Subprocessors
Last updated: August 2026
The Student Blueprint engages a limited number of third-party service providers ("subprocessors") to operate the platform. We have a written data protection agreement with each subprocessor that restricts their use of data to the purposes described below, requires confidentiality, and obligates them to maintain reasonable security practices.
We notify customers under active Data Privacy Agreements of material subprocessor changes prior to onboarding, in accordance with Student Data Privacy Consortium National Data Privacy Agreement (SDPC NDPA) requirements.
Current Subprocessors
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Primary database, authentication, object storage | All application data including student assessments and account records | United States |
| Vercel | Application hosting, CDN, edge functions | Request metadata, IP addresses, application traffic | United States (global edge) |
| Anthropic (Claude) | AI-generated assessment analysis (fallback model) | Assessment data submitted by the student during analysis; not used to train Anthropic models per Anthropic's commercial terms. PII redaction available per tenant policy. | United States |
| Google Gemini API | AI-generated assessment analysis (primary model) | Assessment data submitted by the student during analysis. PII redaction available per tenant policy. Planned migration to Vertex AI for stronger no-training guarantees. | United States |
| Stripe | Payment processing | Billing name, billing address, payment card details. Card numbers and CVV never touch our servers (PCI DSS Level 1). | United States |
| Resend | Transactional email delivery (assessment results, OTP codes, parent notifications) | Recipient email address, email content, delivery metadata | United States |
| Upstash Redis | API rate limiting and queue (QStash) | IP addresses, request counters, job metadata. No assessment data. | United States |
AI Model Use of Student Data
Student assessment data sent to Anthropic and Google for AI analysis is not used to train their underlying models, per the commercial API terms of each provider. District tenants may additionally enable per-tenant settings to (a) disable AI processing entirely, or (b) require PII redaction before any data leaves The Student Blueprint infrastructure.
Data Residency
All primary data storage is located in the United States. Edge caching and CDN delivery may transit Vercel's global edge network for static assets only; authenticated application data is served from U.S. regions.
Notification of Changes
Customers under a Data Privacy Agreement receive advance notice of any new subprocessor. To subscribe to subprocessor change notifications, contact privacy@thestudentblueprint.com.
See also: Privacy Policy · K-12 Privacy Notice · Trust & Security · Terms of Service