Sub-processors
Effective 2026-07-30
These are the third parties currently used to deliver StudySite. We limit each provider to the data and purpose described below. Services that are configured in code but not active are not represented as current subprocessors.
| Sub-processor | Purpose | Data shared | User choice |
|---|---|---|---|
| Render | Application hosting and managed PostgreSQL | Account, course, authoring, learning, and service-log data | Required to provide StudySite |
| Cloudflare | DNS, TLS termination, and network protection | IP address, request metadata, and security signals | Required to provide StudySite |
| Clerk | Authentication, sessions, invitations, and identity management | Name, email, profile image, authentication factors, session and sign-in data | Required for an account |
| OpenAI | Tutor, file search, retrieval, and selected generation workflows | The prompt, chat, code/context, and instructor-approved source content needed for the requested AI feature | Required only when the applicable AI feature is used |
| Gemini AI generation and voice, YouTube search, and user-authorized Docs/Drive integration | Feature prompts and responses; source files or transcripts when required; search queries; user-authorized Google content | AI and connected-account features can be avoided or disconnected | |
| E2B | Isolated student code and notebook execution | Code, selected files, execution input, and resulting output | Required only when code execution is used |
| Inngest | Background-job orchestration | Job identifiers, status, timing, and bounded workflow metadata | Required for scheduled and asynchronous workflows |
| GitHub | User-authorized repository, assignment, commit, and autograder workflows | GitHub identity, repository metadata, selected files, commits, and workflow status | Optional; users can disconnect GitHub |
| Microsoft | User-authorized OneNote import and export | OAuth identity and selected OneNote content | Optional; users can disconnect Microsoft |
| Sentry | Error reporting and performance monitoring | Errors, stack traces, request paths, timing, and device metadata; default PII capture is disabled | Required for platform security and reliability |
| PostHog | Optional product analytics | Pseudonymous account identifier plus page and feature events; never name/email, student code, terminal output, uploads, or free-text responses | Off by default; opt in or out in Settings |
| Featurebase | Help center, support, and feedback | Account identity and content a user deliberately submits to support or feedback | Optional unless the user opens or submits to the service |
| Stripe | Payment processing, receipts, refunds, and entitlement evidence | Billing contact, payment transaction, product, and entitlement metadata; StudySite does not receive full card numbers | Required only for direct purchases |
| Better Stack | External uptime and scheduled-job heartbeat monitoring | Service availability and job-health signals; no learning content | Required for reliability monitoring |
Our processor agreements or applicable service terms restrict providers to delivering their contracted service and require appropriate data protection. We will give account holders and institutional contacts at least 30 days' notice before a new subprocessor begins receiving personal or student data, except when an urgent security replacement is required. Questions or objections may be sent to admin@studysite.ai.