TypeWriter

Student Privacy

Subprocessor List

One company other than TypeWriter can reach student data: the host that runs the application and its database.

Subprocessors of student data

A subprocessor is a company we use to run the service that has access to student data. This is the complete list.

Render render.com
What it doesRuns the TypeWriter application and its managed PostgreSQL database.
WhereUnited States — Oregon (US West).
What it holds Render holds the database, so it holds everything in it. That is:
  • The class code. A teacher-assigned label like SMITH-p3-05, plus a hash of the password the student picks for it. No name, no email address, no student ID number.
  • Submitted work, scores and feedback. What the student wrote or selected, and the teacher's marks, rubric levels and comments on it, filed against that code.
  • Extended-time settings. Where a teacher has entered an accommodation, one number against the code: 1.5x or 2x. Not the 504 or IEP itself, not the reason for it, not a diagnosis.
  • A session cookie. One random sign-in ID and nothing else — no code, no name, no work. It is httpOnly, so scripts on the page cannot read it, and it expires after eight hours.
Render's server logs record an IP address and browser user-agent briefly, as any web host's do. Those sit outside the database and are not tied to a class code.
ProtectionsEncrypted in transit and at rest with AES-256. SOC 2 Type II audited; the public SOC 3 report is available on request. A data processing agreement is in place.

Last reviewed: 6 August 2026.

We review this list at the start of each calendar year (1 January) and each fiscal year (1 July), and whenever a provider changes in between. Districts with a signed data privacy agreement receive the updated list on that schedule. Questions, or a copy for your records: privacy@typewriter.education.