Subprocessors
Subprocessors
The third parties that process data on Coasty Systems’ behalf in the ordinary course of running CoArena — ordered by how much each one holds, each with the honest answer to the only question this page exists for: what of your data actually reaches it. Changes are posted here before they take effect; the date below is the notice.
Last updated August 11, 2026
Supabase
Managed PostgreSQL and private object storage
Every structured record we keep — accounts, tasks, votes, consent records — plus screenshots, masked frames and agent-produced files. The storage bucket is created private; every read is brokered by the application.
Render
Application hosting
Data in the course of serving requests. Holds no store of its own beyond platform logs.
Cloudflare
DNS, CDN and TLS termination
Public traffic in transit. Terminates TLS and proxies to the application.
Daytona
Ephemeral agent sandboxes
The execution environment of a run — a fresh, isolated Linux desktop per run, destroyed when the run ends. Not our stored records.
Anthropic
Model inference
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models. Masking applies to what we store and publish, not to what a model must see to act.
OpenAI
Model inference
The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models.
Google
Model inference and sign-in
Prompts and screenshots for runs assigned to its models. As the sign-in provider it is the source of account identity — name, email, avatar — rather than a recipient of anything we generate.
Resend
Transactional email
Recipient addresses and the content of the emails we send.
No subcontracted labour touches this system — no agency, BPO or contract workforce; the list above is infrastructure, in full. How these providers fit the architecture, and the controls around what they hold, is at /security; what is collected and why is at /privacy. Questions: founders@coasty.ai.