Pathly Legal / Trust
Subprocessor list
Every third-party service provider Pathly uses to run the platform, what each one touches, the status of our data processing agreement with it, and where to verify its security posture yourself. This page is Exhibit B to the Counselor Data Processing Addendum and to the Pathly Partner School Student Data and Privacy Addendum, and is maintained as part of both.
- Version
- 1.1
- Last updated
- July 30, 2026
- Subprocessors
- 6 categories, 9 providers
- Change notices
- Request
The short version
- Six categories of subprocessor, nine providers. All process data in United States regions.
- Every one is under a written data processing agreement, either signed or incorporated into terms Pathly accepted.
- No AI provider is permitted to train on platform data.
- Every security claim below links to the provider's own trust center, so you can check it rather than take our word.
- Pathly gives 30 days' notice before a new subprocessor starts processing.
01 Standards and data location
Every provider below is under a written data processing agreement with Pathly and is linked to its own trust center so you can verify its current security posture directly. Pathly holds internal security reviews and is working toward independent certification; it does not hold a SOC 2 Type II attestation of its own today, and does not claim one.
1.1 What Pathly requires of every subprocessor
Contractual requirements
- A written data processing agreement limiting use to providing services to Pathly
- Encryption in transit using TLS 1.2 or higher, and at rest using AES-256 or equivalent
- Retention limited to what the service requires
- Prompt notification to Pathly of security incidents
- Deletion or return of data on termination
- Compliance with applicable privacy laws, including COPPA and applicable state student and consumer privacy laws
- Industry-standard security controls, verified against the provider's published documentation
1.2 Two ways a data processing agreement is formed
The DPA column below uses two terms, and the difference comes up in every security review, so it is worth stating plainly.
| Status | What it means |
|---|---|
| Executed | A separate agreement signed by both parties. Pathly holds the countersigned copy and can produce it on request. |
| Incorporated | The provider's DPA forms part of its commercial or API terms and becomes binding when those terms are accepted. These providers do not offer a separate signature. The DPA text is published at the linked URL, and Pathly's acceptance is recorded in its account with the provider. |
Both are binding. Incorporation by reference is the standard mechanism among infrastructure and AI providers, and it is the same mechanism by which Pathly's own Counselor DPA takes effect.
1.3 Data location
Pathly configures every service to use United States regions where the provider offers them. Pathly does not intentionally transfer platform data outside the United States. Limited access from outside the United States may occur for vendor support or security operations.
02 Summary
| Subprocessor | Function | Data it touches | DPA | Verify |
|---|---|---|---|---|
| Supabase | Database and hosting | All platform data, as storage | Executed | supabase.com/security |
| OpenAI | AI services | First name and context. No email addresses. | Executed | trust.openai.com |
| Anthropic | AI services, content generation | First name and context. No email addresses. | Incorporated | trust.anthropic.com |
| Google Cloud | AI services | First name and context. No email addresses. | Incorporated | Google Cloud compliance |
| Perplexity | AI services, chat web search | Query context. No email addresses. | Incorporated | perplexity.ai/hub/security |
| PostHog | Product analytics | Anonymized usage only. No personal information. | Executed | trust.posthog.com |
| Resend | Transactional email | Email addresses only | Executed | resend.com/security/soc-2 |
| Sentry | Error monitoring | Technical logs, personal information scrubbed | Executed | sentry.io/security |
| Stripe | Payments and subscription billing | Counselor and family billing details. No student data. | Incorporated | stripe.com/legal/dpa |
Five of these agreements are separately executed and four are incorporated into terms Pathly accepted. Each provider reports SOC 2 Type II or a comparable attestation. Certifications are as reported by providers and may change, which is why every row links to the source rather than restating it. Some providers gate the full report behind a request. Where Pathly has obtained a gated report, it is on file and available to customers on request.
03 Supabase
| Legal entity | Supabase, Inc. |
|---|---|
| Function | PostgreSQL database hosting, authentication and authorization, file storage, row-level security enforcement |
| Reported certifications | SOC 2 Type II, ISO 27001, GDPR, HIPAA |
| Infrastructure | Amazon Web Services, United States regions |
| Encryption | TLS 1.2+ in transit, AES-256 at rest |
| Backup retention | 7 days, automatic rotation |
| DPA status | Executed, countersigned copy on file |
| Verify | supabase.com/security |
Supabase has access to all platform data stored by Pathly. It acts as database infrastructure and does not access or use that data for any purpose beyond providing hosting services to Pathly.
04 AI and research services
Pathly uses more than one AI provider, selected by task, performance, availability, security posture, and cost. A given request may route to any listed provider suited to it.
| Provider | Legal entity | Role | DPA |
|---|---|---|---|
| OpenAI | OpenAI, L.L.C. | Conversational guidance | Executed, copy on file |
| Anthropic | Anthropic PBC | Content generation | Incorporated into Commercial Terms on acceptance, with standard contractual clauses |
| Google Cloud | Google LLC | AI services | Cloud Data Processing Addendum, incorporated into Google Cloud terms |
| Perplexity | Perplexity AI, Inc. | Chat web search and retrieval | Incorporated into API Terms of Service |
DPA text for the incorporated agreements is published by each provider at support.claude.com for Anthropic, perplexity.ai/hub/legal/dpa, and cloud.google.com/terms/data-processing-addendum. Stripe's is at stripe.com/legal/dpa.
4.1 What is sent, and what is not
Included in requests
- Student first name, for conversational tone
- School name and location, where provided
- Grade level, calculated from graduation year
- Stated interests and goals
- Assessment results
- The last 10 messages, for continuity
Never included
- Email addresses
- Last names
- Account or student identifiers
- Demographic information
- Financial or family financial information
- Full conversation history
4.2 Training and retention
Pathly does not permit AI providers to train their models on platform data, and uses the provider settings and contractual terms available to it to disable training and minimize retention. Providers use the contents of a request solely to generate a response to that request. Perplexity's published DPA commits that customer data is not used for model training.
05 PostHog
| Legal entity | PostHog, Inc. |
|---|---|
| Function | Product analytics, feature usage, performance monitoring |
| Reported certifications | SOC 2 Type II, GDPR |
| Encryption | TLS 1.2+ in transit, AES-256 at rest |
| DPA status | Executed, countersigned copy on file |
| Verify | trust.posthog.com |
5.1 How Pathly configures it
Disabled
- Person profiles
- Session recording
- Autocapture
Enabled
- IP anonymization
- Active filtering of personal information fields
Names, email addresses, identifiers, conversation content, and assessment responses or scores are not sent to PostHog.
06 Resend
| Legal entity | Plus Five Five, Inc., doing business as Resend |
|---|---|
| Function | Transactional email: verification, password reset, platform notifications |
| Reported certifications | SOC 2 Type II, GDPR |
| Data access | Email addresses only |
| Retention | 30 days, delivery logs only |
| DPA status | Executed, countersigned copy on file |
| Verify | resend.com/security/soc-2. Full report is gated by the provider; Pathly holds a copy. |
Pathly does not send marketing email to students.
07 Sentry
| Legal entity | Functional Software, Inc., doing business as Sentry |
|---|---|
| Function | Error monitoring, crash reporting, performance tracing |
| Reported certifications | SOC 2 Type II, ISO 27001, GDPR |
| Retention | 90 days, automatic deletion |
| DPA status | Executed, countersigned copy on file |
| Verify | sentry.io/security. Full report is available through the provider's account portal; Pathly holds a copy. |
Personal information scrubbing is configured. Conversation content is not included in error traces.
08 Stripe
Stripe processes payments for counselor and family subscriptions. It sits entirely outside the student data path.
| Function | Payment processing and subscription billing for paid plans |
|---|---|
| Data access | Billing name, email address, and payment details for counselor and family subscribers |
| Student data access | None. Students are never charged, and no student data is transmitted. |
| DPA status | Incorporated. The Stripe Data Processing Agreement forms part of the Stripe Services Agreement, and the Stripe Data Transfers Addendum, which carries the standard contractual clauses, is incorporated into that DPA. No separate signature is offered. |
| Verify | stripe.com/legal/dpa and the DPA FAQs |
Card numbers are captured by Stripe directly and are not transmitted to or stored by Pathly.
09 Hosting summary
| Component | Provider | Region | Retention |
|---|---|---|---|
| Primary database | Supabase | United States | Per Pathly instructions |
| AI processing | OpenAI, Anthropic, Google Cloud, Perplexity | United States | Per provider policy, retention minimized |
| Analytics | PostHog | United States | Indefinite, anonymized |
| Resend | United States | 30 days, logs | |
| Error monitoring | Sentry | United States | 90 days, automatic deletion |
| Payments | Stripe | United States | Per provider policy and tax requirements |
10 How changes work
10.1 Adding a subprocessor
Pathly gives at least 30 days' notice before a new subprocessor begins processing, by updating this page and emailing the address on your account. To receive change notices directly, write to legal@pathly.com.
10.2 If you object
Tell us at legal@pathly.com within 15 days with the specific privacy or security concern, and we will work in good faith to address it.
- Counselor plans. If we cannot resolve it, your remedy is to terminate before the change takes effect and receive a pro-rata refund of prepaid, unused fees.
- Partner School agreements. Objection and resolution follow Section 6.3 of the Student Data and Privacy Addendum, including the right of either party to terminate without penalty where a critical subprocessor concern cannot be resolved.
10.3 Moving between listed AI providers
Routing a request to a different provider already listed in Section 4 is not the addition of a new subprocessor. Pathly reflects such changes on this page. Adding a provider that is not listed follows the 30-day process above.
10.4 Removing a subprocessor
When Pathly stops using a subprocessor, this page is updated and the provider is required to delete or return the data it holds.
10.5 Requesting documentation
Partner Schools may request subprocessor data processing agreements, redacted for commercial confidentiality, and provider security certifications, under Section 6.4 of the Student Data and Privacy Addendum. Counselor plans are served by this published page, under Section 12.1 of the Counselor DPA.