Sub-processors
Last reviewed: August 3, 2026
A sub-processor is a third party that processes personal data on our behalf so we can deliver the service. This is the complete list. Vendors marked Optional are engaged only when a user or an organization turns on the feature that uses them; Core vendors are always in the path.
Under our school data privacy agreement we commit to maintaining this list, binding each sub-processor to written terms no less protective than our own, and giving an institution 30 days' notice before adding a sub-processor that would process student data, with a right to object.
Data residency: our database, authentication and file storage are hosted in the United States, in a US West region, so account and student data is stored in the US with no foreign storage. Several vendors below run global edge networks, so request metadata such as an IP address may transit an edge location while a request is routed. That is transit, not storage.
Core infrastructure
| Vendor | Purpose | Data processed | Engagement |
|---|---|---|---|
| Supabase | Database, authentication, file storage, sync, backups, serverless functions | All account and application data | Core |
| Cloudflare | DNS, web application firewall, rate limiting, TLS, email routing | Request metadata, IP addresses | Core |
| Vercel | Hosting for the web app | Request metadata, IP addresses | Core |
| Microsoft Azure | Hosting for the marketing site | Request metadata, IP addresses | Core |
| Better Stack | Uptime and availability monitoring | Endpoint health only, no user data | Core |
Communications
| Vendor | Purpose | Data processed | Engagement |
|---|---|---|---|
| Resend | Email delivery and open/click engagement | Email address, name, message content, engagement events | Core |
| Twilio | Text message delivery and inbound replies | Phone number, message content, opt-out state | Optional |
| Lob | Printed mail, where an organization chooses to send it | Name, mailing address | Optional |
Payments and commerce
| Vendor | Purpose | Data processed | Engagement |
|---|---|---|---|
| Stripe | Payment processing, payouts, in-person terminal, tax forms | Name, email, transaction and payout data. Card data is collected by Stripe and never by us | Optional |
| RevenueCat | App-store subscription entitlements and receipt validation | Pseudonymous app user ID, purchase and entitlement state | Optional |
Platform and device services
| Vendor | Purpose | Data processed | Engagement |
|---|---|---|---|
| Apple | Sign in with Apple, push notifications, in-app purchases, Health import performed on the device | Account identifier, push token, purchase state | Optional |
| Sign-in, push notifications, Maps and Places lookup, Health Connect import performed on the device, YouTube playback and search | Account identifier, push token, search and location queries | Optional | |
| Microsoft | Sign-in with a Microsoft account | Account identifier, name, email | Optional |
| Meta (Facebook) | Sign-in and optional profile backfill | Account identifier, name, email, and any profile fields the user grants | Optional |
| Discord | Sign-in | Account identifier, name, email | Optional |
Artificial intelligence
| Vendor | Purpose | Data processed | Engagement |
|---|---|---|---|
| Anthropic | AI-assisted features: reading a workout, session, meal, roster, timetable or schedule out of text, a photo or a PDF the user submits, and drafting copy a human then reviews | Only the specific content the user submits for that feature | Optional |
Because this is the question institutions ask most:
- Content is sent only when a user explicitly invokes an AI feature. There is no background or bulk transmission.
- Submitted content is not used to train models.
- Requests are made server-side from our own functions; the app never calls the provider directly.
- For an organization in school-managed mode, outbound AI is off by default and stays off until that institution approves this sub-processor. It is enforced server-side at the single chokepoint every AI feature calls, so it covers all of them. Outside school-managed mode, users control AI features individually.
Reference data
| Vendor | Purpose | Data processed | Engagement |
|---|---|---|---|
| USDA FoodData Central | Nutrition reference lookups | Search terms only, no account data | Optional |
What we deliberately do not use
Stated because questionnaires ask, and because these absences are the substance of most state student-privacy laws:
- No advertising networks or advertising SDKs. Declared to Apple as "Data Not Used to Track You."
- No cross-app tracking, advertising identifiers, or data brokers.
- No third-party analytics SDK. Product analytics live in our own database, with a user-facing opt-out and a global kill switch.
- We do not sell personal data, and we do not profile students for any purpose beyond delivering the service.
Changes
| Date | Change |
|---|---|
| July 28, 2026 | Register first published. Cloudflare, Vercel, Azure and Better Stack were added and the Privacy Policy processor list was updated to match. |
Questions about a sub-processor, or a request to be notified of changes: help@susos.co.