This document is provided for informational purposes during our pre-launch period. A comprehensive, attorney-reviewed version will be published prior to the platform processing student data.
TRANSPARENCY
Subprocessor List
Every third-party service provider used to deliver SPEDScribe.
Last reviewed: April 2026
SPEDScribe.ai uses the following third-party service providers (subprocessors) to deliver our platform. Every subprocessor named below is contracted under a Data Processing Agreement. Anthropic does not use API inputs for model training by default. AssemblyAI processes audio in real-time and does not retain recordings after transcription.
| VENDOR | CATEGORY | PURPOSE | DATA PROCESSED | LOCATION |
|---|---|---|---|---|
| Anthropic | Clinical Intelligence Engine | AI-powered documentation generation (Claude API) | De-identified session transcripts only (PII redacted before processing) | United States |
| AssemblyAI | Speech Recognition | Audio transcription with automatic PII redaction | Session audio recordings; transcripts with PII redacted and deleted after processing | United States |
| Supabase | Database Infrastructure | Encrypted storage of session data and documentation | Account data, de-identified transcripts, generated documentation | United States (US West region) |
| Vercel | Hosting & Deployment | Web application hosting and content delivery | Application code, static assets, request logs (no student data) | United States |
| Clerk | Authentication | User identity verification and SSO | User credentials, session tokens, profile metadata | United States |
| Microsoft Presidio | PII Redaction (self-hosted) | Open-source PII detection and scrubbing layer running on SPEDScribe infrastructure | In-process transcript text only — Presidio is a library, not a hosted service, so no data leaves SPEDScribe | Self-hosted on Vercel (United States) |
| Sentry | Error Monitoring | Production error tracking and stack-trace collection. Session replays disabled per FERPA. | Error metadata with PII scrubbed before send (no email, cookies, request bodies, or query strings). No user-identifying data sent. All Sentry events are stripped of user context before send. | United States |
| Plausible Analytics | Privacy-First Analytics | Cookieless aggregate pageview and event tracking. No personal data collected. GDPR-friendly by design. | Aggregate pageviews, outbound link clicks, custom event names with no personal data props. | European Union |
Note on GoHighLevel: GoHighLevel is NOT listed as a subprocessor because it does not process student data. It is used exclusively for demo booking and sales-contact forms and receives only business contact information (name, email, district name) from prospective customers.
Change Notification
We provide 30 days advance written notice before adding new subprocessors or materially changing the role of existing subprocessors. Notice is provided via email to the designated district privacy contact.
To subscribe to subprocessor change notifications, contact: compliance@spedscribe.ai
Questions
For questions about our subprocessors or data processing practices, contact privacy@spedscribe.ai.