1. Who we are
Tutorio is CRM-class software built specifically for tutors. The service is provided through the web application at tutorio.net.
This Privacy Policy covers all personal data collected and processed in connection with using the platform. For a tutor’s own account data, Tutorio acts as the data owner within the meaning of the Law of Ukraine “On Personal Data Protection”. For data about students that the tutor enters into the system themselves, Tutorio acts as a processor, handling that data on the tutor’s instruction and in their interest.
2. What data is collected
ACCOUNT DATA
- First and last name — to personalise the interface.
- Email address — for logging in and for notifications.
- Hashed password — passwords are never stored in plain text.
STUDENT DATA
- Names of students and parents, entered into the system by the user.
- Students’ contact details (phone, Telegram username) — only to the extent the user enters them.
- Lesson data: dates, subjects, length, statuses, notes.
- Financial records: amounts, lesson packages, payment statuses.
Technical data
- IP address — for security and fraud prevention.
- Browser type and operating system — for correct rendering.
- API request logs — for diagnosing errors and improving the service.
- Cookies — for keeping your session and for analytics (see section 8).
Support requests
- The messages you write in the support chat and to the AI assistant Tori, and your ratings of its answers.
- To answer questions about your account, Tori uses the following account data: your plan and subscription term, limits, the number of students and groups, points, whether Telegram and Google Calendar are connected, and your subscription payment history (date, amount, status, masked card number). Names of students and parents, lesson data and your financial records are not passed to the assistant.
3. How the data is used
The data collected is used solely for the following purposes:
- Providing the platform’s core functions: scheduling, payment tracking, analytics.
- Sending in-platform notifications to tutors.
- Authentication and account security.
- Technical support and answering enquiries.
- Improving the product on the basis of aggregated, anonymised usage data.
- Meeting the requirements of Ukrainian law.
- Running the AI assistant Tori in the support chat: answering questions about using the service, and passing complex requests to the team together with a short summary of the conversation.
4. Legal basis for processing
Users’ personal data is processed on the following legal bases, in line with the Law of Ukraine “On Personal Data Protection”:
5. Sharing data with third parties
Personal data is not sold and is not passed to commercial third parties. Data is shared only with the following:
- Cloud infrastructure providers (hosting, databases) — solely to store and process data as part of running the service.
- Analytics services — only aggregated, anonymised data from which a user cannot be identified.
- Law enforcement — on a valid legal request, or to protect our rights.
- Advertising platforms — Meta Platforms (Facebook, Instagram), and only where you have consented to advertising cookies. What is shared is the fact of a subscription and its amount, an irreversibly transformed (hashed) email address and account number, and technical data about your browser: its identifiers from Meta cookies, its version and your IP address. All of this exists solely to match a payment to the ad you arrived from. A tutor’s student, lesson and payment data is never shared.
- The artificial intelligence model provider — Anthropic PBC (USA), whose model powers the AI assistant Tori in the support chat. Only the messages you write to the assistant and the account data listed in section 2 (“Support requests”) are passed on — and only when they are needed for an answer. Anthropic processes this data solely to produce the answer, does not use it to train its models, and keeps it only for the limited period set out in its terms for commercial customers. If you don’t want your request handled by the AI assistant, press “Message the team” — a person will reply.
- Some infrastructure providers may be located outside Ukraine. Where that is the case, measures are taken to ensure an adequate level of personal data protection as required by law.
Every contractor and provider is obliged to process data in line with this Policy and applicable law.
6. Data retention periods
Data is kept for as long as you use the service, and for a period after the account is closed — to meet legal obligations and resolve disputes.
| Category of data | Retention period |
|---|---|
| Account data | For the life of the account + 30 days after deletion |
| Student and lesson data | For the life of the account + 30 days |
| Financial records | Up to 3 years (as required by law) |
| Technical logs | 90 days |
| Conversations with the AI assistant Tori | 180 days from the last message in the conversation |
| Cookies | From the session up to 12 months (depending on type) |
7. Your rights
Under the Law of Ukraine “On Personal Data Protection”, users have the following rights:
8. Cookies
Tutorio uses cookies so the application works correctly and to improve the user experience. Cookies are small text files stored in the user’s browser.
- Essential cookies — needed for authentication and session security. Without them, logging in is impossible.
- Functional cookies — remember interface settings (language, theme and so on) and your support enquiry: when you write to us in the in-app chat, the conversation identifier is stored in your browser so the reply finds you after a page reload. These records do not depend on consent to analytics cookies and are not used for analytics.
- Analytics cookies — allow anonymised analysis of how the platform is used.
- Advertising cookies — the Meta pixel (Facebook and Instagram). They let us see which of our ads bring teachers in, and stop showing them to people who already use the service. They are only set after separate consent and can be switched off in the cookie settings. If you subscribe, their values are stored with the payment and shared with Meta when the payment is confirmed — see section 5.
- Anonymous page-view counting — works without cookies and therefore does not depend on consent. It stores nothing in your browser, does not recognise you on a later visit and is not linked to an account: we only see how many times a given page was opened.
- The referral source file — the only cookie we write outside that choice. It stores a campaign marker (“Facebook ad” or “newsletter”, say) and the identifier of the click itself, lives only until you close your browser, and exists for exactly one purpose: so we know where someone who eventually signed up came from. It contains none of your data and does not recognise you on other sites.
You can configure or disable cookies through your browser settings, and change your consent to analytics and advertising cookies at any time through the “Cookies” link at the foot of the page. Disabling essential cookies may stop the service working correctly.
A separate word about ad clicks. When you click one of our ads on Facebook or Instagram, Meta adds an identifier for that click to the page address. We send it back to Meta from our server — so we know which ad worked — whether or not you consented to advertising cookies. This applies to the click alone: to carry it through to the end of your visit we use the temporary referral source file described above, and your behaviour on other sites is not available to us. If you did not arrive from one of our ads, nothing is sent to Meta.
9. Data security
Protecting personal data is a priority for the platform. A set of technical and organisational measures is in place:
- HTTPS/TLS encryption for all data in transit.
- Password hashing with bcrypt and a salt.
- Time-limited JWT tokens for authentication.
- Regular security audits and monitoring for suspicious activity.
- Restricted access to personal data — authorised staff only.
Despite every measure taken, no system can guarantee 100% protection. If a security breach is identified that could harm users’ rights, notification is sent within the periods required by law.
10. Minors
The Tutorio platform is intended for tutors, that is, people aged 18 and over. The platform does not collect personal data from children under 18 directly.
Data about students that a tutor enters into the system (whatever their age) is treated as records forming part of the tutor’s business activity. Responsibility for the lawfulness of processing data about minor students rests with the tutor, as the person entering that data into the system.
The service includes a “Student and parent portal” — personal accounts to which a tutor may, at their own discretion, give students and their parents access. Access is by the tutor’s invitation only; self-registration is not possible. Where access is given to a minor student, responsibility for obtaining consent to create that access rests with the tutor and the parents (legal guardians).
The portal shows only the factual teaching data that is meant for the student and their parents anyway: lesson dates and statuses, homework with any attached materials, test results and marks, and payment amounts (if the tutor has enabled showing them). The portal never shows a tutor’s private notes, their rates, or data about other students or families. Lesson notes only become visible when the tutor explicitly marks them as available.
11. Changes to this Privacy Policy
This Policy may be updated from time to time. Users will be told about material changes by email or through the notification centre at least 14 days before they take effect.
Continuing to use Tutorio after changes take effect means you agree to the updated Policy. We recommend reviewing this page from time to time.
Last updated: 13 September 2026
12. Contact us
For any question about this Privacy Policy, about how personal data is processed, or about exercising your rights, get in touch:
Tutorio — Data Protection Officer