Adaptive Tutor

Candidate 2026-09-01 ยท Version 2026-09-01.1

Privacy Policy

Service operator
NOT CONFIGURED โ€” production blocked
Trade name
Adaptive Tutor
Mailing address
NOT CONFIGURED โ€” production blocked
Privacy contact
admin@adaptivetutor.ai
Support contact
admin@adaptivetutor.ai

This candidate Privacy Policy describes how Adaptive Tutor proposes to handle information for students, families, educators, schools, and adult learners. Because the legal operator and several operational commitments are not yet approved, this draft must not be represented as an effective or counsel-reviewed production policy.

1. Information We Collect

2. Child, Guardian, Educator, School, and Operator Responsibilities

Child or student

A child or student must not create or use an account unless a parent, guardian, school, or other legally authorized adult has approved the account and provides the supervision appropriate for the learner. The learner must use only their own account and follow classroom and household rules.

Parent or legal guardian

For direct-to-family use, the parent or legal guardian is responsible for authorizing the learner account, reviewing the notices presented for the child, providing any consent required for collection and use of the child's information, supervising use, and making access, correction, export, or deletion requests for the child.

Teacher or other educator

An educator may invite, manage, or view a learner only when the educator has documented authority from the school or the parent or guardian. A job title alone does not create authority. Educators must follow school policy and must not place information for an unauthorized learner in the service.

School or district

When a school or district contracts for or directs use of the service, it is responsible for defining authorized educational purposes, approving staff access, providing notices, obtaining consent when required, responding to education-record requests, and executing the applicable services agreement or data-processing addendum. The final allocation of controller, processor, school-official, and direct-notice duties must be stated in the signed agreement.

Service operator

The operator is responsible for limiting processing to the disclosed educational and operational purposes, applying role and tenant controls, supporting verified rights requests, maintaining security and deletion procedures, managing subprocessors, and notifying the responsible adult or school as required by the final agreement and applicable law.

3. Purposes of Processing

4. No Sale or Behavioral Advertising

The proposed product commitment is not to sell or rent personal information and not to use student information for third-party behavioral advertising. Counsel and the accountable owner must verify that product analytics, AI providers, public-site tooling, SDKs, and every distribution channel support this statement before publication.

5. Subprocessors and Disclosures

The following is a candidate subprocessor inventory. It intentionally identifies unresolved contracting entities, account settings, regions, and transfer terms. A provider must not be labeled approved until the Adaptive Learning account and applicable agreement have been verified. Information may also be disclosed to an authorized parent, guardian, educator, school, purchaser, or legal authority when the final policy and applicable agreement allow it.

ProviderPurposeDataProcessing locationContract/transfer basisApproval
Render (exact contracting legal entity must be verified for the Adaptive Learning account only)Backend application, managed database, public Static Site, CDN delivery, and related infrastructureAccount, learning, security, support, and billing metadata processed by the backend; ordinary public web request metadata and source-derived browser assets processed by the separate Static SiteBackend deployment region and Static Site/CDN processing locations must be recorded from the Adaptive Learning Render configurationDPA, security terms, deletion terms, and transfer mechanism must be recordedrequires_adaptive_learning_render_account_contract_and_region_verification
Cloudflare (exact contracting legal entity must be verified)Authoritative DNS, DNSSEC, TLS edge, denial-of-service protection, and optional proxy/cache for public site recordsPublic DNS records and ordinary public web request, connection, security, and cache metadata; the API remains DNS-only pending a separate ingress reviewAuthoritative DNS and edge processing locations, logs, and account settings must be recordedService terms, DPA applicability, security and cache/log retention settings, subprocessors, and transfer mechanism must be recordedrequires_contract_account_zone_and_region_verification
IONOS (exact contracting legal entity must be verified)Domain registration and transactional email; temporary static-host rollback during the migration observation windowDomain registration/contact data, email content and delivery metadata, and ordinary request metadata only while the retained rollback host remains reachableRegistrar, mail, and temporary rollback-host processing and log locations must be recordedRegistrar/mail/hosting terms, DPA applicability, log retention, deletion after migration, and transfer mechanism must be recordedrequires_contract_and_region_verification
Stripe (exact contracting legal entity must be verified)Planned checkout, subscription, payment, invoice, refund, and billing portal processing; Stripe checkout is not active in the current releasePurchaser identity and contact details, payment details handled by Stripe, and subscription metadataProcessing and transfer locations must be confirmed from the applicable Stripe agreementController/processor roles, DPA, consumer terms, and transfer mechanism must be approvedrequires_contract_role_and_region_verification
OpenAI (only when the hosted OpenAI route or a user's selected provider route is enabled)Generate optional AI tutoring responses and safety-related output, and transcribe an explicitly requested realtime voice inputPrompt, lesson context, learner response, safety context, transient microphone audio for transcription, resulting transcript, and limited request metadata selected by the product flow; Adaptive Tutor does not intentionally retain the raw audioAccount project, Responses and Realtime API surfaces, model, region options, retention controls, and training settings must be recordedEducation use, DPA, zero-retention or eligible retention controls, and transfer mechanism must be approvedrequires_account_configuration_contract_and_data_control_verification
Google Gemini / Google Cloud (only for a grandfathered text-model route)Generate optional text-based AI tutoring responses and safety-related output for a retained legacy selection; not speech transcriptionPrompt, lesson context, learner response, safety context, and limited request metadata selected by the product flowProject, API surface, model, location, logging, retention, and training settings must be recordedApplicable cloud or API terms, DPA, education eligibility, and transfer mechanism must be approvedrequires_account_configuration_contract_and_data_control_verification
Deployment-specific transactional email providerPassword recovery, account notices, safety/support messages, and billing communicationsRecipient address, message subject/body, delivery status, and limited account contextActual provider, sending region, and log locations are not yet recordedProvider terms, DPA, retention, subprocessor, and transfer terms must be approvedrequires_real_provider_configuration_and_contract_verification

6. AI and User-Selected Providers

When an AI feature is used, the service may send the minimum prompt, learner response, lesson context, safety context, and request metadata needed for the selected feature to the configured provider. When the user explicitly starts voice input, the browser sends bounded microphone audio through Adaptive Tutor to OpenAI Realtime for transcription; Adaptive Tutor does not intentionally persist or log the raw audio, while the resulting transcript can be stored wherever the same typed input would be stored. Hosted provider accounts and personal provider-key routes must be documented separately. A user's selection of a personal key does not remove the operator's duty to present accurate notices or configure the product safely.

The final production configuration must record provider training use, human review, retention, regional processing, zero-retention eligibility, abuse monitoring, and age or education restrictions for each enabled model and API surface.

7. Retention and Deletion Schedule

These are proposed commitments, not verified production behavior. Engineering, the accountable owner, and counsel must reconcile each row with database jobs, backups, provider settings, school contracts, finance obligations, incident holds, and rights-request procedures before approval.

DataRetention triggerProposed periodDispositionOwnerApproval
Account, guardian, school, and learner profileVerified account deletion, end of direct subscription, or school-contract instructionProposed: active service plus 30 days in primary systemsDelete or irreversibly de-identify, except records placed on a documented legal or safety holdPrivacy ownerrequires_operational_validation_and_counsel_approval
Learning progress, responses, assignments, tutor messages, and model contextVerified account deletion or school-contract instructionProposed: active service plus 30 days in primary systemsDelete or irreversibly de-identify; provide an export before deletion when requested and authorizedLearning-data ownerrequires_operational_validation_and_counsel_approval
Authentication, abuse-prevention, security, and privileged audit eventsEvent creation or session expirationProposed: 365 days, shortened where a school agreement or local law requiresDelete after the period unless a documented incident or legal hold is openSecurity ownerrequires_operational_validation_and_counsel_approval
Support, safety, governance, and incident recordsCase closureProposed: 24 months after closureDelete or minimize after the period unless continued retention is documented for safety or legal obligationsSafety and support ownerrequires_operational_validation_and_counsel_approval
Billing, invoices, processor event references, refunds, and tax recordsTransaction, refund, or subscription terminationProposed: the period required by the operator's verified tax, accounting, chargeback, and consumer-law obligationsRetain only required billing records; delete unrelated learner contentFinance ownerrequires_legal_entity_jurisdiction_and_counsel_configuration
Encrypted backupsDeletion from primary systemsProposed: overwrite within 35 daysExpire by backup rotation; do not restore deleted records except for disaster recovery followed by replay of deletion requestsInfrastructure ownerrequires_render_backup_configuration_validation_and_counsel_approval
Temporary student-data export artifactsExport creation15 minutesExpire the capability and remove the temporary artifactPrivacy engineering ownerimplemented_pending_counsel_approval
Transactional email outbox content and delivery metadataMessage creationProposed: 30 days after terminal delivery statusPurge message body and recipient data; retain only minimized aggregate delivery metrics if neededCommunications ownerimplemented_target_pending_operational_validation_and_counsel_approval

8. Access, Correction, Export, and Deletion

An account holder, verified parent or guardian, or authorized school representative may use the privacy contact to request access, correction, an export, or deletion. The operator must verify identity and authority, avoid disclosing another learner's information, route school-controlled education-record requests according to the applicable school agreement, and document any lawful exception or retention hold.

The final policy must state response periods, appeal or complaint channels, authorized-agent rules, and jurisdiction-specific rights after launch locations are approved.

9. Security and Incident Notice

The service is designed to use access controls, encryption in transit, credential protection, audit events, rate limits, and operational monitoring. No system is perfectly secure. The production security review must verify these controls and the incident-notification workflow before this language is approved.

Do not send passwords, AI provider keys, full payment details, or unnecessary learner records by email.

10. International Processing and School DPAs

11. Changes and Contact

A material policy change must receive a new version, regenerate every surface, be reviewed for renewed notice or consent obligations, and receive a new signed owner/counsel attestation. Privacy requests should use the privacy contact above; product and account support should use the support contact.

Generated deterministically from config/legal/policy-source.json. Do not edit this copy directly. This engineering artifact is not legal advice.