Subprocessors
Third-party services that process Scout user data on our behalf. For each: what data flows, why, where it's processed, and the status of any contract (DPA / standard terms) we have with the provider. This page is the canonical transparency surface our privacy policy points to.
Last reviewed: 2026-05-16
- DPA in progress
Anthropic
United StatesLarge-language-model provider — generates Scout's Socratic responses to kid messages.
Data flowConversation text (kid message + Scout system prompt + recent history). Per the Anthropic API terms, prompts and completions are not used to train Anthropic's models.DPA noteRequest workflow: Anthropic Console → Settings → Legal → request DPA. Update this row's status to 'signed' + the signed-on date once executed.Last reviewed2026-05-16 - Standard terms
OpenAI (Whisper STT)
United StatesSpeech-to-text transcription for English voice sessions when voice mode is enabled.
Data flowAudio clip of the child's spoken utterance. Returns the text transcript. Per OpenAI API terms, audio is not retained for model training.DPA noteStandard OpenAI Business Associate / DPA terms apply via the API agreement. No separately-negotiated addendum.Last reviewed2026-05-16 - DPA in progress
ElevenLabs
United StatesText-to-speech synthesis for Scout's spoken voice responses.
Data flowScout's response text (no kid input is sent). Returns synthesized audio.DPA noteDPA request pending — outbound to ElevenLabs legal.Last reviewed2026-05-16 - Standard terms
Microsoft Azure Cognitive Services
United StatesPer-phoneme pronunciation scoring on language drill turns (Spanish / French / German vocabulary).
Data flowAudio clip of the drill utterance + the reference text Scout is teaching. Returns word-level and phoneme-level accuracy scores. Only sent on drill turns — conversational turns are transcribed by OpenAI Whisper, never by Azure.DPA noteMicrosoft Online Services DPA covers Azure Cognitive Services with explicit COPPA and FERPA compliance posture.Last reviewed2026-05-16 - Standard terms
Amazon Web Services (Lightsail + S3)
us-east-1 (United States)Application hosting (Lightsail) and database backup replication via Litestream to S3.
Data flowAll Scout data lives on the hosting volume: user accounts, sessions, exchanges, voice clips, training audit rows. The SQLite database is continuously replicated to a private S3 bucket for disaster recovery.DPA noteAWS Customer Agreement + DPA addendum apply to all Lightsail + S3 usage.Last reviewed2026-05-16 - Standard terms
Cloudflare
Global edge (Cloudflare PoPs)CDN + HTTPS termination for scout-learning.com (Flexible SSL mode currently; Full SSL upgrade tracked separately).
Data flowRequest headers and IP addresses pass through Cloudflare's edge for routing and DDoS protection. Cloudflare does not have access to application-level user data (kid messages, audio, etc.) — that traffic is decrypted only on the Lightsail origin.DPA noteCloudflare standard DPA applies via the account terms.Last reviewed2026-05-16 - DPA in progress
Resend
United StatesTransactional email delivery — signup verification, magic-link sign-in, password reset, weekly digest, consent verification.
Data flowRecipient email address + email body (which contains links, no kid PII beyond the parent's name in some templates).DPA noteDPA request pending — outbound to Resend.Last reviewed2026-05-16
How we maintain this list
- Every third party with access to user data is listed here. If you find a service Scout uses that isn't on this page, please email [email protected] and we'll correct it.
- Each row is re-reviewed at minimum during our bi-weekly audit cycle. The "Last reviewed" date at the top of this page is the most recent of all row reviews.
- "DPA in progress" means we have requested a Data Processing Addendum from the provider and have not yet executed it. "Standard terms" means the provider's published terms include a DPA that applies automatically to our usage. "DPA signed" means we have a separately-executed agreement on file.
- Adding a new subprocessor requires (a) updating this list before the integration ships and (b) updating the privacy policy if the data category is new. Both are tracked under the same PR.