Legal
Subprocessors
Last updated: April 18, 2026
CaseGrade uses a small set of carefully vetted third-party service providers (“subprocessors”) to deliver the Services. This page lists the categories of subprocessor we engage, what each category does, and what data each category processes. Each subprocessor is bound by a data processing agreement that restricts its use of personal information to the services it provides to us. See our Privacy Policy for a full description of how we handle personal information.
Categories of subprocessors
AI model providers
- Purpose
- Real-time voice transcription, AI interviewer response generation, and automated rubric-based scoring of interview transcripts.
- Data
- Voice audio (transient — streamed for real-time transcription only and not persistently stored by CaseGrade); interview transcripts; rubric evaluation inputs and outputs.
- Region
- United States
Database hosting providers
- Purpose
- Managed PostgreSQL infrastructure for storing your account, transcripts, scores, drill attempts, and progress data.
- Data
- Account data, profile information, transcripts, scores, drill attempts, progress, billing metadata.
- Region
- United States
Application hosting and infrastructure providers
- Purpose
- Serving the website and running server-side and edge functions that power the Services.
- Data
- All requests to the Services in transit; edge and server-side function execution; static asset delivery.
- Region
- United States
Payment processors
- Purpose
- Processing credit card charges, managing subscriptions and renewals, and handling refunds.
- Data
- Name, email, billing address, payment-method details (tokenized by the processor), and transaction metadata. CaseGrade does not see, receive, or store full credit card numbers; we use a PCI-DSS Level 1 certified processor.
- Region
- United States and global processing
Transactional email providers
- Purpose
- Delivering account-verification, password-reset, billing-receipt, and security-notification emails.
- Data
- Email address and message content for the listed transactional purposes.
- Region
- United States
Error monitoring and telemetry providers
- Purpose
- Capturing crash reports and performance telemetry so we can find and fix bugs.
- Data
- Stack traces, diagnostic telemetry, and browser/device metadata. PII-scrubbing filters are configured to remove personal identifiers before transmission.
- Region
- United States
Uptime monitoring providers
- Purpose
- Pinging our public health-check endpoint to detect outages and trigger incident alerts.
- Data
- Ping responses from our health-check endpoint only. No user data is sent.
- Region
- Global
Named subprocessor list
The named list of specific vendors within each category is made available to institutional customers (universities, consulting clubs, employers) under a data processing addendum and a confidentiality undertaking. To request the named list and a DPA, contact partnerships@casegrade.io. Individual users with privacy questions are welcome to email privacy@casegrade.io.
Notification of changes
Institutional customers under a data processing addendum may subscribe to receive email notice of any addition or replacement of a subprocessor that materially processes their data, typically at least 30 days before the change takes effect. To subscribe, contact privacy@casegrade.io. If a customer objects to a proposed change on reasonable data protection grounds, we will work in good faith to address the objection or to provide a path to terminate the relevant portion of their subscription.