Last updated: July 11, 2026
Model B uses the service providers listed below to operate the platform. Each is included only because it's necessary to provide the service, and each has access limited to what its specific function requires — nothing is added "just in case."
| Service Provider | Purpose | Data Involved |
|---|---|---|
| Vercel | Application hosting, serverless functions | All data in transit/processing passes through this infrastructure |
| Supabase | Database, authentication, and file storage | The core data processor — effectively all customer data |
| Sign-in (if a user chooses Google OAuth) | Name, email, profile photo | |
| Microsoft | Sign-in (if a user chooses Microsoft OAuth) | Name, email, profile photo |
| Resend | Transactional email | Substitute session invitations, absence notifications, contact form submissions |
| Have I Been Pwned | Password breach checking at sign-up and password reset | A small, non-reversible fragment derived from a password — never the password itself |
| Cloudflare | Automated, encrypted backup storage | A full copy of production data, retained on a rolling 30-day basis |
| Better Stack (Betteruptime) | Uptime monitoring and public status page | URLs of monitored services; no customer or student data |
Model B does not sell personal information to any party, and does not share data with any service provider not listed here.
This page is the single source of truth for Model B's subprocessors — our Privacy Policy and Security Overview link here rather than maintaining separate copies, so this list is always current without risk of drift between documents.
Reach us at hello@modelb.app with any questions about a specific subprocessor or its role.