Privacy operations
Whistle subprocessors
This notice describes the processors used by the open build beta. Final operator details, contract review, and commercial-launch signoff remain pending and do not represent the beta as a finished commercial service.
These companies provide infrastructure or processing used by Whistle. Speech-language pathologists are users or authorized providers, not subprocessors. The build-beta configuration does not send child personal information to a third-party story-generation or live-narration provider.
Microsoft Azure Speech
- Purpose
- Real-time speech recognition and pronunciation scoring; pre-deployment synthesis of fixed publisher narration
- Information
- Temporary live practice audio, prompt text, recognized text, and speech-processing metadata; fixed generic narration text and voice settings containing no child information
Neon
- Purpose
- Hosted PostgreSQL database
- Information
- Adult accounts, consent evidence, pseudonymous reader profiles, practice records, billing state, support, and audit records
Vercel
- Purpose
- Application hosting, delivery, security, and public-page performance measurement
- Information
- Web requests and security records; Analytics and Speed Insights are mounted only on approved public and legal pages
Stripe
- Purpose
- Subscriptions, payments, refunds, fraud review, and chargebacks
- Information
- Adult billing identity, payment information handled by Stripe, and subscription and transaction records
Resend
- Purpose
- Delivery of consent follow-up and operational email when those email workflows are enabled
- Information
- Adult email address, generic consent-notice content, and delivery metadata; direct build-beta profile setup does not require an email delivery
Twilio
- Purpose
- Minimized operator security and retention-failure alerts
- Information
- Operator telephone number and fixed operational alert metadata; no child name, practice content, recognized text, or audio
Cloudflare Email Routing
- Purpose
- Inbound routing for adult operator or public contact addresses
- Information
- Adult sender and recipient addresses, subject and delivery metadata, and transient message content; this is not an authorized channel for child names, recordings, health records, or school records
Restrictions
Whistle does not authorize a processor to sell child information, use it for targeted advertising, build an unrelated profile, or train a general-purpose model. Optional third-party child generation and live narration are disabled. Fixed publisher narration is generated before deployment and is served from Whistle during use.
Twilio and Cloudflare Email Routing are limited to adult/operator communications. Whistle does not authorize either service to receive child practice content. The downstream destination-mailbox provider must be identified, contract-reviewed, and added to this notice before Whistle publishes an inbound email address as a privacy or support channel; the public web form is the designated intake path.
Whistle will give advance notice before adding a processor that materially changes child-data collection or disclosure and will obtain renewed consent when required.