Legal

Privacy Policy

Version 2026-04-22 · Effective April 22, 2026

Who we are

Tutorfy, Inc. ("Tutorfy," "we," "us") operates a K-12 tutoring marketplace at tutorfy.app. We act as a "business" / "controller" for personal information collected from tutors, parents, students, and visitors. For student educational records collected at the direction of a parent, we act as a service provider / processor.

Categories of personal information we collect

In the past 12 months we have collected the following CCPA categories of personal information ("PI"):

  • A. Identifiers — name, email, account ID, IP address, device identifiers.
  • B. Customer records — payment metadata (handled by Stripe; we never store full card numbers), billing address.
  • D. Commercial information — bookings, transaction history, refunds.
  • F. Internet/network activity — pages viewed, searches, click events, browser, device, basic analytics.
  • G. Geolocation — approximate location from IP; for tutors, the city / ZIP / service-radius coordinates you provide.
  • H. Audio / visual — profile photos and, during live sessions, voice and video streams transmitted via our video provider (we do not record sessions by default).
  • I. Professional info — for tutors: bio, subjects, grade levels, hourly rate, years experience, awards.
  • J. Education info — for students: grade level, subjects, learning goals, session reports, mastery levels, monthly progress reports. This is treated as student educational records.
  • K. Inferences — topic mastery, AI-generated summaries and goals.
  • L. Sensitive personal information (SPI) — account credentials, precise geolocation (only if you enable it), and education records of minors. We use SPI only for the purposes permitted by Cal. Civ. Code §1798.121 (operating the Service, security, and limited internal uses) and do not use it to infer characteristics about you.

Sources we collect from

  • You, when you create an account, fill in profile fields, book sessions, send messages, or upload content.
  • Parents, when they invite or link a student account.
  • Tutors, when they submit reports, summaries, and goals about a student.
  • Service providers (Stripe payment confirmations, Daily video session metadata, our email provider).
  • Your browser/device automatically (cookies, log files — see our Cookie Policy).

Why we use it (business & commercial purposes)

  • Provide, personalize, and operate the marketplace and live sessions.
  • Process bookings, payments, refunds, and tutor payouts.
  • Generate session summaries, monthly progress reports, and tutoring copilot suggestions (AI features).
  • Authenticate users and prevent fraud, abuse, and platform misuse.
  • Communicate with you about your account, sessions, and important policy updates.
  • Comply with tax, legal, audit, and dispute-resolution obligations.
  • Aggregate, deidentified analytics to improve the Service.

We do not use personal information for cross-context behavioral advertising, and we do not use student data to train third-party AI models.

Who we share it with

We disclose PI only to the categories of recipients below, each bound by data-protection terms:

  • Other users: the tutor you book, the student you tutor, and the parent linked to a student account.
  • Service providers (processors): Stripe (payments), Daily (live video), Supabase (database and storage), Resend (transactional email), and our AI provider for lesson summaries / copilot. Each is contractually limited to performing services for us and may not sell or share PI.
  • Authorities: when required by law, subpoena, or to protect rights and safety.
  • Successors: in connection with a merger, acquisition, or asset sale, subject to equivalent privacy commitments.

We do not sell personal information for money, and we do not share it with third parties for cross-context behavioral advertising.

No sale, no sharing, no targeted ads

For purposes of CCPA / CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, FDBR, and similar laws: we do not "sell" personal information, we do not "share" it for cross-context behavioral advertising, and we do not engage in profiling that produces legal or similarly significant effects. We honor the Global Privacy Control (GPC) browser signal as an opt-out request. You can also exercise your opt-out via the Do Not Sell or Share My Personal Information page.

Retention

  • Account profiles: while the account is active, plus up to 24 months after closure for audit/dispute defense.
  • Booking and payment records: 7 years (tax/audit obligations).
  • Session messages, reports, summaries, and mastery data: while the related student account is active; deleted on verified request.
  • Server access logs and analytics: 13 months, then aggregated.
  • Marketing email lists: until you unsubscribe.

Your privacy rights

Depending on where you live, you may have the right to:

  • Know / access the PI we hold about you.
  • Correct inaccurate PI.
  • Delete PI we collected from you.
  • Port a copy of your PI in a machine-readable format.
  • Opt out of "sale," "sharing," or targeted advertising (we do none of these by default).
  • Limit our use of sensitive personal information.
  • Opt out of profiling for legal or significant effects.
  • Appeal a denied request (VA, CO, CT, TX, FL).
  • Be free from discrimination for exercising these rights.

Submit a request from your profile settings or email privacy@tutorfy.app. We will verify your identity using your account email and respond within 45 days (extendable once by 45 days). You may designate an authorized agent in writing.

Children's privacy (COPPA / FERPA)

For students under 13, a parent or legal guardian must create and manage the account and provide verifiable parental consent. For students 13–16, California requires our affirmative opt-in before any "sale" or "share" — which we do not engage in either way. We treat student educational records consistent with FERPA principles and limit access to the assigned tutor, the linked parent, and necessary platform staff. Parents may review, export, or delete their child's data at any time by contacting privacy@tutorfy.app.

AI features

Lesson summaries, monthly progress reports, and the AI tutoring copilot send relevant session content to large-language-model providers under contracts that prohibit training on your data and require deletion after processing. Content is transmitted over encrypted connections.

Security

We use TLS in transit, encryption at rest, role-based access controls, row-level security on our database, and bucket-scoped storage policies. No system is perfectly secure — please use a strong, unique password and report suspected incidents to security@tutorfy.app.

International users

The Service is operated from the United States. If you access it from outside the U.S., you understand that your information will be processed in the U.S. under U.S. law.

Changes

We'll post material changes here, bump the version number, and re-prompt you for consent in-app. Significant changes are announced at least 14 days before they take effect.

Contact

Questions, requests, or complaints? Email privacy@tutorfy.app. You may also lodge a complaint with your state Attorney General.

This policy is provided as a template tailored to Tutorfy's current functionality. We recommend a privacy attorney review before going live, especially given that the Service handles data about minors.