Early Bird Special — save up to 38% during launch. Limited time.
Myzo

Legal · Last updated 2026-07-21

Sub-processors

Myzo relies on a small set of third-party services — called sub-processors — to run the app. Every sub-processor we use is listed below, along with what they do for us, the kind of data they touch, and a link to the Data Processing Agreement we have on file with them.

We sign a Data Processing Agreement (DPA) with each sub-processor, including the EU Standard Contractual Clauses as an appendix where the sub-processor is located outside the European Economic Area, the United Kingdom, or Switzerland. Before we route any user data through a new sub-processor, the DPA is in place. Under GDPR (and our COPPA commitments), we notify affected parents at least 30 days before adding a new sub-processor that would handle your or your child's data.

Current sub-processors

VendorPurposeData touchedRegion
Supabase Inc.Primary application database, authentication, edge-function hosting, realtime syncParent email, parent name, child first name + avatar, all task / session / score / reward data, COPPA consent recordsUnited States
PostHog Inc.Product analytics and feature flags. Children are tracked anonymously (no name, email, device ID)Anonymous session IDs for children; adult guardian pseudonymous UUID + event names for adultsUnited States
Resend (Drie Labs Inc.)Transactional and marketing email deliveryParent email address and the contents of the message sentUnited States
650 Industries, Inc. ("Expo")Mobile-app build infrastructure and push-notification delivery pipelineBuild artifacts (no user data); Expo push tokens issued to each installed appUnited States
Cloudflare, Inc.Marketing-site content delivery network and edge hostingWeb-visitor IP address, browser metadata, request logs (no app-user data)Global (processed at the nearest edge)
Apple, Inc.iOS App Store distribution, TestFlight, Apple Push Notification service, In-App PurchaseApp downloads, crash reports, IAP transaction metadataUnited States / EU
Google LLCGoogle Play Store distribution, Firebase Cloud Messaging, In-App Billing (Android)App downloads, crash reports, push delivery routingUnited States / EU
Paddle.com Market LimitedSubscription billing (web checkout), acting as Merchant of RecordParent email, billing address (held by Paddle only), payment method (held by Paddle only). We receive only opaque customer + transaction identifiersUnited Kingdom / United States
Google LLC (Google Workspace)Email hosting for @getmyzo.com corporate emailInternal team email; no user dataUnited States

Children's data

COPPA places extra duties on any service that handles data from children under 13. For every sub-processor that could touch child-level data — Supabase, Expo, Apple, and Google — we confirm in advance that they (a) are COPPA-aware, (b) store only the minimum data we send them, and (c) honor our deletion requests within a documented window as part of the executed DPA.

PostHog never receives child personally identifying data. We send only anonymous, per-session identifiers and event names for children. The marketing site does not set analytics cookies for visitors under 13.

Changes to this list

When we add, remove, or replace a sub-processor that handles user data, we update this page first and then notify parent guardians by email at least 30 days before the change takes effect. If you object to a new sub-processor you can request that we delete your family's data before the change is applied — see the deletion controls in your account or contact privacy@getmyzo.com.

For the full picture of how we handle data, read our Privacy Policy and the Children's Privacy Notice.