Trust & compliance · Last updated 2026-08-05
How Storgy handles your data.
Storgy is built for teachers and school districts that need to know — in writing, with names attached — where their data goes. This page covers the sub-processor list, the AI policy, and the signed Data Processing Agreement on offer. For the full security posture see /security/; for the legal privacy policy see /privacy/.
Independent reviews & agreements
Where we are in the formal review queue.
Common Sense Privacy
Privacy review pending
Storgy is under review by the Common Sense Privacy team. The badge appears here once the evaluation is published.
SDPC National DPA
Signed copy on offer to every district
Storgy has executed the Student Data Privacy Consortium National DPA template. Districts can request a counter-signed copy by emailing privacy@storgy.com. Last signed: pending counter-signature.
Sub-processors
Seven third parties touch customer data. Here they are.
Every external service that processes Storgy customer data is listed below with the specific purpose and a direct link to their privacy policy. If we add or remove a sub-processor, this list is updated and the date band at the top of the page is bumped. Districts on the SDPC DPA are notified by email.
Anthropic
Privacy policy →Claude API — first-pass editorial drafts
OpenAI
Privacy policy →GPT-4o-mini — phrasing pass over Storgy's own editorial text (never customer input)
Resend
Privacy policy →Transactional email — magic-link auth, digests, receipts
Paddle
Privacy policy →Merchant of record for subscriptions opened before the move to Stripe — VAT, renewals and refunds on those
Stripe
Privacy policy →Payment processing and tax calculation for subscriptions opened since the move from Paddle
Hetzner
Privacy policy →Application and Postgres hosting — Falkenstein, Germany
Cloudflare
Privacy policy →Authoritative DNS for storgy.com, and R2 object storage for files you generate (Writing Desk audio, tool images and worksheets)
AI policy
What the models do, and what they do not do.
We draft with Claude (Anthropic). Everything a student or teacher submits to a tool goes to Anthropic and nowhere else.
We use OpenAI (GPT-4o-mini) for a phrasing pass over our OWN editorial writing before we publish it — never on anything you submit.
Every editorial block is read by a human teacher before publishing.
We do not train models on customer data. Both API providers contractually exclude API inputs from training by default.
Customer paste content — anything submitted via the Poem Analyzer, Essay Scaffold, or other tools — is held only to serve the response and to maintain the share URL. It is never reused as training data on our side either.
Going deeper
For procurement teams.
The page you’re reading is the short version. The full security disclosure — encryption, residency, breach notification, vulnerability disclosure, and the honest list of certifications we do not yet hold — lives at /security/. The legal privacy policy with retention windows and contact details lives at /privacy/.