Saplyn Privacy Policy
Effective date: August 31, 2026 · Mommalyn Inc.
Saplyn is a childcare-management platform operated by Mommalyn Inc., a Delaware corporation ("Saplyn," "we," "us"). Childcare centers and other childcare providers ("Centers") use Saplyn to run their operations; parents, guardians, and other household members ("Family Users") use the Saplyn parent portal and mobile app to stay connected with their Center.
This policy explains what personal information we handle, in which capacity we handle it, and the choices available to you. It covers the Saplyn web application at saplyn.co, the Saplyn mobile app, and our public web pages (together, the "Service").
1. The two roles we play
Saplyn handles personal information in two distinct capacities, and your rights differ depending on which applies:
(a) On behalf of your Center (Saplyn as processor / service provider). The records a Center keeps in Saplyn — child profiles, enrollment and attendance records, daily reports and photos, health and allergy information, incident reports, messages, staff employment records, family billing records, and similar operational data ("Center Records") — belong to the Center. The Center decides what is collected and who may see it; we process these records only on the Center's instructions under our Data Processing Addendum. If you want to access, correct, or delete Center Records — including records about you or your child — contact your Center. We will assist the Center in honoring your request, but the decision is the Center's to make (subject to laws that require childcare providers to retain certain records).
(b) For ourselves (Saplyn as controller). We are responsible for:
- Account and sign-in data for all users (name, email address, authentication records, language preference, notification preferences);
- Center subscription and billing data (plan, invoices, payment status);
- Usage analytics about how the Service is used;
- Our public website, including the pricing page, the early-access sign-up form on our home page, and the Discover directory (Section 8). A Center's own public enrollment pages — its application form, and any named application link or QR code it publishes for a campaign — are not ours: what a family submits there becomes that Center's record and is handled under (a);
- Support and communications you send directly to us.
The rest of this policy describes both roles; where a statement applies to only one, we say so.
2. Information we collect
You provide it (or your Center provides it about you):
- All users: name, email address, and account settings. Sign-in is by emailed magic link — we never collect or store passwords.
- Prospective customers: if you ask for early access from our public site, we keep the email address you enter, which page you entered it on, the language the site was in, and when you first and last asked — so we can reply to you in the right language and know you asked twice. This is data we control (Section 1(b)), it is about a business contact rather than any child or family, and you can have it deleted at any time by emailing legal@saplyn.co.
- Center staff: employment profile, role and permissions, schedules, shifts and timesheets, time-off requests, credentials, training and compliance documents, and staff-to-staff messages (Center Records).
- People who have been invited but have not joined yet: when a Center invites someone to work there, when a Center asks a parent to connect their account, or when a family invites another adult into its household, we keep the email address the invitation was sent to, who sent it, what it grants, and when it expires — and, because that email is the only way the invitation can reach them, what became of it: whether our email provider accepted the message and, where the provider tells us, whether their mail server delivered or refused it, or they reported it as spam. Someone who has been invited has no account here yet, so there is nothing we could show them in the app instead; without this, an invitation that never arrived is indistinguishable from one the person has not got round to. It records the fate of the message and not the person's behaviour: we do not track whether an email was opened or a link was clicked. An unaccepted invitation expires and never becomes an account. Center and household invitations are Center Records (Section 1(a)); once someone accepts, what we hold about them is the account data described above.
- Family Users: household and contact details, relationship to each child, emergency contacts, messages with the Center, and — if the Center bills through Saplyn — payment history. Card and bank details are entered directly with our payment processor, Stripe; Saplyn stores only tokens and display metadata (e.g., card brand and last four digits). Where a Center emails a family its enrollment paperwork, we also record, for each adult the paperwork was sent to, what became of that email — and of the reminders that follow it, when forms are still outstanding or a document the Center holds is about to expire: whether our email provider accepted each message and, where the provider tells us, whether that adult's mail server delivered or refused it, or they reported it as spam. The paperwork opens from the emailed link rather than from a login, so a message that never arrived means a family that cannot fill the forms in at all — this is how a Center sees that, instead of chasing them for paperwork they never received. As with the waitlist emails described below, it records the fate of the message and not the person's behaviour: we do not track whether an email was opened or a link was clicked. These are Center Records (Section 1(a)).
- About children (entered by Centers and Family Users, as Center Records): name, date of birth, enrollment and classroom placement — including whether a Center has started an enrollment conditionally while a required document is outstanding, and the date that grace period ends — attendance, the days and hours a child is scheduled to attend, daily-report entries (meals, naps, diapers, moods, milestones), photos, allergies and dietary restrictions, medical information, medication permissions and administration logs, immunization records, incident reports, developmental observations, and the documents a family returns with its enrollment paperwork (for example, a photographed immunization record or health assessment, which a family may return as several files).
- Waitlist applicants: the child's name and date of birth; the applying adult's name, email address, phone number, and relationship to the child; the location, classroom, or program requested, the desired start date, and the days of the week and session length the family is asking for; any priority category the family claims (for example, sibling or staff); the language the family filled the form in, so the Center's messages back to them go out in that language; and any refundable deposit (processed by Stripe). We also record how the family reached the Center's application page: what the family says when asked how they heard about the Center, and — where the Center has published a named application link or QR code for a particular flyer, post, or event — which of those links was used. That is attribution for the Center's own enrollment marketing, so the Center can tell which of its campaigns filled a seat. It is not tracking across other websites, and it involves no advertising identifier. We also record what became of the emails the Center sends that family — a spot offer, a "still interested?" check-in, an automatic update as the application moves along, or a note the director writes after a tour — namely whether our email provider accepted the message and, where the provider tells us, whether the family's mail server delivered or refused it, or the family reported it as spam. That is so a Center can see that a time-limited offer never reached the family and reach them another way, rather than watch it expire. It records the fate of the message, not the family's behaviour: we do not track whether an email was opened or a link was clicked. All of it is a Center Record (Section 1(a)).
- Unfinished applications: if a family starts an application on a Center's public page and does not submit it, we save what has been entered so far — as far as the family got, which may include the child's name and date of birth and the adult's email address and phone number — so they can come back and finish it, and we email that address a link back to what they saved. We record what became of that one message too — whether our email provider accepted it and, where the provider tells us, whether it was delivered, refused, or reported as spam — because the link is the only way back to what the family entered, and a message that never arrived means the work is simply lost. Nothing joins the Center's waitlist until the family submits: an unfinished application is not an applicant, is kept in a separate record, and appears in no queue, count, or report. It is kept for a limited time and then deleted (Section 5), and it is a Center Record (Section 1(a)).
- Voice observations: staff may dictate short voice notes into daily reports; the audio is transcribed by a speech-to-text provider and the audio clip and transcript become part of the report (Center Records).
- Billing assistant requests: where a Center uses the optional billing assistant, we keep a record of each request a director types (for example, "Sofia starts the 3rd, 70/30 split"), the model's structured response, and whether it succeeded — so that failures can be diagnosed and the feature improved. These requests describe children and families and are Center Records. They are kept for 90 days and then deleted (Section 5).
Collected automatically:
- Usage data: pseudonymous analytics events (pages/screens viewed, features used), device and browser type, and feature-flag evaluations, via PostHog.
- Log and security data: IP address, timestamps, and an audit trail of meaningful actions taken in a Center's account (who changed what, when).
- Error reports: when something in the Service fails, we send a technical report to Sentry so we can fix it — the stack trace, the type of request, your account identifier, and our own internal record identifiers for the records involved. We deliberately exclude names, email addresses, request contents and web addresses that could carry them; we do not record your screen or session.
- Cookies: we use strictly necessary cookies (session authentication) and an analytics cookie (PostHog). We do not use advertising cookies. See Section 10.
- Push tokens: if you enable notifications in the mobile app, we store a device push token to deliver them.
From other sources:
- Public licensing records from the Utah Department of Workforce Services, used for the public Discover directory (Section 8).
- Stripe sends us payment outcome events (succeeded, failed, disputed) for payments and subscriptions.
- Resend, our email provider, sends us delivery outcome events (delivered, bounced, reported as spam) for the messages the Service sends on a Center's behalf. We do not receive open or click events.
What we do not collect: we do not knowingly collect precise geolocation, we do not use facial recognition or derive biometric identifiers from photos, and we do not collect information from children directly (Section 7).
3. How we use information
- Provide the Service: operate each Center's account; show each user the records their Center has authorized them to see; deliver daily reports, messages, and notifications; process check-ins (including kiosk and secure tokenized links); run scheduling, billing, compliance, and waitlist features.
- Payments: bill Centers for their Saplyn subscription; process tuition, fees, and deposits that Centers collect from families through Stripe.
- Communications: send transactional email and push notifications (sign-in links, daily reports, billing notices, messages). Emails are sent in the recipient's language preference.
- AI features: several features send data to an AI provider to produce a draft or an answer. Anthropic's Claude API receives the request and the context that feature includes: the Saplyn assistant and the custom report builder; drafting a child's daily summary or a staff message to that child's family from the day's entries; drafting newsletters, lesson plans and a post-tour follow-up email; translating a message someone has drafted before it is sent; and "Ask Saplyn," where a parent or guardian asks a question about their own child's recent days — which sends that child's first name and those days' care entries. OpenAI receives short audio clips when staff dictate a voice observation, and — where a Center turns on the optional billing assistant — the director's request together with that one family's billing picture (child names, payer names and shares, plan and charge amounts, balances and open invoices) to classify the request and draft parent-facing copy; where the Center also turns on the enrollment assistant, the same request carries the Center's current waitlist applicants and the start date, room and schedule each asked for. These providers are bound as subprocessors and do not use this data to train their models by default. AI output is a draft, never an action. None of these features sends an email, posts a charge, enrolls a child, or changes a record on its own: a person reviews the draft and takes the action. The billing and enrollment assistants write nothing until a director approves each proposal.
- Improve and secure the Service: analytics, debugging, abuse prevention, audit logging, and staged feature rollouts.
- Comply with law and enforce our terms.
We do not sell personal information, share it for cross-context behavioral advertising, or use Center Records (including any child's information) for advertising or for training AI models. We may create and use de-identified, aggregated statistics — data that does not identify, and cannot reasonably be used to identify, any Center, child, or person — to improve the Service and produce aggregate industry insights, and we commit to maintaining such data in de-identified form and never attempting to re-identify it.
4. How information is shared
- With your Center and the people it authorizes. Center Records are visible to Center staff according to the Center's own permission settings, and to the Family Users the Center connects to each child. Members of a child's household may see that child's information according to the roles the household holds.
- With our subprocessors — the vendors that host and power the Service — listed with their purposes in our Subprocessor List (Supabase, Vercel, Stripe, Resend, Expo, Anthropic, OpenAI, PostHog, and Sentry).
- With Stripe as payment processor. When you pay through the Service, Stripe processes your payment information under its own privacy policy. Centers that accept payments are onboarded to Stripe Connect, which requires Stripe to collect business and representative verification (KYC) information.
- In a business transfer (merger, acquisition, or sale of assets), in which case this policy continues to apply to transferred information.
- For legal reasons, if required by law or to protect the safety of a child, our users, or the public. Where the request concerns Center Records we will refer the requester to the Center and notify the Center unless legally prohibited.
We never share personal information with third parties for their own marketing.
5. Retention
- Center Records are retained while the Center's account is active and handled per the Center's instructions afterward. On termination, the Center may export its data; we delete or return Center Records as described in the DPA (§ 9). Childcare records are subject to state licensing retention requirements (in Utah and elsewhere); those laws may require a Center to keep records even where a person asks for deletion.
- Controller data: account data is kept while your account is active and deleted or de-identified within 90 days of account deletion, except billing records we must keep for tax and accounting purposes and audit/ security logs retained for 12 months.
- Billing assistant requests (Section 2) are deleted 90 days after they are made. This is a fixed window, not a manual clean-up: an expiry is written on each record and a scheduled job removes them.
- Unfinished applications (Section 2) expire 14 days after they were last saved. The expiry date is written on each saved draft when it is created; on that date the emailed resume link stops working, and the saved draft is deleted rather than shown to anyone who presents the link.
- Residual copies in encrypted backups are purged on the backup provider's rolling schedule.
6. Your rights and choices
- Center Records: contact your Center (Section 1(a)). We contractually assist Centers in responding.
- Your Saplyn account data: email legal@saplyn.co to request access, correction, a copy, or deletion of the data we control. We will verify the request via your account email and respond within the time required by applicable law (45 days under most U.S. state privacy laws, extendable once where permitted). If we deny a request you may appeal by replying to our decision; if we deny the appeal, applicable state law may let you contact your state attorney general.
- Utah residents (UCPA) and residents of other states with consumer privacy laws have rights of access, deletion, portability, and to opt out of targeted advertising and sales — we do neither, so there is nothing to opt out of.
- Notifications: manage notification channels per event type in your settings; disable push in your device settings. Transactional messages (e.g., sign-in links) cannot be disabled while your account is active.
- Analytics: analytics identifiers are pseudonymous and used only for product analytics and feature rollout; we do not currently offer a separate in-product analytics opt-out.
7. Children's privacy
The Service is for adults: Center staff and Family Users must be at least 18. Children do not have accounts, and no part of the Service is directed to children. Information about children is entered by their childcare provider and their own guardians so that the provider can care for them — in COPPA terms, Saplyn collects children's information only as a service provider to the Center and the family, not from children themselves. Centers are responsible for obtaining any parental consents their license, their enrollment agreements, or applicable law require (including consent for photos). If you believe a child's information has been submitted to us outside this arrangement, contact legal@saplyn.co and we will delete it.
8. The Discover directory
Our public Discover page shows a map of licensed childcare providers compiled from Utah Department of Workforce Services public licensing records. This is public government data about licensed businesses, and Saplyn acts as an independent controller of it. Ratings shown are derived from public licensing data, not user reviews. For home-based providers we limit the precision of displayed location information. If you are a licensed provider and want your listing corrected or (for home-based providers) further limited, contact legal@saplyn.co.
9. Security
We take security seriously, and we scope it honestly:
- All data is encrypted in transit (TLS) and at rest by our infrastructure providers.
- Sign-in is passwordless (emailed magic links) with database-backed sessions, so there is no Saplyn password to steal or reuse.
- Every Center's data is isolated by tenant: queries are scoped to the Center's organization, and each read and write is authorized against capability-based permissions the Center controls.
- Meaningful changes are audit-logged.
- Links that stand in for signing in. Several pages open from a link we email rather than from a login, so the link itself is the credential: an enrollment packet, an offer of a spot, a household invitation, an invitation to join a Center's staff or connect to a child, and the link back to an application a family started but did not finish. Each of these carries a 192-bit token generated from a cryptographic random source — generated by the application, never a database default — opens only the one record it was issued for, and stops working once that record is answered, withdrawn, or expires (an enrollment packet once it is archived; an unfinished application 14 days after it was last saved). The public actions behind these links — signing, answering an offer, uploading, saving a partly filled form — are rate-limited both per link and per network address, and any file uploaded through them is identified from its actual bytes against an allowed-type list on our servers before it is stored, so renaming a file does not get it past the check.
- When our own staff need access to a Center's records — to help set the Center up, or to look into a problem it has reported — that access is granted one Center at a time, with a recorded reason, and it expires on its own (7 days by default, 30 at most). The Center sees it in its own audit log, both when it is granted and on every action taken under it, so our work is never mistaken for its staff's — and the Center can end it itself at any time, without asking us.
- Full payment credentials are held by Stripe, not by us.
No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify affected Centers and users as required by law, and Centers without undue delay per the DPA.
10. Cookies
| Cookie | Purpose | Type |
|---|---|---|
| Session cookie (Auth.js) | Keeps you signed in | Strictly necessary |
| CSRF/callback cookies (Auth.js) | Sign-in security | Strictly necessary |
| PostHog analytics | Pseudonymous product analytics and feature flags | Analytics |
We do not use advertising or cross-site tracking cookies, and we do not respond to browser "Do Not Track" signals because we do not track users across other sites.
11. International users
The Service is operated from the United States and all data is stored and processed in the United States. Saplyn is currently offered to U.S. childcare providers. If you access the Service from outside the U.S., you consent to processing in the U.S.
12. Changes
We will post any changes here and update the effective date. For material changes we will notify Centers and account holders by email or in-app notice before the change takes effect.
13. Contact
Mommalyn Inc. 3723 Greenville Ave STE 41398, Dallas, TX 75206 legal@saplyn.co