aitutors.mePrivacy · last reviewed 2026-09-02

Plain-English privacy: what we keep, where it flows, and what we don’t do.

The aitutors.me tutors run in two places: in your browser at aitutors.me/study, where we run the tutoring ourselves, and inside Claude, ChatGPT or Codex through one connector, where the conversation stays in that app. Parents deserve a clear picture of how data moves along each path — not just what we store. This page is that picture, in plain English.

Who we are

aitutors.me is a trading name of Innovatorly Ltd, an indie UK company registered in England and Wales (company no. 16674855; registered office 167–169 Great Portland Street, London W1W 5PF). We are the data controller for parent account data (your email, billing, support correspondence). For your child’s conversation data, you — the parent who holds the account — are the controller, and we act as the data processor on your behalf. We are registered with the UK Information Commissioner’s Office under registration ZC127414.

How your child’s data flows

There are two ways to use the tutors, and the data takes a different path on each. Your family can use either or both.

Path 1 — the browser tutor (aitutors.me/study)

  1. Your child types into the tutor page on aitutors.me. Each message goes to our own servers, which run on Vercel in London.
  2. Our server sends the conversation to Google’s Gemini API to generate the tutor’s reply. Google is our AI processor for this path. (The free demo at aitutors.me/tutor/demo, which needs no account, uses Anthropic’s Claude API instead.) Both are paid, commercial API services.
  3. We store the conversation thread in our UK Supabase database so the tutor can pick up where it left off — see “What we store” below for what that includes and how long it lasts.

Path 2 — the connector (Claude, ChatGPT or Codex)

  1. Your child’s AI app (claude.ai, Claude Desktop, Claude Code, ChatGPT or Codex) sends each message to that app’s own model, under that provider’s terms and your own account with them. The full transcript lives in that app, not with us.
  2. Our MCP server — our pedagogy, prompts and routing — runs on Vercel in London and supplies the tutors’ tools. The only conversation content that reaches it is what the model passes into a tool call (the question being worked on, the hint level, the energy check).
  3. We store a short session record in our UK Supabase database — see “What we store” below.

The important thing to know: on Path 1, every provider we use is on commercial API terms, not consumer-product terms. Under those commercial terms, neither Google nor Anthropic uses the content to train any of their models. We hold them to that, and we do not train any model on it either. On Path 2 the transcript sits in your own Claude, ChatGPT or Codex account, so whether that provider may use it for training is a setting in your account with them — check it, because it is not something we control.

Google publishes the Gemini API terms at ai.google.dev/gemini-api/terms and Anthropic its commercial data-handling commitments at anthropic.com/legal/commercial-terms. If either changes in a way that affects your child’s data, we will update this page and email account holders.

What we store about each session

To give parents transparency over what their child is studying, every tutor session writes a small row to our mcp_sessions table. That row contains:

  • The time the session started and ended.
  • Which tutor was used (Mentor or one of the subject professors) and which topic.
  • A short note the tutor writes summarising what was covered (e.g. “Worked on expanding brackets, two hints needed”).
  • The session duration.

For connector sessions (Path 2) we do not store verbatim transcripts of what your child typed. The full back-and-forth lives only inside your child’s Claude, ChatGPT or Codex app — under your control there, and under that provider’s terms.

For browser-tutor sessions (Path 1) we do store the conversation itself — the messages exchanged with the tutor — because we are the one running the tutor and it needs to pick up where it left off next time. Those threads are kept for as long as your account exists and are deleted with it; email us at any time and we will delete them sooner. They pass through Google’s Gemini API to be answered and are not used to train any model.

Sign-in and web-session activity records also note the device type, browser, and operating system used, derived from your browser’s User-Agent — this helps us recognise unfamiliar sign-ins and troubleshoot device-specific issues.

How long we keep it

Session records (the rows described above) are soft-deleted after 30 days on a rolling basis. This is the default for new accounts. From your dashboard you can choose a shorter window (delete at session end, or 7 days) or a longer one (90 days) — your choice, your data.

You can also email support@aitutors.me and ask us to wipe everything we hold about your account earlier than that. We respond within 30 days, usually within one or two.

Billing records (Stripe customer ID, last-four card digits, invoice history) are kept for as long as UK tax law requires — currently six years.

What we never do

  • We do not train any model on your child’s conversations — not now, not later. Neither do Google or Anthropic on the commercial-API paths the browser tutor and the demo use. Neither does any third party we engage.
  • We do not sell or share personal data with advertisers, brokers or analytics resellers.
  • Analytics cookies are strictly opt-in. Google Analytics stays disabled (no cookies set, nothing collected) unless you explicitly accept it on the cookie banner; declining — or simply ignoring the banner — keeps your visit cookie-free. Learner study sessions never see the banner and are never included in analytics.
  • We do not store payment card numbers. Stripe handles all card data; we only see the last four digits and the brand for support purposes.

How we gate access to the tutors

The browser tutor uses your ordinary signed-in session (and, if you create one, your child’s own login to aitutors.me/study). For the connector, our system mints a short-lived authentication token (a JWT) that lets the AI app you connect — Claude, ChatGPT or Codex — reach the tutors. That token:

  • Is bound to your parent account.
  • Lives for 24 hours, then refreshes automatically while your subscription is active.
  • Carries a subscription_status field, and the tutors also check which subjects your account actually holds, live, on every call.
  • Stops minting the moment you cancel — so access through the connector ends within 24 hours at the latest, cleanly and predictably.

Where we store data

Our database is Supabase Postgres in the London (eu-west-2) region, and our own servers run on Vercel in London. Data is encrypted at rest. We do not transfer your data outside the UK and EEA for our own processing. Google’s Gemini API and Anthropic’s Claude API may process the in-flight conversation in other regions under their own terms; on the connector path, the AI app you connect processes it wherever that provider does. Our transactional email goes through Resend (EU region) and billing through Stripe.

Your rights under UK GDPR

Under the UK General Data Protection Regulation and the Data Protection Act 2018, you have the right to access, correct, erase, port, restrict and object to our processing of your personal data. For your child’s session data you exercise these rights as the controller — we as processor will action your instructions promptly.

Email support@aitutors.me with the subject “GDPR request” and tell us what you want. We respond within 30 days; in practice it is one to two.

Genius Hour newsletter

If you sign up for our weekly email, Genius Hour, we process your email on the lawful basis of consent. We use double opt-in: after you sign up we send a single confirmation email, and you only join the list once you click the link in it.

For the newsletter we store only your email address, your preferred language, the timestamp of your consent, and where you signed up (e.g. the website footer or the Learning Genius quiz). We do not sell or share this list with anyone.

Every newsletter has a one-click unsubscribe link in its footer. If you unsubscribe, or an email to you hard-bounces, we suppress your address straight away and stop sending. To unsubscribe you can also email support@aitutors.me; to have your address erased from the list entirely, ask for a “GDPR request” as described above.

Children’s data

aitutors.me is a parent-account-only service. The account holder is always an adult (18+). You create each child’s profile yourself — a first name or nickname, school year, subjects and study preferences — and you can give the child their own login to the browser tutor at aitutors.me/study, or let them use the tutors inside your own AI app. We collect no child email address and no child contact details; everything about a child sits under your parent account, which you control and can delete. You — the parent — remain in control of your child’s study record.

For more on how we behave when a tutor detects a safeguarding indicator, see our Safeguarding page.

Complaints and the Information Commissioner

aitutors.me is registered as a data controller with the UK Information Commissioner’s Office under registration ZC127414. If you are unhappy with how we have handled your data and a conversation with us hasn’t resolved it, you have the right to complain to the ICO at ico.org.uk/make-a-complaint.