Loading...
Last updated: 9 July 2026
| Provider | Service | Purpose | Data Categories | Region |
|---|---|---|---|---|
| DigitalOcean | Application and managed PostgreSQL hosting | Application hosting and primary production data hosting | Application traffic, teacher and student platform data | Sydney, Australia |
| DigitalOcean Valkey/Redis | Cache, rate limiting, and queue support | Session/cache operations, rate limits, and operational background processing | Session/cache keys, rate-limit counters, queue metadata | Provider-managed infrastructure |
| Cloudflare R2 | Object storage and content delivery | Student and teacher file/media storage, whiteboard snapshots, uploaded assets | Uploaded files, generated/exported assets, object metadata | Provider-managed infrastructure |
| Stripe | Payments | Teacher subscription billing and payment processing | Teacher billing/payment metadata | Provider-managed infrastructure |
| Zoho ZeptoMail | Transactional email | Service emails such as account verification, login codes, and notification messages | Email addresses and delivery metadata | Provider-managed infrastructure |
| OpenRouter | AI model gateway | AI-assisted platform features | AI request/response content as required for feature execution | Provider-managed infrastructure |
The following AI model providers may be reached via OpenRouter, direct provider APIs, or Cloudflare AI Gateway where configured and approved for the relevant feature. Requests are configured to use zero data retention where available and supported by provider/account settings — under those settings, providers do not store prompt or response content after processing and do not use submitted content to train external AI models. Student personal information is excluded from AI provider requests.
| Provider | Service | Purpose | Data Categories | Region / Retention |
|---|---|---|---|---|
| Anthropic | Large language model (Claude family) | AI text generation, marking assistance, vision-based marking of handwritten responses | Task content, student work content (no student personal identifiers) | Provider-managed infrastructure (zero data retention where configured/supported) |
| OpenAI | Large language model (GPT family) | AI text generation and feedback (selected features) | Task content, student work content (no student personal identifiers) | Provider-managed infrastructure (zero data retention where configured/supported) |
| Google AI | Large language model (Gemini family) | AI text generation and feedback (selected features) | Task content, student work content (no student personal identifiers) | Provider-managed infrastructure (zero data retention where configured/supported) |
| Fireworks AI | Large language model and vision model API | AI text generation, feedback, and vision-capable workflows where configured | Task content, student work content (no student personal identifiers) | Provider-managed infrastructure (zero data retention for supported open-weight models where configured) |
| Cloudflare Workers AI / AI Gateway | AI model hosting, model gateway, and AI request routing | AI text, vision, and image-generation workflows where configured | Task content, prompts, student work content where required for feature execution (no student personal identifiers) | Provider-managed infrastructure (zero data retention only for supported models/account settings where configured) |
| Pollinations | Conditional AI image/model provider | Teacher/admin-controlled image-generation or model workflows where enabled in product configuration | Prompts and generated outputs required for the enabled feature; no student personal identifiers by design | Provider-managed infrastructure (used only where enabled or present in active configuration) |
This list is reviewed periodically and updated when material provider or processing-location changes occur. Affected customers are notified before a material change takes effect where practicable, and otherwise as soon as practicable. Schools may request a DPA and supporting compliance documents via [email protected].