We share data with the following third-party providers, each bound by contractual privacy obligations:
- Clerk Authentication & identity · United States
- Email, name, password hash, session tokens. If you choose to sign in with Google, Apple or Facebook rather than a password, Clerk hands you to that provider to sign in and receives back your name and email address.
- Stripe Payment & subscription management · United States, Australia
- Payment details (handled directly by Stripe - never stored on our servers), email, billing country.
- RevenueCat Subscription management for purchases made inside the PocketTutor app · United States
- If you subscribe inside the app on an iOS or Android device, an anonymous account identifier plus the store's own purchase record - which plan you bought, when it started and expires, which store it came from, and the country of that store account. Apple or Google take the payment, and RevenueCat reads the resulting receipt so we know whether a subscription is active.
- Vercel Hosting, database, blob storage · United States, European Union
- All application data.
- OpenAI AI tutoring responses, content moderation, image generation, transcription, and content-matching (embeddings) · United States
- Topic, conversation context, uploaded document text, learner age band (a number, not a date of birth). Inputs are not used to train OpenAI's models on our paid API tier.
- Anthropic Diagram generation (Mermaid / SVG) · United States
- Diagram subject strings only.
- Deepgram Voice input (speech-to-text) and audio narration (text-to-speech) · United States
- For voice input, a learner's spoken audio when they choose to dictate a question or answer using the microphone - available to every signed-in learner. For narration, short paragraphs of generated tutoring text. Audio and transcripts are processed transiently and are not used to train Deepgram's models.
- Resend Transactional emails · United States
- Your email address and the emails we send you, such as sign-in codes, our replies to your help requests and weekly progress summaries.
- Sentry Error monitoring and safety/feedback review · United States
- Sanitised error events (request bodies for AI routes are stripped; emails are redacted), plus your sanitised feedback comments when you rate a response.
- Mixpanel Product usage analytics · United States
- Pseudonymous usage events tied to the account, not the individual child profile: page paths, event names, and categorical or numeric properties only (such as subject codes, quiz scores, subscription state). No name, email, or learner-typed content.
- Google Advertising conversion measurement (Google Ads) on our marketing website and the web app · United States
- Click identifiers (such as
gclid), first-party measurement cookies (such as _gcl_aw), IP address, and basic browser metadata. Used to measure whether visits from our advertising lead to signups. - Meta Advertising conversion measurement and audience building (Meta Pixel and Conversions API, for Facebook and Instagram ads) on our marketing website and the web app · United States
- From your browser: page paths, IP address, and basic browser metadata, plus Meta's own cookies and any click identifier carried across from an ad. When an account is created we also send Meta one server-side record of that signup, so the same signup is not counted twice and can still be measured if the browser tag is blocked. That record contains a one-way scrambled (hashed) form of the registration email address and of the internal account number, together with the IP address, browser details and Meta's own cookies from the browser that registered. The hashing is done before anything is sent, and it is one-way: Meta uses it only to check against accounts it already holds. We never send a child's name, age, year level, school, subjects, questions, uploaded work, results, or anything else about their learning. Used to measure whether visits from our advertising lead to signups, and to build advertising audiences.
- Browser push services Study-reminder delivery in a web browser, via your browser's own push service (Apple, Google, Mozilla, Microsoft) · United States
- If you turn on study reminders, an anonymous push subscription (an endpoint your browser generates) and the notification itself - a short title and message only, with no learning content. Used solely to deliver reminders you have opted into; the message is encrypted so the delivery service cannot read it, and we hold no account with these services.
- Apple and Google notification services Study-reminder delivery in the PocketTutor app (Apple Push Notification service, Firebase Cloud Messaging) · United States
- If you turn on study reminders in the app, an anonymous device identifier for that install and the notification itself - a short title and message only. Unlike the browser push above, an app notification is not encrypted end-to-end, so Apple or Google can read the short title and message they deliver on our behalf. It is used solely to deliver reminders you have opted into.
If you choose to invite another person via a referral link, the invitation page shows your first name so that they know who the invitation is from. You can turn that off in your account, and the page then says "A friend" instead.