Privacy notice
How Tutor1on1 handles data.
Effective date: August 3, 2026. Contact: tutor1on1.org@gmail.com.
What we collect
- Account data such as username, password hash, email for recovery and notices, account status, and timestamps.
- Marketplace and enrollment data such as teacher profiles, course listings, requests, approvals, and related account identifiers.
- Learning data such as course progress, skill-tree status, tutor session history, review outcomes, and mistake-book signals.
- Bundle and artifact metadata such as course versions, file hashes, upload/download timestamps, and operational logs needed for delivery and sync.
- Connection metadata such as IP address, user agent, request timing, and security logs.
How we use it
- Authenticate accounts and protect the service.
- Operate marketplace listings, enrollment approval, and approved course downloads.
- Provide personalized guidance, targeted practice, progress continuity, and mistake review.
- Support sync, abuse prevention, troubleshooting, and service operations.
Optional OpenAI Codex OAuth relay
- When you choose OpenAI Codex (ChatGPT OAuth), authorization happens with OpenAI in Chrome.
- Because browser CORS prevents the app from calling the ChatGPT Codex backend directly, the OpenAI access token and account ID, model-list requests, and tutor prompts/responses pass transiently through fixed authenticated routes at
api.tutor1on1.org. - The relay forwards this data only for the requested Codex operation and does not persist or log the OpenAI credentials, prompts, or responses; normal connection and security metadata may still be processed as described above.
- OpenAI receives the relayed request and handles it under the terms and privacy rules for the user’s OpenAI account.
What we do not do
- We do not sell personal data.
- We do not ask students or teachers to publish sensitive personal information in marketplace profiles or course content.
Retention and deletion
- Operational records are kept as needed to run the service, handle security, and support account/course workflows.
- Backups are kept on a rolling basis for up to 30 days.
- Users can delete their account in the app. Deletion disables login and starts removal of account, marketplace, enrollment, and related service records, subject to backup rotation.
- For privacy or deletion requests, email tutor1on1.org@gmail.com.
Children
Tutor1on1 may be used by minors. Students should not publish sensitive personal information, such as ID numbers or home addresses, in marketplace content or course materials. Guardians may contact us for account questions or deletion requests.