Trust and standards
Your data
A description of what this product does with what you give it, written from how the system behaves rather than from a template.
What we collect
From a student, or a parent or guardian, at most:
- An email address, which is how you sign in.
- A name to show you as.
- Your age or date of birth, as you declared it.
- Your class and your board.
- Your locality — the neighbourhood, never a street address. We do not ask exactly where you live, and we do not store it.
- What you are trying to achieve, if you tell us.
- For an account under 18: the email address of the parent or guardian you nominated, and their name and relationship if you gave them.
Browsing and searching need none of this. If you never sign up, we hold no account for you.
Why we hold it
Consent is tied to a purpose, one purpose at a time. Signing up is not a licence to do whatever we like with what you gave us, and each of these is granted and withdrawn on its own.
- Running the service
Signing you in, keeping your account, and doing the thing you asked for. This one is not optional — without it there is no account.
- Precise location
Only if you switch it on, and only to sort by distance for in-person teaching. Off by default, and the site works without it.
- Sharing your contact details with a tutor
Your details reach a tutor when you send an enquiry, and not before. For a student under 18, the parent or guardian authorises it.
- Product updates by email or by SMS
Two separate choices, both off, and neither bundled into signing up. There is nowhere in the product to switch either on today — and nothing here sends SMS at all, so the second could not be delivered even if there were.
- Behavioural analytics
Building a picture of how you use the site. Adults only, and only where they have opted in. It is never applied to an account under 18 — not as a default you could change, but as a rule the database refuses to break.
We do count things — how many searches happened, how many enquiries were sent — for every kind of account, children’s included. Those counts are not tied to building a picture of a person, and the two kinds of measurement are kept apart structurally rather than by policy. The identifier that groups one visit together is rotated, and does not follow you from visit to visit.
Who can see it
- A tutor sees nothing about you until you send them an enquiry. There is no browsable list of students.
- When contact details are released to a tutor, the release is recorded: whose details, to whom, through which channel, and who authorised it.
- For a student under 18, the contactable person is the parent or guardian, not the child.
- Our own staff reach personal data through named roles, and the sensitive actions — releasing a contact, changing a verification state, publishing or suspending a profile, deleting an account — are written to a log that can be added to but not edited or deleted, not even by an administrator.
How long we keep it
- An unfinished signup, or one still waiting on a parent or guardian: deleted after 7 days, and used for nothing else in the meantime. Today that deletion is run by hand rather than on a timer.
- The record of how consent was given or withdrawn: kept for as long as the account exists. If a parent, or a regulator, asks how consent for a particular child was obtained, that record is the answer, and deleting it would leave us unable to give one.
- One-time codes and links, each with its own life: 10 minutes to enter a sign-in or consent code, 30 for a tutor application, 1 hour for a password reset, and 24 hours for the link that confirms an email address. Only a scrambled form is ever stored.