Subprocessors

Last updated 16 June 2026

ProgramLoop uses a small set of subprocessors to operate the service. The exact set is environment-dependent: the active AI provider depends on the organization configuration and deployment environment, and email/hosting providers are used only where configured. We do not claim certifications on behalf of these providers — please consult each provider for their own compliance documentation.

Database, authentication and storage

Supabase — managed Postgres database, authentication and file storage. Processes account data, organization and programme data, and uploaded documents, with tenant isolation enforced by row-level security.

AI generation

OpenAI or a compatible AI provider — generates AI-assisted reports, recommendations and insights from minimized, sanitized prompts. The active provider and model depend on the organization configuration and deployment environment and may be an OpenAI-compatible provider. When an organization’s AI policy is “No AI”, no data is sent to any AI provider.

Transactional email (if used)

Resend — sends transactional emails such as authentication and notification messages, where this provider is configured for the deployment. Processes recipient email addresses and message content.

Hosting (if used)

Vercel — application hosting and content delivery, where used for the deployment. Processes request metadata necessary to serve the application.

Changes and notes

This list may change as the service evolves; material changes to subprocessors will be reflected here. If your organization requires a specific provider configuration (for example, a particular AI provider or data region), contact contact@programloop.co.