Privacy Policy
The essentials are here first. You can open a question for a little more detail, or read the complete policy when you need the legal specifics.
Last updated: 4 September 2026
Privacy in plain English
TutorConfidante stores the teaching records you choose to enter so you can manage lessons, payments, parent updates, monthly parent summaries and formal reports. We do not use advertising trackers or share your records with advertisers.
Your records stay separate
A signed-in tutor can only reach their own students and lessons.
Parent contacts are protected
Dedicated parent contact fields are optional, encrypted before storage and never sent to the AI provider.
AI runs only when you ask
Lesson information reaches Anthropic only when you choose to generate a parent update, monthly parent summary or formal report. The content of the notes used for that draft is included.
You remain in control
Record only what you need. You can edit records, archive students, delete your account or ask us for help with a specific record.
Common questions
These answers summarise the complete Privacy Policy. The full policy below contains the legal detail and takes precedence if anything appears inconsistent.
Does the AI receive parent contact details?
No. Parent names, email addresses and phone numbers that you put in their own dedicated fields are never included in an AI request.
But your lesson notes are sent exactly as you write them. If you type a parent’s phone number or email into the notes box, it goes too. Keep contact details in the dedicated contact fields, which are not included in AI requests.
What does the AI receive?
It depends on what you ask TutorConfidante to draft. Every AI request uses a placeholder instead of the student name you stored:
- Nothing from the student name field. It is not sent at all. The AI is given a placeholder to write around, and the name you stored is put back afterwards on our own servers.
- For a parent update:that lesson’s date, duration if recorded, and notes
- For a monthly parent summary:the selected month, the student’s year group if recorded, and the dates and notes for lessons in that month, each with a short internal reference so the draft can record which lesson it drew from
- For a formal report:the selected reporting period, the student’s year group if recorded, the learning areas you enter, and the dates, durations if recorded, and notes for lessons in that period, each with a short internal reference so the draft can record which lesson it drew from
The content of your notes is sent. TutorConfidante does not automatically redact or anonymise what you write in them, so anything you include goes too — including a name, if you typed one there. The name field itself does not.
Dedicated parent contact fields, pupil context, payment information, the tuition start date and scheduled sessions are not included in AI requests.
Nothing is sent until you press the relevant button to generate a draft. If you use TutorConfidante only to keep records and never generate one, your lesson information does not reach the AI provider.
Is my information used to train AI?
Anthropic, our AI provider, states that commercial API inputs and outputs are not used to train its models, and that they are normally deleted within 30 days. Documented exceptions apply — for example where content is flagged under its safety policy, or where the law requires longer retention.
Model training is also switched off for TutorConfidante at our hosting provider, Vercel.
Can other tutors see my records?
No. The application checks on every request that the records belong to the tutor asking for them, so a signed-in tutor only reaches their own students and lessons.
We are not going to tell you any system is completely secure, because none is. What we can say is that separating tutors from one another is checked on every request, not assumed.
Where is my information processed?
The database is hosted by Supabase in London, and the application’s server functions are configured to run in Vercel’s London region.
That is not the whole picture. Routing components and the part of the service that checks your login run across Vercel’s global network, and some suppliers — including our AI provider — process outside the UK. Those transfers rely on the agreements set out in the detailed policy below.
What must I not enter?
Please keep all of the following out of the service:
- Medical or diagnostic information
- Disabilities, and other special-category data such as ethnicity, religion or health
- Safeguarding records or concerns
- Anything similarly sensitive about a child or their family
- Contact details in lesson notes — these will be sent to the AI provider if those notes are used to generate any AI draft
This is a restriction on using the service, not a gentle suggestion: the arrangements under which TutorConfidante is hosted do not permit it. Keep safeguarding records in a system built for the purpose.
Where it works for you, a first name, initials or another familiar identifier is plenty — the service is designed to work that way.
What happens when I delete my account?
Your tutor account, your students and your lesson records are removed from the application, and any active subscription is cancelled.
Some copies persist for a while afterwards, outside the application: supplier backups age out on their own cycles, and Stripe keeps billing records to meet tax and other legal obligations. The retention section below sets out each one.
Read the complete Privacy Policy
Who we are
TutorConfidante is a service operated by Simon Feltham, a sole trader based in Malvern, United Kingdom.
For any privacy or data question, contact contact@tutorconfidante.co.uk.
Two different roles, and why it matters
Data protection law distinguishes between the organisation that decides why and how data is used (the controller) and the one that only handles it on someone else’s instructions (the processor). TutorConfidante is in both roles, depending on whose data it is.
- We are the controller for your own tutor account and billing information — your email address, your account settings, and your subscription record. We also keep a record of each AI generation request: the date, type of draft, which model ran, how many tokens it used and an estimated cost, so usage can be controlled and the monthly allowance can be counted. That record holds nothing about a pupil — no names, no notes and no generated text. We decide why we hold it, so the responsibility is ours.
- We are a processor for the information you enter about your students and their parents. You decide what to record and why; we only store and process it to provide the service to you. In that relationship you are the controller.
The processor terms that govern that second relationship are set out in our Terms of Service. They form the written contract that data protection law requires between a controller and a processor.
What we hold, and why
Your tutor account (we are the controller):
- Your email address, which is also your login identifier.
- Your authentication credentials. These are handled by our authentication provider, Supabase, and are not available to us in readable form. We never see your password.
- Your subscription status and billing history.
We hold this because we need it to give you an account and provide the service you signed up for. In legal terms, our basis is performance of our contract with you (UK GDPR Article 6(1)(b)).
Your students and their parents (we are the processor):
- Student names, and any year group, tuition start date or next-lesson date you record. We do not ask for a date of birth.
- Parent names, email addresses and phone numbers, if you choose to add them.
- Pupil context, if you write any — optional background you keep about a pupil, such as learning goals or approaches that work well. You choose what goes in it and can edit or delete it at any time. It is not sent to the AI provider and is not used to draft parent updates, monthly parent summaries or formal reports. The field asks you not to record medical, safeguarding or family information.
- Lesson records — date, duration, amount charged, your notes, and any generated parent update.
- Saved report drafts, if you draft one — the reporting period, the learning areas you named, the report text, and a copy of the lesson notes it was drawn from, kept so the report’s evidence links still show what it was actually based on if you later edit a lesson. Reports are kept when you archive a pupil, and are deleted with the pupil or with your account.
- Saved monthly parent-summary drafts, if you draft one — the month, the summary text, whether you marked that version as sent, and a copy of the lesson notes it was drawn from. The copy keeps its evidence links tied to what the tutor reviewed even if a lesson is edited later. Monthly summaries are deleted with the pupil or with your account.
We hold this only to provide the service to you. Deciding whether you may record it, and on what legal basis, is your call as the controller — see “Your responsibilities as the controller” below.
We have not enabled behavioural advertising or product-analytics tracking, and we do not share your data with advertisers. We do not track how you move around the app for marketing or product-measurement purposes.
That is not the same as saying nothing is recorded anywhere. The suppliers that host and run the service generate operational logs and telemetry — things like request timing, error traces and security events — which are necessary to operate, secure and diagnose it. Those records can include technical identifiers such as IP addresses and the page paths you requested. TutorConfidante uses its access to these records only to operate, secure and diagnose the service. Our suppliers’ handling of operational data is governed by their respective agreements and privacy notices.
What is sent to the AI provider
Information is sent to Anthropic only when you choose to generate a parent update, monthly parent summary or formal report. The information included depends on the draft you request.
- Nothing from the student name field. The AI is given a placeholder to write around, and the name you stored is put back afterwards on our own servers. It previously sent the part of that field before the first space; it no longer sends any of it.
- Parent update:the lesson date, lesson duration if recorded, and that lesson’s notes
- Monthly parent summary:the selected month, the student’s year group if recorded, and the dates and notes for lessons in that month, each with a short internal reference so the draft can record which lesson it drew from
- Formal report:the selected reporting period, the student’s year group if recorded, the learning areas you enter, and the dates, durations if recorded, and notes for lessons in that period, each with a short internal reference so the draft can record which lesson it drew from
Parent names, parent email addresses and parent phone numbers stored in their dedicated fields are never sent. Pupil context, payment information, the tuition start date and scheduled sessions are not sent either.
Because the content of your notes is sent without automatic redaction or anonymisation, what you write in them matters. Keep them factual and about the lesson.
Your responsibilities as the controller
For student and parent information, the decisions are yours, not ours:
- You determine the lawful basis for recording it. Consent is one option, but it is often not the right one — many tutors will be relying on performance of their contract with the parent, or on legitimate interests. We cannot make that assessment for you, and you should not assume consent is required.
- Record the minimum you need. The service works perfectly well with first names or initials. There is no benefit to storing more than your teaching requires.
- You must not enter special-category data or safeguarding material. This is a restriction on using the service, not a suggestion — see below.
Information that must not be entered
Special-category data and safeguarding material must not be entered into TutorConfidante. This is required by the arrangements under which the service is hosted, not optional advice. Our hosting provider’s Data Processing Addendum (effective 31 March 2026) prohibits us from including sensitive data or special categories of data in the data we place on its platform. Entering it would put us in breach of that agreement, so we cannot permit it however the information is recorded.
Special-category data is a defined legal term covering health and medical information, racial or ethnic origin, religious or philosophical beliefs, sex life or sexual orientation, political opinions, trade union membership, genetic data, and biometric data used for identification. A diagnosis or a disability normally falls within it. Processing it lawfully would also require an additional condition under UK GDPR Article 9.
Safeguarding material must not be entered either, whether or not it meets that legal definition. TutorConfidante has no features for handling safeguarding concerns and has not been designed or assessed for them. Keep those records in a system built for the purpose and follow your own safeguarding policy.
Not everything sensitive is special-category data — a student’s family circumstances usually are not — but that does not make this the right place to record it. Apply judgement as well as the legal test, and keep lesson notes to what was taught.
Cookies
We use essential cookies only. These keep you logged in and maintain your session while you use the service — without them, the service cannot work.
We do not use advertising cookies, behavioural tracking cookies, or third-party analytics cookies. There is no cookie banner because there is nothing to consent to beyond the essentials.
The operational logs described above are not cookies and are not set on your device — they are records our suppliers keep on their own systems to run and secure the service. Nothing there is used for advertising or product measurement.
Who else handles your data
Different suppliers see different things. They are not interchangeable, and none of them receives every category of data.
Sub-processors that handle student and parent information:
- Supabase— database and authentication. Our database is hosted in Supabase’s London region (eu-west-2). See Supabase’s Privacy Policy.
- Vercel— application hosting. Every page you load and every record you save passes through Vercel’s infrastructure. See Vercel’s Privacy Policy.
- Anthropic— AI generation of parent updates, monthly parent summaries and formal reports. Receives only the information described in “What is sent to the AI provider” above, and only when you ask TutorConfidante to generate a draft. See Anthropic’s Privacy Policy.
Supplier that handles your billing information only:
- Stripe — subscription payments. Stripe collects your billing name, billing email and card details directly from you. We never see or store your card details. Stripe does not receive your student or parent records through TutorConfidante. Stripe acts partly as our processor and partly as a controller in its own right for fraud prevention and regulatory compliance. See Stripe’s Privacy Policy.
If we intend to add or replace a direct sub-processor that handles student or parent information, we will notify affected tutors at their registered account email address before the change takes effect, where that is reasonably possible. You will have a reasonable opportunity to object on data protection grounds.
Where processing happens
Our database is hosted in the United Kingdom, in Supabase’s London region.
The application is configured to run its server functions in Vercel’s London region (lhr1). That configuration governs the functions that read and write your records. It does not mean all Vercel processing is UK-only: Vercel operates a global network, routing and edge components sit in front of the application worldwide, and Vercel documents that routing middleware — which in this service checks your login session — is deployed to all regions regardless of the region setting. We therefore make no claim that Vercel processes exclusively in the UK.
Anthropic processes in the United States. Stripe operates globally.
Transfers outside the UK need a recognised legal safeguard. A link to a supplier’s privacy policy is not one, and neither is your acceptance of these terms. The safeguard comes from each supplier’s data processing agreement. For the suppliers we use:
- Vercel — its Data Processing Addendum (effective 31 March 2026) applies to customers on Pro and Enterprise plans, under which Vercel acts as processor. It incorporates the Standard Contractual Clauses together with the UK International Data Transfer Addendum. The same document records that Vercel’s primary processing facilities are in the United States.
- Supabase — its Data Processing Addendum applies on acceptance of its terms, and incorporates the Standard Contractual Clauses with the UK Addendum.
- Anthropic — its Privacy Center states that its DPA with Standard Contractual Clauses is automatically incorporated into the Commercial Terms of Service, and that accepting those terms also accepts the DPA. No separate signature is required.
- Stripe — its Data Processing Agreement forms part of its standard terms and incorporates the UK International Data Transfer Addendum issued by the Information Commissioner’s Office.
Each link above is the supplier’s own published document, so you can check the position yourself rather than taking our word for it.
How long data is kept
In the application: we keep your data for as long as your account exists. There is currently no automatic clear-out of dormant accounts — records stay until an account is deleted.
You can delete your account at any time using the Delete account option in your dashboard. That cancels any active subscription and removes your account, your students, your lessons, your parent updates, monthly parent summaries and saved report drafts from the application.
Cancelling a subscription is not deletion. If you cancel but keep the account, everything stays in place so you can resubscribe later without losing your work.
Deleting your account removes the records held in the application. It does not instantly erase every copy held by our suppliers, each of which runs on its own cycle:
- Supabase documents that it takes daily backups of customer projects by default, and that after an agreement ends it deletes covered data following a 30-day export window. Deleted records can therefore persist in backups for a period.
- Vercel — we have not established a documented backup retention period applicable to this service, so we do not state one here.
- Anthropicnormally deletes API inputs and outputs within 30 days, subject to documented exceptions — for example longer retention where content is flagged under its usage policy, or where the law requires it. Anthropic’s Commercial Terms state that it does not train its models on commercial customer content.
- Stripe keeps payment and transaction records for longer, to meet tax, accounting, anti-money-laundering and other legal obligations. This is outside our control and is not removed by deleting your TutorConfidante account.
Your rights
For your own tutor account data, where we are the controller, you have the right to access it, correct it, delete it, receive a portable copy, object to certain processing, and complain to the Information Commissioner’s Office.
For student and parent data, those requests go to you, not to us — you are the controller. What the service lets you do directly:
- Edit any student or lesson record.
- Archive a student. Archiving hides them from your active list but keeps their lesson history. It is not deletion.
- Delete your whole account, which removes all of it together.
You cannot delete an individual student record yourself. There is also no self-service export. If you need one student erased while keeping the rest, or a portable copy to answer someone’s request, contact us and we will carry out that targeted erasure or export for you.
For any of this, email contact@tutorconfidante.co.uk. We aim to respond within one month.
Security
We take reasonable steps to protect the data in the service:
- All connections use HTTPS encryption.
- Parent names, email addresses and phone numbers entered in their dedicated fields are encrypted by TutorConfidante before storage. The encryption key is kept separately from the database.
- Authentication credentials are handled by Supabase and are not available to us in readable form.
- Each tutor can only reach their own records; the application checks ownership on every request.
- Database access is restricted to authorised systems, to our providers’ personnel where their agreements permit, and to the operator.
This additional field-level encryption reduces the risk if stored database records are exposed, but student names and lesson records are not protected by it. These safeguards do not remove the data-protection responsibilities described in this policy.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting data you are responsible for, we will tell you without undue delay so you can meet your own obligations.
Children’s data
TutorConfidante is for use by tutors, who are adults. It is not designed to be used by children, and children do not have accounts. Where you record information about a student under 18, record only what your teaching genuinely needs — first names are enough.
Changes to this policy
If we make a significant change to how data is handled, we will email the address on your account before it takes effect. Minor wording clarifications will simply appear here.
Contact
For any privacy question, email contact@tutorconfidante.co.uk.