Service Providers and Subprocessors
Groves Holdings LLC, doing business as GradePath, uses the providers below to operate selected features. A provider processes only the data needed for features that are enabled and used. Provider locations and subprocessors can vary by account configuration and the provider's own infrastructure.
Current infrastructure and processing providers
| Provider | Role | Data that can be processed | Current boundary |
|---|---|---|---|
| Supabase, Inc. | Authentication, database, and private object storage | Account and course context, Private Content, raw audio, transcripts, Course Commons artifacts and trust records, referrals, subscription entitlement state, and provider-event records. | Raw capture storage is private and owner-scoped. Provider region and retention depend on the configured account. |
| Vercel Inc. | Website, API, function, and delivery infrastructure | Request and response data processed by web and mobile APIs, IP address, route, timestamps, logs, and limited operational metadata. | Sensitive content should not be intentionally written to general logs. Global delivery infrastructure can process network data in multiple locations. |
| OpenAI, L.L.C. | Private audio transcription and routed text generation | Selected raw audio, which can include instructor or classmate voices; prompts; authorized source excerpts; private transcript or note text; limited course and conversation context; and technical request metadata. | Transcription and text requests run only when the relevant feature is enabled and invoked. Region, retention, abuse monitoring, and contract terms depend on the configured provider account. |
| Anthropic, PBC | Tutor and other text generation | Prompts, authorized source excerpts, private transcript or note text, limited course and conversation context, and technical request metadata. | GradePath uses the commercial API path. Provider retention and contract terms depend on the configured provider account. |
| PostHog, Inc. | Product analytics, web performance, and heatmaps | Identifiers, page and selected feature interactions, device and browser data, network data, performance, and campaign attribution. | Browser collection begins only after browser permission through Allow analytics. Session replay is disabled. Used for GradePath product measurement and reliability, not targeted advertising. |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Error details, stack traces, app and browser data, route, identifiers, timestamps, and redacted request metadata. | Content minimization and redaction must remain enabled and tested. |
| Stripe, Inc. | Direct web subscription billing and fraud prevention | Customer, subscription, invoice, settlement, refund, dispute, device, and fraud data. Stripe collects payment details directly. | GradePath receives limited status and identifier data needed to administer subscription access. |
| Cloudflare, Inc. | DNS and support-email routing | Domain and network metadata plus email metadata and content sent to GradePath support through configured routing. | The confirmed public contact is [email protected]. |
Platform and user-directed providers
The following providers may act in their own platform role or at the user's direction rather than solely as a GradePath subprocessor.
| Provider | Role | Data that can be exchanged |
|---|---|---|
| Apple Inc. | App Store distribution, in-app subscription billing, transaction status, and Apple authentication where offered. | Apple Account-linked purchase or authentication data, product and transaction identifiers, entitlement, renewal, cancellation, and refund state. GradePath does not receive full Apple payment credentials. |
| Google LLC | Authentication and any user-directed Google connection that is actually offered. | Profile, email, authentication tokens, and the specific data a user authorizes for an enabled connection. |
Private Content and Course Commons boundary
Raw audio, raw transcripts, and capture transcripts remain Private Content and cannot be sent to Course Commons. OpenAI can receive raw audio only for requested transcription. OpenAI or Anthropic can receive authorized private or Commons excerpts for requested AI features. Other students receive only an eligible derivative that a contributor deliberately submits to the authorized exact-course scope.
Changes and questions
We may change providers as the service changes and will update this page when provider roles materially change. GradePath does not currently offer institutional advance-notice terms. Questions can be sent to [email protected].