TuitoMate (“we”, “us”, “our”) operates https://tuitomate.com (“Service”), software for private tutors to manage scheduling, payments, student progress, and related workflows.
This Privacy Policy explains what information we collect, how we use it, and your choices. If you do not agree, please do not use the Service.
Contact: [email protected]
Operator: TuitoMate
1. Who this policy applies to
- Tutors who create accounts and use the Service.
- Student and guardian information that tutors enter into the Service (we process this on the tutor's behalf).
Tutors are responsible for having a lawful basis to collect and upload student/guardian data and for informing them as required by applicable law.
2. Information we collect
Account and profile
- Login credentials (username; password stored in hashed form).
- Display name, email address, and settings you provide.
- Subscription and billing status (via our payment processor).
Tutoring data you enter
- Student names, guardians, contact details, lesson schedules, attendance, payments, progress notes, exam results, resources, and feedback you submit.
Usage and technical data
- Server logs (e.g. IP address, browser type, timestamps, errors) for security and operations.
- Error reports (e.g. stack traces, request URLs, browser metadata) sent to our error monitoring provider when enabled. We configure it to omit session cookies and authentication headers where possible.
- Cookies used for session authentication and preferences (e.g. theme).
Payment information
Payments are processed by Stripe. We do not store full card numbers. Stripe may collect payment method details according to its own privacy policy: stripe.com/privacy
We may send transactional emails (e.g. account recovery, billing notices, automated payment-failure reminders, feedback acknowledgements) via Resend or similar providers, using the email address on your account.
Contact, support, and feedback
- If you use our contact form, we collect your name, email, optional phone number, and message, plus technical metadata (e.g. IP address, browser type) for spam prevention and support.
- If you submit in-app feedback (issues, suggestions, or testimonials), we collect the content you provide and basic account context (e.g. username, plan). Issue reports may include optional screenshots you attach.
- If you submit a testimonial and opt in to public display, we may publish your preferred name, rating, and testimonial text on our marketing site after review.
Artificial intelligence features
If you use AI features (e.g. lesson planning or report generation), relevant text you provide may be sent to Google Gemini to generate responses. Do not submit information you are not permitted to share with a third-party AI provider.
3. Google Calendar integration
If you connect Google Calendar (tutors only), we request access to:
https://www.googleapis.com/auth/calendarhttps://www.googleapis.com/auth/calendar.events
What we do with Google data
- Create a secondary calendar named “TuitoMate Calendar” in your Google account.
- Sync lesson events one way from TuitoMate into that calendar (TuitoMate → Google). Changes in TuitoMate update Google events; we do not import your other Google Calendar data into TuitoMate.
- Event content may include: lesson title (e.g. student name and subject), date/time, duration, and optional description fields such as parent name, parent contact number, class notes, or group roster — based on what you have stored in TuitoMate.
- Sync window: approximately 7 days in the past and 14 days in the future (subject to change; see in-app behaviour).
- We store an encrypted OAuth refresh token, the Google calendar ID for your TuitoMate calendar, and a mapping of lesson keys to Google event IDs so we can update or delete events when your schedule changes.
What we do not do
- We do not sell Google user data.
- We do not use Google Calendar data for advertising.
- We do not read or display your personal Google Calendar events outside the dedicated TuitoMate calendar we create, except as needed to create, update, or delete those synced events.
Limited Use compliance
TuitoMate's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How to disconnect and revoke access
- In TuitoMate: Settings → Integrations → Google Calendar → Disconnect. We will attempt to delete the TuitoMate calendar and remove stored tokens from our systems.
- In Google: visit myaccount.google.com/permissions and remove TuitoMate's access.
Google's use of data is also governed by: policies.google.com/privacy
4. How we use information
We use information to:
- Provide, maintain, and improve the Service.
- Authenticate users and enforce access controls.
- Process subscriptions and send billing-related communications, including automated reminders when a payment fails or your subscription enters a grace period.
- Diagnose and fix errors through our error monitoring service.
- Sync your lesson schedule to Google Calendar when you enable that integration.
- Provide AI-assisted features when you choose to use them.
- Respond to support requests and feedback.
- Protect against fraud, abuse, and security incidents.
- Comply with legal obligations.
5. Legal bases (where applicable)
Depending on your location, we rely on one or more of: contract (to provide the Service), legitimate interests (security, improvement), consent (e.g. optional integrations), and legal obligation.
6. Sharing with service providers
We use trusted processors to run the Service. Current categories include:
- Railway (or equivalent hosting) — application hosting and database storage
- Stripe — subscription payments
- Resend — transactional email
- Google (Gemini, Calendar API) — optional AI features and optional calendar sync
- Sentry — error monitoring (sentry.io/privacy)
They process data only to perform services for us under appropriate agreements. We will update this list in this policy when we add material new processors.
We may disclose information if required by law or to protect rights, safety, and security.
We do not sell your personal information.
7. International transfers
Your data may be processed in countries where our providers operate (e.g. United States, Singapore). We take reasonable steps to ensure appropriate safeguards where required.
8. Retention
We retain account and tutoring data while your account is active and as needed to provide the Service, resolve disputes, and meet legal requirements.
- If you disconnect Google Calendar, we delete integration tokens and attempt to remove synced calendar data as described in section 3.
- Screenshots attached to in-app issue reports are deleted automatically after 30 days.
- Other feedback text (issues, suggestions, testimonials) is kept until we remove it manually unless you delete your account.
- Billing records may be retained by Stripe according to its policies after account deletion.
You may export your account data or delete your account at any time in Settings → Security. Deletion requires your password and username confirmation. For individual students, you can export, anonymise, or permanently delete records in the workspace. Some data may be retained where we must keep records by law (e.g. payment processor records).
For a fuller category-by-category schedule, contact [email protected].
9. Security
We use technical and organisational measures including encrypted storage of Google OAuth tokens and access controls. No method of transmission or storage is 100% secure.
10. Your rights
Depending on applicable law (e.g. Singapore PDPA, GDPR), you may have rights to access, correct, delete, restrict, or object to processing, and to data portability.
In the Service:
- Settings → Security — export your full account as JSON, or delete your account.
- Student workspace — export a student's data as JSON, anonymise identifiable fields, or permanently delete a student profile.
For other requests, or if you are a student or guardian whose tutor uses TuitoMate, contact your tutor first. You may also contact us at [email protected]. You may lodge a complaint with your local data protection authority.
11. Children
The Service is intended for tutors and adults managing tuition businesses. Student records may relate to minors entered by tutors; tutors must comply with laws governing children's data in their jurisdiction.
12. Changes
We may update this policy. We will post the new version at https://tuitomate.com/privacy with an updated effective date. Continued use after changes constitutes acceptance where permitted by law.
13. Contact
TuitoMate
Email: [email protected]
Website: https://tuitomate.com