Subprocessors
Last updated: August 24, 2026
This is every third-party service that receives data from Mathmatix AI, what each one receives, why, and the terms it is used under. Mathmatix LLC is the operator of the service and the party responsible for this list.
Everything below runs in the United States. We do not sell or rent personal data, and no service on this list is permitted to use student data to train AI models. Schools on a signed agreement with us are notified before a subprocessor is added that would receive their students’ data.
AI and tutoring
| Service | What it does for us | What it receives | Terms |
|---|---|---|---|
| OpenAI | Generates the tutor’s replies; reads photographed homework for grading; text embeddings; fallback speech-to-text. | The tutoring conversation, plus grade level, learning preferences and any accommodations so the tutor can adapt; uploaded work images for grading. Before any request leaves our servers, on every path and for both AI providers, the student’s name is replaced with a placeholder and restored in the reply, and email addresses, phone numbers, street addresses, database ids and IEP goal specifics are removed. This is on by default and not a per-deployment option. Two things cannot be filtered: the pixels of an uploaded photo (a name written on the page goes with it) and the audio of a voice recording sent for fallback transcription. Teacher tools that describe a whole class (the lesson planner) replace student names with numbered labels and send accommodation types only, never IEP goal text or progress figures. OpenAI retains API requests for up to 30 days for abuse monitoring and does not train on them; we do not hold a zero-data-retention agreement with OpenAI. | Signed Data Processing Agreement |
| Anthropic | Independently checks the tutor’s math before an answer is treated as correct — a second model from a different provider, so the model that wrote the reply is never the one grading it. | The math problem and the answer being checked. Not the student’s identity. | Commercial API terms (no training on customer data). Anthropic’s Data Processing Addendum is incorporated into those terms by reference, so it applies to this account without a separately signed document. |
| Mathpix | Reads handwritten and printed math from uploaded photos and PDFs. | The uploaded image or document, with camera and location metadata already stripped. Every request is sent with Mathpix’s retention option turned off, so the upload is processed and discarded rather than kept to improve their models, and each PDF is deleted from Mathpix as soon as the text has been retrieved. Mathpix keeps only billing metadata (page counts and timestamps). | Business API terms |
| Deepgram | Speech-to-text for voice mode. | Microphone audio during a voice session. Voice mode is for users 13 and over; younger students are directed to a text-only flow. | Business API terms |
| Cartesia | Turns the tutor’s written reply into speech. | The tutor’s reply text. Not the student’s words. | Business API terms |
| Simli | Animates the tutor’s face to match its speech during avatar sessions. | The tutor’s synthesized speech audio only. No student audio, video or text is sent. | Business API terms |
| Google Custom Search | Finds educational images (diagrams, number lines) for the tutor to show. | A search query with names and identifiers removed, restricted to an education-site whitelist with SafeSearch enforced. No user identifier or cookie is sent. | Business API terms |
Accounts, sign-in and billing
| Service | What it does for us | What it receives | Terms |
|---|---|---|---|
| Google, Microsoft | Optional single sign-on. | Handled by the provider; we receive the name and email of the account that signed in. | Provider terms |
| Clever | School sign-on and roster sync, when a school chooses it. | Roster information the school shares through Clever: student and teacher names, class membership, school-assigned IDs. | Provider terms; governed by the school’s own agreement with Clever |
| Stripe | Subscription and school-license payments. | Payment details go directly to Stripe and are never stored on our servers. We hold only a customer reference and subscription status. | Stripe services agreement |
Infrastructure
| Service | What it does for us | What it receives | Terms |
|---|---|---|---|
| Render | Hosts the application. | All application traffic passes through it. Runs in Oregon, United States. | Business terms |
| MongoDB | Primary database. | Account and learning data. The most sensitive fields — session summaries, what a student struggled with — are encrypted at the field level before storage. | Business terms |
| Object storage (S3-compatible) | Stores uploaded homework photos and PDFs. | The uploaded files, deleted after 30 days. | Business terms |
| YouTube (Google) | Hosts and plays the lesson videos embedded on the course pages at /courses. |
When a student opens a page with a video, their browser contacts YouTube directly: IP address, browser details and, if they are signed in to a Google account, that identity. We embed through youtube-nocookie.com, which sets no cookie until playback starts. We send YouTube no account or roster data, and the course pages require no sign-in of ours. |
YouTube terms |
| Redis | Short-lived cache to keep tutoring responsive. | A student’s profile and most recent conversation, held for at most five minutes and thirty seconds respectively, then discarded. Used only when configured for the deployment. | Business terms |
| Transactional email (SMTP) | Account emails, parental-consent links, and the weekly progress digest. | Recipient email address; for digests, the child’s first name and a progress summary. | Business terms |
Monitoring
| Service | What it does for us | What it receives | Terms |
|---|---|---|---|
| Sentry | Reports server errors so we can fix them. | The error, the route it happened on, and an internal user ID for correlation. Request bodies, cookies, headers and IP addresses are stripped before sending, so no message content or session identifiers leave the server. | Business terms |
| Better Stack | Collects application logs. | Operational log lines with secrets redacted. May include internal user IDs and request paths; never passwords, tokens or message content. | Business terms |
| Google Analytics | Measures marketing-page traffic. | Standard page-view analytics on public marketing pages only. It is never loaded on any signed-in page — not the tutor, not a dashboard — and that boundary is enforced by an automated test in our codebase. | Google terms |
A Facebook Pixel integration exists in the codebase but is not enabled.
This list is maintained in step with the code: an automated test in our repository fails if a new third-party integration is added without an entry here. Questions, or a school data-privacy agreement to complete? Contact us. See also the Safety & Privacy overview and the Privacy Policy.
