Skip to content
Draft, pending counsel review. Version 2026-09-04-draft. This text is not in force until counsel review is recorded.

Privacy policy

What Natural Tutor collects, from whom, why, who receives it, how long it is kept, and how to review, export, delete, or revoke.

1. Who we are and what this covers

Natural Tutor is operated by the company named on the pricing page. The operator’s registered name, address, and telephone number are not yet published here; they will be, before any profile for a learner under 13 is allowed to collect anything.

This policy covers the website, the tutor sessions, the learner and parent dashboards, and any email we send. It is written for parents first, because a learner under 18 uses the service only through a profile that an adult account holder created and controls.

2. What we collect

From the account holder (a parent, or an adult learning for themselves)

  • Email address, display name, and a password hash. Passwords are never stored in clear text.
  • A sign-in session token hash and its expiry, so you stay signed in and can sign out everywhere.
  • Birth year for an adult who signs up for themselves — a neutral age screen. The year is not shown to anyone else.
  • Subscription status, plan, period, minute counters, and a Stripe customer id. Card details go to Stripe directly and we never see your full card number.
  • Consent records: which notice and policy version you agreed to, when, by which method, whether the camera was included, and when you revoked.
  • Deletion requests: ids and timestamps, so we can show a right was exercised.
  • Your settings: camera sensing on or off, which attention-recovery steps you switched off, and your email preference.

From and about a learner profile

  • Display name, birth year, and the age band derived from it. For a teen, a login name and password hash.
  • Every turn of a session as text: what the learner says or types, what the tutor says, what is drawn on the whiteboard, check questions and answers, and the session summary.
  • Problems the learner uploads. We keep the text we read out of a photo or PDF, on the coursework item. We do not keep the image or the PDF — the file is held in memory only for as long as it takes to read it. The file itself is sent to the model provider that reads it, as listed in section 6.
  • A per-skill progress estimate, open and resolved misconception tags, a short profile of which explanations worked, and an append-only record of the evidence behind each progress claim.
  • Session timing, minutes used, and the estimated cost of each turn, for metering and the plan cap.
  • Reports made with the report button, including any note you or the learner typed, and the record that a person reviewed it.
  • Per-session attention aggregates — an attention percentage and counts of drifts, aways, and recoveries — from signals such as whether the tab is in front and whether anyone has answered. See section 4 on the camera.

What we never collect anywhere: no audio file, no camera image, no face landmark, no facial embedding or template, no voiceprint or other biometric identifier, no precise location, no contact list, and no advertising identifier. No table in our database has a column for any of them.

3. Voice

The microphone is used only to answer what the learner is asking. The recording streams to our transcription provider, is turned into text, and is discarded. We do not store audio files, we do not use voice for identification, and we do not create voice prints or any other biometric identifier. Only the transcript is kept.

That is verified in our own systems: the clip is held in memory for one request, the only thing written is a count of seconds for metering, and neither the audio nor the transcript reaches a log line. What our transcription provider does with the clip after it arrives is governed by our contract with them, and that review is still in progress — see section 6.

4. Camera

The camera is not used. There is no camera feature in Natural Tutor today. Nothing in the product opens a camera, and the internal switch that would allow it is off.

If on-device attention sensing is ever built, we will describe it here before it is offered to anyone, and these conditions are fixed in advance. It would run entirely inside the browser: a face-landmark model would estimate whether the learner is looking at the lesson, and no image, landmark, embedding, or template would ever be transmitted or stored— not to our servers, not to a database, not to logs, analytics, or error reports. The only thing leaving the device would be a coarse state (attending, drifting, away, no face), and the only thing kept would be the per-session aggregate. A visible indicator would run whenever the camera was active. It would be named separately in the consent flow and never bundled with consent to use the service, a parent could switch it off at any time, and the tutor would still work without it. It would be off for ages 13 and over and for adults, and it would ship only after a children’s-privacy lawyer had reviewed it.

5. Why we use the data

  • To run the session: reply, draw, grade, summarise, and pick the next skill.
  • To remember across sessions what a learner struggled with, so the tutor does not start from zero.
  • To show the account holder transcripts and the progress report.
  • To meter minutes, enforce the plan and the cost ceilings, and bill.
  • To keep learners safe: safety rules in the tutor, the report button, and human review of flagged sessions.
  • To operate the service: persistent identifiers are used internally for security, metering, and error reports, and for nothing else.

We do not use any learner data to train models. We do not show ads, we do not use ad networks or ad software, and we do not track anyone across other sites. Analytics are first-party events with ids and counts, never content, and a learner under 18 is never given a tracking cookie or browser storage for analytics.

6. Who receives data

These providers process data for us. Our terms with each of them must permit minors’ data, prohibit training on our inputs, limit use to our purposes, and include data-processing terms. That review is not finished. It will be completed, and any provider that fails will be replaced, before any profile for a learner under 13 is allowed to collect anything.

RoleProviderWhat it receives
Language modelsGoogle (Gemini), Anthropic (Claude), and OpenAI, per the stage routing the operator configuresThe text of the session turn, the learner’s skill context, and — for reading an uploaded problem — the uploaded image or PDF itself. Used to produce the tutor’s reply, grade a check, and write the session summary.
Speech to textOpenAI (Whisper) by default; another configured provider if the operator routes it thereThe learner’s voice clip for one turn, to transcribe it. The clip is discarded after transcription.
Text to speechOpenAI by default; another configured provider if the operator routes it thereThe tutor’s sentence text, to produce the audio the learner hears. Never the learner’s words.
HostingVercelRuns the application and handles every request.
DatabaseNeon (Postgres)Stores accounts, profiles, transcripts, coursework text, checks, progress, consent records, and usage.
Product analyticsPostHog, a first-party projectEvent names with ids, counts, timings, age band, skill id, and misconception tag. No names, transcripts, audio, images, or session recordings.
Error reportsSentryA scrubbed message and stack with ids as tags. No request bodies, no breadcrumbs, no session replay.
PaymentsStripeCard details and billing address, entered on Stripe’s pages; we receive a customer id and the subscription status.

We do not disclose learner data to any other third party. If that ever changed, it would require its own separate opt-in consent, never bundled with the consent to use the service.

7. How long we keep it

Audio is never retained. Uploaded images and PDFs are never retained. Transcripts, checks, summaries, coursework text, and progress data are kept while the profile exists.

A written retention policy setting a maximum period after a profile’s last activity is in draft and is not yet in force; it will be published here, and running in the product, before any profile for a learner under 13 is allowed to collect anything. Until then, data is removed when you ask for it to be removed.

When you request a deletion, the profile is frozen immediately so nothing further is collected, and the data is erased after 30 days. The dashboard shows the date. Records of the deletion itself — ids and timestamps — are kept, as are billing amounts with the learner, session, and turn identifiers removed.

8. Your rights as a parent or account holder

  • Review: read every transcript and the progress data from the parent dashboard.
  • Export: download a learner’s data as a file, from the data page.
  • Delete: delete a learner profile or the whole account, from the data page. The profile freezes at once.
  • Refuse further collection: revoke consent from settings, which freezes the profile immediately. Revoking does not itself delete what already exists — use Delete for that.
  • A support path: write to the contact address published on the pricing page, and a person will answer.

We are still extending the export so that it covers every category in section 2; today it covers the profile, sessions, transcripts, progress, misconceptions, evidence, and consent records. Ask us and we will supply anything it does not yet include.

9. Children under 13

A profile for a child under 13 — which includes the 9-to-12 band — can be created now, and stays locked until the parental-consent flow is live and a children’s-privacy lawyer has signed off. A locked profile cannot start a session, and collects nothing beyond the name and birth year you entered.

When it opens: you receive a direct notice before anything is collected from your child; you give consent by an affirmative act tied to that notice’s version, followed by a verification step that satisfies the law’s requirements for verifiable parental consent; the microphone and the camera are named separately and neither is bundled; we collect only what the tutoring needs, and never condition your child’s use of the service on more; you can review, export, delete, and revoke at any time; and revoking freezes the profile.

10. Security

Data is encrypted in transit and at rest. Access is limited to what each person or system needs. Provider keys exist only on the server and never reach a browser. Every database query filters on the account that owns the row. Error reports are scrubbed of content before they are sent. A written security program covering key rotation, incident response, and vendor breach terms is in draft and will be in place before the under-13 gate opens. We will notify affected account holders of a breach as the law requires.

11. Where the data is

The service is hosted in the United States. If you use it from elsewhere, your data is transferred to and processed there.

12. Changes to this policy

Changes are posted here with a new version number. A consent record always names the version it was given for; a material change that affects a child’s data asks the parent again.

13. Contact

Questions, requests, and complaints about privacy: write to the contact address published on the pricing page. The label AI tutor inside a session is also a reminder that you are talking to software, and that this policy applies to what you say to it.