Last updated: August 21, 2026 Last reviewed: August 21, 2026
Advoly uses a small set of trusted third-party service providers ("subprocessors") to operate the Advoly mobile and web applications. We publish this list so that you, as a parent or guardian uploading sensitive records about your child, can see exactly who is downstream in the picture. (During our beta period, Advoly is available to Texas residents only - see our Terms of Service and Privacy Policy.)
This page is updated when our subprocessor relationships change. For material additions or substitutions in a sensitive role (AI processing, database hosting, document storage, key management, or any new role that handles document body text), we aim to provide at least 30 days' advance notice where practicable - through this page, by email to active paid subscribers, and to anyone who has subscribed to subprocessor change notifications. For changes required for security, legal compliance, or service continuity, notice may be shorter or may follow the change. To subscribe, email support@advoly.com with the subject "Subscribe to subprocessor notifications."
A subprocessor is a third-party company we use to operate the Services. Each subprocessor processes information only as needed for its specific role (for example, Stripe processes payments; Anthropic processes AI requests) and only under a written data processing agreement that restricts its use of the data.
A subprocessor is not a recipient. We do not "share" your data with subprocessors in the sense that they receive it for their own purposes. They process it on our behalf, on our instructions, subject to our agreements with them.
When you delete a document or your account from Advoly, our cascade-delete removes your data from our live database and our document storage immediately, transactionally rather than eventually. Advoly does not operate a separate backup system; backups are operated by our hosting platform and your deleted data ages out of them within roughly 14 days (90 days at the outside). In addition, our subprocessors maintain their own retention windows for their own purposes, which run independently of Advoly's deletion:
Our AI provider retains commercial-API requests for a limited period for abuse-monitoring before deletion (see the Anthropic entry below).
Our hosting platform retains platform-level database backups on its own schedule - approximately 14 days (see the Supabase entry below).
We do not control these subprocessor retention timers. We disclose them honestly. They are real, and they are bounded; but if you are deleting your account because you want every trace of your data gone immediately, you should know that the AI provider's request log for prior requests will continue running on its own clock.
Role: AI model provider. Anthropic is currently our AI provider for all production AI features.
What it does for Advoly: Powers the Pocket Advocate AI, the IEP Audit feature, the Meeting Prep features, the Draft Emails generator, and any other AI-driven feature in Advoly, plus the supporting flows listed below. There are four distinct data flows from Advoly to Anthropic:
What we send to Anthropic, and what we don't.
Data categories processed: AI prompts, Events Log content, profile and intake fields, decrypted body-text excerpts of educational records, image-based document content sent for OCR, parent/guardian names and household address (identity extraction), and Pocket Advocate message text (relevance classification). May include sensitive information about your child where that information is in the records or needed to answer your question.
No model training. Advoly is a commercial-API customer of Anthropic, operating under Anthropic's standard Commercial Terms of Service and standard Data Processing Addendum. Under those terms, Anthropic does not use commercial-API traffic to train Anthropic's models. This applies to all four flows above.
Anthropic's commercial-API retention. Anthropic retains commercial-API requests and responses for a limited period for abuse-monitoring and trust-and-safety purposes before deletion. This retention runs independently of Advoly's deletion of your account. Once a request has been sent to Anthropic, Anthropic's retention timer for that request is on Anthropic's clock, not Advoly's. For the current published retention window and the full text of Anthropic's commercial terms, see the Anthropic links below - those are the authoritative sources.
Note on Anthropic's separate consumer Claude.ai service. Anthropic operates a separate consumer product (Claude.ai) under different terms. Anthropic's consumer-product changes - including the September 28, 2025 introduction of an opt-in toggle for consumer Claude.ai users to share conversations for model training - do not apply to commercial-API customers like Advoly.
Location of processing: United States.
Role: Backend hosting (database, key management, file storage, edge functions, authentication).
What it does for Advoly: Supabase plays four distinct operational roles for Advoly:
document_extracted_text) as AES-256-GCM ciphertext in a bytea column, with row-level security scoping reads to the authenticated owning user.Data categories processed: Substantially all User Content and account information. The encrypted document body-text column uses AES-256-GCM with an Advoly-controlled key. Other tables and the Storage bucket are encrypted at rest by the Supabase platform itself.
Supabase platform backups. Supabase maintains automated daily platform-level backups of the database tier, currently retained for approximately 14 days. Advoly does not operate a separate backup system of its own. When you delete data from Advoly, the live row is deleted immediately by cascade; your data then ages out of the platform backups within that window (and in no event later than 90 days).
Location of processing: United States (AWS infrastructure, provisioned through Lovable Cloud).
Role: Payments and subscription management.
What it does for Advoly: Processes subscription payments. Stores your payment method on Advoly's behalf. Handles recurring billing, refunds, and chargebacks.
Data categories processed: Payment method information (which Advoly does not see or store), subscription status, billing email.
Location of processing: United States.
Role: Application development and hosting platform; managed transactional email delivery.
What it does for Advoly: Advoly is built and deployed on the Lovable platform, which manages the backend infrastructure described in the Supabase entry on Advoly's behalf. Lovable's managed email service sends Advoly's account emails (password resets, account confirmations, security notices) from the advoly.app domain. Lovable also provides the platform's built-in analytics for the published app - aggregate page views and performance metrics, not used for advertising or cross-site tracking.
Data categories processed: For email delivery: recipient email address and the subject and body of sent messages (account emails do not include the contents of your documents or conversations). For platform analytics: aggregate usage and performance metrics. As platform operator: administrative access to the infrastructure described in the Supabase entry, governed by its terms and privacy policy.
Location of processing: United States.
Note on email delivery: Lovable operates email delivery as a managed platform service and does not publicly name downstream delivery infrastructure; delivery is governed by Lovable's terms and privacy policy.
Role: Underlying cloud infrastructure for Supabase.
What it does for Advoly: Provides physical compute, storage, and network infrastructure for the Supabase services that store and serve your data - including the database, Vault, Storage buckets, and Edge Functions described in the Supabase entry.
Data categories processed: Same as Supabase, at the infrastructure layer. Encrypted at rest at the storage layer.
Location of processing: United States.
Advoly does not currently use a third-party error-monitoring service (such as Sentry) or a third-party analytics provider. The only analytics are the hosting platform's built-in aggregate metrics, described in the Lovable entry above. If we add either category of provider, it will be added to this list with notice as described at the top of this page.
For clarity, Advoly does not use:
Before adding a subprocessor that will handle user data, our practice is to evaluate it against the following criteria. These criteria describe how we select vendors; they are not a warranty of any subprocessor's performance, and we retain discretion in how we apply them:
We update this page when our subprocessors change. For material changes - adding a new subprocessor that will handle User Content, or substituting a subprocessor in a sensitive role like AI processing, database hosting, document storage, or key management - we aim to provide at least 30 days' advance notice where practicable, through this page and by email to active paid subscribers, and to anyone subscribed via support@advoly.com. For changes required for security, legal compliance, or service continuity, notice may be shorter or may follow the change.
You always retain the right to delete your account and your data if a change to our subprocessor list is unacceptable to you.
June 12, 2026: Initial subprocessor list published, reflecting the architecture as of publication: Anthropic's four data flows, Supabase's database/Vault/Storage/Edge Functions roles, Stripe, Lovable (platform and managed email), and AWS.