Legal
Subprocessors and Measurement Providers
Last updated: September 23, 2026
These are the 30 providers used by LaunchSite OS, LLC, what each one does, and which categories of data it can see. Providers processing data on our behalf and independent controllers are identified separately. This page is generated from the application's provider register.
How to read this
- "Handles client data" means the provider can access client health-related information - check-ins, labs, photos, programming, or the AI prompts built from them. Providers without that marker see only account, billing, messaging, or diagnostic data.
- References below identify provider terms and documentation. Processing, retention, security monitoring, and model-training settings depend on the applicable service and account configuration. A reference alone does not establish that a particular agreement has been executed.
- Providers marked as connection-dependent are not in the path at all unless a coach or client chooses to connect them. Disconnecting stops the flow.
- Visitor-consented measurement is separate from connected coaching services. Its tag does not load unless the visitor allows it, it does not run in coach or client workspaces, and the Google Ads measurement service receives no coaching records. Independent controllers have their own data-handling terms and are identified below. See privacy choices and rights.
- LaunchSite does not offer a BAA or support use requiring one. Ordinary data-processing terms do not authorize HIPAA-regulated use of this service. See the Privacy Policy.
Always active
These providers are part of running the platform for every account.
Supabase · handles client data
Primary database, authentication, and file storage (lab files, progress photos).
- Data it can see: Account and profile information; Client wellness and health-related records; Lab files and extracted markers; Historical chart tables and saved charts; Progress photos and movement video; Connected device and wearable metrics; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Campaign and engagement records; AI prompts, outputs, and workspace memory; Usage, device, and diagnostic data; Public AI demo requests
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://supabase.com/legal/dpa
Stores the bulk of client data. Encrypted in transit and at rest; access scoped by row-level security.
Microsoft Azure (Container Apps, Blob Storage, Key Vault, Application Insights, Log Analytics) · handles client data
Application hosting, large-file and managed-app secret storage, performance monitoring, and error logging.
- Data it can see: Account and profile information; Client wellness and health-related records; Lab files and extracted markers; Historical chart tables and saved charts; Progress photos and movement video; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; AI prompts, outputs, and workspace memory; Usage, device, and diagnostic data; Public AI demo requests; Business identity for a white-label app listing
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: Microsoft Products and Services Data Protection Addendum (DPA).
Application Insights receives timing and diagnostic traces only - never prompt, reply, or document text. The Log Analytics workspace additionally holds 30 days of request failure records, which include the requesting IP address and user-agent, but no request or response bodies. Key Vault holds provider credentials for managed coach apps; the application database stores only opaque vault references.
Sentry
Application error monitoring.
- Data it can see: Usage, device, and diagnostic data
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://sentry.io/legal/dpa/
Configured to exclude request bodies, cookies, and personal data from error events.
Microsoft Azure AI Services (including Azure OpenAI and Foundry Models) · handles client data
AI-assisted drafting, embeddings, image generation, audio transcription, OCR and document-layout extraction for uploaded lab reports, retrieval-only context generation and relevance reranking for coach documents, private Zyx goal reviews and optional progress-photo observations, answering a client’s own questions through the assistant their coach enables, turning a coach’s recorded demonstration into a Launch Bot’s written instructions and tool list, and the public meal-plan demo on the marketing site.
- Data it can see: Client wellness and health-related records; Lab files and extracted markers; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; AI prompts, outputs, and workspace memory; Progress photos and movement video; Public AI demo requests; Pages and optional screen images Co-Work uses; Recorded demonstrations of a coach’s own workflow
- Processing region: Global processing (Azure resources are located in the United States).
- When it is in the path: Always active
- Data-protection terms: Microsoft Products and Services Data Protection Addendum (DPA).
The admin lab OCR workbench also sends transient OCR text for marker transcription and marker-derived queries for platform reference retrieval. It displays assembled analysis inputs without generating or saving a review. When the lab OCR lane is enabled, the full uploaded lab PDF is sent to Azure Document Intelligence and Azure returns page text, confidence and layout coordinates; those results are used to create reviewable marker facts, and provider response bodies are not written to application logs. LaunchSite requests deletion of the provider-side analyze result after retrieval; Microsoft documents automatic deletion after 24 hours when early deletion is not confirmed. Microsoft states that prompts and outputs for models sold directly by Azure are not made available to the model provider. Context generation sends a coach document to the same Azure-operated service and stores its output separately from the clean source passage; generated context is used only to retrieve, and is never shown or cited as evidence. Reranking sends the search query and a bounded candidate set to an Azure-hosted model and stores no provider response as source evidence.
Anthropic · handles client data
AI-assisted drafting and analysis, including private Zyx goal reviews and optional progress-photo observations when this provider is selected.
- Data it can see: Client wellness and health-related records; Lab files and extracted markers; Messages and conversation content; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; AI prompts, outputs, and workspace memory; Progress photos and movement video
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://www.anthropic.com/legal/commercial-terms
Requests use the configured Anthropic endpoint, including Azure-hosted Foundry when configured; the SDK can use the commercial Anthropic API when no custom endpoint is set. Provider retention and model-training handling depend on the applicable service configuration and terms. LaunchSite does not use client health information to train models.
Resend
Transactional, campaign and review-request email delivery, coach-domain verification and sending-key provisioning, fixed administrator test messages, and delivery, engagement, bounce and complaint webhooks.
- Data it can see: Account and profile information; Messages and conversation content; Campaign and engagement records; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://resend.com/legal/dpa
Managed coach apps use separate verified domains and domain-scoped sending keys within the LaunchSite Resend account. The one-time key value is transferred directly to Azure Key Vault. A platform administrator may send a fixed provisioning test to a chosen recipient; Resend receives that address and message.
Amazon Web Services (Simple Email Service)
Alternate transactional, campaign and review-request email delivery path.
- Data it can see: Account and profile information; Messages and conversation content; Campaign and engagement records
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://aws.amazon.com/service-terms/
Apple and Google (sign-in)
Verifying who you are when you sign in with "Continue with Apple" or "Continue with Google" instead of a password.
- Data it can see: Account and profile information
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://developer.apple.com/support/terms/apple-developer-program-license-agreement/
Offered on the web login page and in the mobile app, and only in the path for a user who chooses one of those buttons - a password sign-in involves neither. The provider tells us the email address and a stable identifier for the account, and learns that you signed in to LaunchSite OS; it receives no health, message, or coaching data. Apple users may substitute a private relay address, which works exactly like any other address here. Signing in this way does not create an account: it can only open one a coach or the web signup already made, matched on the email address.
Stripe
Subscription billing, including the separate Pro CRM add-on and CRM website-domain subscriptions, payment processing (including managed mobile app setup and maintenance), marketplace payouts to coaches (Stripe Connect), and payment for consultations booked on a coach’s public booking page.
- Data it can see: Account and profile information; Subscription and payment information; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://stripe.com/legal/dpa
Processes billing data (name, email, card) only - no client health data. Coaches who sell through the marketplace complete Stripe Connect onboarding directly with Stripe, which collects the identity and bank details required by financial regulation. When a coach charges for a call on their public booking page, the charge is taken DIRECTLY on that coach’s own connected account with no platform fee - the coach is the merchant of record and the funds never enter a LaunchSite balance. Card details are entered on Stripe’s own hosted checkout and are never seen or stored by LaunchSite; we keep only the amount, the currency, whether it was paid, and Stripe’s session identifiers. For managed coach apps, a permanent purchase-specific payment link opens Stripe Checkout. Expired checkout sessions can be renewed using the same approved purchase, saved prices, and Stripe Customer; the shared payment link has no scheduled expiry. CRM website-domain purchases use a separate recurring Stripe subscription; LaunchSite keeps the selected domain and provisioning state, while Stripe receives billing details.
n8n
Internal workflow automation for our own outbound marketing operations.
- Data it can see: Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: Available on request.
Used by LaunchSite OS for our own prospect outreach. It is not part of a coach’s workspace and sees no client data.
GitHub (Microsoft) · handles client data
Source control, automated provisioning of coach site repositories, CI runners that build, test, and deploy the application, and private storage of retrieval evaluation reports.
- Data it can see: Account and profile information; Client wellness and health-related records; Lab files and extracted markers; Progress photos and movement video; Connected device and wearable metrics; Messages and conversation content; Voice input, call recordings, transcripts, and synthetic voice; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Campaign and engagement records; AI prompts, outputs, and workspace memory; Usage, device, and diagnostic data; Public AI demo requests; Business identity for a white-label app listing
- Processing region: United States
- When it is in the path: Always active
- Data-protection terms: https://github.com/customer-terms/github-data-protection-agreement
Engineering infrastructure. The nightly production database backup is produced on a GitHub-hosted runner, so the database contents transit that runner before being written to Azure Blob and shredded; file contents in Supabase Storage (lab documents, progress photos) are not part of that dump, only the rows describing them. GitHub does not appear on Microsoft's published HIPAA BAA in-scope service list, and GitHub's Data Protection Agreement s12.B asks that protected health information not be provided without GitHub's prior written consent. Retrieval evaluation runs on the same private runner/artifact boundary. Its report contains aggregate rank metrics, committed golden questions, bounded expected-answer excerpts for misses, source names, and corpus counts; it does not copy retrieved candidate passages or user-authored search queries. Managed-app provisioning also runs on a GitHub-hosted runner: validated coach artwork and public app configuration are committed to a generated source pull request, while the Apple private key is retrieved from Key Vault into a temporary runner file and deleted at the end of the job.
Active only when connected
These providers process data only for accounts that have connected them.
TypeSafe AI (Jev) · handles client data
CRM classification of lead activity, permitted form answers, conversation text, and draft messages into structured recommendations, when a coach requests it and, only for coaches who turn on Ghost Opportunities background analysis (off by default), when new evidence arrives for an open opportunity.
- Data it can see: Prospect, lead, and CRM contact information; Messages and conversation content; Connected mailbox correspondence; AI prompts, outputs, and workspace memory; LaunchSite OS business contacts and activity
- Processing region: Processing locations governed by TypeSafe account terms; no regional restriction configured.
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://typesafe.ai/legal/data-processing
Receives bounded text when a coach requests Jev analysis directly or through Nova, including for a batch of up to 25 opportunities the coach selects from a list. The workspace owner may also turn on Ghost Opportunities background analysis, which is off by default. Once it is on, the same bounded lead snapshot is sent without a click after a new inbound WhatsApp or Instagram message on a linked lead, a new email from a verified sender, or new form, quiz or intake answers arrive for an open opportunity. Synchronized mailbox email currently has no sender verification, so it does not start a background analysis, and website chat alone never starts one. Background analysis never runs for contacts held for review, excluded from Ghost Opportunities, opted out or awaiting email consent. It covers at most 200 opportunities a day, is paid from the coach’s own AI credits within a monthly Ghost cap (3 USD by default), and pauses once the coach’s usage reaches 80% of the monthly credit limit. A reading never moves an opportunity by itself: moves made from Ghost Opportunities or proposed by Nova need the coach’s confirmation, and an unreviewed background reading does not satisfy a workflow condition. A label the coach accepts can satisfy a workflow condition the coach set up, and that workflow may then move the opportunity. Direct contact identifiers are minimized, internal record identifiers use request-local aliases, and form answers excluded from AI use are withheld. Free-text correspondence may still contain sensitive information. Structured labels, source references and coach corrections are retained in the CRM; usage telemetry contains counts and timing, not message bodies. TypeSafe publishes a no-training commitment and offers enterprise zero data retention, but account-specific agreement execution, sensitive-data terms and zero retention have not been verified. Published DPA sensitive-data schedule states N/A; operators must confirm applicable terms with counsel before using sensitive correspondence. Outcome prediction training stays within LaunchSite and does not send records to TypeSafe.
Firecrawl (SideGuide Technologies, Inc.)
Read public research articles selected by Scientist for coaching research.
- Data it can see: Public research for coaching briefs
- Processing region: United States (per published privacy policy)
- When it is in the path: Only if a coach connects it
- Data-protection terms: Published privacy terms: https://www.firecrawl.dev/privacy-policy. A DPA and account-specific execution have not been verified; request and review them with the vendor.
Receives public research article URLs selected by Scientist and fetches their public content. Lead Scout does not use this provider. The integration sends no coach account identifiers, private workspace records, cookies or target-site credentials. Scrape caching is disabled, which does not establish zero retention for provider logs. Provider retention and deletion require separate review.
Fullscript · handles client data
Optional coach-selected supplement storefront and authorized practice connection. Fullscript hosts account onboarding, prescribing, payment, purchases and fulfillment. With account linking enabled, LaunchSite retrieves patient names and email addresses for explicit matching and reads released supplement recommendations for the owning coach and matched client. Requests send Fullscript credentials and its patient identifier; LaunchSite does not create patients, plans, orders or labs.
- Data it can see: Account and profile information; Client wellness and health-related records; Subscription and payment information; Usage, device, and diagnostic data; Optional Fullscript account and supplement connection
- Processing region: External service; processing locations are described in Fullscript’s privacy statement.
- When it is in the path: Only if a coach connects it
- Role: Independent controller for the measurement information it receives; not a processor of coaching records.
- Data-protection terms: https://fullscript.com/legal/privacy
Independent-controller classification describes Fullscript’s own practitioner, patient and commerce service; account-specific API roles and contractual obligations still require review before real-data production use. US sandbox access was created September 23, 2026. No executed DPA, BAA or production approval has been verified. Tokens are encrypted server-side; plan payloads are projected to supplement fields without lab data, invitation links or checkout links. Fullscript data is not sent to an AI provider by this integration.
Cloudflare
DNS, domain registration, and custom-domain provisioning for coach sites.
- Data it can see: Account and profile information
- Processing region: Global edge network
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://www.cloudflare.com/cloudflare-customer-dpa/
Receives the registrant details a coach supplies when they register or connect a domain. ICANN requires those details for registration; it sees no client health data.
OpenAI · handles client data
Hosted AI Atelier website and funnel planning, drafting, visual review, brand extraction, creative project file editing and optional original image generation guided by selected reference images; Realtime and GPT-Live voice sessions for the co-work surface, including the Responses model a Live session delegates tool use to; and writing a coach’s recorded Loom check-in review into its structured written review through the direct OpenAI API.
- Data it can see: Voice input, call recordings, transcripts, and synthetic voice; Client wellness and health-related records; AI prompts, outputs, and workspace memory; Progress photos and movement video
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://openai.com/policies/data-processing-addendum
API terms: inputs and outputs are not used to train models. The Draft from Loom lane sends the captured Loom transcript and the client context for that check-in to OpenAI; the transcript text is deleted from our storage once the review is approved, and OpenAI does not retain API inputs for training.
Unipile · handles client data
Connected WhatsApp and Instagram conversations and coach-configured conversation workflows in paid Pro CRM, and Google/Outlook mailbox authorization, inbox reading, manual replies, read-state updates and email synchronization chosen by a coach.
- Data it can see: Messages and conversation content; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Connected mailbox correspondence
- Processing region: European Union
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://www.unipile.com/dpa/
Only active for coaches who connect an external inbox or mailbox. Receives account authorization and conversation content. The Conversations Email tab transiently reads mailbox message lists and plain-text threads, and sends coach-authored replies through the connected Google or Outlook account. Read status changes require a coach action. Remote HTML, images and attachments are not loaded by the inbox. Background synchronization retains only correspondence matched to a unique existing CRM lead, email headers needed for matching and authentication, and processing outcomes. Unmatched bodies and attachments are not retained by the importer. Campaign and other CRM email continues through the configured delivery provider, optionally using a verified connected mailbox as Reply-To.
Meta Platforms (WhatsApp Business Platform)
WhatsApp message delivery and inbound webhooks.
- Data it can see: Messages and conversation content; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity
- Processing region: United States / global
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://www.whatsapp.com/legal/business-data-processing-terms
Meta Platforms (Facebook and Instagram business accounts)
Connect authorized business assets, retrieve public Facebook recommendations, ad spend and selected lead-form submissions, publish coach-approved review replies and scheduled Facebook/Instagram content, and return observed engagement.
- Data it can see: Account and profile information; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Campaign and engagement records
- Processing region: United States / global
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://www.facebook.com/legal/terms/dataprocessing
Separate from connected inbox messaging. OAuth credentials are encrypted in our database; the browser receives account names, identifiers and connection status. Each discovered account starts disabled until the coach selects it. Disconnecting clears stored credentials. The applicable Meta contractual terms require operator verification before production activation; this entry does not represent an executed agreement.
Apple, Google, and Mozilla push services
Delivery of web and mobile push notifications to your own device.
- Data it can see: Usage, device, and diagnostic data
- Processing region: Global
- When it is in the path: Only if a client connects it
- Data-protection terms: Available on request.
A push service receives an opaque device token and the notification payload. Notification copy is written to avoid carrying health details.
Expo · handles client data
Managed mobile project creation, cloud builds, over-the-air updates, App Store connection and submission, and push notification delivery.
- Data it can see: Usage, device, and diagnostic data; Business identity for a white-label app listing
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://expo.dev/terms
For a managed coach app, Expo receives its public app configuration, bundle/package identifiers, generated artwork and the Apple organization credential used for non-interactive build or submission work. Provider secrets are materialized only on the runner and are not committed to source.
Google · handles client data
Two-way Calendar sync for a coach, read-only Calendar display for a client who connects their own account, Drive file browsing for the coach library, separately authorized discovery of Google Business Profile locations and Google Ads accounts, retrieval of business reviews, daily advertising performance and selected lead-form submissions, and publication of review replies the coach explicitly submits.
- Data it can see: Account and profile information; Client wellness and health-related records; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity; Campaign and engagement records
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://cloud.google.com/terms/data-processing-addendum
Only for users who connect it. A client may connect their own Google Calendar to see their own events in the app; those events are read on demand for display and are not stored. Calendar is a sensitive scope; the Drive scope is restricted and coach-only. Google API Calendar and Drive data is used only to provide those connected features, never for advertising or model training. Marketing connections use separate consent and encrypted credentials; they do not repurpose Calendar or Drive data. A coach selects which discovered business locations and advertising accounts the workspace may use.
Zoom
Creating meetings for booked sessions, and receiving meeting webhooks.
- Data it can see: Account and profile information; Prospect, lead, and CRM contact information; LaunchSite OS business contacts and activity
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-protection terms: https://explore.zoom.us/en/gdpr/
Whoop · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-protection terms: https://developer.whoop.com/
Oura · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-protection terms: https://cloud.ouraring.com/docs/
Fitbit (Google) · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-protection terms: https://dev.fitbit.com/legal/platform-terms-of-service/
Ultrahuman · handles client data
Wearable metric sync, at the client’s direction.
- Data it can see: Connected device and wearable metrics
- Processing region: United States
- When it is in the path: Only if a client connects it
- Data-protection terms: Available on request.
Apple (HealthKit) · handles client data
Reading the Apple Health categories a client approves, in the iOS app.
- Data it can see: Connected device and wearable metrics
- Processing region: On device; aggregates sent to our United States infrastructure
- When it is in the path: Only if a client connects it
- Data-protection terms: Available on request.
Apple is the source, not a recipient: HealthKit data flows from the device to us after the client approves Apple’s permission prompt. Apple’s platform rules prohibit using it for advertising or selling it, and we do neither.
Loom
Embedding and drafting around coach-recorded walkthrough videos.
- Data it can see: Account and profile information
- Processing region: United States
- When it is in the path: Only if a coach connects it
- Data-protection terms: Available on request.
Optional public-site measurement
This provider receives measurement information only after a visitor allows it on selected public marketing and signup pages. It is an independent controller, not a subprocessor of coaching records. Visitors can withdraw measurement consent through Cookie preferences in the public marketing footer or Privacy Policy.
Google Ads (optional public-site measurement)
Measure visits to selected LaunchSite marketing pages and whether an advertisement led to a new coach signup or a first paid platform subscription.
- Data it can see: Optional public-site advertising measurement
- Processing region: Global, including the United States
- When it is in the path: Only after a visitor allows public-site measurement
- Role: Independent controller for the measurement information it receives; not a processor of coaching records.
- Data-protection terms: https://business.safety.google/adscontrollerterms/
The tag loads only after a visitor allows measurement on selected public marketing and signup pages at launchsite-os.com. It does not run in coach or client workspaces, coach-owned sites, or development environments. Ad personalization and enhanced conversions are disabled. We do not send names, email addresses, form contents, client records, or health information. Google receives the measurement data described in the Privacy Policy as an independent controller under its applicable terms, rather than as a processor of coaching records. The linked terms describe the service; they do not certify that an agreement has been executed.
Changes to this list
We update this register when a provider is added, removed, or changes what it processes. Coaches who want advance notice of additions can request it at privacy@launchsite-os.com; where a Data Processing Addendum with us is in place, the notice and objection process in that addendum applies.
Contact
Questions about a provider on this list: privacy@launchsite-os.com · LaunchSite OS, LLC.
This register describes our vendor relationships and is not legal advice. Confirm each provider's executed data-processing terms with counsel before relying on this page as a contractual statement.
