Sub-Processor List

Last updated: August 24, 2026

This page lists the third parties that process data on behalf of Mr. A's Writing Tools to deliver the Service. It is referenced by our Privacy Policy, Terms of Service, and Data Processing Agreement, and is incorporated into the DPA by reference. We update this list when sub-processors are added, removed, or materially changed.

The AI sub-processor used for coaching feedback receives student writing content and assignment context only. Submissions are associated with an opaque token internal to our system — we do not transmit student names, email addresses, or account identifiers to it.

Two optional integrations are different, and are listed separately below: a teacher may connect an outside AI assistant, or link a class to Google Classroom. Both send student names or school email addresses and progress. Each is off unless that teacher turns it on, and neither sends student writing.

AI Inference

OpenAI, L.L.C.

Purpose AI inference for coaching feedback on student writing
Data categories sent Student writing content; assignment, rubric, and prompt context; an opaque internal token used for request tracing. No student names, email addresses, or account identifiers.
Processing location United States
Training on inputs No. By default the vendor does not train models on API inputs or outputs, and we have not opted in to any data-sharing programs.
Retention Up to 30 days for safety and abuse monitoring under the vendor's default API retention policy, after which content is deleted. Not used for model improvement, advertising, or any commercial purpose.
Encryption TLS 1.2+ in transit; AES-256 at rest
Certifications SOC 2 Type 2; ISO/IEC 27001:2022; ISO/IEC 27701:2019
Compliance posture Publicly states support for customer compliance with FERPA, GDPR, and CCPA. Signed DPA in place, incorporated by reference into the vendor's Services Agreement.
Public reference openai.com/enterprise-privacy · trust.openai.com

Payments

Paid subscriptions are processed by the vendor below. This vendor receives the account holder's billing details — never student writing content.

Stripe, Inc.

Purpose Payment processing for paid subscriptions — checkout, recurring billing, and the customer billing portal (update card, view invoices, cancel).
Data categories sent The account holder's name and email, and the payment details they enter at checkout. Card numbers are collected and stored by Stripe directly in its PCI-DSS environment — we never see or store full card numbers. No student writing content, and no student names or identifiers.
Whose data The paying adult (parent or teacher account holder) only. Students never have payment data and are never sent to this vendor.
Processing location United States
Retention Payment and transaction records are retained by the vendor as required for financial, tax, and anti-fraud purposes under its own retention policy.
Encryption TLS 1.2+ in transit; AES-256 at rest
Certifications PCI-DSS Level 1 Service Provider; SOC 1 Type 2; SOC 2 Type 2; ISO/IEC 27001
Compliance posture Processing governed by the Stripe Services Agreement and Stripe's Data Processing Agreement.
Public reference stripe.com/privacy · stripe.com/legal/dpa

Teacher-Connected Integrations (optional, off by default)

A teacher may connect their Writing Tools account to an outside service they already use, so the two work together. Each integration below is off for every account unless a teacher turns it on, is granted one teacher at a time, and can be disconnected at any time.

These are integration partners, not sub-processors. We did not engage them to process data on our behalf: the teacher connects their own account with that provider, data flows at the teacher's direction, and the provider handles it under the agreement between that provider and the teacher or their school. We list them here anyway, because a school deciding what to allow deserves to see them.

Use a school teacher account. Because a teacher authorizes these connections with the Google account they sign in to Writing Tools with, teachers should sign in with the account their school issued them — not a personal one. That keeps student information inside the school's own Google and provider agreements, where it belongs.

These are the only places where student names leave the Service, and each one happens only after a teacher turns it on. Student writing content is never sent through either integration, and neither are student passwords or login credentials.

Anthropic, PBC — Claude

Purpose Answers a teacher's questions about their own classes inside Claude — for example which students are behind, what a class has been assigned, or assigning new work.
Who initiates The teacher, from their own Claude account. Disabled by default for every account and every school; nothing is transmitted until a teacher completes a consent screen naming the categories below.
Data categories sent Class names, student display names, grade level, assignment titles and due dates, completion status, scores, and last-active dates — for the connecting teacher's own classes only. No student writing content. No student email addresses, passwords, or login credentials. No data from any other teacher's classes.
Scope limits Access is limited to the classes the connecting teacher owns or co-teaches, is re-checked on every request, and ends the moment the teacher disconnects or their teacher role is removed.
Logging Every request made through the connection is recorded against the teacher's account, so a school can be told exactly what was accessed and when.
Processing location United States
Governing terms Data sent through this connection arrives in the teacher's or school's own Claude account and is handled under the agreement between that account holder and Anthropic — not under our AI-inference agreement. Schools that need specific training, retention, or residency commitments should confirm them on their own Claude plan.
School control A school with a signed DPA may instruct us in writing to disable this connection for its teachers, and we will do so.
Public reference privacy.claude.com · trust.anthropic.com

Google LLC — Google Classroom

Purpose Posts a Writing Tools assignment into the teacher's linked Google Classroom course, and writes the resulting grade back to the Classroom gradebook.
Who initiates The teacher, by linking one of their classes to one of their Google Classroom courses. This requires a separate Google permission prompt beyond ordinary sign-in, and is off until the teacher completes it.
Data categories sent Assignment title, description, due date, and a link back to the student's workspace; on completion, the student's grade as a percentage. Students are matched to their existing Classroom roster entry by school email address or Google account ID. No student writing content. No passwords or login credentials.
Scope limits Only classes the teacher has explicitly linked, and only courses that teacher already has access to in Classroom. Unlinking a class stops all further posting and grade write-back.
Processing location Per the school's own Google Workspace for Education configuration.
Governing terms Data posted to Classroom lands in the school's own Google Workspace for Education tenant and is governed by the school's existing agreement with Google — the same place the roster and gradebook already live.
School control A school may instruct us in writing to disable this integration for its teachers, and may also control it directly through its Google Workspace administration.
Public reference edu.google.com — privacy and security

Other Sub-Processors

The Service also depends on the following sub-processors, listed here for completeness. None of these vendors receive student writing content.

Changes to This List

We will update the "Last updated" date above whenever we add, remove, or materially change a sub-processor. Schools with a signed DPA will receive reasonable advance notice of changes that affect the processing of Student Data and may object in writing per Section 7 of the DPA.

Questions: aaron@writingtools.org