Trust & compliance · Last updated 2026-05-22
How Storgy handles your data.
Storgy is built for teachers and school districts that need to know — in writing, with names attached — where their data goes. This page covers the sub-processor list, the AI policy, and the signed Data Processing Agreement on offer. For the full security posture see /security/; for the legal privacy policy see /privacy/.
Independent reviews & agreements
Where we are in the formal review queue.
Common Sense Privacy
Privacy review pending
Storgy is under review by the Common Sense Privacy team. The badge appears here once the evaluation is published.
SDPC National DPA
Signed copy on offer to every district
Storgy has executed the Student Data Privacy Consortium National DPA template. Districts can request a counter-signed copy by emailing privacy@storgy.com. Last signed: pending counter-signature.
Sub-processors
Six third parties touch customer data. Here they are.
Every external service that processes Storgy customer data is listed below with the specific purpose and a direct link to their privacy policy. If we add or remove a sub-processor, this list is updated and the date band at the top of the page is bumped. Districts on the SDPC DPA are notified by email.
Anthropic
Privacy policy →Claude API — first-pass editorial drafts
OpenAI
Privacy policy →GPT-4o-mini — humaniser pass over AI-drafted text
Resend
Privacy policy →Transactional email — magic-link auth, digests, receipts
Paddle
Privacy policy →Billing merchant of record — global VAT and refunds
Hetzner
Privacy policy →Application and Postgres hosting — Falkenstein, Germany
Cloudflare
Privacy policy →CDN + WAF — read-only HTML and image cache, no PII at edge
AI policy
What the models do, and what they do not do.
We draft with Claude (Anthropic).
We humanise with OpenAI (GPT-4o-mini).
Every editorial block is read by a human teacher before publishing.
We do not train models on customer data. Both API providers contractually exclude API inputs from training by default.
Customer paste content — anything submitted via the Poem Analyzer, Essay Scaffold, or other tools — is held only to serve the response and to maintain the share URL. It is never reused as training data on our side either.
Going deeper
For procurement teams.
The page you’re reading is the short version. The full security disclosure — encryption, residency, breach notification, vulnerability disclosure, and the honest list of certifications we do not yet hold — lives at /security/. The legal privacy policy with retention windows and contact details lives at /privacy/.