← Radlic

Service Providers and Subprocessors

Beta version. In effect from 25 September 2026. We will email parents before we make any material change to it.

How to read this

A service provider processes data on our instructions and for no purpose of its own. Under COPPA, handing children's personal information to a third party for the third party's own purposes is a disclosure, and disclosure needs separate parental consent. The right-hand column is therefore the column that matters.

The list

VendorWhat it does for usDoes it receive information about a child?Exactly whatWhereBasis
SupabaseThe entire backend — database, authentication, file storage. The browser talks to it directly.Yes. This is the only service that holds a child's information.First name, avatar number, age band, grade, chosen lessons; lesson progress, points, game-time settings; "didn't get it" taps; product events; crash records; the child's sign-in credentialsus-east-1 (read from the provider's API)Service provider — integral to delivering the service
Supabase platform logs (same vendor, separate matter)The provider's own request logging, outside our database schemaYes, incidentally. Every request a child's device makesIP address, user agent, and an approximate location derived from IP — city, region and country — on every request sampled, plus the signed-in account id on mostSameService provider. Outside our own retention jobs — see the Retention Policy
VercelHosting and content deliveryYes, incidentally. Request logs, and crash lines written to the consoleIP address, request path, user agent; a crash line can carry a child's internal id and the page being viewedFunctions run in iad1, Washington, D.C., USA (confirmed from the Vercel dashboard, 24 September 2026)Service provider — integral
StripeSubscription checkout and billing — not used during the beta: billing is switched off and no data is sent to StripeNo.None during the betaService provider, parent data only, once billing starts
ResendDelivers every email the service sends. It is configured as the SMTP relay behind the authentication service's mailer, so although the application contains no email code of its own, every message a parent receives is delivered by ResendNo, unless a progress email is ever built that names a child — none existsThe parent's email address and the content of the messageUnited States: North Virginia, us-east-1 (confirmed from the Resend dashboard, 24 September 2026)Service provider
Google Sign-InOptional sign-in for adultsNo. Adults only, by top-level redirect; we send nothingNot a recipient of our data
GitHub ActionsEncrypted database backups, stored as a 30-day build artifactWould — a backup contains everythingThe whole database, encryptedGitHub (github.com), United States; kept 30 days, set by our backup jobService provider. Backups working again from 23 September 2026; a full restore was proven that day. See the Security Program.
Google FontsNothing at runtimeNo. Fonts are downloaded at build time and served from our own domain. Verified: 212 font files emitted, zero references to Google's font host in the built stylesheetNot a runtime recipient

Services that receive nothing about a child

No analytics provider. No error or crash monitoring provider. No advertising or tracking service. No AI or text-to-speech provider at runtime — every audio clip a child hears is a static file served from our own domain, and where a clip is missing the fallback is the browser's own on-device speech. No child's input is ever sent to an AI or audio vendor.

How this absence was established, so it can be checked again rather than taken on trust: no analytics package is installed; no external script, beacon, sendBeacon, WebSocket or tracking pixel exists in the source; the Content-Security-Policy served by production restricts connections to our own origin and Supabase, so the browser is structurally unable to reach an analytics host; and a real child session driven on production — module list, a full lesson with audio, practice problems — produced 56 requests to exactly one origin, our own, with zero third-party requests. The same capture shows the audio and page loads, which proves the capture was live rather than empty.

Questions about your child's data? Email support@radlor.com. You can download or delete everything from the parent dashboard.