not part of that dump, only the rows describing them. GitHub does not appear on Microsoft's published HIPAA BAA in-scope service list, and GitHub's Data Protection Agreement s12.B asks that protected health information not be provided without GitHub's prior written consent.
Active only when connected
These providers process data only for accounts that have connected them.
Cloudflare
DNS, domain registration, and custom-domain provisioning for coach sites.
- Data it can see: Account and profile information
- Processing region: Global edge network
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://www.cloudflare.com/cloudflare-customer-dpa/
Receives the registrant details a coach supplies when they register or connect a domain. ICANN requires those details for registration; it sees no client health data.
OpenAI · handles client data
Realtime voice sessions for the co-work surface.
- Data it can see: Voice input, call recordings, transcripts, and synthetic voice; AI prompts, outputs, and workspace memory
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://openai.com/policies/data-processing-addendum
API terms: inputs and outputs are not used to train models.
ElevenLabs · handles client data
Text-to-speech audio for coach-facing playback.
- Data it can see: Voice input, call recordings, transcripts, and synthetic voice; AI prompts, outputs, and workspace memory
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://elevenlabs.io/dpa
Receives the text to be spoken and the configured voice id.
Twilio
SMS delivery, inbound keyword handling (STOP/START/HELP), and delivery receipts.
- Data it can see: Messages and conversation content; Campaign and engagement records; Prospect, lead, and CRM contact information
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://www.twilio.com/legal/data-protection-addendum
Carries message bodies and phone numbers. 10DLC registration and Advanced Opt-Out mean the carrier enforces the same STOP rules the platform does.
Unipile
Aggregated inbox for WhatsApp, Instagram, and Slack conversations a coach connects.
- Data it can see: Messages and conversation content; Prospect, lead, and CRM contact information
- Processing region: European Union
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://www.unipile.com/dpa/
Only active for coaches who connect an external inbox. Sees those conversations and the accounts they belong to.
Meta Platforms (WhatsApp Business Platform)
WhatsApp message delivery and inbound webhooks.
- Data it can see: Messages and conversation content; Prospect, lead, and CRM contact information
- Processing region: United States / global
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://www.whatsapp.com/legal/business-data-processing-terms
Apple, Google, and Mozilla push services
Delivery of web and mobile push notifications to your own device.
- Data it can see: Usage, device, and diagnostic data
- Processing region: Global
- When it is in the path: Only if a client connects it
- Data-processing terms: Available on request.
A push service receives an opaque device token and the notification payload. Notification copy is written to avoid carrying health details.
Expo
Push notification delivery to the mobile app.
- Data it can see: Usage, device, and diagnostic data
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-processing terms: https://expo.dev/terms
Google · handles client data
Two-way Calendar sync for a coach, read-only Calendar display for a client who connects their own account, and Drive file browsing for the coach library.
- Data it can see: Account and profile information; Client wellness and health-related records; Prospect, lead, and CRM contact information
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://cloud.google.com/terms/data-processing-addendum
Only for users who connect it. A client may connect their own Google Calendar to see their own events in the app; those events are read on demand for display and are not stored. Calendar is a sensitive scope; the Drive scope is restricted and coach-only. Google API data is used only to provide the connected feature, never for advertising or model training.
Zoom
Creating meetings for booked sessions, and receiving meeting webhooks.
- Data it can see: Account and profile information; Prospect, lead, and CRM contact information
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-processing terms: https://explore.zoom.us/en/gdpr/
Whoop · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-processing terms: https://developer.whoop.com/
Oura · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-processing terms: https://cloud.ouraring.com/docs/
Fitbit (Google) · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-processing terms: https://dev.fitbit.com/legal/platform-terms-of-service/
Ultrahuman · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-processing terms: Available on request.
Apple (HealthKit) · handles client data
Reading the Apple Health categories a client approves, in the iOS app.
- Data it can see: Connected device and wearable metrics
- Processing region: On device; aggregates sent to our United States infrastructure
- When it is in the path: Only if a client connects it
- Data-processing terms: Available on request.
Apple is the source, not a recipient: HealthKit data flows from the device to us after the client approves Apple’s permission prompt. Apple’s platform rules prohibit using it for advertising or selling it, and we do neither.
Loom
Embedding and drafting around coach-recorded walkthrough videos.
- Data it can see: Account and profile information
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-processing terms: Available on request.
Changes to this list
We update this register when a provider is added, removed, or changes what it processes. Coaches who want advance notice of additions can request it at privacy@launchsite-os.com; where a Data Processing Addendum with us is in place, the notice and objection process in that addendum applies.
Contact
Questions about a provider on this list: privacy@launchsite-os.com · LaunchSite OS, LLC.
This register describes our vendor relationships and is not legal advice. Confirm each provider's executed data-processing terms with counsel before relying on this page as a contractual statement.