Last updated: August 19, 2026
This list describes the vendors AntiBoTech currently uses or expects to use to operate the service. Contact [email protected] with privacy or subprocessor questions.
Purpose: Database, authentication, row-level security, storage, and private oral-audio bucket.
Data potentially processed: Teacher accounts, student accounts, rosters, assignments, essays, drafts, submissions, grades, comments, process events, oral sessions, transcripts, temporary raw oral audio, and operational metadata.
Purpose: AI grading, structured feedback, rubric/marking support, oral question generation, and oral summary features.
Data potentially processed: Assignment prompts, rubrics, calibration anchors, essays, selected spans, teacher notes, oral-defence context, transcripts, prompts/responses, and usage metadata.
Purpose: Speech-to-text transcription and selected feedback, polish, detection, or ensemble features where enabled.
Data potentially processed: Audio for transcription, transcripts, selected spans, teacher notes, essay/context prompts, prompts/responses, and usage metadata.
Purpose: Checkout, subscriptions, billing, tax/payment status, and top-ups.
Data potentially processed: Teacher billing identity, Stripe customer/subscription/payment IDs, invoices/receipts, payment status, and tax metadata. AntiBoTech does not store full card numbers.
Purpose: Transactional email.
Data potentially processed: Teacher or student email addresses where provided, verification/reset links, invitation links, submission confirmations, delivery metadata, and email content.
Purpose: Application hosting, network traffic, logs, and runtime environment.
Data potentially processed: Request metadata, server logs, app traffic, operational telemetry, and possibly user identifiers depending on logging configuration.
Sentry may be used for error monitoring if enabled. Error traces could include user IDs, route data, or accidental personal information, so PII scrubbing should be configured before use.
Langfuse may be used for observability only if enabled. Prompt/response observability can expose essays, prompts, rubrics, transcripts, or student data if wired carelessly, so prompt logging for student data should be limited.
Canvas, Moodle, Blackboard, or institutional LTI platforms are customer-controlled integrations. They may provide LMS user IDs, course IDs, roster data, assignment metadata, and submission metadata depending on the integration.
AntiBoTech should not publish a stronger vendor, residency, retention, no-training, compliance, or security claim than the signed vendor contract supports.