Supabase
Authentication, application database and uploaded-media storage
- Data
- Account, studio, lesson, message, uploaded-media and billing records
- Role
- Processor for hosted authentication, application data and uploaded media
- Status
- Active
- Region
- European Union for primary project data; support, edge services and subprocessors may operate elsewhere
- Transfer basis
- 2021 Standard Contractual Clauses under Supabase's DPA where required
- Last updated
- 2026-09-11
- Provider documents
- PrivacyDPA
Vercel
Hosting, server execution and operational logs
- Data
- Requests, IP addresses, account content in transit and operational logs
- Role
- Processor for hosted customer data; separate controller for its own account and service data
- Status
- Active
- Region
- United States for server processing, with global edge delivery and subprocessors
- Transfer basis
- 2021 Standard Contractual Clauses under Vercel's DPA where required
- Last updated
- 2026-09-10
- Provider documents
- PrivacyDPA
Resend
Authentication and transactional email
- Data
- Email addresses, names, delivery metadata and message content
- Role
- Processor for Nutmeg email content; separate controller for its own account and usage data
- Status
- Active
- Region
- Customer data stored in the United States; selected sending region affects routing rather than storage
- Transfer basis
- 2021 Standard Contractual Clauses under Resend's DPA where required
- Last updated
- 2026-09-10
- Provider documents
- PrivacyDPA
Cloudflare
Turnstile bot protection and inbound email routing
- Data
- Connection, device and challenge data; routed-email metadata and content
- Role
- Processor for covered customer content, with separate controller activities for Cloudflare service data
- Status
- Active
- Region
- Global network, including processing in the United States
- Transfer basis
- EU-US Data Privacy Framework and EU Standard Contractual Clauses under Cloudflare's DPA where applicable
- Last updated
- 2026-09-08
- Provider documents
- PrivacyDPA
Sentry
Error and performance monitoring
- Data
- Scrubbed error, device, route and technical diagnostic data
- Role
- Processor for error-monitoring data
- Status
- Active
- Region
- United States service region
- Transfer basis
- Accepted Sentry DPA; EU-US Data Privacy Framework and 2021 Standard Contractual Clauses where applicable
- Last updated
- 2026-09-11
- Provider documents
- PrivacyDPA
bunny.net
Video processing, storage and delivery
- Data
- User-uploaded video and playback/delivery metadata
- Role
- Processor for uploaded video and delivery telemetry
- Status
- Active
- Region
- Primary storage in Frankfurt, Germany; replication in Los Angeles, New York and Singapore; global CDN delivery
- Transfer basis
- Accepted Article 28 DPA with BunnyWay d.o.o. in Slovenia; under its DPA and applicable data-protection law, Bunny is responsible for appropriate safeguards when using a non-EEA subprocessor
- Last updated
- 2026-09-11
- Provider documents
- PrivacyDPA
PostHog
Optional product analytics for public visitors and teachers after opt-in; never student or parent accounts
- Data
- Consent-gated pseudonymous usage and device events
- Role
- Processor when optional analytics is enabled
- Status
- Conditional
- Region
- United States service configuration
- Transfer basis
- Executed PostHog DPA incorporating the 2021 Standard Contractual Clauses (Module 2) and EU-US Data Privacy Framework where applicable
- Last updated
- 2026-09-13
- Provider documents
- PrivacyDPA