Legal · Last updated 2026-07-21
Sub-processors
Myzo relies on a small set of third-party services — called sub-processors — to run the app. Every sub-processor we use is listed below, along with what they do for us, the kind of data they touch, and a link to the Data Processing Agreement we have on file with them.
We sign a Data Processing Agreement (DPA) with each sub-processor, including the EU Standard Contractual Clauses as an appendix where the sub-processor is located outside the European Economic Area, the United Kingdom, or Switzerland. Before we route any user data through a new sub-processor, the DPA is in place. Under GDPR (and our COPPA commitments), we notify affected parents at least 30 days before adding a new sub-processor that would handle your or your child's data.
Current sub-processors
| Vendor | Purpose | Data touched | Region |
|---|---|---|---|
| Supabase Inc. | Primary application database, authentication, edge-function hosting, realtime sync | Parent email, parent name, child first name + avatar, all task / session / score / reward data, COPPA consent records | United States |
| PostHog Inc. | Product analytics and feature flags. Children are tracked anonymously (no name, email, device ID) | Anonymous session IDs for children; adult guardian pseudonymous UUID + event names for adults | United States |
| Resend (Drie Labs Inc.) | Transactional and marketing email delivery | Parent email address and the contents of the message sent | United States |
| 650 Industries, Inc. ("Expo") | Mobile-app build infrastructure and push-notification delivery pipeline | Build artifacts (no user data); Expo push tokens issued to each installed app | United States |
| Cloudflare, Inc. | Marketing-site content delivery network and edge hosting | Web-visitor IP address, browser metadata, request logs (no app-user data) | Global (processed at the nearest edge) |
| Apple, Inc. | iOS App Store distribution, TestFlight, Apple Push Notification service, In-App Purchase | App downloads, crash reports, IAP transaction metadata | United States / EU |
| Google LLC | Google Play Store distribution, Firebase Cloud Messaging, In-App Billing (Android) | App downloads, crash reports, push delivery routing | United States / EU |
| Paddle.com Market Limited | Subscription billing (web checkout), acting as Merchant of Record | Parent email, billing address (held by Paddle only), payment method (held by Paddle only). We receive only opaque customer + transaction identifiers | United Kingdom / United States |
| Google LLC (Google Workspace) | Email hosting for @getmyzo.com corporate email | Internal team email; no user data | United States |
Children's data
COPPA places extra duties on any service that handles data from children under 13. For every sub-processor that could touch child-level data — Supabase, Expo, Apple, and Google — we confirm in advance that they (a) are COPPA-aware, (b) store only the minimum data we send them, and (c) honor our deletion requests within a documented window as part of the executed DPA.
PostHog never receives child personally identifying data. We send only anonymous, per-session identifiers and event names for children. The marketing site does not set analytics cookies for visitors under 13.
Changes to this list
When we add, remove, or replace a sub-processor that handles user data, we update this page first and then notify parent guardians by email at least 30 days before the change takes effect. If you object to a new sub-processor you can request that we delete your family's data before the change is applied — see the deletion controls in your account or contact privacy@getmyzo.com.
For the full picture of how we handle data, read our Privacy Policy and the Children's Privacy Notice.