Subprocessors
Last updated 16 June 2026
ProgramLoop uses a small set of subprocessors to operate the service. The exact set is environment-dependent: the active AI provider depends on the organization configuration and deployment environment, and email/hosting providers are used only where configured. We do not claim certifications on behalf of these providers — please consult each provider for their own compliance documentation.
Database, authentication and storage
Supabase — managed Postgres database, authentication and file storage. Processes account data, organization and programme data, and uploaded documents, with tenant isolation enforced by row-level security.
AI generation
OpenAI or a compatible AI provider — generates AI-assisted reports, recommendations and insights from minimized, sanitized prompts. The active provider and model depend on the organization configuration and deployment environment and may be an OpenAI-compatible provider. When an organization’s AI policy is “No AI”, no data is sent to any AI provider.
Transactional email (if used)
Resend — sends transactional emails such as authentication and notification messages, where this provider is configured for the deployment. Processes recipient email addresses and message content.
Hosting (if used)
Vercel — application hosting and content delivery, where used for the deployment. Processes request metadata necessary to serve the application.
Changes and notes
This list may change as the service evolves; material changes to subprocessors will be reflected here. If your organization requires a specific provider configuration (for example, a particular AI provider or data region), contact contact@programloop.co.