Subprocessors
Where service data can go.
This list covers providers used by the current Seneca codebase. A school’s signed schedule must narrow it to the features actually enabled for that program.
| Provider | Purpose and possible data | Location / transfer | School-pilot status |
|---|---|---|---|
| Supabase Pte. Ltd. | Authentication, PostgreSQL database, object storage. Account identifiers and learning records. | Primary Seneca project: Singapore (ap-southeast-1); support and subprocessors may involve other locations under provider terms. | Required infrastructure; school agreement and deletion test required. |
| Netlify, Inc. | Site delivery and serverless application functions. Request metadata and content sent to an enabled feature. | Distributed service; processing location is not limited to Singapore. | Required infrastructure; contract terms must be reviewed. |
| Google LLC | Optional Google sign-in, read-only Gmail invitation detection, read-only Classroom import, and Gemini API feedback/extraction. Data varies by feature. | Global provider. Gemini API prompts and outputs are retained by Google for 55 days solely for abuse monitoring, then deleted; Google does not state where that copy is held. | Each feature opt-in. Paid, billing-enabled Gemini API project (verified September 22, 2026). School-program material is sent to Gemini only where the school's signed schedule names it. |
| Anthropic, PBC | Not a subprocessor since September 20, 2026: no Seneca feature sends data to the Claude API. Anthropic receives data only when a learner connects Claude to their own record, as a recipient the learner chose. | Not applicable. | Not used. |
Model training
Vindica does not use school-program data to train a general-purpose model and will not opt school data into provider training. Seneca calls the Gemini API from a paid, billing-enabled Cloud project, verified on September 22, 2026. Under Google's Gemini API Additional Terms (effective March 23, 2026), for paid services “Google doesn't use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products.” Google “retains the following data for fifty-five (55) days for the purposes of detecting and preventing violations of the Prohibited Use Policy” and then deletes it. Human review is not part of the paid tier's terms. No Seneca feature calls the Anthropic or OpenAI API.
Encryption
All traffic is HTTPS with HSTS enforced. Supabase states that “all customer data is encrypted at rest with AES-256” and in transit via TLS, and that its platform is SOC 2 Type 2 compliant and ISO 27001 certified. Those are Supabase's attestations for its platform; Vindica holds no certification of its own. Access tokens, client secrets and PINs are stored only as one-way hashes. Column-level encryption is not in use: records are protected by row-level security and the platform's disk encryption.
Primary references: Gemini API terms, Gemini API usage policies (55-day retention), Supabase security, Anthropic commercial training explanation, and Supabase regions.
Change notice
For an executed school agreement, subprocessor additions and notice timing must be set in that agreement. This public page alone does not create a notice period or right to object.