Privacy Policy
1. Who we are
Tutinama (“we”, “us”, “our”) is operated by Jamie Mata, trading as Tutinama, a sole trader based in England. We are the data controller for the personal data described in Section 3 below, except where Section 2 explains that a tutor is the controller instead.
We are a sole trader (not yet an incorporated company — we intend to incorporate a UK limited company before full launch, at which point this policy will be updated and tutors will be notified of the change of contracting entity).
Address: 80 Ladbrook Road, Solihull, West Midlands, United Kingdom, B91 3RN · jamie.mata981@gmail.com · tutinama.com
We are registered with the ICO. Registration reference: CSN1368811.
2. Who is responsible for what — tutors and Tutinama
Tutinama works differently to most apps you might be used to, so it's worth explaining clearly:
- Your tutor decides to use Tutinama to support your (or your child's) learning, and enters the information needed to set it up. In data protection terms, your tutor is the “data controller” for that pupil information — they decide what is collected and why, as part of the tutoring relationship you already have with them.
- Tutinama is the “data processor” — we provide the platform and only process pupil data on our tutors' instructions, following the rules set out in a Data Processing Agreement between us and each tutor.
- Tutinama is the controller in its own right for tutor account data (the tutor's own name, email, and billing details), and for any data we use for our own purposes, such as improving the platform. We do not use pupil data for our own purposes beyond delivering the service to that pupil.
This means that for questions specifically about a pupil's data — for example, correcting something on file or understanding why it was collected — your tutor is usually the right first point of contact, since they hold the relationship and the underlying decisions. Tutinama remains responsible for how the data is handled on the platform, and you can always contact us directly using the details in Section 1.
3. What data we hold
3.1 Tutor account data
- Name, email address, and phone number
- Authentication credentials (managed by our authentication provider, Supabase)
- Billing information, once paid subscriptions begin
3.2 Pupil data (entered by your tutor)
We deliberately avoid holding pupils' real names anywhere the AI Tutor Assistant or day-to-day platform can see. Pupils are identified throughout by username only.
- Username, year group, and age
- Guardian name and guardian email, for any pupil recorded as under 18. Both are mandatory for under-18 pupils. The guardian email is used to send account-creation notifications, including login details, regardless of which email address the pupil later uses day-to-day.
- Contact email and phone (optional) used for day-to-day login — for under-18 pupils this may be the pupil's own email once the account has been created
- Accessibility needs and notes, where disclosed by the tutor
- Subject enrolment details: exam board, qualification, subject, spec code, current/target/goal grade, exam dates
- Academic context set by the tutor: strengths, weaknesses, misconceptions, learning style and pace preferences, communication tone preference, interests used to make examples relevant, and the tutor's professional notes
- A numeric practice score (1–99) reflecting progress, generated from tutor input and session activity
- Wellbeing notes, where recorded by the tutor. These are encrypted at rest, are never shown to the AI Tutor Assistant or used in pupil-facing sessions, and are for the tutor's own reference only.
- Session records: date, time, duration, topics covered, an AI-generated summary of the session, any flags raised by the AI, and an optional note the pupil can add
- Weekly practice schedules and progress updates set by the tutor
We do not store full transcripts of conversations between a pupil and the AI Tutor Assistant. The conversation exists only in the pupil's browser during the session; when the session ends, it is sent once to generate a summary and then discarded.
4. How we use this data
Pupil data is used only to run the AI Tutor Assistant for that specific pupil, to generate progress summaries and scores, and to support the tutor in reviewing and adjusting the pupil's learning plan. We do not use pupil data for advertising, do not sell it to third parties, and do not use it to build commercial profiles.
Tutor account data is used to provide the tutor with access to the platform, communicate with them about their account, and, once applicable, to bill for subscriptions.
5. Lawful basis for processing
As the controller for pupil data, your tutor is responsible for identifying an appropriate lawful basis, typically the legitimate interest of supporting your (or your child's) education as part of an existing tutoring relationship, or consent. Tutinama, as processor, relies on the tutor's instructions and the contract between us.
For tutor account data, Tutinama relies on the contract with the tutor (to provide the service they've signed up for) and, where applicable, legitimate interest in operating and improving the platform.
6. Who we share data with
We use a small number of specialist providers (“sub-processors”) to run the platform. They only process data on our instructions and are bound by their own data processing terms.
- Anthropic (United States) — provides the AI model (Claude) that powers the AI Tutor Assistant and generates session summaries. Anthropic receives the assembled academic context and session conversation, identified only by pupil username — never a pupil's real name, and never wellbeing notes.
- Vercel (United States; may also process in other countries where Vercel or its own sub-processors operate) — hosts the Tutinama application.
- Supabase (European Union) — provides our database and authentication.
- Resend (United States) — sends transactional emails such as login credentials and password resets.
- GoCardless (United Kingdom) — collects tutor subscription payments by Direct Debit. GoCardless only ever processes tutor billing and bank account details — it has no access to pupil data.
We do not sell personal data to anyone, and we do not share it for advertising purposes.
Anthropic, Vercel, and Resend process data outside the UK. Where this happens, we rely on the EU Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum, as our transfer mechanism under UK GDPR Chapter V. GoCardless processes data within the UK, so this doesn't apply to tutor payment data.
7. How long we keep data
- Session records, progress updates, enrolment data, and wellbeing notes (including any flagged as a safeguarding concern): retained for 12 months after a pupil's account is closed or they leave the platform, then deleted.
- Tutor account data: retained for the duration of the tutor's subscription and a reasonable period afterwards for accounting and legal purposes.
These are our default retention periods. A tutor, as controller for their pupils' data, can instruct us to delete a specific pupil's data sooner.
8. Your rights
If you are a parent, guardian, or pupil, you have rights under UK GDPR including the right to: be informed about how data is used; access a copy of the data held; have inaccurate data corrected; request deletion; restrict or object to processing; and request data in a portable format.
Because your tutor is the controller for pupil data, the quickest route is usually to raise this with them directly. You can also contact Tutinama directly using the details in Section 1, and we will support you and, where relevant, your tutor in responding.
9. Children's data
Tutinama is designed for use by pupils aged 14–18 studying UK GCSE and A-Level qualifications. We've designed the platform with data minimisation in mind for this age group — pupils are identified by username rather than real name, and full conversation transcripts are never stored. Guardian details are collected for every pupil recorded as under 18, and account-creation communications for under-18 pupils are always sent to the guardian, not the pupil directly.
10. Security
We use industry-standard measures to protect personal data, including encryption of sensitive fields (wellbeing notes are encrypted at rest using AES-256-GCM), EU-region database hosting, and access controls limiting who can view pupil information.
11. Cookies
We only use strictly necessary cookies, needed to keep you logged in and to operate the platform securely. We do not use cookies for advertising or tracking, so no cookie consent banner is required.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify tutors and, where appropriate, guardians.
13. Contact us
If you have any questions about this policy or how your data is used, contact us at jamie.mata981@gmail.com.
See also our Tutor Terms and Conditions (which includes our Data Processing Agreement) and our Pupil/Parent Notice.