Service Providers and Subprocessors

Last reviewed: July 28, 2026

Scholar Within, Inc. operates Fluent Within and remains responsible for the service. This page is a code-and-configuration-verified inventory of outside providers the current application is built to use and the information each integration is designed to receive.

What verification here does—and does not—mean

A listed integration is verified in the repository; listing it does not by itself establish a signed DPA, a particular legal classification, a production region, or a no-training, zero-retention, or no-logging setting. Provider agreements and production account settings must be confirmed and maintained separately before the related child-data flow is enabled.

Current child assessment and read-aloud recording flows use the approved Azure Speech and Deepgram integrations. They fail closed when the required secure speech service is unavailable and do not fall back to an unidentified browser- or operating-system speech-recognition service.

Child and student content processing

These integrations can receive child or student information when an authorized reading or account workflow uses them.

Microsoft Corporation — Azure Speech

Purpose
Automated speech recognition, pronunciation assessment, and speech synthesis.
Information involved
Reading audio, reference passage text, recognized words, timing, pronunciation, and scoring output; and selected passage or word text or SSML submitted for synthesis, with generated narration audio and timing output.
Operational status and limits
The application integration is verified in this repository. The repository does not establish the current production Speech resource region, logging and provider-side retention settings, data-use settings, or applicable agreement. Those items must be verified in the production Azure account and contract records.

Deepgram, Inc.

Purpose
Live and prerecorded speech-to-text used in reading analysis.
Information involved
Reading audio, transcript, word timing, and confidence output.
Operational status and limits
The current application code adds mip_opt_out=true to streaming and prerecorded requests. That request parameter does not by itself prove a project-level no-logging setting, provider-side retention period, or applicable agreement; those items must be verified in the production Deepgram project and contract records.

Supabase, Inc.

Purpose
Account authentication, database, and application data services.
Information involved
Adult account identity; student profiles; assessments and results; consent, authorization, sharing, retention, research-governance, and audit records; and saved-audio metadata and locators.
Operational status and limits
The application integration is verified in this repository. The repository does not establish the current production project region, backup and deletion-cycle settings, provider-side retention, or applicable agreement; those items must be verified separately.

Vercel Inc.

Purpose
Application hosting and Vercel Blob object storage.
Information involved
Saved reading audio, authorized share snapshots, application content and assets, and request metadata needed to operate and secure the service.
Operational status and limits
The hosting and Blob integrations are verified in this repository. The repository does not establish every production region, storage or log-retention setting, deletion-cycle result, or applicable agreement; those items must be verified separately.

Content generation, adult verification, communications, and payment

These providers support generated instructional audio, adult-facing verification, notices, receipts, and monetary transactions.

Amazon Web Services, Inc. — SES, SNS, and Polly

Purpose
Transactional email and SMS delivery, plus speech synthesis for passage and drill audio.
Information involved
Adult or parent email address or mobile number, transactional notice and message content, secure-link or code delivery data, message identifiers, status, and delivery events; and passage or drill text encoded as SSML for Polly, with generated audio and speech-mark output.
Operational status and limits
The SES, SNS, and Polly integrations are verified in this repository. Email delivery also reaches the recipient's email provider, and SMS delivery uses the recipient's mobile carrier; those downstream providers vary by recipient and are not fixed in the code. Production AWS regions, account settings, service-side retention, and applicable agreements must be verified separately.

Stripe, Inc.

Purpose
Payments and the available monetary parent-verification method.
Information involved
Adult payer and billing information supplied directly to Stripe, account email, transaction and Checkout identifiers and status, and versioned notice or attestation metadata needed to validate the transaction. Fluent Within does not intentionally send child reading audio or assessment results to Stripe.
Operational status and limits
The Stripe integration is verified in this repository. Stripe, rather than Fluent Within, receives the full payment-card details. Current production account settings, provider retention, and applicable agreements must be verified separately.

Optional adult sign-in providers

An adult may choose one of these providers instead of an email-and-password sign-in.

Google LLC

Purpose
Optional adult OAuth sign-in through Supabase Auth.
Information involved
Adult account identity returned for authentication, such as name, email address, and provider account identifier. Child reading audio and assessment results are not deliberately included in the OAuth sign-in exchange.
Operational status and limits
The optional Google sign-in path is verified in this repository. The enabled production OAuth configuration, scopes, and applicable agreements must be verified in the provider and Supabase dashboards.

Meta Platforms, Inc. — Facebook Login

Purpose
Optional adult OAuth sign-in through Supabase Auth.
Information involved
Adult account identity returned for authentication, such as name, email address, and provider account identifier. Child reading audio and assessment results are not deliberately included in the OAuth sign-in exchange.
Operational status and limits
The optional Facebook sign-in path is verified in this repository. The enabled production OAuth configuration, scopes, and applicable agreements must be verified in the provider and Supabase dashboards.

Same-company systems and changes

Scholar Within's WordPress and WooCommerce systems exchange account, qualifying-order, policy, authorization, and program information with Fluent Within. Scholar Within, Inc. operates both services, so that internal integration is not listed above as a separate outside provider.

We will update this page before a new outside provider receives child or student information. A material change to child-data collection, use, or disclosure still requires the direct notice and any new verifiable consent required by law; posting a provider-list update or relying on continued use does not replace that process.

Review the Privacy Policy and Terms of Use. Questions may be sent to hello@scholarwithin.com.