Tutorio logo
Tutorio
← Home
Privacy

Privacy Policy

We respect your privacy and are committed to protecting your personal data. This page explains how users’ personal data is collected, used and protected.

In effect from: 27 September 2026

1. Who we are

Tutorio is CRM-class software built specifically for tutors. The service is provided through the web application at tutorio.net.

This Privacy Policy covers all personal data collected and processed in connection with using the platform. For a tutor’s own account data, Tutorio acts as the data owner within the meaning of the Law of Ukraine “On Personal Data Protection”. For data about students that the tutor enters into the system themselves, Tutorio acts as a processor, handling that data on the tutor’s instruction and in their interest.

Users’ personal data is not passed on or sold to third parties. Data is collected only to the extent needed to run the service.

2. What data is collected

ACCOUNT DATA

  • First and last name — to personalise the interface.
  • Email address — for logging in and for notifications.
  • Hashed password — passwords are never stored in plain text.

STUDENT DATA

  • Names of students and parents, entered into the system by the user.
  • Students’ contact details (phone, Telegram username) — only to the extent the user enters them.
  • Lesson data: dates, subjects, length, statuses, notes.
  • Financial records: amounts, lesson packages, payment statuses.

Technical data

  • IP address — for security and fraud prevention.
  • Browser type and operating system — for correct rendering.
  • API request logs — for diagnosing errors and improving the service.
  • Cookies — for keeping your session and for analytics (see section 8).

Support requests

  • The messages you write in the support chat and to the AI assistant Tori, and your ratings of its answers.
  • To answer questions about your account, Tori uses the following account data: your plan and subscription term, limits, the number of students and groups, points, whether Telegram and Google Calendar are connected, and your subscription payment history (date, amount, status, masked card number). Names of students and parents, lesson data and your financial records are not passed to the assistant.
We don’t receive the full card number, its expiry date or the CVV: subscription payments are handled by the WayForPay payment service. To renew the subscription automatically, we keep only the card token it issues (encrypted) and the masked card number (for example, 4441****1055), so we can show in your account which card is linked.

3. How the data is used

The data collected is used solely for the following purposes:

  • Providing the platform’s core functions: scheduling, payment tracking, analytics.
  • Sending in-platform notifications to tutors.
  • Authentication and account security.
  • Technical support and answering enquiries.
  • Improving the product on the basis of aggregated, anonymised usage data.
  • Meeting the requirements of Ukrainian law.
  • Running the AI assistant Tori in the support chat: answering questions about using the service, and passing complex requests to the team together with a short summary of the conversation.

Users’ personal data is processed on the following legal bases, in line with the Law of Ukraine “On Personal Data Protection”:

Performance of a contract. Processing needed to provide the service under the platform’s terms of use.
Legitimate interest. Improving security, analytics, technical support.
Consent. Marketing notifications, where the user has given consent. Consent can be withdrawn at any time.
Legal obligation. Where processing is required by applicable law.

5. Sharing data with third parties

Personal data is not sold and is not passed to commercial third parties. Data is shared only with the following:

  • Cloud infrastructure providers (hosting, databases) — solely to store and process data as part of running the service.
  • Analytics services — only aggregated, anonymised data from which a user cannot be identified.
  • Law enforcement — on a valid legal request, or to protect our rights.
  • Advertising platforms — Meta Platforms (Facebook, Instagram), and only where you have consented to advertising cookies. What is shared is the fact of a subscription and its amount, an irreversibly transformed (hashed) email address and account number, and technical data about your browser: its identifiers from Meta cookies, its version and your IP address. All of this exists solely to match a payment to the ad you arrived from. A tutor’s student, lesson and payment data is never shared.
  • The artificial intelligence model provider — Anthropic PBC (USA), whose model powers the AI assistant Tori in the support chat. Only the messages you write to the assistant and the account data listed in section 2 (“Support requests”) are passed on — and only when they are needed for an answer. Anthropic processes this data solely to produce the answer, does not use it to train its models, and keeps it only for the limited period set out in its terms for commercial customers. If you don’t want your request handled by the AI assistant, press “Message the team” — a person will reply.
  • Some infrastructure providers may be located outside Ukraine. Where that is the case, measures are taken to ensure an adequate level of personal data protection as required by law.

Every contractor and provider is obliged to process data in line with this Policy and applicable law.

6. Data retention periods

Data is kept for as long as you use the service, and for a period after the account is closed — to meet legal obligations and resolve disputes.

Category of dataRetention period
Account dataFor the life of the account + 30 days after deletion
Student and lesson dataFor the life of the account + 30 days
Financial recordsUp to 3 years (as required by law)
Technical logs90 days
Conversations with the AI assistant Tori180 days from the last message in the conversation
CookiesFrom the session up to 12 months (depending on type)

7. Your rights

Under the Law of Ukraine “On Personal Data Protection”, users have the following rights:

Access. To receive a copy of the personal data held in the system.
Rectification. To require inaccurate or incomplete data to be corrected.
Erasure. To require personal data to be deleted (subject to conditions).
Restriction of processing. To require processing to be paused temporarily.
Data portability. To receive your data in a structured, machine-readable format.
Objection. To object to processing based on legitimate interest.
To exercise any of these rights, write to privacy@tutorio.net. We reply within 30 calendar days.

8. Cookies

Tutorio uses cookies so the application works correctly and to improve the user experience. Cookies are small text files stored in the user’s browser.

  • Essential cookies — needed for authentication and session security. Without them, logging in is impossible.
  • Functional cookies — remember interface settings (language, theme and so on) and your support enquiry: when you write to us in the in-app chat, the conversation identifier is stored in your browser so the reply finds you after a page reload. These records do not depend on consent to analytics cookies and are not used for analytics.
  • Analytics cookies — allow anonymised analysis of how the platform is used.
  • Advertising cookies — the Meta pixel (Facebook and Instagram). They let us see which of our ads bring teachers in, and stop showing them to people who already use the service. They are only set after separate consent and can be switched off in the cookie settings. If you subscribe, their values are stored with the payment and shared with Meta when the payment is confirmed — see section 5.
  • Anonymous page-view counting — works without cookies and therefore does not depend on consent. It stores nothing in your browser, does not recognise you on a later visit and is not linked to an account: we only see how many times a given page was opened.
  • The referral source file — the only cookie we write outside that choice. It stores a campaign marker (“Facebook ad” or “newsletter”, say) and the identifier of the click itself, lives only until you close your browser, and exists for exactly one purpose: so we know where someone who eventually signed up came from. It contains none of your data and does not recognise you on other sites.

You can configure or disable cookies through your browser settings, and change your consent to analytics and advertising cookies at any time through the “Cookies” link at the foot of the page. Disabling essential cookies may stop the service working correctly.

A separate word about ad clicks. When you click one of our ads on Facebook or Instagram, Meta adds an identifier for that click to the page address. We send it back to Meta from our server — so we know which ad worked — whether or not you consented to advertising cookies. This applies to the click alone: to carry it through to the end of your visit we use the temporary referral source file described above, and your behaviour on other sites is not available to us. If you did not arrive from one of our ads, nothing is sent to Meta.

9. Data security

Protecting personal data is a priority for the platform. A set of technical and organisational measures is in place:

  • HTTPS/TLS encryption for all data in transit.
  • Password hashing with bcrypt and a salt.
  • Time-limited JWT tokens for authentication.
  • Regular security audits and monitoring for suspicious activity.
  • Restricted access to personal data — authorised staff only.

Despite every measure taken, no system can guarantee 100% protection. If a security breach is identified that could harm users’ rights, notification is sent within the periods required by law.

10. Minors

The Tutorio platform is intended for tutors, that is, people aged 18 and over. The platform does not collect personal data from children under 18 directly.

Data about students that a tutor enters into the system (whatever their age) is treated as records forming part of the tutor’s business activity. Responsibility for the lawfulness of processing data about minor students rests with the tutor, as the person entering that data into the system.

The service includes a “Student and parent portal” — personal accounts to which a tutor may, at their own discretion, give students and their parents access. Access is by the tutor’s invitation only; self-registration is not possible. Where access is given to a minor student, responsibility for obtaining consent to create that access rests with the tutor and the parents (legal guardians).

The portal shows only the factual teaching data that is meant for the student and their parents anyway: lesson dates and statuses, homework with any attached materials, test results and marks, and payment amounts (if the tutor has enabled showing them). The portal never shows a tutor’s private notes, their rates, or data about other students or families. Lesson notes only become visible when the tutor explicitly marks them as available.

A tutor can revoke any portal access at any time. Once revoked, previously loaded data is no longer shown on the next login.

11. Changes to this Privacy Policy

This Policy may be updated from time to time. Users will be told about material changes by email or through the notification centre at least 14 days before they take effect.

Continuing to use Tutorio after changes take effect means you agree to the updated Policy. We recommend reviewing this page from time to time.

Last updated: 13 September 2026

12. Contact us

For any question about this Privacy Policy, about how personal data is processed, or about exercising your rights, get in touch:

Tutorio — Data Protection Officer

Website: tutorio.net
Response time: up to 30 calendar days