Security
Your session, and what we do with it
What happens when you submit a problem
When you type or paste a problem, the text is sent to our server, forwarded to a model provider to produce the tutoring session, and stored in our database against your account so you can review the session again. That is the whole journey.
The text is transmitted over TLS 1.2 or better and stored encrypted at rest by our database provider. It is never posted anywhere public, never shared with another student or customer, and never sent to any third party other than the model provider running your session.
Model providers, and training
Tutorly routes sessions across providers. The routing table on the How the AI works page shows which model handles which step.
We use these providers under their business API terms, which prohibit training on API traffic. We do not fine-tune any model on student sessions, we do not use your work to improve prompts without asking, and we do not sell or license student content to anyone for any purpose.
| Data | What the model provider receives | Used for training? |
|---|---|---|
| Problem text | Yes, to produce your session | No |
| Session turns | Yes, to continue the conversation | No |
| Account details | No | No |
| Usage stats | No | No |
Students under 18, and the parent view
Many of our students are minors. We take that seriously. A student's tutoring sessions are their own work and are not visible to parents through the parent view.
The parent view shows only the subjects and topics covered and the time spent in each session. It never shows the content of a conversation. If a parent wants to know more, the student can choose to share a session link themselves.
For students under 13, a parent or guardian must create and oversee the account, consistent with COPPA requirements.
Who at Tutorly can read your sessions
Access to the production database is limited to the two engineers who operate it, and it is used to fix things, not to browse. We do not read student sessions for product research.
If you open a support ticket about a specific session and send us the link, we may open that one session to answer your question. If you would rather we did not, say so in the ticket and we will work from your description instead.
How long we keep it
- Sessions and the problem text stored with them: until you delete them, or until 30 days after you delete your account, whichever is sooner.
- Account records: for as long as the account is open, then 30 days.
- Form submissions from the contact, help and careers forms: 24 months.
- Server logs, which record request paths and timings but not session content: 30 days.
- Backups: rolling 7 days, after which deleted data is gone from backups too.
Deleting your data
Delete any single session from your account home, which removes the problem text and the session. Delete your whole account from Settings, which removes every session, the stored text and the account record.
Both are immediate and neither needs a support ticket. If you want written confirmation for your own records, email us and we will send it.
Accounts and access
- Passwords are hashed with scrypt and a per-user salt. We never store or log a password, and nobody at Tutorly can see one.
- Sessions are httpOnly, sameSite cookies signed with a server-side secret, and they expire after 30 days.
- Google sign in is supported so you do not have to keep another password at all.
- Every request for a session checks that the session belongs to the account asking for it, in the database query itself rather than in the page.
Our own posture
- Two-factor authentication is required on every service Tutorly uses, with no exceptions and no shared logins.
- Production access is limited to two engineers and reviewed quarterly.
- Dependencies are updated on a weekly cadence and security advisories are actioned within 72 hours for anything reachable from production.
- We do not yet hold a SOC 2 report. We are a pre-seed company and would rather tell you that than imply otherwise. If you need a completed security questionnaire, email us and we will fill it in honestly.
Reporting something
Email security@tutorlylabs.com. We acknowledge within two business days, we will not threaten you for reporting in good faith, and we will tell you when it is fixed. If you want to be credited, say so and we will.
This page describes what Tutorly does today. The privacy policy is the legal version of the same thing, and the terms cover the rest. Last reviewed July 2026.