TRUST / SUBPROCESSORS

Subprocessors and data purposes

The external services intended to operate CodeTutor accounts, hosted applications, managed AI, email, and billing.

Beta disclosure · Last updated

CodeTutor is operated as a public beta. Commercial launch is not complete. Operator identity, governing-law details, and production support contacts must be finalized before paid plans are offered.

1. Current intended service chain

CodeTutor minimizes cloud records, but a managed service still requires specialized infrastructure. The following providers are present in the production design; activation and region details must be verified before commercial launch.

ProviderPurposeTypical data
SupabaseAuthentication and account databaseIdentity, profile, sessions, preferences, learning sync, usage and ledger records
VercelHosted web/cloud functions and AI Gateway routingRequest metadata and transient managed-AI request content needed for generation
Upstream model providersGenerate the model response selected by the userTransient prompt context and necessary repository excerpts
StripeCheckout, subscription, tax, invoices, refunds and disputesCustomer, transaction, tax and payment records; CodeTutor does not receive full card details
ResendCustom authentication and transactional emailEmail address, delivery metadata and message content
GitHubSource hosting, releases, issue/support workflow and optional OAuthGitHub identity and activity when those features are used

2. Model choice

The selected model determines the upstream provider that processes a managed-AI request. CodeTutor must show the actual model identity and should not silently switch to another paid model. If a compatible fallback is offered, user approval and relevant price information are required.

3. Changes

Before adding a production subprocessor, CodeTutor should document its purpose, data boundary, security posture, retention, regional availability, and contractual role. Material changes require a new update date and an appropriate user notice.

4. Missing launch details

Final legal entity names, processing regions, transfer mechanisms, data-processing terms, and advance-notice period are not yet verified. They remain commercial launch blockers rather than being inferred here.