Sub- processors.

Last updated 6 September 2026

These are the companies that process personal data on our behalf so Bluestift can work. Each one is here for a single named purpose and has no right to use the data for anything else.

Where we are today. Bluestift has just launched. We are working through each provider's data processing agreement, including the standard contractual clauses that cover transfers out of the EEA and the UK. Until this page says a given agreement is in place, assume it is still in progress — and if that matters to your decision, ask us and we'll tell you exactly where it stands. We would rather be checkable than sound finished.

Current sub-processors

ProviderWhat it doesData it seesWhere
SupabaseDatabase, authentication and file storage — the system of recordEverything stored: accounts, conversations, uploads, learning signalsEU
VercelApplication hosting and scheduled jobsRequests in transit, server logsEU / US
RailwayHosts the Kernel — the cognitive engine that reads each tutoring exchange and maintains the model of what a learner understandsThe text of tutoring turns sent for analysis, learning signals, an account identifierUS
Google (Gemini)Generates Raya's repliesThe text of a tutoring turn and the context sent with itUS
GroqFallback model for replies, and speech-to-text for voiceThe text of a tutoring turn; recorded audio when voice is usedUS
PostHogProduct analytics — only for accounts that opted in, never under-18sPage views, a few product events, an account identifierEU
CloudflareTurnstile bot protection on public forms and sign-upA challenge token and network metadataGlobal
ResendTransactional email — join requests and their decisions, plan activation, payment receiptsEmail address and the message contentEU / US
CinetPayCard and mobile-money paymentsPayment details and the amount. We never store full card numbersAfrica / EU
StripeCard payments outside the mobile-money regionsPayment details and the amount. We never store full card numbersEU / US
Google ClassroomOptional LMS import, only for schools that connect itCourse and roster data the school chooses to shareUS

What we require of them

  • They process data only on our documented instructions, for the purpose named above.
  • We use model providers on their API terms, which do not feed content into training of their public models.
  • Transfers outside the EEA or the UK must be covered by Standard Contractual Clauses or an adequacy decision — see the note above on where we are with that.
  • They are bound to confidentiality and to appropriate security.

Changes

We update this page before a new sub-processor starts handling school data, and notify school administrators by email. A school may object on reasonable data protection grounds — see the data processing addendum.

Raya works without several of these. A school that has not connected Google Classroom is never touched by that row; an account that declined analytics is never touched by PostHog.

Questions: hello@thebluestift.com.