Where Is Your Students’ Text Actually Processed? Data Residency Compared (2026)

Scoring basis, stated before the table: this compares one thing only — what each vendor publishes about where submitted text is processed and under what transfer mechanism. It is not a comparison of retention or training use, which is a different question answered in our ranking of AI writing platforms. Everything below was read on the vendors’ own pages in August 2026, and every gap is reported as a gap.

Vendor Processing location published? Transfer mechanism named Document it appears in Usable in a DPIA as-is?
Grammarly Yes — one named region. “Amazon Web Services data centers in the US East region” Not named on the security page Security page Partly — location yes, mechanism no
Writefull (Digital Science) Partly. Transfers to “Digital Science US, in the United States” from the EEA and UK EU-US Data Privacy Framework and the UK Extension Privacy notice Partly — mechanism yes, precise location no
Turnitin Not stated in the readable policy EU-US DPF (plus UK Extension and Swiss-US DPF); Standard Contractual Clauses “where required”, details on request 🔴 Website privacy policy — not a product document No — wrong document
Paperpal 🔴 Could not read. Privacy URLs returned 404 No
Tesify for Institutions Answered per institution in the data processing agreement Set in the DPA DPA Yes, but only once you have the DPA

Read the fourth column before the second. It contains the finding.

The finding: you are reading the wrong document

Not one vendor in this category answers the residency question in a document that is about student work.

What is publicly readable is a website privacy policy or a security marketing page. Those govern people who visit the site — prospective customers, newsletter subscribers, support contacts. Your students’ submissions travel a different route, under an institutional agreement, and are governed by a data processing agreement that is not published anywhere.

Turnitin’s is the clearest illustration, and this is an observation about document structure rather than about the company. Its readable policy is explicitly the Turnitin Website Privacy Policy. It is a detailed, well-organised document covering DPF certification and transfer mechanisms. It is not the document that governs a submission made through your LMS integration, and quoting it in a DPIA as though it were would be an error your data protection officer should catch.

So the practical rule is short: treat every public page as a lead, and get the DPA before you conclude anything. What follows is how to read the leads.

Two separate printed policy documents side by side on a desk
The document you can read and the document that governs your students are rarely the same document.

A transfer mechanism is not a location

This is the conflation that produces most of the confusion in procurement papers, and it is worth being pedantic about because the two answers satisfy different obligations.

  • Location answers: where is the data physically stored and processed? That is a factual question about infrastructure.
  • Mechanism answers: what makes it lawful to send it there? That is a legal question about instruments.

The EU-US Data Privacy Framework is a mechanism. A DPF certification means a transfer to the United States can be made lawfully. It does not mean data stays in Europe — it means the opposite, in the sense that the framework exists precisely because the data is going to the US. Turnitin names DPF certification including the UK Extension and the Swiss-US DPF; Writefull’s notice states that its parent participates in the EU-US DPF and the UK Extension, and that the notice applies to personal data transferred to Digital Science US, in the United States, from the EEA and the UK.

Standard Contractual Clauses are likewise a mechanism. Turnitin’s policy states that “where required, we will implement Standard Contractual Clauses with our third parties or rely on such other transfer mechanisms to ensure that the transfer of your Personal Information outside of your country is lawful,” and invites you to request details of the mechanisms relied on. That invitation is worth taking up in writing during procurement rather than after.

Neither instrument keeps a single byte inside the EEA. If your institution has a residency requirement — because of a national rule, a research funder condition, or a categorically sensitive dataset — a DPF certification does not satisfy it, and a paper that treats it as though it does will fail at the second reading.

What each vendor actually publishes

Grammarly — the most specific location statement in the category

Grammarly’s security page states that it “hosts data in Amazon Web Services data centers in the US East region” and uses native backup tools for availability. It adds that AWS is certified as compliant with ISO 27001 and has received a SOC 2 (Type 2) report, that all components processing data operate in Grammarly’s private network with each user’s data isolated from other users’ data, that servers and network ports sit behind load balancers and a web application firewall, and that data is encrypted in transit and at rest. External penetration testing and a multi-step vendor review process are also described.

What that gives you: a single named region, which is genuinely more than most vendors offer, and a serviceable security section for a DPIA. What it does not give you: a transfer mechanism, and no European hosting option appears on that page. For an institution with a residency requirement, this is a clear early answer — which is useful, because a clear no in week one is worth more than an ambiguous maybe in month four.

Writefull — the mechanism is named, the location is at group level

Writefull’s privacy notice sets out that Digital Science participates in the EU-US Data Privacy Framework and the UK Extension, and applies to personal data transferred to Digital Science US, in the United States, from the EEA and the UK in reliance on it. On the wider picture it says that “in order to run our business and provide Writefull, we may transfer personal data from the UK or the European Economic Area (EEA), including to our affiliates and service providers, many of whom are located outside of these jurisdictions,” with an appropriate level of protection ensured.

What that gives you: a named framework and an explicit acknowledgement of onward transfers to service providers outside the EEA. That last clause is the honest part and the part to follow up: “many of whom are located outside” is the sub-processor question, and it needs a list.

Turnitin — thorough, and about the wrong data flow

Covered above. The document names DPF certification across three regimes and SCCs where required, with a named contact for transfer-mechanism details. Ask for the institutional equivalent.

Paperpal — not verifiable

We attempted its privacy pages at two addresses in August 2026 and both returned 404. We are recording that rather than substituting a summary from elsewhere. A page that does not resolve is a fact about a request rather than about a company’s practices, and the correct action is to ask the vendor directly — but it does mean the evidence cannot be gathered from public sources in the way the other entries can.

One service icon connected onward to a chain of further processors
The vendor’s own region is the first link. The AI inference provider behind it is the one nobody asks about.

The layer beneath: sub-processors

A vendor can host in a region you approve and still send your text somewhere you have not considered, because the generative features in these products frequently run on a third-party model provider.

That provider is a sub-processor, it has its own processing geography, and it is the layer at which residency commitments most often leak. Writefull’s notice is unusually candid about the general shape of this; most are silent.

Three requirements settle it:

  1. A current sub-processor list with the location of each. Not a category (“cloud infrastructure”) — names and regions.
  2. Advance notice of any addition or relocation, with a defined objection window, rather than a notification after the fact.
  3. An express statement covering the AI inference path specifically, because it is the newest link and the one least likely to be described in a DPA drafted before the feature existed.

The recommendation, and the alternative profile

Recommendation: do not select on published residency claims at all. Select on whether a vendor will commit to a named region in the agreement, supply a located sub-processor list, and accept a change-of-region clause. On that criterion, an option answered per institution in the DPA is stronger than a webpage statement, because a webpage can be edited and a contract cannot.

Alternative profile: if your requirement is a hard EU-residency rule rather than a preference, shortlist only vendors that will write a European region into the contract, and use the published statements above to eliminate early rather than to decide. Grammarly’s US East statement, for instance, resolves that question in one sentence.

Neither, if: your actual concern is retention or model training rather than geography. Those are separate permissions with separate answers — see why retention and training are not the same permission.

What to send every shortlisted vendor

  1. In which regions is institutional data stored and processed, and will you name them in the agreement?
  2. Send the data processing agreement that governs institutional deployments, not the website privacy policy.
  3. Supply the current sub-processor list with the location of each and the notice period for changes.
  4. Which transfer mechanism applies to our data specifically, and can we see the executed instrument?
  5. Where is the AI inference path processed, and is that provider on the sub-processor list?

Send these with the rest of the pack rather than separately — the fuller set is in our procurement question bank, and the review that consumes the answers is in how to run a data protection review before deploying an AI writing tool.

To receive the processing locations and sub-processor list for a specific deployment scope before any commitment, request an institutional evaluation.

Frequently asked questions

Does DPF certification mean our data stays in Europe?

No. It is a mechanism that makes a transfer to the United States lawful. It answers how, not where, and its existence implies the data is going to the US.

Which vendor publishes the clearest hosting location?

Grammarly. Its security page names Amazon Web Services data centers in the US East region — a single named region, which is more specific than the rest of the category offers.

Why is a website privacy policy the wrong document?

Because it governs site visitors, not student submissions made through an institutional deployment. Those are different data flows under different agreements.

What is the right document?

The data processing agreement for institutional deployments. It is not published, so it has to be requested during procurement.

Are Standard Contractual Clauses a residency guarantee?

No. Like the DPF, they legalise a transfer rather than prevent one. Turnitin’s policy offers details of the mechanisms relied on to anyone who asks, which is worth doing in writing.

What is the most commonly missed layer?

Sub-processors, particularly the AI inference provider behind a generative feature. It has its own processing geography and is often absent from a DPA drafted before the feature existed.

What should a sub-processor list contain?

Names and locations, not categories, plus a notice period and an objection window for additions or relocations.

Should a change of processing region be a notification or a right?

A right. Make relocation outside the agreed regions a termination-triggering event, or the commitment is advisory.

Is a US-hosted vendor unusable for a European institution?

Not in general — a lawful transfer mechanism exists for exactly this situation. It becomes unusable where you have a specific residency requirement from national rules, a funder condition or a sensitive dataset.

What do we do about a vendor whose privacy pages do not resolve?

Record the attempt and the date, then ask directly. An unreachable page is a fact about a request; the absence of an answer to a written question is a fact about the vendor.

Can we rely on the infrastructure provider’s certifications?

Only for the infrastructure layer. AWS holding ISO 27001 and a SOC 2 Type 2 report says something about AWS, not about how the application built on it handles your data.

How often should this be re-checked?

At every renewal and on any major feature release. Adding a generative feature can introduce a new sub-processor in a new jurisdiction without any change to the hosting region you approved.