TutorPal

Legal

Privacy Policy

Effective September 28, 2026

This Privacy Policy explains how TutorPal (operated by Omar Soto) handles information in TutorPal. It is written for U.S. families. Effective date: September 28, 2026.

Who we are

TutorPal (operated by Omar Soto) is a sole proprietor. There is no LLC. TutorPal is a bilingual AI tutor for ages 6–14. A parent creates the account. Contact: support@gettutorpal.com.

Children and COPPA

Children under 13 use TutorPal. The parent or legal guardian is the account holder. By creating the account and starting a trial or subscription with a payment card, that adult gives verifiable parental consent for the child profiles they add, including collection of the data described below.

We do not knowingly collect personal information from a child independently of a parent account. We do not show third-party ads, we do not sell personal information, and we do not use children’s data for behavioral advertising. Parents can review, correct, export, or delete a child’s information by emailing support@gettutorpal.com. We will ask enough to confirm you control the household account before we act.

Information we collect

From the parent: language preference, optional email, optional Clerk sign-in identifier if that feature is turned on, a hashed 4-digit PIN, and Stripe customer and subscription identifiers and status (not the full card number).

From child profiles: first name or nickname, grade (kindergarten through 8), language, and (in the on-device household cookie) age 6–14. We do not ask for last name, school name, or home address.

From use of the tutor: chat message text, which tutor face was chosen, subject (math, literature, history, science), and progress such as stars, streaks, daily missions, and collectibles.

What we store vs what is transient

Stored (in Neon Postgres when a database URL is configured, otherwise in first-party cookies on the device, and progress also in browser localStorage): parent and child profile fields above; Stripe billing status fields; chat session records and message text; a flag that a homework photo was attached to a turn (not the image bytes); language and household cookies needed to keep the family logged in on that browser.

Not stored by TutorPal (processed in memory for that request only): homework-page photos sent to OpenAI so the tutor can hint from the worksheet; voice recordings sent to OpenAI Whisper to turn speech into text; audio files generated by OpenAI text-to-speech to play the tutor’s voice. Photo thumbnails may exist only in the current browser tab and are not written to our database.

How we use information

We use this information to run the tutor, keep the Family subscription, show the parent a high-level weekly summary (minutes, stars, streak, subjects — not the full chat unless it is already on the device), improve reliability, and provide support. We do not use children’s chats to train a public ad model of our own. OpenAI processes prompts under its services as our processor so the tutor can reply.

Third-party processors

We share data with service providers only to operate TutorPal:

  • Vercel — hosting the website and app.
  • Neon — Postgres database when we have configured one (profiles, chat text, billing status).
  • Stripe — checkout, subscriptions, customer portal, and invoices. Stripe handles the card.
  • Clerk — parent authentication, only if Clerk keys are enabled on the site.
  • OpenAI — tutor replies, homework-photo vision, speech-to-text, and text-to-speech.

No ads, no sale of data

We do not sell personal information as that term is used in U.S. state privacy laws. We do not run behavioral advertising on TutorPal. We do not allow third parties to track children inside the tutor for ads.

Retention and deletion

We keep account, chat, and progress data while the household uses TutorPal and for a short period after, so you can return. If you ask us to close the account, or when a subscription has ended and you request deletion, we delete stored profiles, messages, and progress we control in our database, and we tell you if cookies on your devices still need to be cleared. Stripe may keep payment records as required by financial law. OpenAI retains prompts according to its own retention for API customers.

To delete a child’s data or the whole household, email support@gettutorpal.com from the parent. We will confirm and then delete.

Parent rights

You may review child profiles in the parent area, refuse further collection by canceling and stopping use, and request a copy or deletion by email. We will not require a child to give more data than needed to tutor.

U.S. state privacy rights (including California)

If you are a U.S. resident, including in California, you may have rights to know, access, correct, or delete personal information, and to opt out of “sale” or “sharing” for cross-context advertising. We do not sell or share personal information for advertising. To exercise rights, email support@gettutorpal.com. We will not discriminate against you for exercising them. We do not have actual knowledge that we sell or share the personal information of consumers under 16.

Security

We use HTTPS, hashed PINs, and access limited to the household cookies or parent sign-in. No method is perfect. Do not put secrets in the chat. Homework photos should be the worksheet only, not faces.

Changes

We may update this policy. The effective date at the top will change. If we make material changes to how we treat children’s data, we will provide additional notice in the parent area or by email when we have an address.

Contact

Privacy questions and deletion requests: support@gettutorpal.com. Operator: TutorPal (operated by Omar Soto).

Back to home