Subprocessors

Version 1.1.0-draft · Effective 2026-08-10 · Last updated 2026-08-10

These are the providers involved in running ClassDay today, compiled from the running implementation. A provider is only listed once it is actually in use; we do not pad this list with vendors we might adopt later. Where an entry is marked unconfirmed, we have inferred it from our own configuration and have not yet confirmed it against the vendor's documentation or a contract.

Current subprocessors

Lovable

Application platform: builds, hosts and serves the ClassDay web app and its server functions.

Data categories
  • Account identifiers
  • Request metadata (IP address, user agent)
  • Application and error logs
Processing location
to be confirmed
Transfer mechanism
to be confirmed

Supabase

Managed database, authentication and private file storage used through Lovable Cloud.

Data categories
  • Account and authentication data
  • Profile details
  • Course, syllabus, lesson and progress records
  • Uploaded files and extracted text
  • Usage and rate-limit records
  • Diagnostic error events (error type, short scrubbed message, page path, request ID)
Processing location
to be confirmed
Transfer mechanism
to be confirmed

Lovable AI Gateway

Routes model requests from ClassDay's server functions to the underlying model provider, and records token/cost metering.

Data categories
  • Prompts assembled by ClassDay (course context, retrieved excerpts of your uploads, your questions and answers)
  • Model outputs
  • Token counts and request metadata
Processing location
to be confirmed
Transfer mechanism
to be confirmed

OpenAIunconfirmed

Underlying large-language-model provider reached through the Lovable AI Gateway. ClassDay currently calls the GPT-5.6 family for curriculum design, lesson generation, answer feedback and tutor replies.

Data categories
  • Prompt content
  • Model outputs
Processing location
to be confirmed
Transfer mechanism
to be confirmed

Google

Identity provider for optional "Continue with Google" sign-in. Used only when you choose that sign-in method.

Data categories
  • Google account identifier
  • Email address
  • Name and profile picture, where provided
Processing location
to be confirmed
Transfer mechanism
to be confirmed

Categories we do not currently use

To be explicit about what is absent, none of the following is part of ClassDay today. Account emails such as confirmation and password reset are sent by the authentication service listed above.

  • Payment processor
  • Product analytics
  • Marketing / advertising platform
  • Third-party error-monitoring service (error diagnostics stay inside ClassDay's own database; no external monitoring vendor is used)
  • Standalone transactional email provider (account emails are sent by the authentication service)
  • Customer support helpdesk software

Changes to this list

We will update this page before a new provider begins processing personal data, and note the change in the Legal Center. To ask about a specific vendor's terms, use the privacy contact route once it is published (to be confirmed).