SUBPROCESSORS

Every outside service has a named boundary.

The proposed provider register names each service, purpose, data boundary, processing location, and retention control planned for launch.

Effective policy approved for publication.Version: subprocessors-2026-08-08-v1Effective date: 8 August 2026
01

Google Firebase Authentication

Purpose
Adult Google and verified-email sign-in, session identity and recovery
Data boundary
Adult email, Firebase UID, provider/session state; no story content
Processing/location boundary
Google/Firebase infrastructure
Retention/control
Account/session life; revocation and deletion controls
02

Google Cloud Run, Firestore, Cloud Storage, Cloud Tasks, KMS, Secret Manager and Monitoring

Purpose
Private application API, household records, approved stories/media, jobs, encryption and minimized operational telemetry
Data boundary
Account/household/story/product records required for the service; operational logs exclude ordinary content and direct identifiers
Processing/location boundary
Primary application region me-central1 Doha; provider control plane may be global
Retention/control
Per the approved retention matrix; private IAM and delete protection
03

Google Firebase App Check and Play Integrity

Purpose
App authenticity and abuse protection
Data boundary
Package/certificate/integrity verdict, request binding and security metadata
Processing/location boundary
Google infrastructure
Retention/control
Minimized security period; no advertising use
04

Google Gemini / Vertex AI

Purpose
Story planning, drafting, classification, illustration and approved narration capabilities
Data boundary
Minimized story instructions/content only; no account identity, billing record, household membership or raw voice in prompts
Processing/location boundary
Text/image requests may use owner-approved global endpoints; supported narration endpoints follow the model registry
Retention/control
Task/provider boundary; temporary assembly maximum 24 hours; model/prompt versions retained without ordinary content in logs
05

Google Cloud Text-to-Speech / Speech-to-Text

Purpose
Approved narration and optional adult recipe transcription if separately enabled
Data boundary
Story chapter text or temporary adult recipe audio; read-to-parent audio is not uploaded at launch
Processing/location boundary
Approved regional endpoint where supported; otherwise feature stays disabled
Retention/control
Recipe audio deleted after transcription, maximum one hour; generated narration follows story retention
06

Google Play

Purpose
Android distribution, purchases, subscription lifecycle and refunds
Data boundary
Adult Play account/payment handled by Google; Hadoty receives purchase/product lifecycle data, not card details
Processing/location boundary
Google Play infrastructure
Retention/control
Play policy plus minimized Hadoty ledger up to the approved financial period
07

Firebase Cloud Messaging

Purpose
Optional notifications and device delivery
Data boundary
FCM token, generic notification type/route and delivery state; no story text or child name in lock-screen payload by default
Processing/location boundary
Google/Firebase infrastructure
Retention/control
Token until revocation/account deletion; delivery detail 90 days
08

Register and change boundary

Hadoty does not use an advertising network, data broker, public community processor, child-account provider, third-party family voice-cloning provider, or public analytics tracker at launch.

Material additions or purpose changes require security/privacy review, an updated version, and notice where applicable. Removing a disabled or unused provider does not authorize a new provider.