Subprocessor List

Effective Date: 2026-07-16 Last Updated: 2026-07-16 2026-07-16: corrected the AI-model rows (OpenAI is the production conversation provider; Google provides OCR and the Gemini Live standby), disclosed the Railway weekly-summary generation job and Apple push-notification delivery, and corrected the KWS row (the active consent method is the typed-name e-signature). 2026-07-16: added Netlify, Inc. — marketing-website hosting and waitlist form storage (email addresses from the parents-and-educators waitlist; no child or family-account data). Owner: privacy@lanternlearning.io


What's a subprocessor?

A subprocessor is a third-party service Scout uses to provide the Products and Services. Subprocessors may process data on Scout's behalf. We require contractual commitments from every subprocessor to:

A current subprocessor's certifications are verified annually. Scout reviews each subprocessor relationship at least once per year.


Current Subprocessors

Core AI providers

Provider Purpose Data shared In scope for Location Cert
OpenAI (Realtime API) Real-time conversational AI on the device — the voice the child talks with (production provider since 2026-06-29) Voice audio (transient), text prompts All families US DPA + certifications under verification
Google LLC Text recognition (OCR — standard Gemini endpoint, separate API key) for book pages + handwriting; standby conversational AI (Gemini Live API) Camera + handwriting frames (transient, OCR); voice audio (transient, Live) only if the Gemini Live standby is active; text prompts All families US SOC 2 Type II, ISO 27001, FedRAMP
Deepgram, Inc. Speech-to-text for reading-mode assessment Voice audio (transient — deleted post-transcription) All families US SOC 2 Type II, HIPAA
Anthropic, PBC (Claude API) Session analysis, profile updates, reading scoring, weekly parent progress summaries Session transcripts, aggregated metrics, system prompts All families US SOC 2 Type II

Operational platform

Provider Purpose Data shared In scope for Location Cert
Supabase, Inc. Cloud database (Postgres) + storage for Parent App Account info, session summaries, reading metrics All families US SOC 2 Type II
Railway Corp. Application hosting for consent web app + Parent App backend; hosting for Scout's weekly-summary generation job (a dedicated container holding service-role database credentials that reads children's learning data across the roster and writes each family's weekly summary via the Anthropic API) Operational logs, environment config; children's learning data processed in the weekly generation job (results stored in Supabase, not on Railway) All families US SOC 2 Type II
Netlify, Inc. Marketing-website hosting (lanternlearning.io) + waitlist form storage (Netlify Forms) Waitlist email addresses (form directed to parents and educators), standard web server logs Site visitors and waitlist subscribers only — no child or family-account data US SOC 2 Type II
Apple Inc. (Apple Push Notification service) Delivery of the optional weekly summary notification to the iOS Parent App (one per family per week, Sunday evenings) Device push token; notification content — the child's first name inside a fixed weekly-summary message (no summary content), processed only for delivery Families who enable notifications US Apple platform provider — attestations verified at onboarding
Resend Labs, Inc. Transactional email (receipts, magic links, alerts) Email content + recipient address All families US SOC 2 Type II
Epic Games, Inc. (Kids Web Services) Verifiable parental consent (KWS) — integration dormant; not the active VPC method Parent email, location code Not currently active — all families today use the typed-name e-signature method (16 CFR §312.5(b)(2)(i)) US ESRB Privacy Certified, kidSAFE Seal, SOC 2 (Epic's certifications, not Scout's)
Stripe, Inc. (or equivalent) Payment processing for hardware sales Billing info, payment card data (Stripe holds, we don't see card numbers) Hardware purchasers only — pilot families receive devices on loan US PCI-DSS Level 1, SOC 2 Type II

Observability and developer tools

Provider Purpose Data shared In scope for Location Cert
GitHub, Inc. Source code hosting + CI Source code only; no production data n/a (no production data) US SOC 2 Type II
Error-tracking service (planned) Error tracking (Sentry / equivalent) Sanitized error stack traces, sanitized request context When enabled — disclosed in advance US SOC 2 Type II (verify per vendor)
Log-aggregation service (planned) Log aggregation (Datadog / Logtail / equivalent) Sanitized operational logs When enabled — disclosed in advance US SOC 2 Type II (verify per vendor)

Not currently in scope (planned for future, listed for transparency)

Provider Future purpose Status
Shipping-logistics provider Hardware shipping logistics TBD — added when hardware shipping starts
Crash-reporting service Mobile app crash reporting (e.g., Crashlytics) TBD — added when mobile app launches
Product-analytics service Privacy-preserving product analytics TBD — strictly no children's data, aggregate-only
Content-delivery network Content delivery network for static assets TBD — for Parent App (the marketing Site is now hosted on Netlify — see Operational platform)

Cross-references

Each subprocessor that processes family or children's data is also referenced in:

If any such subprocessor is removed, added, or substantially changed, those documents must also be updated. Subprocessors that touch only public-website visitor data (for example, the marketing-site host) are disclosed on this list and in Privacy Policy §3.1.


Notification policy

Material changes to this list (adding a new subprocessor or removing an existing one) trigger:

  1. Update to this document with the new effective date
  2. Email notification to all active Parent App accounts at least thirty (30) days before the change takes effect (sooner if required by law)
  3. Update to the Privacy Policy cross-reference
  4. Where the change is "material" enough to be in scope of COPPA's "material change in practices" rule, renewed verifiable parental consent collection via the /re-consent flow

For B2B customers under a Data Processing Agreement, the DPA's notification requirements apply in addition.


Decommissioned subprocessors

(Historic list, kept for COPPA recordkeeping)

Provider Used from Used until Replaced by Reason
(none decommissioned yet)


Questions? Email privacy@lanternlearning.io. To file a complaint, contact the FTC at reportfraud.ftc.gov or your state attorney general.