HigherCoach by HigherOps / Legal
HigherCoach subprocessors
Last updated 2026-09-18
DRAFT for review. Not in force. A lawyer reviews this before the first paying workspace.
The companies that process personal data for HigherCoach, what for and what data. The privacy policy refers to this list.
| Company | Purpose | Data | Location |
|---|---|---|---|
| HigherOps | Operates HigherCoach | Everything in the service, for support and operations only | [REVIEW: HigherOps location] |
| Supabase | Database and sign-in | Everything a workspace stores; account name and email | United States (AWS us-east-1) |
| Railway | Runs the application and background jobs | Everything in transit while it is processed. Nothing is stored there except application logs, which can include call titles, company names, email addresses and error messages [REVIEW: Railway log retention period] | United States (us-west2) |
| Resend | Sends email (invitations, weekly digests, alerts) | Recipient email address, name, and the email's content, which can include call titles and counts | [REVIEW: Resend processing region] |
| Sentry | Error reporting, from our servers and from your browser | Error reports, scrubbed first: values under names such as api key, token, secret or password removed, known key and token formats redacted, email addresses cut to their domain, text over 1000 characters replaced by its length, no cookies or local program variables | [REVIEW: Sentry region chosen for the account, and IP address storage turned off in its settings] |
| The language model provider your workspace chooses | Classifies and analyses calls | Transcript text and prompts for each call analysed | Set by the provider |
About the last row: the workspace chooses and connects one of Anthropic, OpenAI or OpenRouter under the customer's own account, or OpenAI through a ChatGPT subscription login under the customer's own account (how that works). HigherCoach uses the customer's key and the customer's agreement with that provider applies.
Also chosen and connected by the customer, under the customer's own accounts, and not engaged by HigherOps: the transcript sources (Fellow, Fireflies), HubSpot, and the sign-in provider (Google or Microsoft).
[REVIEW: how customers are told about a change to this list, and any objection period]