Cognity — Sub-processors
Last updated: 2026-07-29
Cognity engages the third parties below to process personal data on behalf of the schools and organisations that use the service. Each is bound by contract to process data only on our instructions, and AI providers are contractually barred from using school or student data to train their models.
Which providers see student prompts?
Google LLC — Gemini API (paid tier) — sending a prompt to the AI provider is intrinsic to how Cognity works, so this transfer cannot be switched off while the service is in use. Every other provider listed here handles hosting, analytics or billing and does not receive prompts.
Sub-processor register
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Google LLC — Gemini API (paid tier) | AI generation, tutoring and evaluation (Jello, project, rubric and image generation) | Prompts, submissions, AI output | United States |
| Amazon Web Services, Inc. | Hosting, storage and security | All service data | United States (EU region available under an enterprise agreement) |
| Google LLC — Google Analytics | Product analytics | Usage and technical data | United States |
| Paddle.com Market Ltd | Merchant of Record — billing and tax collection | Billing name and contact, transaction records | United Kingdom |
Does regional storage keep AI processing in that region?
No. Under an enterprise agreement a school can ask that its data be stored in a specified region, such as the EU. AI generation currently runs through the Google Gemini API, which processes requests in the United States, so prompts are transmitted there even when other data is stored elsewhere.
How do we announce changes?
This page is the authoritative, versioned list, and the overseas-transfer table in the Privacy Policy is kept consistent with it. For questions about a specific sub-processor, or to request a copy of the transfer safeguards, write to cognity@ctcorp.ai.