Amosia Grid
HomeHow it worksFor schoolsGDPR & security
ENEnglishCZČeština
Sign inTry for free

Sub-processors list

These third parties process personal data on Amosia's behalf so that we can deliver the service to your school. Each is bound by a data-processing agreement that limits what it may do with the data, in line with the GDPR and applicable privacy rules. Your school remains the controller of its pupils' and staff's data and Amosia is its processor; where a provider below acts in a different role, its row says so.

Last reviewed on August 13, 2026

ProviderPurposePersonal data processedProcessing location
Vercel

Vercel Inc., USA

Hosting of the application, edge network and CDN, serverless compute, the web application firewall, the durable workflows that dispatch transactional e-mail, and the AI Gateway that routes requests to the language model.

All application data in transit, request and function logs, visitors' IP addresses, and the redacted prompts passed on to the language model.

Global edge network; compute and logs in the deployment's configured region.

PlanetScale

PlanetScale, Inc., USA

Managed PostgreSQL — the single database the whole application runs on.

All application data at rest: staff accounts (name, e-mail, password hash), sign-ins (IP address, browser), pupils (name, date of birth, notes), class rosters, teachers' observations, reflections, and the audit log.

The database cluster's configured cloud region.

Anthropic

Anthropic PBC, USA

Language-model inference for AI-drafted pupil reflections, reached through the Vercel AI Gateway. A draft is only ever a suggestion — a teacher reads, edits and approves it before it becomes a record. The model used is the one configured for your school; pointing that setting at another provider changes who processes the data, and this list with it.

The reflection prompt: the school's prompt text, teachers' observations, lesson progress, the current reflection, and — when a teacher asks for a rewrite — the draft on screen together with their instruction. The pupil's name and its variants are struck out of every free text before it leaves the application, and no account identifiers are sent.

USA.

Resend

Plus Five Five, Inc. (Resend), USA

Transactional e-mail — the password-reset and welcome messages sent to staff. Amosia sends no marketing e-mail.

The recipient's e-mail address and name, the school's name, and the message body including its single-use link.

USA.

Sentry

Functional Software, Inc. (Sentry), USA

Error monitoring, performance tracing and sampled session replay of the staff interface, plus the in-app feedback form, so that faults are found and can be reported.

Error events and stack traces, browser and device metadata, and sampled recordings of staff sessions. Automatic reporting carries no user identity, no AI inputs or outputs, no request bodies and no IP-bearing headers, cookies or query parameters. The in-app feedback form is the exception: it sends what the member writes, their e-mail address (prefilled from their account, editable and removable before sending) and a recording of the session.

EU (Germany) — the project uses Sentry's European data region.

Google

Google Ireland Limited, Ireland

The optional “Sign in with Google” button for staff accounts. Only staff who choose that button reach Google; signing in with e-mail and password does not. For the Google account itself, Google acts as an independent controller rather than as our sub-processor.

Google account identifier, e-mail address and display name, exchanged at sign-in.

EU and USA.

Vercel

Vercel Inc., USA

Purpose

Hosting of the application, edge network and CDN, serverless compute, the web application firewall, the durable workflows that dispatch transactional e-mail, and the AI Gateway that routes requests to the language model.

Personal data processed

All application data in transit, request and function logs, visitors' IP addresses, and the redacted prompts passed on to the language model.

Processing location

Global edge network; compute and logs in the deployment's configured region.

PlanetScale

PlanetScale, Inc., USA

Purpose

Managed PostgreSQL — the single database the whole application runs on.

Personal data processed

All application data at rest: staff accounts (name, e-mail, password hash), sign-ins (IP address, browser), pupils (name, date of birth, notes), class rosters, teachers' observations, reflections, and the audit log.

Processing location

The database cluster's configured cloud region.

Anthropic

Anthropic PBC, USA

Purpose

Language-model inference for AI-drafted pupil reflections, reached through the Vercel AI Gateway. A draft is only ever a suggestion — a teacher reads, edits and approves it before it becomes a record. The model used is the one configured for your school; pointing that setting at another provider changes who processes the data, and this list with it.

Personal data processed

The reflection prompt: the school's prompt text, teachers' observations, lesson progress, the current reflection, and — when a teacher asks for a rewrite — the draft on screen together with their instruction. The pupil's name and its variants are struck out of every free text before it leaves the application, and no account identifiers are sent.

Processing location

USA.

Resend

Plus Five Five, Inc. (Resend), USA

Purpose

Transactional e-mail — the password-reset and welcome messages sent to staff. Amosia sends no marketing e-mail.

Personal data processed

The recipient's e-mail address and name, the school's name, and the message body including its single-use link.

Processing location

USA.

Sentry

Functional Software, Inc. (Sentry), USA

Purpose

Error monitoring, performance tracing and sampled session replay of the staff interface, plus the in-app feedback form, so that faults are found and can be reported.

Personal data processed

Error events and stack traces, browser and device metadata, and sampled recordings of staff sessions. Automatic reporting carries no user identity, no AI inputs or outputs, no request bodies and no IP-bearing headers, cookies or query parameters. The in-app feedback form is the exception: it sends what the member writes, their e-mail address (prefilled from their account, editable and removable before sending) and a recording of the session.

Processing location

EU (Germany) — the project uses Sentry's European data region.

Google

Google Ireland Limited, Ireland

Purpose

The optional “Sign in with Google” button for staff accounts. Only staff who choose that button reach Google; signing in with e-mail and password does not. For the Google account itself, Google acts as an independent controller rather than as our sub-processor.

Personal data processed

Google account identifier, e-mail address and display name, exchanged at sign-in.

Processing location

EU and USA.

Amosia Grid

There is one north. There are as many paths as there are children.

© 2026 Amosia Labs s.r.o.

info@amosia.app

Legal

  • Terms of Service
  • Privacy Policy
  • Sub-processors list