Skip to document

Privacy operations

Whistle subprocessors

Last updated July 15, 2026

This notice describes the processors used by the open build beta. Final operator details, contract review, and commercial-launch signoff remain pending and do not represent the beta as a finished commercial service.

These companies provide infrastructure or processing used by Whistle. Speech-language pathologists are users or authorized providers, not subprocessors. The build-beta configuration does not send child personal information to a third-party story-generation or live-narration provider.

Microsoft Azure Speech

Purpose
Real-time speech recognition and pronunciation scoring; pre-deployment synthesis of fixed publisher narration
Information
Temporary live practice audio, prompt text, recognized text, and speech-processing metadata; fixed generic narration text and voice settings containing no child information

Neon

Purpose
Hosted PostgreSQL database
Information
Adult accounts, consent evidence, pseudonymous reader profiles, practice records, billing state, support, and audit records

Vercel

Purpose
Application hosting, delivery, security, and public-page performance measurement
Information
Web requests and security records; Analytics and Speed Insights are mounted only on approved public and legal pages

Stripe

Purpose
Subscriptions, payments, refunds, fraud review, and chargebacks
Information
Adult billing identity, payment information handled by Stripe, and subscription and transaction records

Resend

Purpose
Delivery of consent follow-up and operational email when those email workflows are enabled
Information
Adult email address, generic consent-notice content, and delivery metadata; direct build-beta profile setup does not require an email delivery

Twilio

Purpose
Minimized operator security and retention-failure alerts
Information
Operator telephone number and fixed operational alert metadata; no child name, practice content, recognized text, or audio

Cloudflare Email Routing

Purpose
Inbound routing for adult operator or public contact addresses
Information
Adult sender and recipient addresses, subject and delivery metadata, and transient message content; this is not an authorized channel for child names, recordings, health records, or school records

Restrictions

Whistle does not authorize a processor to sell child information, use it for targeted advertising, build an unrelated profile, or train a general-purpose model. Optional third-party child generation and live narration are disabled. Fixed publisher narration is generated before deployment and is served from Whistle during use.

Twilio and Cloudflare Email Routing are limited to adult/operator communications. Whistle does not authorize either service to receive child practice content. The downstream destination-mailbox provider must be identified, contract-reviewed, and added to this notice before Whistle publishes an inbound email address as a privacy or support channel; the public web form is the designated intake path.

Whistle will give advance notice before adding a processor that materially changes child-data collection or disclosure and will obtain renewed consent when required.