Skip to content
iVenza ← Trust Center

Sub-processors

Last reviewed: August 3, 2026

A sub-processor is a third party that processes personal data on our behalf so we can deliver the service. This is the complete list. Vendors marked Optional are engaged only when a user or an organization turns on the feature that uses them; Core vendors are always in the path.

Under our school data privacy agreement we commit to maintaining this list, binding each sub-processor to written terms no less protective than our own, and giving an institution 30 days' notice before adding a sub-processor that would process student data, with a right to object.

Data residency: our database, authentication and file storage are hosted in the United States, in a US West region, so account and student data is stored in the US with no foreign storage. Several vendors below run global edge networks, so request metadata such as an IP address may transit an edge location while a request is routed. That is transit, not storage.

Core infrastructure

VendorPurposeData processedEngagement
SupabaseDatabase, authentication, file storage, sync, backups, serverless functionsAll account and application dataCore
CloudflareDNS, web application firewall, rate limiting, TLS, email routingRequest metadata, IP addressesCore
VercelHosting for the web appRequest metadata, IP addressesCore
Microsoft AzureHosting for the marketing siteRequest metadata, IP addressesCore
Better StackUptime and availability monitoringEndpoint health only, no user dataCore

Communications

VendorPurposeData processedEngagement
ResendEmail delivery and open/click engagementEmail address, name, message content, engagement eventsCore
TwilioText message delivery and inbound repliesPhone number, message content, opt-out stateOptional
LobPrinted mail, where an organization chooses to send itName, mailing addressOptional

Payments and commerce

VendorPurposeData processedEngagement
StripePayment processing, payouts, in-person terminal, tax formsName, email, transaction and payout data. Card data is collected by Stripe and never by usOptional
RevenueCatApp-store subscription entitlements and receipt validationPseudonymous app user ID, purchase and entitlement stateOptional

Platform and device services

VendorPurposeData processedEngagement
AppleSign in with Apple, push notifications, in-app purchases, Health import performed on the deviceAccount identifier, push token, purchase stateOptional
GoogleSign-in, push notifications, Maps and Places lookup, Health Connect import performed on the device, YouTube playback and searchAccount identifier, push token, search and location queriesOptional
MicrosoftSign-in with a Microsoft accountAccount identifier, name, emailOptional
Meta (Facebook)Sign-in and optional profile backfillAccount identifier, name, email, and any profile fields the user grantsOptional
DiscordSign-inAccount identifier, name, emailOptional

Artificial intelligence

VendorPurposeData processedEngagement
AnthropicAI-assisted features: reading a workout, session, meal, roster, timetable or schedule out of text, a photo or a PDF the user submits, and drafting copy a human then reviewsOnly the specific content the user submits for that featureOptional

Because this is the question institutions ask most:

  • Content is sent only when a user explicitly invokes an AI feature. There is no background or bulk transmission.
  • Submitted content is not used to train models.
  • Requests are made server-side from our own functions; the app never calls the provider directly.
  • For an organization in school-managed mode, outbound AI is off by default and stays off until that institution approves this sub-processor. It is enforced server-side at the single chokepoint every AI feature calls, so it covers all of them. Outside school-managed mode, users control AI features individually.

Reference data

VendorPurposeData processedEngagement
USDA FoodData CentralNutrition reference lookupsSearch terms only, no account dataOptional

What we deliberately do not use

Stated because questionnaires ask, and because these absences are the substance of most state student-privacy laws:

  • No advertising networks or advertising SDKs. Declared to Apple as "Data Not Used to Track You."
  • No cross-app tracking, advertising identifiers, or data brokers.
  • No third-party analytics SDK. Product analytics live in our own database, with a user-facing opt-out and a global kill switch.
  • We do not sell personal data, and we do not profile students for any purpose beyond delivering the service.

Changes

DateChange
July 28, 2026Register first published. Cloudflare, Vercel, Azure and Better Stack were added and the Privacy Policy processor list was updated to match.

Questions about a sub-processor, or a request to be notified of changes: help@susos.co.

© 2026 iVenza · Show Up Show Out LLC Trust Center Privacy Policy Your Privacy Choices Security Back to iVenza.app