QuantCore Learning Hub
Sub-processors
Last Updated: June 19, 2026
What this page is: A “sub-processor” is a vetted third-party service that helps us run the QuantCore Learning Hub and may process data on our behalf. We disclose every sub-processor here, what it does, and what data it receives. Each is bound by contract to confidentiality, security, and use restrictions equivalent to our own, and all are located in the United States. We update this list whenever a sub-processor is added or removed.
1. Current Sub-processors
| Sub-processor | Function | Data it receives |
|---|---|---|
| Vercel | Application hosting and global edge delivery for the web app and APIs. | Encrypted application traffic; technical log data. No data stored at rest. |
| Supabase | Primary database, authentication, and file storage. | Account data, learning records, and AEGIS conversation history. |
| Upstash | Redis caching and rate limiting. | Transient technical data (no durable personal data). |
| xAI | Language model powering the AEGIS market-analysis assistant. | Public market data + the market question the user types. No student PII. |
| Anthropic | Language model for market-intelligence analysis features. | Public market data + the user’s typed query. No student PII. |
| Polygon.io | Public stock and options market-data feed. | Requested asset symbols only. No user data. |
| Unusual Whales | Public options-flow and market-tide data feed. | Requested asset symbols only. No user data. |
| CoinMarketCap | Public cryptocurrency market-data feed. | Requested asset symbols only. No user data. |
| Bunny.net | Video streaming and content delivery for lesson media. | Lesson video content; viewer IP address for delivery. |
| Firebase (Google) | Push/in-app notifications and messaging. | Device push tokens and notification content. |
| Convex | Real-time backend for live, collaborative features. | Real-time session and activity data. |
| Resend | Transactional email (account, security, and service messages). | Recipient name and email address; message content. |
| Stripe | Payment processing for subscriptions and licenses. | Billing contact and payment tokens. We do not store card numbers. |
| Sentry | Application error monitoring and performance tracking. | Technical error and diagnostic telemetry. |
2. Which Sub-processors Receive Student Data
Most data-processing happens inside our own infrastructure. To make the data flow clear for school reviewers:
- Receive student personal information (on our instruction, for the contracted purpose only): Supabase, Vercel (in transit), Resend, Firebase, and Sentry (diagnostic telemetry).
- Receive no student personal information: the AI providers (xAI, Anthropic) and market-data feeds (Polygon, Unusual Whales, CoinMarketCap) receive only market data and the market question typed by the user — never names, emails, IDs, grades, or education records.
- Stripe receives billing-contact and payment information, which for school accounts is the school’s billing contact — not student data.
3. Changes & Notification
We review our sub-processors regularly and update this page whenever one is added or removed. For school-managed accounts, we notify the school’s designated administrator of any new sub-processor that will process student data, consistent with our Data Privacy Agreement, allowing the school to review or object before the change takes effect.
4. Questions
Questions about our sub-processors or to request copies of our vendor agreements: email info@qntcore.ai with the subject “Sub-processor Inquiry.”
5. Related Documents
- Security & Compliance overview — including the full AEGIS AI data-flow disclosure.
- Parents’ Bill of Rights — your rights under NY Education Law § 2-d (DPA Attachment C).
- Privacy Policy.
- Compliance packet (PDF) — the full security & data-privacy compliance document for download.