This document is provided for informational purposes during our pre-launch period. A comprehensive, attorney-reviewed version will be published prior to the platform processing student data.

TRANSPARENCY

Subprocessor List

Every third-party service provider used to deliver SPEDScribe.

Last reviewed: April 2026

SPEDScribe.ai uses the following third-party service providers (subprocessors) to deliver our platform. Every subprocessor named below is contracted under a Data Processing Agreement. Anthropic does not use API inputs for model training by default. AssemblyAI processes audio in real-time and does not retain recordings after transcription.

VENDORCATEGORYPURPOSEDATA PROCESSEDLOCATION
AnthropicClinical Intelligence EngineAI-powered documentation generation (Claude API)De-identified session transcripts only (PII redacted before processing)United States
AssemblyAISpeech RecognitionAudio transcription with automatic PII redactionSession audio recordings; transcripts with PII redacted and deleted after processingUnited States
SupabaseDatabase InfrastructureEncrypted storage of session data and documentationAccount data, de-identified transcripts, generated documentationUnited States (US West region)
VercelHosting & DeploymentWeb application hosting and content deliveryApplication code, static assets, request logs (no student data)United States
ClerkAuthenticationUser identity verification and SSOUser credentials, session tokens, profile metadataUnited States
Microsoft PresidioPII Redaction (self-hosted)Open-source PII detection and scrubbing layer running on SPEDScribe infrastructureIn-process transcript text only — Presidio is a library, not a hosted service, so no data leaves SPEDScribeSelf-hosted on Vercel (United States)
SentryError MonitoringProduction error tracking and stack-trace collection. Session replays disabled per FERPA.Error metadata with PII scrubbed before send (no email, cookies, request bodies, or query strings). No user-identifying data sent. All Sentry events are stripped of user context before send.United States
Plausible AnalyticsPrivacy-First AnalyticsCookieless aggregate pageview and event tracking. No personal data collected. GDPR-friendly by design.Aggregate pageviews, outbound link clicks, custom event names with no personal data props.European Union

Note on GoHighLevel: GoHighLevel is NOT listed as a subprocessor because it does not process student data. It is used exclusively for demo booking and sales-contact forms and receives only business contact information (name, email, district name) from prospective customers.

Change Notification

We provide 30 days advance written notice before adding new subprocessors or materially changing the role of existing subprocessors. Notice is provided via email to the designated district privacy contact.

To subscribe to subprocessor change notifications, contact: compliance@spedscribe.ai

Questions

For questions about our subprocessors or data processing practices, contact privacy@spedscribe.ai.