Candidate 2026-09-01 ยท Version 2026-09-01.1
Privacy Policy
- Service operator
- NOT CONFIGURED โ production blocked
- Trade name
- Adaptive Tutor
- Mailing address
- NOT CONFIGURED โ production blocked
- Privacy contact
- admin@adaptivetutor.ai
- Support contact
- admin@adaptivetutor.ai
This candidate Privacy Policy describes how Adaptive Tutor proposes to handle information for students, families, educators, schools, and adult learners. Because the legal operator and several operational commitments are not yet approved, this draft must not be represented as an effective or counsel-reviewed production policy.
1. Information We Collect
- Account and profile information, including username, email, password verifier, display name, role, age band or birthday, grade level, preferences, accessibility settings, and optional parent, guardian, teacher, school, district, or classroom information.
- Learning and usage information, including curriculum assignments, responses, scores, progress, knowledge-tracing signals, vocabulary practice, tutor messages, learner reflections, goals, feedback, library activity, and classroom activity.
- AI, voice, and safety information, including prompts, responses, lesson context, selected provider and model, explicitly captured microphone audio sent transiently for transcription, resulting transcripts, agent workflow state, safety reports, governance events, review notes, and limited diagnostic metadata. Adaptive Tutor does not intentionally persist raw microphone audio.
- Billing information, including plan, trial, subscription, invoice, last-four display information, renewal timing, access entitlement, discounts, refunds, and processor event identifiers. Payment card details are handled by the payment processor rather than intentionally stored by Adaptive Tutor.
- Restricted billing-dispute evidence, including bounded interaction and usage-ledger metadata, pricing-rate and reconciled-cost metadata, and a pseudonymous evidence reference. This view is metadata-first; prompt and tutor-response content is available only after an explicit site-administrator request for the case, and that access is recorded in a metadata-only audit event. The underlying interaction and usage records remain in the existing application PostgreSQL database; the view creates no separate billing database or storage, and does not establish a processor charge-to-content linkage.
- Technical and security information, including session identifiers, login and revocation events, IP-derived security events, request metadata, abuse-control signals, app/build version, crash and error reports, and privileged audit events.
- Support and communications information, including password-recovery requests, support cases, safety escalations, transactional messages, delivery status, and information supplied with a request.
- Optional personal AI provider credentials when a user chooses to store one. The application is designed to encrypt saved credentials and use them only for the selected provider route, but the final policy depends on production key-management verification.
2. Child, Guardian, Educator, School, and Operator Responsibilities
Child or student
A child or student must not create or use an account unless a parent, guardian, school, or other legally authorized adult has approved the account and provides the supervision appropriate for the learner. The learner must use only their own account and follow classroom and household rules.
Parent or legal guardian
For direct-to-family use, the parent or legal guardian is responsible for authorizing the learner account, reviewing the notices presented for the child, providing any consent required for collection and use of the child's information, supervising use, and making access, correction, export, or deletion requests for the child.
Teacher or other educator
An educator may invite, manage, or view a learner only when the educator has documented authority from the school or the parent or guardian. A job title alone does not create authority. Educators must follow school policy and must not place information for an unauthorized learner in the service.
School or district
When a school or district contracts for or directs use of the service, it is responsible for defining authorized educational purposes, approving staff access, providing notices, obtaining consent when required, responding to education-record requests, and executing the applicable services agreement or data-processing addendum. The final allocation of controller, processor, school-official, and direct-notice duties must be stated in the signed agreement.
Service operator
The operator is responsible for limiting processing to the disclosed educational and operational purposes, applying role and tenant controls, supporting verified rights requests, maintaining security and deletion procedures, managing subprocessors, and notifying the responsible adult or school as required by the final agreement and applicable law.
3. Purposes of Processing
- Create, authenticate, secure, and administer accounts and authorized family, classroom, and school relationships.
- Deliver tutoring, curriculum, assessments, vocabulary practice, library tools, progress reporting, accessibility settings, and optional AI-assisted learning.
- Operate subscriptions, trials, access grants, invoices, refunds, and purchaser support.
- Respond to verified access, correction, export, deletion, safety, and support requests.
- Protect learners and the service, detect abuse, investigate incidents, audit privileged actions, troubleshoot failures, and improve reliability and safety.
- Meet documented contractual and legal obligations after the operator, launch jurisdictions, and school agreements are approved.
4. No Sale or Behavioral Advertising
The proposed product commitment is not to sell or rent personal information and not to use student information for third-party behavioral advertising. Counsel and the accountable owner must verify that product analytics, AI providers, public-site tooling, SDKs, and every distribution channel support this statement before publication.
5. Subprocessors and Disclosures
The following is a candidate subprocessor inventory. It intentionally identifies unresolved contracting entities, account settings, regions, and transfer terms. A provider must not be labeled approved until the Adaptive Learning account and applicable agreement have been verified. Information may also be disclosed to an authorized parent, guardian, educator, school, purchaser, or legal authority when the final policy and applicable agreement allow it.
| Provider | Purpose | Data | Processing location | Contract/transfer basis | Approval |
|---|---|---|---|---|---|
| Render (exact contracting legal entity must be verified for the Adaptive Learning account only) | Backend application, managed database, public Static Site, CDN delivery, and related infrastructure | Account, learning, security, support, and billing metadata processed by the backend; ordinary public web request metadata and source-derived browser assets processed by the separate Static Site | Backend deployment region and Static Site/CDN processing locations must be recorded from the Adaptive Learning Render configuration | DPA, security terms, deletion terms, and transfer mechanism must be recorded | requires_adaptive_learning_render_account_contract_and_region_verification |
| Cloudflare (exact contracting legal entity must be verified) | Authoritative DNS, DNSSEC, TLS edge, denial-of-service protection, and optional proxy/cache for public site records | Public DNS records and ordinary public web request, connection, security, and cache metadata; the API remains DNS-only pending a separate ingress review | Authoritative DNS and edge processing locations, logs, and account settings must be recorded | Service terms, DPA applicability, security and cache/log retention settings, subprocessors, and transfer mechanism must be recorded | requires_contract_account_zone_and_region_verification |
| IONOS (exact contracting legal entity must be verified) | Domain registration and transactional email; temporary static-host rollback during the migration observation window | Domain registration/contact data, email content and delivery metadata, and ordinary request metadata only while the retained rollback host remains reachable | Registrar, mail, and temporary rollback-host processing and log locations must be recorded | Registrar/mail/hosting terms, DPA applicability, log retention, deletion after migration, and transfer mechanism must be recorded | requires_contract_and_region_verification |
| Stripe (exact contracting legal entity must be verified) | Planned checkout, subscription, payment, invoice, refund, and billing portal processing; Stripe checkout is not active in the current release | Purchaser identity and contact details, payment details handled by Stripe, and subscription metadata | Processing and transfer locations must be confirmed from the applicable Stripe agreement | Controller/processor roles, DPA, consumer terms, and transfer mechanism must be approved | requires_contract_role_and_region_verification |
| OpenAI (only when the hosted OpenAI route or a user's selected provider route is enabled) | Generate optional AI tutoring responses and safety-related output, and transcribe an explicitly requested realtime voice input | Prompt, lesson context, learner response, safety context, transient microphone audio for transcription, resulting transcript, and limited request metadata selected by the product flow; Adaptive Tutor does not intentionally retain the raw audio | Account project, Responses and Realtime API surfaces, model, region options, retention controls, and training settings must be recorded | Education use, DPA, zero-retention or eligible retention controls, and transfer mechanism must be approved | requires_account_configuration_contract_and_data_control_verification |
| Google Gemini / Google Cloud (only for a grandfathered text-model route) | Generate optional text-based AI tutoring responses and safety-related output for a retained legacy selection; not speech transcription | Prompt, lesson context, learner response, safety context, and limited request metadata selected by the product flow | Project, API surface, model, location, logging, retention, and training settings must be recorded | Applicable cloud or API terms, DPA, education eligibility, and transfer mechanism must be approved | requires_account_configuration_contract_and_data_control_verification |
| Deployment-specific transactional email provider | Password recovery, account notices, safety/support messages, and billing communications | Recipient address, message subject/body, delivery status, and limited account context | Actual provider, sending region, and log locations are not yet recorded | Provider terms, DPA, retention, subprocessor, and transfer terms must be approved | requires_real_provider_configuration_and_contract_verification |
6. AI and User-Selected Providers
When an AI feature is used, the service may send the minimum prompt, learner response, lesson context, safety context, and request metadata needed for the selected feature to the configured provider. When the user explicitly starts voice input, the browser sends bounded microphone audio through Adaptive Tutor to OpenAI Realtime for transcription; Adaptive Tutor does not intentionally persist or log the raw audio, while the resulting transcript can be stored wherever the same typed input would be stored. Hosted provider accounts and personal provider-key routes must be documented separately. A user's selection of a personal key does not remove the operator's duty to present accurate notices or configure the product safely.
The final production configuration must record provider training use, human review, retention, regional processing, zero-retention eligibility, abuse monitoring, and age or education restrictions for each enabled model and API surface.
7. Retention and Deletion Schedule
These are proposed commitments, not verified production behavior. Engineering, the accountable owner, and counsel must reconcile each row with database jobs, backups, provider settings, school contracts, finance obligations, incident holds, and rights-request procedures before approval.
| Data | Retention trigger | Proposed period | Disposition | Owner | Approval |
|---|---|---|---|---|---|
| Account, guardian, school, and learner profile | Verified account deletion, end of direct subscription, or school-contract instruction | Proposed: active service plus 30 days in primary systems | Delete or irreversibly de-identify, except records placed on a documented legal or safety hold | Privacy owner | requires_operational_validation_and_counsel_approval |
| Learning progress, responses, assignments, tutor messages, and model context | Verified account deletion or school-contract instruction | Proposed: active service plus 30 days in primary systems | Delete or irreversibly de-identify; provide an export before deletion when requested and authorized | Learning-data owner | requires_operational_validation_and_counsel_approval |
| Authentication, abuse-prevention, security, and privileged audit events | Event creation or session expiration | Proposed: 365 days, shortened where a school agreement or local law requires | Delete after the period unless a documented incident or legal hold is open | Security owner | requires_operational_validation_and_counsel_approval |
| Support, safety, governance, and incident records | Case closure | Proposed: 24 months after closure | Delete or minimize after the period unless continued retention is documented for safety or legal obligations | Safety and support owner | requires_operational_validation_and_counsel_approval |
| Billing, invoices, processor event references, refunds, and tax records | Transaction, refund, or subscription termination | Proposed: the period required by the operator's verified tax, accounting, chargeback, and consumer-law obligations | Retain only required billing records; delete unrelated learner content | Finance owner | requires_legal_entity_jurisdiction_and_counsel_configuration |
| Encrypted backups | Deletion from primary systems | Proposed: overwrite within 35 days | Expire by backup rotation; do not restore deleted records except for disaster recovery followed by replay of deletion requests | Infrastructure owner | requires_render_backup_configuration_validation_and_counsel_approval |
| Temporary student-data export artifacts | Export creation | 15 minutes | Expire the capability and remove the temporary artifact | Privacy engineering owner | implemented_pending_counsel_approval |
| Transactional email outbox content and delivery metadata | Message creation | Proposed: 30 days after terminal delivery status | Purge message body and recipient data; retain only minimized aggregate delivery metrics if needed | Communications owner | implemented_target_pending_operational_validation_and_counsel_approval |
8. Access, Correction, Export, and Deletion
An account holder, verified parent or guardian, or authorized school representative may use the privacy contact to request access, correction, an export, or deletion. The operator must verify identity and authority, avoid disclosing another learner's information, route school-controlled education-record requests according to the applicable school agreement, and document any lawful exception or retention hold.
The final policy must state response periods, appeal or complaint channels, authorized-agent rules, and jurisdiction-specific rights after launch locations are approved.
9. Security and Incident Notice
The service is designed to use access controls, encryption in transit, credential protection, audit events, rate limits, and operational monitoring. No system is perfectly secure. The production security review must verify these controls and the incident-notification workflow before this language is approved.
Do not send passwords, AI provider keys, full payment details, or unnecessary learner records by email.
10. International Processing and School DPAs
- Production launch countries are not yet declared. The accountable owner must list every country in which the service will be offered, marketed, sold, or used by a participating school.
- Before international launch, counsel must approve the applicable controller/processor roles, lawful bases, child-consent ages, transparency language, data-subject rights workflow, representative or data-protection-officer requirements, breach duties, and cross-border transfer mechanism.
- A school DPA or services agreement must identify instructions, permitted purposes, security measures, subprocessors, deletion or return at contract end, audit/cooperation duties, incident notice, rights-request handling, and the parties' education-record responsibilities.
- The final policy must identify any regional supplement and a contact for privacy rights. The service must not claim GDPR, UK GDPR, Canadian, Australian, or other international compliance merely because this engineering gate exists.
11. Changes and Contact
A material policy change must receive a new version, regenerate every surface, be reviewed for renewed notice or consent obligations, and receive a new signed owner/counsel attestation. Privacy requests should use the privacy contact above; product and account support should use the support contact.
Generated deterministically from config/legal/policy-source.json. Do not edit this copy directly. This engineering artifact is not legal advice.