Sub-Processors
To provide the School Planner service, we engage a limited set of third-party providers ("sub-processors") to process data on our behalf. Each sub-processor is bound by a Data Processing Agreement containing data-protection obligations no less protective than those in our .
We will provide thirty (30) days' advance notice before adding a new sub-processor that materially changes the categories of data processed (subject to beta-period limitations described in the Terms of Service). Schools may subscribe to updates by emailing legal@synthed.co.
Required sub-processors
These services are necessary for the core operation of the platform. All Schools are subject to processing by these sub-processors.
| Sub-processor | Purpose | Data accessed | Location | DPA |
|---|---|---|---|---|
| Resend | Transactional email delivery (notifications, invites, password resets). | Recipient email address, recipient name, email subject and body. May contain task titles and event names when present in notification content. | United States | View |
| Sentry | Application error monitoring and performance tracing. | Scrubbed request URLs (PII removed), error stack traces, user identifiers (hashed where possible). Attachment URLs and student-identifying fields are scrubbed before transmission. | United States | View |
| PostHog | Product analytics — usage patterns, feature adoption, and aggregate metrics. | User identifier and email address; event names; role and institutional context (staff role, department, school and district name/type/size, billing and add-on status); non-PII event properties (task counts, attachment types, school IDs). Customer Content (task titles, notes, attachment URLs) is not transmitted. | United States | View |
| Tigris (S3-compatible object storage) | Encrypted storage for user-uploaded files (task attachments, profile images). | File contents (encrypted at rest), file names, file metadata. Files are addressable only by signed URLs scoped to authenticated users in the same School. | United States | View |
| Fly.io | Application hosting (the servers the platform runs on). | All Customer Content passes through the application servers in the course of serving requests (encrypted in transit). Fly.io operates as a hosting infrastructure provider under a Data Processing Addendum. | United States | View |
| Neon | Managed Postgres — the primary database. | All Customer Content and account data at rest (encrypted at rest and in transit), including its 7-day point-in-time-recovery history. | United States | View |
| Cloudflare (R2 object storage) | Off-site storage for encrypted database backups. | Nightly full-database backup archives. Every archive is encrypted (age, X25519) before upload, so Cloudflare only ever stores ciphertext it cannot read. Retention schedule below. | United States | View |
| Stripe | Payment processing and invoicing. Engaged when a School is invoiced for or pays for a plan. | School billing contact name and email, billing address, purchase order number, plan and add-on selections, and invoice amounts and status. Card and bank details are entered directly with Stripe and are never received or stored by synthEd. No Student Data and no Customer Content are transmitted to Stripe. | United States | View |
Optional sub-processors
These services are engaged only when a School or individual user opts in to a related feature.
| Sub-processor | Purpose | Data accessed | Location | DPA |
|---|---|---|---|---|
| OpenRouter | Routes AI Planner requests to the underlying model operator. Engaged when AI features are used — normally only by Schools with the AI Planner add-on, though a district administrator can invoke AI features on a school’s behalf. | Prompts and the Customer Content needed for the request (event and task structure, template content, school name, grade levels). Inputs and outputs may not be retained for model training. | United States | View |
| OpenAI (reached via OpenRouter) | The model operator that generates AI Planner suggestions. Currently openai/gpt-5.6-luna; this entry is updated if the configured model operator changes. | The same prompt and Customer Content passed through by OpenRouter, for the duration of the request. OpenAI’s API terms do not use submitted prompts or responses to train its models. | United States | View |
| Google Workspace (Sign in with Google) | Optional single sign-on for schools that run Google Workspace for Education. | Google account ID, hosted Workspace domain, name, email address, and profile picture URL. Only requested when a user explicitly chooses to sign in with Google. The Workspace domain is what we check the sign-in against; it is retained so an administrator can approve your district once. No Student Data is transmitted to Google. | United States | View |
| Microsoft Entra ID (Sign in with Microsoft) | Optional single sign-on for schools that run Microsoft 365 Education. | Microsoft object ID, directory tenant ID, display name, and email address (or user principal name). Only requested when a user explicitly chooses to sign in with Microsoft. The tenant ID is what we check the sign-in against; it is retained so an administrator can approve your district once. No Student Data is transmitted to Microsoft. | United States | View |
| Google Drive (Open in Google) | Creates a document in an individual user’s own Google Drive when they choose "Open in Google" for an AI-generated artifact. | Only the artifact the user chooses to export, plus the ID of the file we create. Uses the drive.file scope, which grants access solely to files this application creates — we cannot see, search, or read anything else in the user’s Drive. | United States | View |
| Google Calendar (calendar sync) | Writes a user’s School Planner events into a synthEd calendar in their own Google Calendar, when that user turns sync on. | Event and action-item title, date, and a short description for that user’s own schedule, written as all-day entries (the planner stores no time-of-day or location). Uses the calendar.app.created scope, which grants access solely to the calendar this application creates — we cannot read the user’s other calendars. | United States | View |
Backup retention
Database backups are encrypted before they leave our infrastructure and expire on the schedule below. When Customer Content is deleted from the live system, it ages out of each backup tier as that tier expires; deletion from the long-term archive is available on request, as described in our Terms of Service §15 and Privacy Policy §7.
| Backup tier | Retained for |
|---|---|
| Point-in-time recovery history (Neon) | 7 days |
| Daily encrypted backups (Cloudflare R2) | 30 days |
| Weekly encrypted backups (Cloudflare R2) | 180 days |
| Monthly encrypted backups (Cloudflare R2) | 5 years |
| Yearly encrypted archive (Cloudflare R2) | Retained long-term for disaster recovery; deleted on request once the archive’s tamper-protection lock allows (≤ 12 months) |
Material changes to this list, including adding a new sub-processor or expanding the data categories an existing sub-processor receives, will be communicated to your School's designated administrator by email and posted here. The effective date will be set out in the notice.
To object to a new sub-processor, write to legal@synthed.co before the effective date. If we cannot accommodate the objection, you may terminate per the Terms of Service.