Services that process data for Coarena, and what each receives. Changes are posted here before they take effect; the date below is the notice.
Last updated August 12, 2026
Supabase
Managed PostgreSQL and private object storage
Every structured record we keep — accounts, tasks, votes, consent records — plus screenshots, masked frames and agent-produced files. The storage bucket is created private; every read is brokered by the application.
Render
Application hosting
Data in the course of serving requests. Holds no store of its own beyond platform logs.
Cloudflare
DNS, CDN and TLS termination
Public traffic in transit. Terminates TLS and proxies to the application.
Daytona
Ephemeral agent sandboxes
The execution environment of a run — a fresh, isolated Linux desktop per run, destroyed when the run ends. Not our stored records.
Anthropic
Model inference
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models. If you attach files to a task, whatever the agent reads from them reaches the model the same way. Masking applies to what we store and publish, not to what a model must see to act.
OpenAI
Model inference
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models.
Model inference and sign-in
Prompts and screenshots for runs assigned to its models. As the sign-in provider it is the source of account identity — name, email, avatar — rather than a recipient of anything we generate.
Fireworks AI
Model inference (open-weight models)
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to the open-weight models it serves. It is the HOST, not the maker: the models on this lane are built by Meta, Moonshot AI, Alibaba and Thinking Machines, and it is Fireworks that receives your data on their behalf.
Meta
Model inference
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models on Meta's own API. Meta-built models also run on the Fireworks lane above; that traffic reaches Fireworks, not Meta.
xAI
Model inference
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models.
OpenRouter
Model inference (router)
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to the models it routes. It is a ROUTER: it forwards each request to an upstream inference provider, which therefore receives the same data. We pin that upstream per model so the set of recipients is known rather than whatever routing chose that day.
Resend
Transactional email
Recipient addresses and the content of the emails we send.
Decodo
Managed egress proxy for agent web traffic
The URLs agents visit and the page traffic of their runs, in transit — agent browsing egresses through this gateway when it is healthy, and falls back to direct egress when it is not. It holds no store of ours.
No subcontracted labour touches this system — no agency, BPO or contract workforce; the list above is infrastructure, in full. How these providers fit the architecture, and the controls around what they hold, is at /security; what is collected and why is at /privacy. Questions: founders@coasty.ai.