← Back

Subprocessors

Last updated: August 21, 2026 · Version v6
Contents
  1. What "subprocessor" means here
  2. Retention windows are independent
  3. The current list
  4. Anthropic, PBC
  5. Supabase, Inc.
  6. Stripe, Inc.
  7. Lovable Labs Incorporated (development platform and managed email delivery)
  8. Amazon Web Services, Inc. (cloud infrastructure underlying Supabase)
  9. Error monitoring and analytics
  10. What we do NOT use
  11. How we evaluate subprocessors
  12. Notice of changes to this list
  13. Subprocessor change history
  14. Contact

Advoly Subprocessors

Last updated: August 21, 2026 Last reviewed: August 21, 2026

Advoly uses a small set of trusted third-party service providers ("subprocessors") to operate the Advoly mobile and web applications. We publish this list so that you, as a parent or guardian uploading sensitive records about your child, can see exactly who is downstream in the picture. (During our beta period, Advoly is available to Texas residents only - see our Terms of Service and Privacy Policy.)

This page is updated when our subprocessor relationships change. For material additions or substitutions in a sensitive role (AI processing, database hosting, document storage, key management, or any new role that handles document body text), we aim to provide at least 30 days' advance notice where practicable - through this page, by email to active paid subscribers, and to anyone who has subscribed to subprocessor change notifications. For changes required for security, legal compliance, or service continuity, notice may be shorter or may follow the change. To subscribe, email support@advoly.com with the subject "Subscribe to subprocessor notifications."

# What "subprocessor" means here

A subprocessor is a third-party company we use to operate the Services. Each subprocessor processes information only as needed for its specific role (for example, Stripe processes payments; Anthropic processes AI requests) and only under a written data processing agreement that restricts its use of the data.

A subprocessor is not a recipient. We do not "share" your data with subprocessors in the sense that they receive it for their own purposes. They process it on our behalf, on our instructions, subject to our agreements with them.

# Retention windows are independent

When you delete a document or your account from Advoly, our cascade-delete removes your data from our live database and our document storage immediately, transactionally rather than eventually. Advoly does not operate a separate backup system; backups are operated by our hosting platform and your deleted data ages out of them within roughly 14 days (90 days at the outside). In addition, our subprocessors maintain their own retention windows for their own purposes, which run independently of Advoly's deletion:

Our AI provider retains commercial-API requests for a limited period for abuse-monitoring before deletion (see the Anthropic entry below).

Our hosting platform retains platform-level database backups on its own schedule - approximately 14 days (see the Supabase entry below).

We do not control these subprocessor retention timers. We disclose them honestly. They are real, and they are bounded; but if you are deleting your account because you want every trace of your data gone immediately, you should know that the AI provider's request log for prior requests will continue running on its own clock.

# The current list

# Anthropic, PBC

Role: AI model provider. Anthropic is currently our AI provider for all production AI features.

What it does for Advoly: Powers the Pocket Advocate AI, the IEP Audit feature, the Meeting Prep features, the Draft Emails generator, and any other AI-driven feature in Advoly, plus the supporting flows listed below. There are four distinct data flows from Advoly to Anthropic:

  1. Grounding context for AI features. When you use an AI feature, Advoly's servers assemble a "grounding context" from the active Child Profile's record and send it, along with your prompt, to Anthropic's Claude API. The grounding context typically includes your profile, intake answers, Events Log entries, and excerpts of the decrypted body text of relevant educational records (for example, the IEP your child's school provided). Anthropic processes the request and returns the AI response, which we deliver to your app.
  2. OCR for image-based documents. When a document is image-based (a scanned PDF without a text layer, a photo of a physical document) and standard text extraction returns no text, Advoly sends the document - including the images it contains - to Anthropic's vision-capable model for text extraction. The extracted text is then stored encrypted in your account record and used the same way text-extracted document content is used. Whether a document enters this OCR flow is governed by the document type assigned at upload (see Privacy Policy §10.1).
  3. Family-identity extraction (account integrity). When you upload an IEP, the document text is sent to Anthropic to extract the parent/guardian names and household address listed in it. The extracted fields are stored on the Child Profile and used to enforce the one-household, up-to-four-Child-Profiles account rule; an Advoly admin reviews them only when the profiles on one account don't appear to belong to the same household (see Privacy Policy §5.4).
  4. Chat relevance classification (account integrity). Each message you send to the Pocket Advocate is sent to Anthropic to be classified as on-topic or off-topic relative to the active Child Profile, to deter account sharing. The resulting per-message flag is stored with your chat history (see Privacy Policy §5.5).

What we send to Anthropic, and what we don't.

  • Advoly does not accept medical records, prescription information, insurance documents, or similar medical-care content. Uploads identified as medical records (based on the document's filename and upload information) are refused and not saved (and our Terms prohibit uploading them). A refused upload's content is not retained by Advoly.
  • For educational records - IEPs, school correspondence, behavior plans, progress reports, ARD/IEP notes, and similar - body text is encrypted in our database, then decrypted and sent to Anthropic in the moment AI features are used, as described in flow 1.
  • Data shared. The text of documents you upload, including educational evaluations and the scores and findings they contain, plus your notes, events, and messages to Maya - sent when you use an AI feature. The provider does not train models on this information and does not retain it beyond its stated processing window.
  • Document text extraction (including image-based PDFs). Scanned or photographed documents, including evaluations, are processed to convert their images to text. Evaluation pages are included. See Privacy Policy §10.1 for the best-effort document-type identification limits.

Data categories processed: AI prompts, Events Log content, profile and intake fields, decrypted body-text excerpts of educational records, image-based document content sent for OCR, parent/guardian names and household address (identity extraction), and Pocket Advocate message text (relevance classification). May include sensitive information about your child where that information is in the records or needed to answer your question.

No model training. Advoly is a commercial-API customer of Anthropic, operating under Anthropic's standard Commercial Terms of Service and standard Data Processing Addendum. Under those terms, Anthropic does not use commercial-API traffic to train Anthropic's models. This applies to all four flows above.

Anthropic's commercial-API retention. Anthropic retains commercial-API requests and responses for a limited period for abuse-monitoring and trust-and-safety purposes before deletion. This retention runs independently of Advoly's deletion of your account. Once a request has been sent to Anthropic, Anthropic's retention timer for that request is on Anthropic's clock, not Advoly's. For the current published retention window and the full text of Anthropic's commercial terms, see the Anthropic links below - those are the authoritative sources.

Note on Anthropic's separate consumer Claude.ai service. Anthropic operates a separate consumer product (Claude.ai) under different terms. Anthropic's consumer-product changes - including the September 28, 2025 introduction of an opt-in toggle for consumer Claude.ai users to share conversations for model training - do not apply to commercial-API customers like Advoly.

Location of processing: United States.

  • Anthropic's commercial terms: https://www.anthropic.com/legal/commercial-terms
  • Anthropic's privacy posture: https://www.anthropic.com/legal/privacy
  • Anthropic's data usage and retention details: https://privacy.claude.com/
  • DPA reference: Anthropic's Data Processing Addendum, executed and on file.

# Supabase, Inc.

Role: Backend hosting (database, key management, file storage, edge functions, authentication).

What it does for Advoly: Supabase plays four distinct operational roles for Advoly:

  1. Postgres database hosting - your account information, profile, intake, Child Profile information, Events Log entries, and document metadata are stored in a Supabase-managed Postgres database. The body text of educational records is stored in a dedicated table (document_extracted_text) as AES-256-GCM ciphertext in a bytea column, with row-level security scoping reads to the authenticated owning user.
  2. Vault (key management) - the AES-256-GCM encryption key Advoly uses to encrypt and decrypt document body text is stored in Supabase Vault, the platform's native secrets manager. The key is controlled by Advoly LLC (it is not the platform's default-managed key); Vault is the storage substrate. Application code reads the key into module-level cache at function start so the key never appears in logs or error traces.
  3. Storage - original document files (PDFs, Word documents, etc.) you upload are stored in Supabase Storage buckets, RLS-scoped to the owning user, encrypted at rest by the platform.
  4. Edge Functions (serverless compute) - Supabase Edge Functions run the document-extraction pipeline (PDF and DOCX text extraction), the AI request orchestration (assembling grounding context and calling the AI provider, including the OCR, identity-extraction, and relevance-classification flows described in the Anthropic entry), and the per-user account-export endpoint.

Data categories processed: Substantially all User Content and account information. The encrypted document body-text column uses AES-256-GCM with an Advoly-controlled key. Other tables and the Storage bucket are encrypted at rest by the Supabase platform itself.

Supabase platform backups. Supabase maintains automated daily platform-level backups of the database tier, currently retained for approximately 14 days. Advoly does not operate a separate backup system of its own. When you delete data from Advoly, the live row is deleted immediately by cascade; your data then ages out of the platform backups within that window (and in no event later than 90 days).

Location of processing: United States (AWS infrastructure, provisioned through Lovable Cloud).

  • Supabase's privacy posture: https://supabase.com/privacy
  • DPA reference: Supabase's Data Processing Addendum, executed and on file.

# Stripe, Inc.

Role: Payments and subscription management.

What it does for Advoly: Processes subscription payments. Stores your payment method on Advoly's behalf. Handles recurring billing, refunds, and chargebacks.

Data categories processed: Payment method information (which Advoly does not see or store), subscription status, billing email.

Location of processing: United States.

  • Stripe's privacy posture: https://stripe.com/privacy
  • DPA reference: Stripe Services Agreement and Data Processing Addendum.

# Lovable Labs Incorporated (development platform and managed email delivery)

Role: Application development and hosting platform; managed transactional email delivery.

What it does for Advoly: Advoly is built and deployed on the Lovable platform, which manages the backend infrastructure described in the Supabase entry on Advoly's behalf. Lovable's managed email service sends Advoly's account emails (password resets, account confirmations, security notices) from the advoly.app domain. Lovable also provides the platform's built-in analytics for the published app - aggregate page views and performance metrics, not used for advertising or cross-site tracking.

Data categories processed: For email delivery: recipient email address and the subject and body of sent messages (account emails do not include the contents of your documents or conversations). For platform analytics: aggregate usage and performance metrics. As platform operator: administrative access to the infrastructure described in the Supabase entry, governed by its terms and privacy policy.

Location of processing: United States.

  • Privacy posture: https://lovable.dev/privacy

Note on email delivery: Lovable operates email delivery as a managed platform service and does not publicly name downstream delivery infrastructure; delivery is governed by Lovable's terms and privacy policy.

# Amazon Web Services, Inc. (cloud infrastructure underlying Supabase)

Role: Underlying cloud infrastructure for Supabase.

What it does for Advoly: Provides physical compute, storage, and network infrastructure for the Supabase services that store and serve your data - including the database, Vault, Storage buckets, and Edge Functions described in the Supabase entry.

Data categories processed: Same as Supabase, at the infrastructure layer. Encrypted at rest at the storage layer.

Location of processing: United States.

  • Privacy posture: https://aws.amazon.com/privacy/

# Error monitoring and analytics

Advoly does not currently use a third-party error-monitoring service (such as Sentry) or a third-party analytics provider. The only analytics are the hosting platform's built-in aggregate metrics, described in the Lovable entry above. If we add either category of provider, it will be added to this list with notice as described at the top of this page.

# What we do NOT use

For clarity, Advoly does not use:

  • Advertising networks (Google Ads, Meta Pixel, TikTok Pixel, etc.) - we do not advertise to you, and we do not allow advertisers to target you.
  • Data brokers.
  • Marketing automation platforms with access to User Content.
  • Any OCR provider other than our AI provider. Text-extractable PDF and DOCX content is parsed inside our own Supabase Edge Functions and is not sent to any third-party OCR service. For image-based PDFs (scans without a text layer, photos of physical documents), text extraction is performed via Anthropic's vision capability under Anthropic's commercial-API terms - described in the Anthropic entry above. We do not currently use any other OCR provider. Audio transcription is not currently offered; if it becomes a feature, we intend to update this list and provide notice as described below.
  • Any AI provider other than Anthropic for production AI features - currently. Anthropic is currently our AI provider for all production AI features, including the OCR, identity-extraction, and relevance-classification flows described above. We may evaluate other providers for internal engineering purposes using non-user data. If we add or substitute an AI provider that will handle user data, we will update this list, and we aim to provide advance notice - typically at least 30 days where practicable - as described under "Notice of changes to this list" below. We state this in the present tense deliberately: it is a description of today's architecture, not a forever promise, and the notice mechanism is designed so that you hear about changes before they happen.

# How we evaluate subprocessors

Before adding a subprocessor that will handle user data, our practice is to evaluate it against the following criteria. These criteria describe how we select vendors; they are not a warranty of any subprocessor's performance, and we retain discretion in how we apply them:

  • The subprocessor must offer a written Data Processing Addendum (DPA) that contractually limits its use of data to providing the contracted service.
  • The subprocessor must maintain industry-standard security practices appropriate to its role (for example, SOC 2 Type II attestation for our database and infrastructure providers).
  • For AI providers, the subprocessor must contractually agree not to train models on Advoly customer data.
  • For subprocessors playing a key-management role (such as our backend host's secrets manager), the subprocessor must support customer-controlled keys in a hosted vault, must scope key access to authenticated server-side roles only, and must not expose key material to client applications under any circumstances.
  • The subprocessor must offer reasonable transparency about its own subprocessors and security incidents.

# Notice of changes to this list

We update this page when our subprocessors change. For material changes - adding a new subprocessor that will handle User Content, or substituting a subprocessor in a sensitive role like AI processing, database hosting, document storage, or key management - we aim to provide at least 30 days' advance notice where practicable, through this page and by email to active paid subscribers, and to anyone subscribed via support@advoly.com. For changes required for security, legal compliance, or service continuity, notice may be shorter or may follow the change.

You always retain the right to delete your account and your data if a change to our subprocessor list is unacceptable to you.

# Subprocessor change history

June 12, 2026: Initial subprocessor list published, reflecting the architecture as of publication: Anthropic's four data flows, Supabase's database/Vault/Storage/Edge Functions roles, Stripe, Lovable (platform and managed email), and AWS.

# Contact

  • Subscribe to subprocessor change notifications: support@advoly.com (subject: "Subscribe to subprocessor notifications").
  • Other questions about subprocessors: support@advoly.com.

Disclaimer

Advoly LLC is not a law firm. Advoly and its AI features are not a substitute for the advice of an attorney, and nothing you store in or send through Advoly is protected by attorney-client privilege. Advoly does not refer you to, connect you with, or share your information with any attorney or law firm.

Terms of ServicePrivacy PolicySubprocessors