Sub-processor List
Every third-party service AssisT can send text to, what triggers it, what is sent, and whether it is opt-in.
Applies to AssisT 1.0.0 · Last updated 13 September 2026
Read this first
Fiavaion has no sub-processors for AssisT. We operate no server that receives data from the extension, we hold no account for you, and no text you process ever reaches us. Under GDPR we are neither controller nor processor of your personal data.
What follows is therefore not a sub-processor list in the usual sense. It is the complete list of third-party services the extension can talk to, so that a disability service or data protection officer can see exactly where text can go and decide what to tell students.
Where a student switches one of these on, that provider becomes the student’s own sub-processor, under the agreement between the student (or the institution, if it supplies the key) and that provider. Fiavaion is not in that chain and cannot see what passes through it.
The list
| Provider | Purpose | When it is used | Data sent | Provider terms | Opt-in status |
|---|---|---|---|---|---|
| MyMemory (Translated srl) | Translation | Whenever the student uses Translate and has not configured another provider. MyMemory is the default. | The text selected for translation, plus the source and target language | Usage and privacy | Default provider. Used the first time Translate is used, without a key. A student who never uses Translate never contacts it |
| DeepL (DeepL SE) | Translation | Only if the student enters a DeepL API key and selects DeepL as the translation provider | The text selected for translation, plus the source and target language | Privacy policy · DPA | Opt-in. Requires the student’s own API key |
| Azure Translator (Microsoft) | Translation | Only if the student enters an Azure Cognitive Services key and selects Azure as the translation provider | The text selected for translation, plus the source and target language | Microsoft privacy statement · Microsoft Products and Services DPA | Opt-in. Requires the student’s own API key |
| Free Dictionary API | Word definitions | When the student looks a word up | The single word looked up. No surrounding text, no page URL | dictionaryapi.dev | Used by the dictionary lookup feature. No key, no account |
| Google (Gemini) | Cloud AI | Only if the student selects Cloud AI mode with a Google Gemini API key | The text the student asked AssisT to work on (summarise, explain, rewrite and similar), plus the prompt | Gemini API terms · Google privacy policy | Opt-in. Requires the student’s own API key. Google offers a free tier |
| Anthropic (Claude) | Cloud AI | Only if the student selects Cloud AI mode with an Anthropic API key | The text the student asked AssisT to work on, plus the prompt | Privacy policy · Commercial terms | Opt-in. Requires the student’s own API key |
| OpenAI | Cloud AI | Only if the student selects Cloud AI mode with an OpenAI API key | The text the student asked AssisT to work on, plus the prompt | Privacy policy · DPA | Opt-in. Requires the student’s own API key |
| Perplexity | Cloud AI | Only if the student selects Cloud AI mode with a Perplexity API key | The text the student asked AssisT to work on, plus the prompt | Privacy policy | Opt-in. Requires the student’s own API key |
Hugging Face (Hugging Face, Inc.) — huggingface.co, hf.co, xethub.hf.co | Model download at setup | Only if the student switches Browser AI (WebLLM) on. The model file is fetched once, then cached in the browser | IP address and the model request. No user text, no account, no key. Inference afterwards is local and makes no further request | Privacy policy | Opt-in. Browser AI is off until the student turns it on |
GitHub (Microsoft) — raw.githubusercontent.com | Model download at setup | Alongside the Hugging Face download: the configuration files the in-browser model needs | IP address and the file request. No user text, no account, no key | GitHub privacy statement | Opt-in. Same trigger as the Hugging Face row above |
| Google (Chrome Web Store) | Distribution and updates | When Chrome installs or updates the extension | Standard Chrome Web Store telemetry, between the browser and Google. AssisT sends nothing of its own | Google privacy policy | Unavoidable for any Chrome extension. Governed by the institution’s existing relationship with Google, not by AssisT |
What is not on this list, and why
- Ollama (Local AI) — runs on the student’s own machine at a loopback address. Nothing leaves the device, so there is no processor. Chrome asks for permission to reach it the first time Local AI is switched on, not at install.
- WebLLM (Browser AI) inference — runs in the browser tab via WebGPU and makes no network call.
The one-off model download does contact Hugging Face and
raw.githubusercontent.com, so those two are on the list above. - Gemini Nano (Chrome built-in AI) — Chrome’s own on-device model. No text leaves the browser.
- Text-to-speech and speech-to-text — use the browser’s own APIs. Where Chrome’s speech recognition is itself server-backed, that is a property of the browser and of the institution’s relationship with Google, not something AssisT introduces.
- Fonts — Lexend and OpenDyslexic ship inside the extension. No font CDN is contacted, so no request carries a student’s IP address to a third party.
- Analytics, crash reporting, error tracking — none. AssisT contains no analytics or telemetry of any kind.
For a data protection officer
- Default posture: nothing leaves the device except translation (MyMemory) and dictionary lookups, and only when the student uses those features on text they selected.
- Strictest posture: tell students not to use Translate or Dictionary, not to configure a cloud AI provider, and not to switch Browser AI on (its one-off model download is the only other outbound request). AssisT then makes no outbound request at all beyond Chrome’s own update checks. All 29 supports still work.
- No DPA is needed with Fiavaion because there is no processing to agree over. If your procurement process requires a signed statement of that fact, email [email protected] and ask.
- Changes to this list are published here and noted in the privacy policy change log. There is no mailing list for it; check the page, or watch the repository.