← Back to StarSprout
Sub-processors
Version subprocessors-v1 (2026-07) · Pending external legal review before public launch.
Who we use, and what each receives
StarSprout runs on a deliberately small set of providers. Each receives only what its job requires — and child surfaces load nothing from any third party at all (our build fails if they try).
| Provider | What it does | What it receives | Region |
|---|---|---|---|
| Supabase | Database, authentication, file storage, realtime | All family data described in the Privacy Policy, encrypted at rest; adult sign-in emails; proof photos | United Kingdom (London) |
| Vercel | Application hosting and scheduled jobs | Request traffic in transit; no family data at rest | EU/UK edge |
| Anthropic | AI text generation (storylines, lessons, nudges, weekly narrative) | Enumerated tokens only: an age band, an avatar theme, a chore category, or clamped weekly counts. Never names, photos, locations, or child-written text. Not used for model training. | API (US), no data retained for training |
| Resend | Email delivery | Adult email addresses and the content of the emails we send them | EU/US |
| PostHog | Product analytics — parent and marketing surfaces ONLY, never child surfaces | Pseudonymous usage events from adults; no child identifiers exist to send | EU |
| Sentry | Error monitoring | Error reports with personal identifiers stripped (sendDefaultPii is off) | EU |
Changes
We update this register before any new provider touches family data, and the change is announced in the app.