SaplynSign in

Saplyn Subprocessor List

Last updated: August 31, 2026 · Mommalyn Inc. ("Saplyn")

Mommalyn Inc., a Delaware corporation ("Saplyn," "we"), uses the third-party subprocessors below to provide the Saplyn childcare-management platform (the "Service"). A subprocessor is a third party we engage that may process Customer Data (as defined in our Data Processing Addendum) on our behalf. Before engaging any subprocessor, we assess its security and confidentiality practices and bind it by contract to obligations no less protective than those in our DPA.

We will provide notice of new subprocessors as described in the DPA (§ 6) before giving a new subprocessor access to Customer Data.

Infrastructure subprocessors

These subprocessors may process any category of Customer Data, because they host or transmit the Service itself.

SubprocessorPurposeData processedLocation
Supabase, Inc.Primary database (PostgreSQL) and file storage (photos, report media, message and document attachments)All Customer Data at restUnited States
Vercel Inc.Application hosting, serverless compute, and content delivery for the web application and APIAll Customer Data in transit through the applicationUnited States

Functional subprocessors

These subprocessors receive only the data categories listed, only when the corresponding feature is used.

SubprocessorPurposeData processedLocation
Stripe, Inc.Payment processing: (a) Saplyn's subscription billing to Centers; (b) tuition, fees, and waitlist deposits collected by Centers from families via Stripe ConnectPayer name and email; payment method details (card / U.S. bank account, collected directly by Stripe — full card and bank numbers never reach Saplyn's servers); invoice and payment amounts; Center business and representative details for Connect onboarding (KYC)United States
Resend, Inc.Transactional email delivery: sign-in magic links, notification emails, invitations, and the tokenized links a waitlist or enrollment family needs; and reporting delivery outcomes back to SaplynRecipient name and email address; email content, which may reference children by name (e.g., daily-report and billing notifications). Resend also returns delivery events for messages it has already carried — whether a recipient's mail server accepted, refused, or the recipient reported the message — which Saplyn records against the message it sent. Resend receives no additional data in order to send them. Saplyn does not enable Resend's open- or click-trackingUnited States
Expo (650 Industries, Inc.)Mobile push-notification delivery for the Saplyn mobile appDevice push tokens; notification title/body, which may reference children by name; delivery receiptsUnited States
Anthropic, PBCAI drafting and question-answering. Every one of these returns a draft or an answer for a person to read — none of them sends, posts, or saves anything on its own: (a) the in-app "Saplyn" assistant; (b) the natural-language custom report builder; (c) drafting a child's daily-report summary, and a staff message to that child's family, from the day's entries; (d) drafting newsletters and lesson plans; (e) drafting a follow-up email to a family after a tour; (f) translating a message someone has already drafted, before it is sent; (g) "Ask Saplyn," where a Family User asks a question about their own child's recent daysThe prompt and whatever tenant data that feature includes as context, which differs by feature: report parameters, classroom names and age groups, and staff-typed text for (a), (b) and (d), with no child data; one child's first name and that day's care record — attendance times, meals, naps, diapers, moods, milestones, activities, absence reason and staff notes — for (c) and (g); a prospective child's and guardian's first names for (e); and the message text as drafted, whatever it contains, for (f). Sent via the Claude API, which does not use API inputs/outputs to train models by defaultUnited States
OpenAI, LLC (see notes below)(a) Speech-to-text transcription of staff voice observations dictated into daily reports; (b) the optional billing assistant: classify a director's natural-language request and draft parent-facing bill copy. The model does not compute amounts or post charges — a staff member must approve before anything is recorded on the ledger(a) Short audio clips recorded by staff, which may mention children by name; resulting transcripts. (b) Billing-assistant prompts: the director's request together with a compact picture of the one family it names — child first and last names, payer names and their share of the bill, tuition plan names and amounts in cents, subsidy and split-payer context, each payer's outstanding balance, recent posted charges and open invoice totals. Where a Center also enables the enrollment assistant, the same prompt carries that Center's current waitlist applicants — the child's first and last name, the requested start date, classroom and schedule — for children not yet enrolled anywhere. API inputs and outputs are not used to train OpenAI models by defaultUnited States
PostHog, Inc.Product analytics and feature-flag delivery (web and mobile)Pseudonymous user identifier, organization identifier, page/screen views, feature-usage events, device and browser metadata. Not child records.United States (us.i.posthog.com)
Functional Software, Inc. d/b/a Sentry (added August 25, 2026 — see notice below)Application error tracking and crash reporting for the web application, its scheduled jobs and payment webhooks, and the mobile appStack traces and source file paths; the request method and a redacted request path (query strings, request bodies, cookies and authorization headers are never sent, and single-use tokens in public link paths are replaced before transmission); the signed-in user's account identifier; our own internal record identifiers (organization, billing account, invoice, payment, charge, and child ids) and Stripe event and account identifiers, so an error can be traced to the record it concerns; counts, statuses and amounts in cents; the deployed commit. No names, email addresses, photographs, health or attendance records, or message content. Device and operating-system metadata for mobile crashes. Session Replay is not enabled.United States (us.sentry.io)

Not subprocessors (for clarity)

  • Ubiquiti / UniFi camera systems. Centers may connect their own on-premises UniFi camera hardware. The cameras and recordings belong to and are operated by the Center; Saplyn relays snapshots on demand to the Center's authorized staff and stores the connection details the Center provides. Ubiquiti is the Center's vendor, not Saplyn's subprocessor.
  • Apple Inc. / Google LLC act as conduits for push notifications delivered to iOS and Android devices via Expo, under their platform terms.
  • Utah Department of Workforce Services. Saplyn's public "Discover" directory is compiled from Utah DWS public childcare-licensing records. This is public government data about licensed providers, not Customer Data.

Note on transcription: the transcription integration is OpenAI-API-compatible and may be repointed to an alternative provider (e.g., Groq, Inc.). If that is done in production, this list must be updated before the change takes effect.

Note on the billing assistant: this purpose uses OpenAI's Responses API (not Whisper). Prefer a separate OpenAI project with Zero Data Retention for billing so spend, key rotation, and retention are independent of transcription. The assistant is feature-flagged and off by default.

Notice for Sentry (added August 25, 2026): Sentry is listed here under the 15-day notice period in DPA § 6.3, which for the web application runs ahead of use: its error reporting stays inert until a Sentry key is configured, no key is configured in any environment as of the date above, and none will be set before September 9, 2026. The Saplyn mobile app reports crashes to Sentry in released (non-development) builds. The identifiers Sentry receives are our own database ids, which are meaningless outside the Service — they let us find the record an error concerns without sending anything about the person it belongs to.

Questions

legal@saplyn.co