Legal · Last updated 2026-09-18
Sub-processors
Myzo relies on a small set of third-party services, called sub-processors, to run the app. Every sub-processor we use is listed below, along with what they do for us, the kind of data they touch, and the date the Data Processing Agreement (DPA) we have on file with them was executed.
We sign a DPA with each sub-processor, including the EU Standard Contractual Clauses as an appendix where the sub-processor is located outside the European Economic Area, the United Kingdom, or Switzerland. Before we route any user data through a new sub-processor, the DPA is in place. Under GDPR (and our COPPA commitments), we notify affected parents at least 30 days before adding a new sub-processor that would handle your or your child's data.
Current sub-processors
| Vendor | Purpose | Data touched | Region | DPA executed |
|---|---|---|---|---|
| Supabase Inc. | Primary application database, authentication, edge-function hosting, realtime sync | Parent email, parent name, child first name + avatar, all task / session / score / reward data, COPPA consent records | United States | 2026-07-29 |
| PostHog Inc. | Product analytics and feature flags. Children are tracked anonymously (no name, email, device ID) | Anonymous session IDs for children; adult guardian pseudonymous UUID + event names for adults | United States | 2026-07-29 |
| Resend (Drie Labs Inc.) | Transactional and marketing email delivery | Parent email address and the contents of the message sent | United States | 2026-07-29 |
| 650 Industries, Inc. ("Expo") | Mobile-app build infrastructure and push-notification delivery pipeline | Build artifacts (no user data); Expo push tokens issued to each installed app | United States | 2026-07-23 |
| Cloudflare, Inc. | Marketing-site content delivery network and edge hosting | Web-visitor IP address, browser metadata, request logs (no app-user data) | Global (processed at the nearest edge) | 2026-07-29 (Customer DPA v6.4) |
| Google LLC (Google Workspace) | Email hosting for @getmyzo.com corporate email and shared file storage for internal legal records | Internal team email; no user data | United States | 2026-07-29 |
| Apple, Inc. | iOS App Store distribution, TestFlight, Apple Push Notification service, In-App Purchase | App downloads, crash reports, IAP transaction metadata | United States / EU | Covered by the Apple Developer Program License Agreement |
| RevenueCat, Inc. | In-app subscription management for the Myzo Parents and Myzo College apps: verifies App Store purchases and tracks subscription status | Opaque account identifier (the parent's or student's account ID) and purchase and renewal records from the app store. No payment card details and no child data; the Myzo Kids app does not communicate with RevenueCat | United States | Data Processing Addendum incorporated in RevenueCat's Terms of Service |
| Google LLC (Play Store + FCM) | Google Play Store distribution, Firebase Cloud Messaging, In-App Billing (Android) | App downloads, crash reports, push delivery routing | United States / EU | To be executed before Android launch |
| Paddle.com Market Limited | Subscription billing (web checkout), acting as Merchant of Record | Parent email, billing address (held by Paddle only), payment method (held by Paddle only). We receive only opaque customer + transaction identifiers | United Kingdom / United States | Pending live account activation, sandbox terms apply in the meantime |
| Anthropic PBC | AI processing to generate the multiple-choice distractor answers shown in the Flash Cards feature. Under Anthropic's API data-retention policy, request content is not retained after the response is returned and is never used to train Anthropic's models | Scanned page images uploaded by a parent from the Parents app, and the question + answer text a child writes when they author a custom card in the Kids app. The child's first name is not sent | United States | Data Processing Addendum incorporated in Anthropic's Commercial Terms of Service |
Children's data
COPPA places extra duties on any service that handles data from children under 13. For every sub-processor that could touch child-level data, Supabase, Expo, Apple, Google, and Anthropic, we confirm in advance that they (a) are COPPA-aware, (b) store only the minimum data we send them, and (c) honor our deletion requests within a documented window as part of the executed DPA. Anthropic in particular does not retain child-authored flash-card text or scanned page images after returning its response, and never uses them to train its models.
PostHog never receives child personally identifying data. We send only anonymous, per-session identifiers and event names for children. The marketing site does not set analytics cookies for visitors under 13.
Changes to this list
When we add, remove, or replace a sub-processor that handles user data, we update this page first and then notify parent guardians directly inside the Myzo Parents app. Notifications appear the next time you open the app and remain visible for at least 30 days before the change takes effect. If you object to a new sub-processor you can request that we delete your family's data before the change is applied, see the deletion controls in your account or contact privacy@getmyzo.com.
For the full picture of how we handle data, read our Privacy Policy and the Children's Privacy Notice.