Legal

Privacy policy

Last updated: 2 September 2026

1. Who we are

Tutorly Learning Ltd ("Tutorly", "we", "us") is a company registered in England & Wales (company no. 17249477, registered office: 77a Brighton Road, Surbiton, KT6 5NF), and we are the data controller for the personal data collected through tutorly.com. The one exception is pupils whose school has bought Tutorly for them, where the school is the controller and we act on its instructions (see section 6).

This policy is written to be read, including by the young people who use Tutorly. If anything here is unclear, ask us and we will explain it properly.

Questions, requests, or complaints about your data? Email privacy@tutorly.com.

2. What we collect

Depending on who you are and how you use Tutorly, we collect:

  • Account data: name, email, a password held in scrambled (hashed) form, your role (student, parent, tutor or school), and your date of birth.
  • Phone number: where phone verification is enabled, students aged 18 or over, parents and tutors give us a mobile number and confirm it with a code we text them. We keep the number and the date it was confirmed. It is used to check the account belongs to a real person and to reach you about your account or a session — never for marketing, and it is not shown to other users. Under-18 students do not give us a number; their parent or guardian verifies one instead.
  • Profile data: for students, your level, subjects, goals, target grade and the child code we generate for you; for parents, a phone number if you give one, which we use only to reach you urgently about your child's safety; for tutors, your bio, subjects, exam boards, hourly rate, availability and photo. Approved tutor listing photos are published on your public profile page.
  • Tutor qualification and DBS evidence: certificates you upload for our team to review, the review decision, who reviewed it and any reason for a rejection. A DBS certificate contains criminal-records information — see section 4.
  • Booking & session data: who booked whom, when, for how long, the price, any note you add to a booking, cancellation reasons, parent approval decisions, and join and leave times for the video room.
  • Messages: messages you send on the platform and files you share, plus in-call chat during a lesson. These are kept reviewable for safety (see Safeguarding).
  • Study data (Tutorly Learn): lessons taken, practice and mock answers including your written working, how confident you said you were, essays you submit and the marking they receive, flashcards and any notes you paste in to make them, streaks and study plans.
  • What your tutor writes about you: topic check-ins, progress notes and the coaching guidance a tutor sets for Bao. Your tutor writes these; you can ask to see them.
  • Mock exam monitoring: where your tutor switches it on, we note if you leave fullscreen or switch tab during a mock (see section 7).
  • Payment data: we never see or store your card number. Stripe handles all card details. We store amounts, dates, the fee split and Stripe's own reference numbers for the payment, your membership and — for tutors — the connected Stripe account we pay you through.
  • Safety and support records: complaints, safeguarding reports, reported reviews and our notes on them. These can contain what someone has written about another person, including a child.
  • Things you tell us about other people: a student typing a parent's email, a parent creating a child's account, a school uploading a pupil's email. We use those details only to send that person an invitation and to set the accounts up.
  • Before you have an account: waitlist and "tell me when a tutor is available" sign-ups (email, role, subject); tutor applications and feedback you send us. Your name and date of birth are also held in your browser while you are part-way through signing up, so a refresh does not lose your progress.
  • Usage data: pages viewed, device and browser type, and IP addresses in standard server logs. Your IP address is also used briefly to stop people abusing our forms and AI features (see section 5).

3. Why we are allowed to use it

We rely on these UK GDPR lawful bases:

  • Contract: everything needed to actually run the service you signed up for — accounts, profiles, matching, messaging, bookings, payments, membership, Tutorly Learn, the AI features you choose to use, and the emails that go with all of that.
  • Legal obligation: keeping accounting and tax records, and meeting our safeguarding duties.
  • Legitimate interest: keeping the platform safe and working — fraud prevention, abuse and rate limiting, logging who joined a session, reviewing complaints, publishing tutor listings, and the weekly parent digest (which parents can switch off in settings at any time).

Where we rely on legitimate interest, we have weighed it against your rights and you can object at any time by emailing us.

4. DBS and criminal-records information

A DBS check is optional for tutors on Tutorly. Where a tutor has one, their DBS status is shown openly on their profile so families can see it and decide for themselves. Not every tutor has one, and we do not claim otherwise. What we do check for every tutor before they can be listed is their qualifications, reviewed by a person on our team.

Information from a DBS certificate is criminal-offence data under Article 10 UK GDPR. We process it for the substantial public interest of safeguarding children, under the condition in Schedule 1 Part 2 paragraph 18 of the Data Protection Act 2018, and we handle it under an Appropriate Policy Document that sets out how it is stored, who can see it and when it is deleted. Certificates are held in private storage that only the tutor and our reviewing admins can open, are never shown to students or parents, and are kept only while the tutor is listed with us.

5. Who we share it with

We do not sell your data. Ever. We share it only with the companies that run parts of the service for us (our processors), and with the people the product is designed to share it with.

Companies that process data for us:

  • Supabase: our database, login system and file storage, hosted in the UK (London).
  • Stripe: payment processing and membership subscriptions. Tutors also set up a Stripe Connect account, and give Stripe their bank details and identity documents directly so Stripe can pay them; Stripe, not Tutorly, holds those documents and is responsible for them.
  • Anthropic: the AI behind Bao, auto-marking, practice generation and flashcards. Section 8 explains exactly what is sent.
  • Daily.co: the video room for live lessons. Daily.co receives only a room reference and your account ID — no name, no email. Sessions are not recorded.
  • Resend: sends our emails — verification and password resets, booking confirmations and approvals, homework, reminders, the weekly parent digest, waitlist and invite emails. The full text of those emails passes through Resend, which can include a child's name and activity.
  • Twilio: sends the verification text and checks the code you type, where phone verification is enabled. Twilio receives your mobile number and the code; it never receives your name, your email or anything about your lessons. We do not store the code ourselves.
  • Vercel: hosts the website and keeps standard server logs, which include IP addresses.
  • Upstash: runs the short-lived counters that stop people hammering our forms and AI features. Those counters are keyed on your IP address or your account ID and expire within hours. Nothing else is sent.
  • Discord: our tutor community runs on Discord. When a tutor verifies their community account, their name and email address are posted into a private moderation channel our team can see. This applies to tutors only — no student or parent data is ever sent to Discord.

People we share it with:

  • Your booked tutor: a tutor you book sees the study signals they need to teach you well — recent stuck topics, practice and stage-check results, essays you send them, mock results including anything noted during a mock exam, and the mastery check-ins they record. Tutors do not see your Bao conversations.
  • Your linked parent or guardian: parents see their child's booked sessions, billing, and homework, plus a weekly progress digest (activity, stuck topics, tutor check-ins). Private messages between a student and their tutor are not shared with parents.
  • Your school, if your school gave you Tutorly: see section 6.
  • Authorities, where we have to: if a child is at risk, or the law requires it, we will share what is necessary with the police, social services or another authority.

6. If your school gave you Tutorly

Some schools buy Tutorly Learn for their pupils. If your school has enrolled you, staff at that school can see your name and how you are getting on: lessons finished and in progress, your average practice score, your latest mock percentage, how many topics you are stuck on, when you were last active, how confident you said you were (including answers you were sure about but got wrong), and a topic-by-topic picture of what you have mastered. They can also download that information for their whole cohort as a spreadsheet.

For school-enrolled pupils the school decides what that information is used for — the school is the data controller and Tutorly is its processor, acting on the school's written instructions. If you want to know what your school does with it, ask your school; if you want to know what we hold, email us and we will tell you.

7. Mock exams and your camera

Your tutor can set a mock exam with exam-style conditions turned on. Where they do:

  • If you switch to another tab or window, or leave fullscreen, that is noted on your submission and your tutor can see it. We tell you before you start which of these are switched on.
  • If the camera is required, your camera turns on as a sign that you are there and sitting the paper yourself. Nothing is recorded. The picture is shown only on your own screen, is never saved, and is never sent to us, to your tutor or to anyone else. It stops the moment you leave the exam page.

We do not use your camera anywhere else on Tutorly, and we do not record live lessons.

8. Bao and our other AI features

Bao is an AI study assistant, and some parts of Tutorly Learn use AI too. All of them run on Anthropic's Claude API. Anthropic processes this data in the United States, and under its commercial API terms your data is used only to generate the response — it is not used to train Anthropic's models.

What is sent to Anthropic when you chat with Bao:

  • If you are a student: your messages, your first name, the full names of the tutors you have booked, the subject, date, time, length and status of your recent and upcoming sessions, your homework titles and due dates, the written feedback your tutor left on your homework (quoted, up to 140 characters), and any coaching guidance your tutor has set for Bao.
  • If you are a parent: your messages, each of your children's names and levels, bookings waiting for your approval with the tutor's name, time and price, their upcoming sessions, their homework, and how much you have spent this month in total and per child.
  • If you are a tutor: your messages, your hourly rate, your verification status and any rejection reason, the names of your students with how many sessions you have done together, your upcoming sessions and the homework you have set, and your earnings totals.

What is sent to Anthropic elsewhere in Learn:

  • Auto-marking: practice and mini-mock questions are marked by AI, which means the question, the mark scheme and your written answer (up to 5,000 characters) are sent to Anthropic.
  • Flashcards: notes you paste in to generate cards (up to 8,000 characters) are sent to Anthropic.
  • Practice questions: generating new practice sends the topic and your recent performance signals.

Essay marking is not AI. Essays you submit are marked by a real tutor you have booked with, who writes the bands and comments themselves.

We do not store your Bao conversations at all — not on our servers, and not in any database. Each message is sent, answered, and gone. Your tutor cannot see them, and neither can your parent.

9. Where your data goes

Our database, your files and your login live with Supabase in the UK (London). Some of the companies in section 5 are based outside the UK, which means your data is transferred there:

  • United States: Anthropic (AI), Resend (email), Vercel (hosting and logs), Daily.co (video), Discord (tutor community), and — where phone verification is enabled — Twilio (verification texts).
  • United States or the EU: Upstash (rate-limit counters), depending on the region we run in.
  • Global: Stripe processes payments across its US and EU infrastructure.

These transfers are made under each provider's data processing terms, which incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the IDTA itself). Those terms are the safeguard required by Chapter V of the UK GDPR. You can ask us for details of the terms we rely on for any particular provider.

10. How long we keep it

  • Your account, profile and study data: kept while your account is open. When you delete your account it goes with it (see section 11).
  • In-call chat and files shared during a lesson: automatically and permanently deleted after 90 days, by a job that runs every night.
  • Messages between people on the platform: kept for as long as the account exists, because being able to look back at them is part of how we keep young people safe.
  • Bao conversations: never stored by us.
  • Tutor DBS and qualification evidence: kept while the tutor is listed with us, and deleted when their account is closed.
  • Payment and financial records: kept for as long as tax and accounting law requires. When you delete your account these records are detached from you, so what remains is an anonymised receipt rather than a record about you.
  • Safety records: where a safeguarding concern or complaint is open, or has been reported to an authority, the records that relate to it may be kept beyond the periods above for as long as they are needed for that investigation.
  • Waitlist and "notify me" sign-ups: kept until you ask us to remove them. Email us and we will.
  • A record that an account was deleted: we keep the account's internal ID, its role and the date, so we can show that a deletion request was carried out. It contains no name, email or content.

11. Your rights

Under UK GDPR you can:

  • Delete your account and data. You can do this yourself from Settings, under "Danger zone". It removes your profile, your bookings, homework, study data, and the profile photos and verification documents you uploaded, and it cancels an active £15/month membership straight away so you are not billed again. Three things stay behind: payment records, kept in anonymised form for tax and accounting (see section 10); the safety records described in section 10; and messages you sent to other people, which stay in their copy of the conversation with your account detached from them. We also keep a bare record that a deletion happened.
  • Get a copy of your data, or ask for it in a portable format.
  • Correct anything wrong. Your name, email and password are editable in Settings, along with your level, subjects and (for tutors) your listing. For anything you cannot edit yourself, such as your date of birth, email us and we will correct it.
  • Object to processing, or ask us to restrict it. Parents can also switch off the weekly digest in settings without contacting us.
  • Complain to the Information Commissioner's Office (ico.org.uk) if you think we have got it wrong. We would rather you told us first so we can fix it.

For anything that is not a button in the app, email privacy@tutorly.com and we will respond within one month. If you are a parent asking on behalf of your child, say so and tell us their name so we can find the right account.

12. Young people and parents

There is no minimum age to learn on Tutorly, and Tutorly is built as a platform where a parent or guardian can see what is going on. Tutors must be 18 or over.

When a student under 18 signs up, we ask for a parent or guardian's email address so we can invite them to link their account. Students also get a child code they can give a parent to link at any time later. Once linked, a parent approves and pays for bookings: a session booked by an under-18 is never paid for or confirmed until their linked parent approves it, and it expires if they do not.

If you are a parent and want to link to your child's account, ask them for their child code, or email us. If you want your child's account closed, or want to know what we hold about them, email privacy@tutorly.com and we will help. Safety concerns go to safeguarding@tutorly.com. Our Safeguarding page explains the rest of how we protect young people.

13. Cookies

We set only the cookies the site needs to work — keeping you signed in, and honouring invite links. There are no advertising cookies, no analytics cookies and no third-party trackers, which is why you do not see a cookie banner. The full list, and what your browser stores locally, is in our cookie policy.

14. Security and changes to this policy

Your data is protected by database-level access rules, private file storage, encrypted connections, and admin access limited to the people who need it. No system is perfect: if a breach happens that puts you at risk, we will tell you and the ICO as the law requires.

If we change how we use your data we will update this page and change the date at the top. Where a change is significant we will tell you directly rather than waiting for you to notice.