Who else handles your data
Version subprocessors-3.1.0 · in force from 18 September 2026
Course++ — a product of CoursePlusPlus LLC
A short, complete list. If a company is not here, it does not receive your data.
01
The AI path
Three models, offered by tier, all reached through OpenRouter. You pick one of the three below in Settings (or Course++ picks a default) — never a fourth, and never one you didn't select.
| Tier | Model | Made by | Actually runs on |
|---|---|---|---|
| Quick | GLM 5.3 Flash | Z.AI | One of: Cloudflare, Together AI, Fireworks AI, or Z.AI's own servers |
| Standard | Gemini 3.5 Flash Lite | Google Cloud Vertex AI | |
| Thorough | Claude Haiku 4.5 | Anthropic | Google Cloud Vertex AI (Anthropic's models are offered through Google's Vertex Model Garden; verified live, 2026-09-17, that our own configuration only ever resolves this model there, never to Anthropic's own servers) |
OpenRouter is the switchboard for all three: it never runs a model itself, it forwards your request to whichever company's servers actually have that model running, and it enforces the same two rules on every one of those companies before it will route to them at all — see below.
Why "one of four" for the Quick tier, not one name: OpenRouter selects whichever of those four companies is available at the moment of your request, and it can genuinely differ turn to turn — confirmed directly by making the same request repeatedly and watching which one answered. All four are named here for exactly that reason: naming only the one we saw most recently would be a guess, not a disclosure.
| OpenRouter, Inc. | Whichever company serves the request | |
|---|---|---|
| Role | Routes our request to one of the companies above | Runs the model |
| Receives | Your instruction and course content, after personal data is stripped | The same |
| Used for training? | No | No — see each company's own commitment below |
| Stored? | No — their terms make prompt retention opt-in, and we have not opted in | No, by each company's own published policy — quoted below |
| Retains | Request metadata — token counts, cost, model, timing | — |
What each company that can actually run your request says about it, in their own words:
- Google Cloud (Vertex AI) — we route only to endpoints that do not retain request data.
- Cloudflare (Workers AI) — "Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services." (developers.cloudflare.com/workers-ai/platform/data-usage)
- Together AI — "Under ZDR, the content you submit... and any outputs provided to you... are not stored, retained, or used for model training, product improvements, or any secondary purposes except as needed to provide the Services to you." (together.ai/privacy)
- Fireworks AI — "We do not use your prompts, training data, or API inputs to train or improve our AI models without your explicit opt-in." (fireworks.ai/privacy-policy)
- Z.AI — the maker of the GLM model; reachable as one of its own four possible hosts above.
How this is enforced, in two independent places:
- On our account — Zero Data Retention is on, Google AI Studio endpoints are disabled so only Vertex is reachable for Google-hosted traffic, and every "allow training" option is off, including the discount that would trade your prompts for cheaper inference.
- On every single request, for every one of the companies above — the same restrictions (
data_collection: deny, and a fixed list of which companies may even be considered) are sent with the request itself, so they hold even if an account setting were ever changed. If a company cannot meet them, the request fails rather than quietly routing somewhere weaker — this is exactly what happens today with OpenAI's models, which is why none of the three tiers uses one.
Two things we will not claim
We cannot guarantee processing happens inside the United States. Region-pinned routing is not available on our plan. If that matters to you, do not use Course++ with anything you would not want processed abroad.
Web search is outside the no-retention arrangement. If you ask Course++ to search the web, the query goes to a search service through OpenRouter, and their retention guarantee covers model routing rather than search. Course++ builds a topical query and does not put course content into one.
02
Everything else
| Who | What they do | What they receive |
|---|---|---|
| Cloudflare, Inc. | Runs our API, website and inbound email — and, separately, may be one of the four possible servers for the Quick tier's AI model, listed in "The AI path" above | Requests in transit; request metadata. No request or response bodies are logged |
| Supabase, Inc. | Stores accounts, plans, credit balances and the ledger; handles sign-in | Your email, plan, balance, transactions |
| Stripe, Inc. | Payments, checkout and the cancellation portal | Name, email, billing address, payment history. Card details go to Stripe and never to us |
| Resend | Sends our outbound email | Your email address and the message |
| Google LLC | Sign-in, if you choose that option over a one-time email code | That you signed in |
03
What none of them get
- Your Canvas password or API token. We never see a credential.
- Your course content stored anywhere. It passes through to reach the model and is not written to any database, log or file of ours.
- Student records. Course++ cannot read them — see What Course++ can and can't see.
04
Changes
If we add a subprocessor that receives your content, we will update this page and tell you before it takes effect.
CoursePlusPlus LLC · 392 E Todd Pl, Washington, UT 84780 · support@courseplusplus.com