Skip to main content
Close Search
Pathly
  • Sign Up Now
Menu
  • How it Works
  • For Counselors
  • Testimonials
  • Resources
    • Blog
    • Career Library
  • Contact
  • Sign Up Now
  • Login
Pathly

Home » Trust and Legal Center » Subprocessor List

Pathly Legal / Trust

Subprocessor list

Every third-party service provider Pathly uses to run the platform, what each one touches, the status of our data processing agreement with it, and where to verify its security posture yourself. This page is Exhibit B to the Counselor Data Processing Addendum and to the Pathly Partner School Student Data and Privacy Addendum, and is maintained as part of both.

Version
1.1
Last updated
July 30, 2026
Subprocessors
6 categories, 9 providers
Change notices
Request

Contents

  1. Standards and data location
  2. Summary
  3. Supabase
  4. AI and research services
  5. PostHog
  6. Resend
  7. Sentry
  8. Stripe
  9. Hosting summary
  10. How changes work

The short version

  • Six categories of subprocessor, nine providers. All process data in United States regions.
  • Every one is under a written data processing agreement, either signed or incorporated into terms Pathly accepted.
  • No AI provider is permitted to train on platform data.
  • Every security claim below links to the provider's own trust center, so you can check it rather than take our word.
  • Pathly gives 30 days' notice before a new subprocessor starts processing.

01 Standards and data location

Every provider below is under a written data processing agreement with Pathly and is linked to its own trust center so you can verify its current security posture directly. Pathly holds internal security reviews and is working toward independent certification; it does not hold a SOC 2 Type II attestation of its own today, and does not claim one.

1.1 What Pathly requires of every subprocessor

Contractual requirements

  • A written data processing agreement limiting use to providing services to Pathly
  • Encryption in transit using TLS 1.2 or higher, and at rest using AES-256 or equivalent
  • Retention limited to what the service requires
  • Prompt notification to Pathly of security incidents
  • Deletion or return of data on termination
  • Compliance with applicable privacy laws, including COPPA and applicable state student and consumer privacy laws
  • Industry-standard security controls, verified against the provider's published documentation

1.2 Two ways a data processing agreement is formed

The DPA column below uses two terms, and the difference comes up in every security review, so it is worth stating plainly.

Executed versus incorporated
StatusWhat it means
ExecutedA separate agreement signed by both parties. Pathly holds the countersigned copy and can produce it on request.
IncorporatedThe provider's DPA forms part of its commercial or API terms and becomes binding when those terms are accepted. These providers do not offer a separate signature. The DPA text is published at the linked URL, and Pathly's acceptance is recorded in its account with the provider.

Both are binding. Incorporation by reference is the standard mechanism among infrastructure and AI providers, and it is the same mechanism by which Pathly's own Counselor DPA takes effect.

1.3 Data location

Pathly configures every service to use United States regions where the provider offers them. Pathly does not intentionally transfer platform data outside the United States. Limited access from outside the United States may occur for vendor support or security operations.

02 Summary

All current subprocessors
SubprocessorFunctionData it touchesDPAVerify
SupabaseDatabase and hostingAll platform data, as storageExecutedsupabase.com/security
OpenAIAI servicesFirst name and context. No email addresses.Executedtrust.openai.com
AnthropicAI services, content generationFirst name and context. No email addresses.Incorporatedtrust.anthropic.com
Google CloudAI servicesFirst name and context. No email addresses.IncorporatedGoogle Cloud compliance
PerplexityAI services, chat web searchQuery context. No email addresses.Incorporatedperplexity.ai/hub/security
PostHogProduct analyticsAnonymized usage only. No personal information.Executedtrust.posthog.com
ResendTransactional emailEmail addresses onlyExecutedresend.com/security/soc-2
SentryError monitoringTechnical logs, personal information scrubbedExecutedsentry.io/security
StripePayments and subscription billingCounselor and family billing details. No student data.Incorporatedstripe.com/legal/dpa

Five of these agreements are separately executed and four are incorporated into terms Pathly accepted. Each provider reports SOC 2 Type II or a comparable attestation. Certifications are as reported by providers and may change, which is why every row links to the source rather than restating it. Some providers gate the full report behind a request. Where Pathly has obtained a gated report, it is on file and available to customers on request.

03 Supabase

Provider detail
Legal entitySupabase, Inc.
FunctionPostgreSQL database hosting, authentication and authorization, file storage, row-level security enforcement
Reported certificationsSOC 2 Type II, ISO 27001, GDPR, HIPAA
InfrastructureAmazon Web Services, United States regions
EncryptionTLS 1.2+ in transit, AES-256 at rest
Backup retention7 days, automatic rotation
DPA statusExecuted, countersigned copy on file
Verifysupabase.com/security

Supabase has access to all platform data stored by Pathly. It acts as database infrastructure and does not access or use that data for any purpose beyond providing hosting services to Pathly.

04 AI and research services

Pathly uses more than one AI provider, selected by task, performance, availability, security posture, and cost. A given request may route to any listed provider suited to it.

Current AI providers
ProviderLegal entityRoleDPA
OpenAIOpenAI, L.L.C.Conversational guidanceExecuted, copy on file
AnthropicAnthropic PBCContent generationIncorporated into Commercial Terms on acceptance, with standard contractual clauses
Google CloudGoogle LLCAI servicesCloud Data Processing Addendum, incorporated into Google Cloud terms
PerplexityPerplexity AI, Inc.Chat web search and retrievalIncorporated into API Terms of Service

DPA text for the incorporated agreements is published by each provider at support.claude.com for Anthropic, perplexity.ai/hub/legal/dpa, and cloud.google.com/terms/data-processing-addendum. Stripe's is at stripe.com/legal/dpa.

4.1 What is sent, and what is not

Included in requests

  • Student first name, for conversational tone
  • School name and location, where provided
  • Grade level, calculated from graduation year
  • Stated interests and goals
  • Assessment results
  • The last 10 messages, for continuity

Never included

  • Email addresses
  • Last names
  • Account or student identifiers
  • Demographic information
  • Financial or family financial information
  • Full conversation history

4.2 Training and retention

Pathly does not permit AI providers to train their models on platform data, and uses the provider settings and contractual terms available to it to disable training and minimize retention. Providers use the contents of a request solely to generate a response to that request. Perplexity's published DPA commits that customer data is not used for model training.

05 PostHog

Provider detail
Legal entityPostHog, Inc.
FunctionProduct analytics, feature usage, performance monitoring
Reported certificationsSOC 2 Type II, GDPR
EncryptionTLS 1.2+ in transit, AES-256 at rest
DPA statusExecuted, countersigned copy on file
Verifytrust.posthog.com

5.1 How Pathly configures it

Disabled

  • Person profiles
  • Session recording
  • Autocapture

Enabled

  • IP anonymization
  • Active filtering of personal information fields

Names, email addresses, identifiers, conversation content, and assessment responses or scores are not sent to PostHog.

06 Resend

Provider detail
Legal entityPlus Five Five, Inc., doing business as Resend
FunctionTransactional email: verification, password reset, platform notifications
Reported certificationsSOC 2 Type II, GDPR
Data accessEmail addresses only
Retention30 days, delivery logs only
DPA statusExecuted, countersigned copy on file
Verifyresend.com/security/soc-2. Full report is gated by the provider; Pathly holds a copy.

Pathly does not send marketing email to students.

07 Sentry

Provider detail
Legal entityFunctional Software, Inc., doing business as Sentry
FunctionError monitoring, crash reporting, performance tracing
Reported certificationsSOC 2 Type II, ISO 27001, GDPR
Retention90 days, automatic deletion
DPA statusExecuted, countersigned copy on file
Verifysentry.io/security. Full report is available through the provider's account portal; Pathly holds a copy.

Personal information scrubbing is configured. Conversation content is not included in error traces.

08 Stripe

Stripe processes payments for counselor and family subscriptions. It sits entirely outside the student data path.

Provider detail
FunctionPayment processing and subscription billing for paid plans
Data accessBilling name, email address, and payment details for counselor and family subscribers
Student data accessNone. Students are never charged, and no student data is transmitted.
DPA statusIncorporated. The Stripe Data Processing Agreement forms part of the Stripe Services Agreement, and the Stripe Data Transfers Addendum, which carries the standard contractual clauses, is incorporated into that DPA. No separate signature is offered.
Verifystripe.com/legal/dpa and the DPA FAQs

Card numbers are captured by Stripe directly and are not transmitted to or stored by Pathly.

09 Hosting summary

Component, provider, region, retention
ComponentProviderRegionRetention
Primary databaseSupabaseUnited StatesPer Pathly instructions
AI processingOpenAI, Anthropic, Google Cloud, PerplexityUnited StatesPer provider policy, retention minimized
AnalyticsPostHogUnited StatesIndefinite, anonymized
EmailResendUnited States30 days, logs
Error monitoringSentryUnited States90 days, automatic deletion
PaymentsStripeUnited StatesPer provider policy and tax requirements

10 How changes work

10.1 Adding a subprocessor

Pathly gives at least 30 days' notice before a new subprocessor begins processing, by updating this page and emailing the address on your account. To receive change notices directly, write to legal@pathly.com.

10.2 If you object

Tell us at legal@pathly.com within 15 days with the specific privacy or security concern, and we will work in good faith to address it.

  • Counselor plans. If we cannot resolve it, your remedy is to terminate before the change takes effect and receive a pro-rata refund of prepaid, unused fees.
  • Partner School agreements. Objection and resolution follow Section 6.3 of the Student Data and Privacy Addendum, including the right of either party to terminate without penalty where a critical subprocessor concern cannot be resolved.

10.3 Moving between listed AI providers

Routing a request to a different provider already listed in Section 4 is not the addition of a new subprocessor. Pathly reflects such changes on this page. Adding a provider that is not listed follows the 30-day process above.

10.4 Removing a subprocessor

When Pathly stops using a subprocessor, this page is updated and the provider is required to delete or return the data it holds.

10.5 Requesting documentation

Partner Schools may request subprocessor data processing agreements, redacted for commercial confidentiality, and provider security certifications, under Section 6.4 of the Student Data and Privacy Addendum. Counselor plans are served by this published page, under Section 12.1 of the Counselor DPA.

Exhibit B to the Pathly Counselor Data Processing Addendum and to the Pathly Partner School Student Data and Privacy Addendum, version 1.1. Pathly Labs, Inc., a Delaware corporation. South Carolina.

Certifications are as reported by providers and may change over time. Pathly maintains the standards described in Section 1.1 regardless. Security questions: security@pathly.com. Privacy and legal: legal@pathly.com.

  • Legal hub
  • Counselor DPA
  • Data inventory
  • Privacy Policy

Guiding students confidently toward college, careers, and beyond.

Student Safety

Trust & Legal Center

Privacy Policy

Terms of Service

Cookie Settings

Let’s Connect

Contact Us

Linkedin

Create a free acount

©  2026 Pathly Labs, Inc. All Rights Reserved.

Pathly™ and the Pathly logo are trademarks of Pathly Labs, Inc. U.S. trademark application pending.

Close Menu
  • How it Works
  • For Counselors
  • Testimonials
  • Resources
    • Blog
    • Career Library
  • Contact
  • Login
Pathly
Cookie Preferences

Cookie Preferences
We use cookies to keep this site secure, to see which pages get used, and to measure our advertising. Nothing loads until you choose. Student data from Pathly accounts is never used for marketing.

Strictly necessary Always active
Keeps the site secure and remembers your cookie choices. Always on.
Functional
Remembers preferences like display settings.
Analytics
Shows us which pages get used, so we can improve them. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Measures our advertising and how people find Pathly.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Preferences
  • {title}
  • {title}
  • {title}