SaplynSign in

Saplyn Privacy Policy

Effective date: August 9, 2026 · Mommalyn Inc.

Saplyn is a childcare-management platform operated by Mommalyn Inc., a Delaware corporation ("Saplyn," "we," "us"). Childcare centers and other childcare providers ("Centers") use Saplyn to run their operations; parents, guardians, and other household members ("Family Users") use the Saplyn parent portal and mobile app to stay connected with their Center.

This policy explains what personal information we handle, in which capacity we handle it, and the choices available to you. It covers the Saplyn web application at saplyn.co, the Saplyn mobile app, and our public web pages (together, the "Service").

1. The two roles we play

Saplyn handles personal information in two distinct capacities, and your rights differ depending on which applies:

(a) On behalf of your Center (Saplyn as processor / service provider). The records a Center keeps in Saplyn — child profiles, enrollment and attendance records, daily reports and photos, health and allergy information, incident reports, messages, staff employment records, family billing records, and similar operational data ("Center Records") — belong to the Center. The Center decides what is collected and who may see it; we process these records only on the Center's instructions under our Data Processing Addendum. If you want to access, correct, or delete Center Records — including records about you or your child — contact your Center. We will assist the Center in honoring your request, but the decision is the Center's to make (subject to laws that require childcare providers to retain certain records).

(b) For ourselves (Saplyn as controller). We are responsible for:

  • Account and sign-in data for all users (name, email address, authentication records, language preference, notification preferences);
  • Center subscription and billing data (plan, invoices, payment status);
  • Usage analytics about how the Service is used;
  • Our public website, including the pricing page, enrollment interest forms, and the Discover directory (Section 8);
  • Support and communications you send directly to us.

The rest of this policy describes both roles; where a statement applies to only one, we say so.

2. Information we collect

You provide it (or your Center provides it about you):

  • All users: name, email address, and account settings. Sign-in is by emailed magic link — we never collect or store passwords.
  • Center staff: employment profile, role and permissions, schedules, shifts and timesheets, time-off requests, credentials, training and compliance documents, and staff-to-staff messages (Center Records).
  • Family Users: household and contact details, relationship to each child, emergency contacts, messages with the Center, and — if the Center bills through Saplyn — payment history. Card and bank details are entered directly with our payment processor, Stripe; Saplyn stores only tokens and display metadata (e.g., card brand and last four digits).
  • About children (entered by Centers and Family Users, as Center Records): name, date of birth, enrollment and classroom placement, attendance, daily-report entries (meals, naps, diapers, moods, milestones), photos, allergies and dietary restrictions, medical information, medication permissions and administration logs, immunization records, incident reports, and developmental observations.
  • Waitlist applicants: the child and contact details submitted with an application, and any refundable deposit (processed by Stripe).
  • Voice observations: staff may dictate short voice notes into daily reports; the audio is transcribed by a speech-to-text provider and the audio clip and transcript become part of the report (Center Records).

Collected automatically:

  • Usage data: pseudonymous analytics events (pages/screens viewed, features used), device and browser type, and feature-flag evaluations, via PostHog.
  • Log and security data: IP address, timestamps, and an audit trail of meaningful actions taken in a Center's account (who changed what, when).
  • Cookies: we use strictly necessary cookies (session authentication) and an analytics cookie (PostHog). We do not use advertising cookies. See Section 10.
  • Push tokens: if you enable notifications in the mobile app, we store a device push token to deliver them.

From other sources:

  • Public licensing records from the Utah Department of Workforce Services, used for the public Discover directory (Section 8).
  • Stripe sends us payment outcome events (succeeded, failed, disputed) for payments and subscriptions.

What we do not collect: we do not knowingly collect precise geolocation, we do not use facial recognition or derive biometric identifiers from photos, and we do not collect information from children directly (Section 7).

3. How we use information

  • Provide the Service: operate each Center's account; show each user the records their Center has authorized them to see; deliver daily reports, messages, and notifications; process check-ins (including kiosk and secure tokenized links); run scheduling, billing, compliance, and waitlist features.
  • Payments: bill Centers for their Saplyn subscription; process tuition, fees, and deposits that Centers collect from families through Stripe.
  • Communications: send transactional email and push notifications (sign-in links, daily reports, billing notices, messages). Emails are sent in the recipient's language preference.
  • AI features: when a Center uses the Saplyn assistant or the custom report builder, relevant tenant data is sent to Anthropic's Claude API to generate the response; when staff dictate voice observations, the audio is sent to a speech-to-text provider for transcription. These providers are bound as subprocessors and do not use this data to train their models by default. AI output is drafted for human review — a staff member approves actions before they take effect.
  • Improve and secure the Service: analytics, debugging, abuse prevention, audit logging, and staged feature rollouts.
  • Comply with law and enforce our terms.

We do not sell personal information, share it for cross-context behavioral advertising, or use Center Records (including any child's information) for advertising or for training AI models. We may create and use de-identified, aggregated statistics — data that does not identify, and cannot reasonably be used to identify, any Center, child, or person — to improve the Service and produce aggregate industry insights, and we commit to maintaining such data in de-identified form and never attempting to re-identify it.

4. How information is shared

  • With your Center and the people it authorizes. Center Records are visible to Center staff according to the Center's own permission settings, and to the Family Users the Center connects to each child. Members of a child's household may see that child's information according to the roles the household holds.
  • With our subprocessors — the vendors that host and power the Service — listed with their purposes in our Subprocessor List (Supabase, Vercel, Stripe, Resend, Expo, Anthropic, our speech-to-text provider, and PostHog).
  • With Stripe as payment processor. When you pay through the Service, Stripe processes your payment information under its own privacy policy. Centers that accept payments are onboarded to Stripe Connect, which requires Stripe to collect business and representative verification (KYC) information.
  • In a business transfer (merger, acquisition, or sale of assets), in which case this policy continues to apply to transferred information.
  • For legal reasons, if required by law or to protect the safety of a child, our users, or the public. Where the request concerns Center Records we will refer the requester to the Center and notify the Center unless legally prohibited.

We never share personal information with third parties for their own marketing.

5. Retention

  • Center Records are retained while the Center's account is active and handled per the Center's instructions afterward. On termination, the Center may export its data; we delete or return Center Records as described in the DPA (§ 9). Childcare records are subject to state licensing retention requirements (in Utah and elsewhere); those laws may require a Center to keep records even where a person asks for deletion.
  • Controller data: account data is kept while your account is active and deleted or de-identified within 90 days of account deletion, except billing records we must keep for tax and accounting purposes and audit/ security logs retained for 12 months.
  • Residual copies in encrypted backups are purged on the backup provider's rolling schedule.

6. Your rights and choices

  • Center Records: contact your Center (Section 1(a)). We contractually assist Centers in responding.
  • Your Saplyn account data: email legal@saplyn.co to request access, correction, a copy, or deletion of the data we control. We will verify the request via your account email and respond within the time required by applicable law (45 days under most U.S. state privacy laws, extendable once where permitted). If we deny a request you may appeal by replying to our decision; if we deny the appeal, applicable state law may let you contact your state attorney general.
  • Utah residents (UCPA) and residents of other states with consumer privacy laws have rights of access, deletion, portability, and to opt out of targeted advertising and sales — we do neither, so there is nothing to opt out of.
  • Notifications: manage notification channels per event type in your settings; disable push in your device settings. Transactional messages (e.g., sign-in links) cannot be disabled while your account is active.
  • Analytics: analytics identifiers are pseudonymous and used only for product analytics and feature rollout; we do not currently offer a separate in-product analytics opt-out.

7. Children's privacy

The Service is for adults: Center staff and Family Users must be at least 18. Children do not have accounts, and no part of the Service is directed to children. Information about children is entered by their childcare provider and their own guardians so that the provider can care for them — in COPPA terms, Saplyn collects children's information only as a service provider to the Center and the family, not from children themselves. Centers are responsible for obtaining any parental consents their license, their enrollment agreements, or applicable law require (including consent for photos). If you believe a child's information has been submitted to us outside this arrangement, contact legal@saplyn.co and we will delete it.

8. The Discover directory

Our public Discover page shows a map of licensed childcare providers compiled from Utah Department of Workforce Services public licensing records. This is public government data about licensed businesses, and Saplyn acts as an independent controller of it. Ratings shown are derived from public licensing data, not user reviews. For home-based providers we limit the precision of displayed location information. If you are a licensed provider and want your listing corrected or (for home-based providers) further limited, contact legal@saplyn.co.

9. Security

We take security seriously, and we scope it honestly:

  • All data is encrypted in transit (TLS) and at rest by our infrastructure providers.
  • Sign-in is passwordless (emailed magic links) with database-backed sessions, so there is no Saplyn password to steal or reuse.
  • Every Center's data is isolated by tenant: queries are scoped to the Center's organization, and each read and write is authorized against capability-based permissions the Center controls.
  • Meaningful changes are audit-logged.
  • Full payment credentials are held by Stripe, not by us.

No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify affected Centers and users as required by law, and Centers without undue delay per the DPA.

10. Cookies

CookiePurposeType
Session cookie (Auth.js)Keeps you signed inStrictly necessary
CSRF/callback cookies (Auth.js)Sign-in securityStrictly necessary
PostHog analyticsPseudonymous product analytics and feature flagsAnalytics

We do not use advertising or cross-site tracking cookies, and we do not respond to browser "Do Not Track" signals because we do not track users across other sites.

11. International users

The Service is operated from the United States and all data is stored and processed in the United States. Saplyn is currently offered to U.S. childcare providers. If you access the Service from outside the U.S., you consent to processing in the U.S.

12. Changes

We will post any changes here and update the effective date. For material changes we will notify Centers and account holders by email or in-app notice before the change takes effect.

13. Contact

Mommalyn Inc. 3723 Greenville Ave STE 41398, Dallas, TX 75206 legal@saplyn.co