Version 1.1 · Effective August 2, 2026
To run PD That Works, we rely on a small number of service providers ("subprocessors") that process data on our behalf under our instructions. This page lists them, what each does, and the categories of data each handles. We do not sell personal information to any of them.
| Provider | What it does for us | Data it handles |
|---|---|---|
| Supabase | Database, sign-in/authentication, and file storage | Account data and all stored content, including Private Teacher Content |
| Anthropic | AI processing — generates coaching responses and report narratives (commercial API) | Teacher reflections, goals, and related coaching text |
| Stripe | Payments, subscriptions, and invoices | Billing and subscription details. Card numbers are entered with Stripe and are never stored by us. |
| Resend | Transactional email (account, coaching, and report messages) and internal alerts | Recipient email address and message content |
| Loops | Lifecycle and onboarding email automation | Contact email, name, and activity events |
| Vercel | Hosting and execution of the application (app.pdthatworks.com) | Request data in transit and application logs |
| Netlify | Hosting of the marketing website (pdthatworks.com) | Website request and hosting logs |
We currently do not use any advertising, cross-site tracking, or website-analytics providers.
Supabase — our database, authentication, and file storage — processes data in the US East region under a confirmed data-processing agreement.
Anthropic — our AI provider — processes data under Anthropic's Commercial Terms of Service, which incorporate its data-processing addendum and Standard Contractual Clauses. Under those terms our data is not used to train Anthropic's models without our express permission, which we have not given, and text sent to the API is deleted within 30 days. Content flagged by Anthropic's automated safety systems is the exception and may be kept longer; see section 5 of our Privacy Notice.
For the remaining providers — Stripe, Resend, Loops, Vercel, and Netlify — we are still confirming the executed data-processing agreement, processing region, and retention terms. Until each is confirmed in writing, we describe it as unconfirmed rather than summarize terms we have not verified. This page is updated as each one is settled.
We keep this page current. Before we add or change a subprocessor that handles personal data, we will update this page and provide notice. For schools, the specific notice mechanism and any objection window are set in the data-processing addendum to the school agreement. Questions: hello@pdthatworks.com.