For DPOs
AI & hosting attestations
Last reviewed: 4 September 2026
1. Why attestations matter
Class Prayer uses other firms to store data and to help draft prayers. Schools reasonably ask for written proof that those firms will not keep or train their models on what children write, and that data stays in safe places. Our approach is trust, but verify: marketing statements are not enough, so we obtain and keep written attestations from each provider on file for school Data Protection Officers.
2. What each attestation confirms
Each written attestation we hold from an AI or hosting provider confirms, as a minimum:
- No model training. Prompts and pupil content sent to the AI provider are not used to train, fine-tune, or improve any machine-learning model.
- No retention beyond the response. The AI provider does not retain prompt content beyond the time needed to generate and return a response.
- EU/adequate routing. AI requests are routed within the European Union or another UK-adequate jurisdiction, and application data is stored in data centres covered by a UK adequacy regulation (currently the Republic of Ireland).
- Confidentiality. Provider personnel cannot access customer content except under documented, audited, least-privilege controls.
- Onward flow-down. The same conditions apply to any upstream sub-processor the provider itself uses (for example, the underlying model provider behind our AI gateway).
3. Attestations currently held
| Provider | Role | Attestation held |
|---|---|---|
| Lovable Cloud (Supabase: Postgres, Auth, Storage) | Primary database, authentication and file storage | Written confirmation of EU data residency (Republic of Ireland, AWS eu-west-1), encryption at rest, and no secondary use of stored data. |
| Lovable AI Gateway → Google (Gemini family models) | AI-assisted drafting of prayer, theme and homily content | Written confirmation that inputs are not used to train models, are not retained beyond the response, and are routed within the EU under Lovable-managed routing. |
| Lovable Emails (Mailgun upstream) | Account, magic-link and notification email delivery | Written confirmation of EU-region processing (Frankfurt) and no use of message content for any purpose other than delivery. |
The ESV API (Crossway) receives only Scripture reference strings — never personal data — so no attestation is required for that transfer.
4. How school DPOs can verify
Copies of the written attestations summarised above are available to school DPOs and procurement officers on request. Email info@classprayer.app with the subject line AI and hosting attestations - [school name]. We respond within 5 working days.
Attestations are reviewed and refreshed whenever a provider changes its terms, its routing, or its upstream model providers, and at least annually. Any change to the providers themselves follows the 30-day change-notice procedure in our sub-processor list.