← Back to QuantegyAI

Subprocessor List

Last updated: August 27, 2026

This page lists the third-party service providers ("subprocessors") that QuantegyAI uses to operate the Services. We update this list when material changes occur. Institutional customers receive at least thirty days' advance written notice of any intended addition or replacement of a subprocessor. Each subprocessor is bound by a written agreement that imposes obligations equivalent to those in our Privacy Policy and our institutional Data Processing Addendum.

Function Subprocessor Country Categories of data
Application hosting and continuous deployment Netlify, Inc. United States HTTP request logs, deploy artefacts
Database, authentication, edge functions Supabase, Inc. United States All processed data: account info, learning interactions, audit events
Payment processing Stripe, Inc. United States Customer ID, subscription ID, billing email, payment metadata. Card data never reaches QuantegyAI.
Error monitoring Functional Software, Inc. d/b/a Sentry United States Stack trace, request correlation ID, optional user ID hash
Bot and abuse protection on sign-in / sign-up Cloudflare, Inc. (Turnstile) United States IP address, user-agent, and challenge-solving signals at the moment a form is submitted. No learning data.
Website analytics (consent-gated) Umami Software, Inc. United States Page URL, referrer, browser and device type, coarse country. Cookieless — nothing is stored in the visitor's browser. Marketing pages only; never the signed-in application, and not loaded at all unless the visitor accepts analytics cookies.
Marketing analytics and advertising Google LLC United States Marketing pages, plus the checkout-start and purchase-completed moments only inside the signed-in application (never anything else there), and only with the matching consent (analytics for Google Analytics, advertising for Google Ads): online identifiers, page and event interactions, approximate location from IP, and — for the two checkout events only — a plan name, exam, amount, and order reference. Google Analytics, Tag Manager and Google Ads. No learning data, ever.
Advertising and retargeting Meta Platforms, Inc. United States Marketing pages, plus the checkout-start and purchase-completed moments only inside the signed-in application (never anything else there), and only with advertising consent: online identifiers and page/event interactions collected by the Meta pixel, and — for the two checkout events only — a plan name, exam, amount, and order reference. No learning data, ever.
Domain registration and DNS GoDaddy.com, LLC United States Domain administrative contact only; no user data

Notes

Hosting and database. The application is deployed on Netlify; user-account data, progress, audit events, and Edge Functions live in Supabase. The selection of these subprocessors materially affects data residency; both currently operate in United States regions.

Email. Transactional email (verification, password reset, billing notices) is delivered through Supabase Auth's email pipeline. Marketing email is out of scope.

Stripe. Card data, CVV, and expiration date are entered directly into Stripe's hosted Checkout page; QuantegyAI receives only customer and subscription identifiers and the billing email. We retain those identifiers to apply entitlements and to process refunds.

Sentry. Active when configured. Scrubbing rules at the SDK level remove form values, headers, and cookies; only stack trace and correlation ID are forwarded.

Advertising and marketing platforms. QuantegyAI runs a paid advertising campaign using Google (Google Analytics, Google Ads and Google Tag Manager), Meta (advertising measurement and retargeting, including the Meta Pixel) and Mailchimp (marketing email). Advertising and analytics tags load only for visitors who have accepted the matching consent category, and are not used on institutional or cohort deployments at all. They are otherwise not present in the signed-in application, with one narrow, named exception: the checkout-start and purchase-completed moments, which report only a plan name, exam, amount and order reference — never anything about what a student studied or how they performed. See our Cookie Policy and Privacy Policy §2.2 for the full description of that exception.

Umami. Analytics are gated on consent: the script is not requested at all until the visitor accepts. Umami is cookieless and sets no browser storage. We do not send it any exam response, score, or mastery estimate.

Change log

August 25, 2026 — Added Cloudflare (Turnstile) and Umami, both already in use and previously unlisted. Added the standing note on advertising platforms ahead of the first campaign.

April 28, 2026 — Initial public list.

← Back to QuantegyAI