Last updated: July 5, 2026
This page lists the third parties that process data on behalf of Mr. A's Writing Tools to deliver the Service. It is referenced by our Privacy Policy, Terms of Service, and Data Processing Agreement, and is incorporated into the DPA by reference. We update this list when sub-processors are added, removed, or materially changed.
The AI sub-processor below receives student writing content and assignment context only. Submissions are associated with an opaque token internal to our system — we do not transmit student names, email addresses, or account identifiers.
| Purpose | AI inference for coaching feedback on student writing |
|---|---|
| Data categories sent | Student writing content; assignment, rubric, and prompt context; an opaque internal token used for request tracing. No student names, email addresses, or account identifiers. |
| Processing location | United States |
| Training on inputs | No. By default the vendor does not train models on API inputs or outputs, and we have not opted in to any data-sharing programs. |
| Retention | Up to 30 days for safety and abuse monitoring under the vendor's default API retention policy, after which content is deleted. Not used for model improvement, advertising, or any commercial purpose. |
| Encryption | TLS 1.2+ in transit; AES-256 at rest |
| Certifications | SOC 2 Type 2; ISO/IEC 27001:2022; ISO/IEC 27701:2019 |
| Compliance posture | Publicly states support for customer compliance with FERPA, GDPR, and CCPA. Signed DPA in place, incorporated by reference into the vendor's Services Agreement. |
| Public reference | openai.com/enterprise-privacy · trust.openai.com |
Paid subscriptions are processed by the vendor below. This vendor receives the account holder's billing details — never student writing content.
| Purpose | Payment processing for paid subscriptions — checkout, recurring billing, and the customer billing portal (update card, view invoices, cancel). |
|---|---|
| Data categories sent | The account holder's name and email, and the payment details they enter at checkout. Card numbers are collected and stored by Stripe directly in its PCI-DSS environment — we never see or store full card numbers. No student writing content, and no student names or identifiers. |
| Whose data | The paying adult (parent or teacher account holder) only. Students never have payment data and are never sent to this vendor. |
| Processing location | United States |
| Retention | Payment and transaction records are retained by the vendor as required for financial, tax, and anti-fraud purposes under its own retention policy. |
| Encryption | TLS 1.2+ in transit; AES-256 at rest |
| Certifications | PCI-DSS Level 1 Service Provider; SOC 1 Type 2; SOC 2 Type 2; ISO/IEC 27001 |
| Compliance posture | Processing governed by the Stripe Services Agreement and Stripe's Data Processing Agreement. |
| Public reference | stripe.com/privacy · stripe.com/legal/dpa |
The Service also depends on the following sub-processors, listed here for completeness. None of these vendors receive student writing content.
We will update the "Last updated" date above whenever we add, remove, or materially change a sub-processor. Schools with a signed DPA will receive reasonable advance notice of changes that affect the processing of Student Data and may object in writing per Section 7 of the DPA.
Questions: aaron@writingtools.org