Obra Subprocessors¶
Last Updated: August 14, 2026
This page is the current list of subprocessors referenced by section 7.1 of the Obra Privacy Policy. It lists the third parties that process data on Obra's behalf in order to operate the Obra SaaS service, and it distinguishes them from third parties you engage yourself.
It lists what is actually in use. If a service is not on this page, Obra does not use it.
1. Subprocessors Obra engages¶
| Subprocessor | Entity | What it does for Obra | Data involved | Location |
|---|---|---|---|---|
| Google Cloud Platform / Firebase | Google LLC (United States) | Cloud Firestore (account, session, and orchestration state), Firebase Authentication (sign-in and identity), Cloud Functions (the orchestration control plane), Cloud Logging (operational and diagnostic logs) | Account identifiers, session inputs and outputs, orchestration state, terms-acceptance records, operational logs | United States primary; Google may process and replicate across regions |
| Cloudflare | Cloudflare, Inc. (United States) | Hosting for obra.dev, including this page and the published Terms and Privacy Policy; and storage of website access-request (waitlist) records in Cloudflare Workers KV |
Ordinary web request data for visitors to the site. Access-request records: the email address submitted, browser user-agent, referring page, a Cloudflare-derived two-letter country code, and the submission timestamp — stored in Workers KV with a 24-month expiration set on each record, and also appearing in Cloudflare's request logs for the site. No account data, session data, or orchestration data is stored here | Global edge network |
Google Cloud Platform and Firebase are the only place Obra stores your account
and session data. Firebase project: obra-205b0.
2. Identity providers you sign in through¶
Firebase Authentication federates sign-in to the provider you choose. Obra never receives your password for these accounts.
- Google (Google LLC)
- GitHub (GitHub, Inc., a Microsoft company)
These providers authenticate you. Obra does not send them your session content.
3. Third-party LLM providers — you engage these, not Obra¶
The AI model providers Obra sends your prompts and task context to are configured by you and billed to your own accounts. They are not Obra's subprocessors, because Obra is not the party that engages them: your credentials or subscription, and your agreement with that provider, govern the relationship. Their handling of your data is covered by their terms and privacy policies, not by Obra's. Section 7.1a of the Privacy Policy states this role in privacy terms: they are recipients you direct data to, not processors acting on Obra's instructions.
Remote providers Obra can send data to, when you configure one:
- Anthropic
- OpenAI
Section 5 of the Privacy Policy describes what is transmitted to whichever providers you configure. Section 6 of the Beta Software Agreement records that provider behaviour and provider retention are outside Obra's control.
3a. Local models (Ollama) — no recipient at all¶
Ollama is listed separately because it is not a third party in this chain. When you configure Obra to use a locally-run model through Ollama, inference happens on hardware you control and nothing is transmitted to any third party for it: there is no processor, no subprocessor, no recipient, and no transfer to disclose. Ollama appears here as a supported configuration option, not as a party that receives your data.
Obra's SaaS control plane still has to be reachable for prompt and policy serving even when the model is local, so the Google Cloud Platform / Firebase row in section 1 continues to apply to the control-plane data described there.
4. What Obra does not use¶
Stated because absence is a fact worth publishing, not an oversight:
- No separate error-tracking or crash-reporting service. Error and diagnostic logs stay inside Google Cloud Logging alongside the rest of the control plane.
- No product-analytics, session-replay, or behavioural-tracking service.
- No advertising, marketing-automation, or data-broker subprocessor. Obra does not sell or share personal information for advertising.
- No content-scanning or moderation subprocessor. Obra does not scan, filter, or redact session content, which is also why the Privacy Policy tells you not to submit data whose exposure you cannot accept.
5. Retention¶
Retention of the data held by the subprocessors in section 1 is governed by section 6.3 of the Privacy Policy. Control-plane retention classes and their expiration targets are implemented as executable desired state rather than as prose; provider deletion is asynchronous, so the stated windows are the retention targets Obra sets, not a guarantee of the exact moment a record is physically removed.
Access-request (waitlist) records are kept for 24 months from the most recent submission. That window is carried as an expiration set on each record in Cloudflare Workers KV at the moment it is written, rather than applied by a later cleanup job. Re-submitting the form renews the window on the same record. Deletion on request is available at any time through [email protected], per section 8.3 of the Privacy Policy.
6. Changes to this list¶
This page is the current list. When a subprocessor is added, removed, or changes role, this page is updated and the Last Updated date above changes with it. Customers under a separate written business agreement receive notice before a new subprocessor is added, on the terms of that agreement.
Questions: [email protected]