Cocovox uses carefully selected third-party service providers ("subprocessors") to deliver our educational platform. This page provides complete transparency about who processes student data, why, and how it's protected.
Subprocessors are third-party companies that process data on behalf of Cocovox to provide specific services. We carefully vet all subprocessors to ensure they meet our strict privacy and security standards, especially for children's data under COPPA and FERPA.
This table is generated from the repo-managed processor registry used for diligence and public disclosures.
| Processor | Purpose | Data sent | Retention | DPA status |
|---|---|---|---|---|
| Anthropic(opens in a new tab) | Primary conversational AI for tutoring, explanations, and adaptive responses | Learner prompts, model instructions, and structured learning context. Direct identifiers are reduced where the application flow allows, but message content can still contain learner-provided information. | API processing via Cocovox backend; investor-facing DPA status tracked in repo metadata, not in this public page. | Tracked outside the repo |
| OpenAI(opens in a new tab) | Fallback transcription and alternative model processing | Fallback transcription can temporarily handle raw audio server-side before submission. Some flows also send conversation text and structured context. | Temporary server-side files may exist during fallback processing; derived transcripts can persist in Cocovox records after raw audio is removed. | Tracked outside the repo |
| ElevenLabs(opens in a new tab) | Speech-to-text and text-to-speech processing | Voice flows can send raw audio for speech processing and text for voice synthesis. Cocovox may persist transcripts and derived note artifacts even when raw audio is not intentionally retained. | Raw audio is intended to be ephemeral in Cocovox processing paths, but transcript and note artifacts can persist under the account retention rules. | Tracked outside the repo |
| DigitalOcean(opens in a new tab) | Application, database, and storage hosting | Primary platform hosting for stored learner and parent data. | Data persists according to Cocovox retention rules until deleted or aged out. | Tracked outside the repo |
| SendGrid(opens in a new tab) | Transactional email delivery for verification and parent notices | Parent, teacher, and account-holder contact details plus message content needed to deliver notices. | Delivery logs retained under provider settings and Cocovox operational needs. | Tracked outside the repo |
| Sentry(opens in a new tab) | Crash and error reporting, so we find out when something breaks for a learner instead of waiting to be told | Error events plus the technical trail around them: the page address, recent in-app network calls and their status codes (request URLs can contain resource identifiers), console error text written by Cocovox developers, and the Cocovox account ID via Sentry.setUser. sendDefaultPii is false, so no identity is attached automatically — but that setting does not sanitise strings our own code logs, which is a discipline control, not a technical guarantee. Session replays attach on error with maskAllText and blockAllMedia; 2% of performance traces are sampled. | Held by Sentry under our account's retention settings; Cocovox keeps no separate copy. Settings and the signed agreement are tracked outside the repo. | Not established in repo |
| Stripe(opens in a new tab) | Credit-card verification for verifiable parental consent | Parent verification requests use Stripe payment method details for low-value authorization and identity verification. | Verification artifacts retained according to Cocovox audit needs and Stripe account settings. | Tracked outside the repo |
| Google OAuth(opens in a new tab) | Optional sign-in and identity federation | Only account identity fields needed for optional OAuth login. | Identity data persists with the Cocovox account until deleted. | Tracked outside the repo |
These companies power our AI tutoring features:
| Purpose | Primary conversational AI for tutoring interactions |
|---|---|
| Data Shared | User messages, prompts, and chat context |
| Data Retention | Zero data retention - processed and immediately deleted |
| Location | United States |
| Designed for COPPA | Yes (with parental consent for under 13) |
| Privacy Policy | anthropic.com/privacy(opens in a new tab) |
| Purpose | Alternative AI model and speech-to-text transcription (Whisper API) |
|---|---|
| Data Shared | User messages, audio recordings (when voice features are used) |
| Data Retention | Zero data retention - API calls opted out of training |
| Location | United States |
| Designed for COPPA | Yes (with parental consent for under 13) |
| Privacy Policy | openai.com/privacy(opens in a new tab) |
| Purpose | Text-to-speech voice synthesis for audio responses |
|---|---|
| Data Shared | Text responses to be converted to audio |
| Data Retention | Processed in real-time, no persistent storage |
| Location | United States |
| Children's Data | Not used for children under 13 without explicit parental consent |
| Privacy Policy | elevenlabs.io/privacy(opens in a new tab) |
Services that host and secure our platform:
| Purpose | Cloud infrastructure hosting for application servers and database |
|---|---|
| Data Stored | All user data, including accounts, messages, and learning progress |
| Location | United States (configurable by region) |
| Security | SOC 2 Type II certified, encrypted at rest and in transit |
| Privacy Policy | digitalocean.com/legal/privacy-policy(opens in a new tab) |
Optional third-party login providers:
| Purpose | Optional "Sign in with Google" authentication |
|---|---|
| Data Shared | Email address, name, profile picture (if you choose to use Google sign-in) |
| Location | United States |
| Note | This is entirely optional - users can create accounts with email/password instead |
| Privacy Policy | policies.google.com/privacy(opens in a new tab) |
Services used for transactional email delivery:
| Purpose | Transactional email delivery for account verification, parental consent requests, and notifications |
|---|---|
| Data Shared | Email addresses, recipient names (within email content) |
| Data Retention | Email logs retained for 30 days per Twilio's data retention policy |
| Location | United States |
| Designed for COPPA | Yes - processes parent email addresses for COPPA consent verification only |
| Privacy Policy | twilio.com/legal/privacy(opens in a new tab) |
One service helps us notice when the app breaks:
| Purpose | Tells us when the app breaks, so we can fix it instead of waiting for someone to report it |
|---|---|
| Data Shared | What broke. Which page it happened on. Which parts of the app were being called just before. And a code number for the account signed in — we do not attach a name or an email to it. We also send a short replay of the seconds before the error. Before it leaves the device, every word on the screen is covered by a grey block. Every picture and video is removed. So the replay shows where someone clicked. Not what they wrote, or what they were looking at. One honest caveat. An error message written by our own developers could mention something it should not. We treat that as a bug and fix it. We would rather name that risk than promise it can never happen. |
| Data Retention | Sentry deletes these reports on a schedule set by our plan with them. We cannot promise you an exact number of days here yet, and we would rather say so than guess. Cocovox keeps no copy of its own. |
| Location | United States |
| Children's Data | A child's session is handled exactly the same way. There is no path in Cocovox that sends a child's voice recording to Sentry, and the replay masking covers what they write and draw. |
| Note | We use this only to find and fix problems. We do not use it to learn about your child, to sell anything, or to follow anyone around other websites. We pass none of it on. Sentry is its own company, with its own suppliers. What happens on their side is covered by their privacy policy, linked below. Any questions, email us at support@cocovox.ai. |
| Privacy Policy | sentry.io/privacy(opens in a new tab) |
For transparency, here are common third-party services we explicitly do not use:
One thing to be straight about. Some of these companies get something the moment a page loads, without you or your child choosing it. Sentry is one, each time the app breaks — what it gets, and what it never gets, is under Error Reporting above. Others send the fonts, pictures and map tiles a page needs. We are still writing those up properly, and we would rather tell you that than leave it out.
We will update this page whenever we add, remove, or change subprocessors. Significant changes will be communicated via email to account holders.
If you have questions about our subprocessors or data processing, please contact us at support@cocovox.ai
The patient tutor every kid deserves.