A short reference for tutors, parents, and schools who want to understand how TutorMi handles student data — particularly when students are minors.
Roles
The tutor is the data controller for their students' records — they decide what to record and why. TutorMi acts as a data processor — we store and secure the data on the tutor's behalf under these commitments.
What is stored per student
Name, optional email, subject/level, topic progress, lesson notes, homework assigned by the tutor, and files the student submits. Nothing else is collected automatically.
Isolation
Each tutor's workspace is isolated at the database row level. No tutor can read another tutor's students, lessons, homework, or notes. Students see only their own workspace, never another student's.
Security
Data in transit is TLS-encrypted. Passwords are hashed. Access to the underlying database is restricted to authorized operators and audited.
Minors
Tutors are responsible for obtaining any parental consent required by local law before entering a minor's data. Parents or guardians may request access, correction, or deletion of a minor's records by contacting the tutor.
Retention & deletion
Records are retained while the tutor's account is active. On request or account deletion, personal data is removed within 30 days.
No third-party training
Student data is not sold and is not used to train third-party AI models.