Tutorito Privacy Policy

Effective: 30 September 2026

Tutorito is a personal language tutor you use through your own AI assistant. It keeps the record a private tutor would keep — what you have met, what you can do unaided, the mistakes you repeat — so each lesson starts where the last one ended. This page says what information Tutorito keeps, what it's used for, who can see it, and how to get rid of it. It's written to be read, not skimmed past.

The short version: we store your learning record so the service works, we don't run ads, we don't sell or share your data for advertising, and you can delete your account and your record yourself, immediately, from your account page.

What we store

Your account. Your email address. If you sign in with Google, we receive your email address and basic profile from Google (see "Signing in with Google" below). We never see or store a password — sign-in is a one-time emailed code, or Google.

Your learning record. This is the product, and it exists so your assistant can teach from it:

  • The languages you're learning, your native language, and how long you like a lesson to be.
  • Every word, meaning and grammar point you have met, and how well you know each one — a status, how often you produced it correctly, how often it slipped, and when it is due for review.
  • Each lesson's record, as your assistant reports it: the language, the kind of lesson, whether it was spoken or typed, how long it ran, which items you practised, the grade your assistant gave each one, the kind of mistake when there was one, and its short reason in its own words; the repeated mistakes it is tracking for you, and at the end of each lesson whether you showed each one corrected; and the lesson's plan, summary, headline and what to teach next, which your assistant writes.
  • Notes your assistant leaves when our word data was missing something it needed — the word or grammar point it looked for, and why.
  • Facts you tell your assistant about yourself that it chooses to keep for later lessons: why you're learning, what interests you, what bores you, how often you want to practise, which variety of the language you want, and whether you want accent marks graded.

What we don't store: the conversation. Tutorito never receives your chat. Your assistant reports what happened in a lesson in structured form plus short notes in its own words, which may quote a phrase you wrote when explaining a mistake. The lesson itself stays with your assistant.

Records of each request. For each request your assistant makes, we record which tool it called, what it sent and what we sent back, whether it worked, how long it took, and when. What it sent is the same lesson report described above; what we sent back is your record as the assistant read it. We keep these so we can reproduce a lesson when something went wrong. They are kept 60 days, then deleted.

Access tokens and connections. If you create a personal access token, we store only a cryptographic hash of it — the token itself is shown to you once and cannot be recovered by anyone, including us. When you connect an AI app, we keep a record of that connection: which app, when you approved it, when it was last used, and its access tokens, again stored only as hashes. We also note the identifier of each kind of AI app that has ever connected, without any link to you.

What we use it for

  • To teach you: handing your assistant your record so it can start each lesson where the last one ended, choose what to review, and practise your mistakes.
  • To keep the service working: we read the records of requests, and how each account is using the service (which languages, which tools, how often), to find and fix what is slow, failing, or teaching badly.
  • To improve the word data: each night, the notes assistants left about missing words and grammar points — labelled with a lesson number and a letter such as "learner B", never with your name or email — are reviewed with the help of an AI model (see "Who else touches your data"), and the gaps they reveal are filled.

That's the entire list. No advertising, no profiles for ad targeting, no selling of data, no sharing with data brokers, and we don't train AI models on your record. Tutorito sends you no email except the sign-in codes you request.

Your AI assistant

You talk to Tutorito through an assistant you choose (Claude, ChatGPT, or any compatible client), and that assistant does the teaching — Tutorito itself never calls an AI while you learn. When you connect an assistant and approve access, it can read and update your record on your behalf. Two things follow:

  • You decide who gets access, and you can revoke it at any time — disconnect Tutorito in the assistant's own settings, revoke any personal access tokens on your account page, or delete your account, which ends every connection at once.
  • What an assistant does with data it reads is governed by that assistant's own privacy policy, not this one. We show you, at the moment you approve access, where that access is going.

Signing in with Google

If you choose "Continue with Google", Google sends us a signed token identifying you: your email address, name, and basic profile. We use it only to sign you in — matching you to your Tutorito account by your verified email address, or creating an account if you're new. We use your email address and sign-in identity and nothing else from that profile; we request no access to your Gmail, Drive, contacts, or anything else, and we never share Google user data with anyone. Retention and deletion are the same as for the rest of your account: it lives until you delete your account, and deletion is described below. Tutorito's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Who else touches your data

We run on well-known providers, who process data on our behalf and under their own security terms:

  • Supabase — sign-in and our database (hosted in the United States, us-west-2).
  • Railway — runs the server (United States, US West).
  • Cloudflare R2 — encrypted-at-rest storage for nightly backups.
  • Resend — sends the sign-in code emails, and our own operational reports, which identify accounts only by a code, never by name or email address.
  • GitHub — runs our nightly maintenance and keeps its reports, including the notes about missing words described above, in a private repository.
  • Anthropic (Claude) — the AI model that reviews those notes each night.

The word data your assistant is taught from is our own copy of Wiktionary, kept on our server — no lookup leaves it. No one else. We don't embed analytics, ad scripts, or social-media trackers — the pages you load from Tutorito contain only our own code. Sign-in state is kept in your browser for the tab you signed in on, not in tracking cookies. We will disclose data if the law genuinely compels it, and we'll tell you unless we're legally barred from doing so.

Tracking and "Do Not Track"

We don't track you across other websites, and no other party collects information about your activity through Tutorito — our pages carry no advertising, analytics, or social-media scripts. Because there is no cross-site tracking here to switch off, Tutorito does not change its behaviour in response to your browser's "Do Not Track" signal: there is nothing for it to stop. California law asks every site to state both of those things plainly, so those are our answers.

How long we keep things, and how deletion works

Your record lives until you delete it. You can delete your account yourself, right now, on your account page — no email, no waiting, no "retention review". Deletion immediately and permanently removes your record, lessons, review schedule, records of your requests, tokens, connections, and login. Nightly backups exist so a disaster can't destroy everyone's data; each backup is kept 30 days, so deletion completes fully when the last backup containing your data expires — at most 30 days after you delete. Records of requests expire after 60 days on their own schedule even if you keep your account. The nightly maintenance reports keep the notes about missing words they reviewed, labelled by lesson number and letter rather than by your name or email, and are not removed when you delete your account.

Security

Everything travels over TLS. Access tokens are stored only as hashes. The database and backups are encrypted at rest by our providers. Our web pages run under a strict content-security policy that loads no third-party code. No system is perfect; if we learn of a breach affecting your data, we'll tell you what we know and what we're doing about it.

Your rights

Depending on where you live (GDPR, UK GDPR, CCPA and similar laws), you have rights to access, correct, export, and delete your personal data, and to object to or restrict some processing. Tutorito's plain summary: you can read your learning record any time — ask your connected assistant, it has access to all of it — and you can delete it, with your account, yourself. For anything else (a copy of the records of your requests, a portable copy, a correction you can't make in the product, or any privacy question), email [email protected] and we'll respond within 30 days. We don't sell personal data, so there is nothing to opt out of, and we will never treat you worse for exercising a privacy right. If you're in the EU/UK and believe we've fallen short, you can complain to your local data protection authority.

Children

Tutorito isn't directed at children under 13, and we don't knowingly collect their data. If you believe a child has an account, email us and we'll look into it.

Changes

If this policy changes in a way that matters — especially anything touching Google user data — the change lands on this page with a new effective date, and material changes get a notice on the site before they take effect.

Contact

[email protected] · Tutorito, qa.tutorito.ai