Skip to content
Tutorly

Privacy

Privacy policy

Effective 1 July 2026. Written to be read, with a table where detail is easier to scan than prose.
01

Who we are

Tutorly Inc. is a Delaware C corporation with its office at 100 Summer Street, Suite 1600, Boston, MA 02110, United States. We are the controller of the personal information described here. Questions go to privacy@tutorlylabs.com.

02

What we collect

WhatWhyKept for
Name, email, grade levelTo run your account and reply to youLife of the account, then 30 days
Password hashTo sign you in. We never see the password itselfLife of the account
Problem text and attempts you submitTo run your tutoring session and let you review itUntil you delete it
Sessions we produceSo you can come back to themUntil you delete them
Usage countsTo enforce the free tier and bill correctly24 months
Form submissionsTo answer your message or application24 months
Server logsReliability and abuse prevention. No session content30 days
03

What we do not collect

  • We do not run advertising trackers, and there are no third-party advertising cookies on this site.
  • We do not buy personal information from data brokers.
  • We do not ask for payment card numbers. If you subscribe, Stripe handles the card and we never see it.
  • We do not collect special category information, and you should not put sensitive personal details into a tutoring session.
  • For students under 13, we do not knowingly collect personal information without verified parental consent. See the Children section below.
04

Your work is yours

The problems you submit and the session we produce from them belong to you. We send your work to a model provider only to run the session, under API agreements that prohibit the provider from training on that traffic. Your work is not used to train any model, it is not sold, and it is not shared with any other customer or third party.

You can export or delete any session at any time from your account. Deleting the account removes all sessions from our database within 30 days.

05

Who your information goes to

Our model providers receive the problem text and conversation needed to produce your session, under business API terms that prohibit training on that traffic. The routing table on the How the AI works page names which models are live.

Our hosting and database providers store the data on our behalf inside the United States. Stripe processes payments if you subscribe. That is the complete list of processors. If it changes, this page changes.

06

Legal bases

Where the GDPR or UK GDPR applies to you, we rely on: performance of a contract, to give you the service you asked for; legitimate interests, to keep the service secure, prevent abuse and understand aggregate usage; and consent, for anything optional, which you can withdraw at any time.

07

Your rights

You can ask for a copy of what we hold, correct it, delete it, or object to a particular use. Most of this you can do yourself: sessions delete from your account home and the whole account deletes from Settings.

For anything else, email privacy@tutorlylabs.com and we will answer within 30 days. We will not make you jump through hoops and we will not charge you for it. If you are in California, the CCPA rights to know, delete and opt out of sale apply, and we do not sell personal information.

08

Children

Tutorly is designed to serve students of all ages, including those under 13. For students under 13, we require a parent or guardian to create the account and provide consent before the student uses the service.

The parent view shows only the topics covered and time spent, not the content of any tutoring session, because a student's work is theirs. If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete it promptly.

09

Changes

If we change this policy in a way that matters, we will email account holders before it takes effect rather than quietly updating a date. This version is effective 1 July 2026.

The practical version of this, with the actual retention windows and what happens to a submitted problem, is on the security page. Cookies are covered on the cookies page.