Skip to main content
Myzo

Legal · Last updated 2026-09-18

Sub-processors

Myzo relies on a small set of third-party services, called sub-processors, to run the app. Every sub-processor we use is listed below, along with what they do for us, the kind of data they touch, and the date the Data Processing Agreement (DPA) we have on file with them was executed.

We sign a DPA with each sub-processor, including the EU Standard Contractual Clauses as an appendix where the sub-processor is located outside the European Economic Area, the United Kingdom, or Switzerland. Before we route any user data through a new sub-processor, the DPA is in place. Under GDPR (and our COPPA commitments), we notify affected parents at least 30 days before adding a new sub-processor that would handle your or your child's data.

Current sub-processors

VendorPurposeData touchedRegionDPA executed
Supabase Inc.Primary application database, authentication, edge-function hosting, realtime syncParent email, parent name, child first name + avatar, all task / session / score / reward data, COPPA consent recordsUnited States2026-07-29
PostHog Inc.Product analytics and feature flags. Children are tracked anonymously (no name, email, device ID)Anonymous session IDs for children; adult guardian pseudonymous UUID + event names for adultsUnited States2026-07-29
Resend (Drie Labs Inc.)Transactional and marketing email deliveryParent email address and the contents of the message sentUnited States2026-07-29
650 Industries, Inc. ("Expo")Mobile-app build infrastructure and push-notification delivery pipelineBuild artifacts (no user data); Expo push tokens issued to each installed appUnited States2026-07-23
Cloudflare, Inc.Marketing-site content delivery network and edge hostingWeb-visitor IP address, browser metadata, request logs (no app-user data)Global (processed at the nearest edge)2026-07-29 (Customer DPA v6.4)
Google LLC (Google Workspace)Email hosting for @getmyzo.com corporate email and shared file storage for internal legal recordsInternal team email; no user dataUnited States2026-07-29
Apple, Inc.iOS App Store distribution, TestFlight, Apple Push Notification service, In-App PurchaseApp downloads, crash reports, IAP transaction metadataUnited States / EUCovered by the Apple Developer Program License Agreement
RevenueCat, Inc.In-app subscription management for the Myzo Parents and Myzo College apps: verifies App Store purchases and tracks subscription statusOpaque account identifier (the parent's or student's account ID) and purchase and renewal records from the app store. No payment card details and no child data; the Myzo Kids app does not communicate with RevenueCatUnited StatesData Processing Addendum incorporated in RevenueCat's Terms of Service
Google LLC (Play Store + FCM)Google Play Store distribution, Firebase Cloud Messaging, In-App Billing (Android)App downloads, crash reports, push delivery routingUnited States / EUTo be executed before Android launch
Paddle.com Market LimitedSubscription billing (web checkout), acting as Merchant of RecordParent email, billing address (held by Paddle only), payment method (held by Paddle only). We receive only opaque customer + transaction identifiersUnited Kingdom / United StatesPending live account activation, sandbox terms apply in the meantime
Anthropic PBCAI processing to generate the multiple-choice distractor answers shown in the Flash Cards feature. Under Anthropic's API data-retention policy, request content is not retained after the response is returned and is never used to train Anthropic's modelsScanned page images uploaded by a parent from the Parents app, and the question + answer text a child writes when they author a custom card in the Kids app. The child's first name is not sentUnited StatesData Processing Addendum incorporated in Anthropic's Commercial Terms of Service

Children's data

COPPA places extra duties on any service that handles data from children under 13. For every sub-processor that could touch child-level data, Supabase, Expo, Apple, Google, and Anthropic, we confirm in advance that they (a) are COPPA-aware, (b) store only the minimum data we send them, and (c) honor our deletion requests within a documented window as part of the executed DPA. Anthropic in particular does not retain child-authored flash-card text or scanned page images after returning its response, and never uses them to train its models.

PostHog never receives child personally identifying data. We send only anonymous, per-session identifiers and event names for children. The marketing site does not set analytics cookies for visitors under 13.

Changes to this list

When we add, remove, or replace a sub-processor that handles user data, we update this page first and then notify parent guardians directly inside the Myzo Parents app. Notifications appear the next time you open the app and remain visible for at least 30 days before the change takes effect. If you object to a new sub-processor you can request that we delete your family's data before the change is applied, see the deletion controls in your account or contact privacy@getmyzo.com.

For the full picture of how we handle data, read our Privacy Policy and the Children's Privacy Notice.