Home/Legal/Privacy

Privacy Policy.

Version 1.6Last updated 29 August 2026

A quick summary for younger learners. PocketTutor is a tutor that uses AI to help you learn. Here's what you should know about how it handles your information:

  • We need an account owner's name and email so you can sign in. Normally an adult will provide their details as part of the sign-up process.
  • When you ask PocketTutor a question, it goes to a few AI services to help create the answer. They don't keep your questions to train their AI models.
  • We keep your chat history, quiz results, and study plans so PocketTutor remembers how you're going. A parent or carer can delete all of this whenever they want - if you want your data to be deleted, just ask a parent or contact us in the app.
  • If you turn on study reminders, we can send a notification to your device. You can turn these off whenever you like.
  • Some of your information is stored in other countries (mostly the United States), because some companies that PocketTutor uses are based there.

The full policy below explains all of this in much more detail. Some of the wording is a bit more advanced, so ask a parent to help you with this if you're keen to learn more.

01

Introduction

PocketTutor is operated by PocketTutor Australia Pty Ltd (ABN 39 698 457 331), the entity responsible for handling your personal information. We are committed to protecting your personal information and handling it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what information we collect, how we use it, who we share it with, where it is stored, and the choices you have.

02

Information we collect

  • Account information. Your name and email address, captured when you sign up. Authentication is handled by our identity provider (see "Sharing your information" below).
  • Payment information. If you subscribe to a paid plan on our website, your billing details are collected and processed by our payment provider. If you subscribe inside the PocketTutor app on an iOS or Android device, the purchase is handled by Apple's or Google's own in-app purchase system under their terms and privacy policies, and all we receive is a record that a subscription is active and which plan it is. Either way, we do not store credit-card numbers on our servers.
  • Learning activity. Topics you explore, conversation history with the tutor, quiz answers and results, study-plan goals and progress, calendar events, and any documents you upload to use with the tutor.
  • Technical information. IP address, browser type, device characteristics, and other diagnostic data collected automatically when you use the service.
  • Usage analytics. Pseudonymous information about how the app is used, collected via our analytics provider - page paths, event names, and categorical or numeric properties (such as subject codes or quiz scores). This does not include your name, email, or anything a learner types.
  • Local device storage. Preferences (theme, sidebar state) and short-lived session data stored in your browser.
  • Notification data. If you turn on study reminders, we store the push subscription your browser generates, or - in the PocketTutor app - the anonymous device identifier Apple or Google issues for that install, so we can deliver the notifications you've opted into. It carries no learning content, and you can turn reminders off at any time.
  • Referrals. If you invite another person with a referral link, we record that their account joined through your link, along with the dates and status of any reward earned.
  • We also record actions you take in the app, including any feedback you give us about the AI's responses and your acceptance of age and policy requirements at signup.
03

How we use your information

We use your information to:

  • Provide the tutoring service: generate personalised responses, quizzes, study plans, and feedback.
  • Manage your account, including authentication and subscription status.
  • Process payments through our payment provider, or - for a subscription bought inside the app - through Apple's or Google's in-app purchase system.
  • Send essential administrative communications (e.g. account, billing, or service updates).
  • Send parents / account owners a weekly email about their learners' progress so they can support their learning.
  • Enforce rate limits and prevent abuse.
  • Understand how the service is used and measure the effectiveness of our advertising, so we can improve PocketTutor and reach families who would benefit from it.
04

Sharing your information

We share data with the following third-party providers, each bound by contractual privacy obligations:

Clerk Authentication & identity · United States
Email, name, password hash, session tokens. If you choose to sign in with Google, Apple or Facebook rather than a password, Clerk hands you to that provider to sign in and receives back your name and email address.
Stripe Payment & subscription management · United States, Australia
Payment details (handled directly by Stripe - never stored on our servers), email, billing country.
RevenueCat Subscription management for purchases made inside the PocketTutor app · United States
If you subscribe inside the app on an iOS or Android device, an anonymous account identifier plus the store's own purchase record - which plan you bought, when it started and expires, which store it came from, and the country of that store account. Apple or Google take the payment, and RevenueCat reads the resulting receipt so we know whether a subscription is active.
Vercel Hosting, database, blob storage · United States, European Union
All application data.
OpenAI AI tutoring responses, content moderation, image generation, transcription, and content-matching (embeddings) · United States
Topic, conversation context, uploaded document text, learner age band (a number, not a date of birth). Inputs are not used to train OpenAI's models on our paid API tier.
Anthropic Diagram generation (Mermaid / SVG) · United States
Diagram subject strings only.
Deepgram Voice input (speech-to-text) and audio narration (text-to-speech) · United States
For voice input, a learner's spoken audio when they choose to dictate a question or answer using the microphone - available to every signed-in learner. For narration, short paragraphs of generated tutoring text. Audio and transcripts are processed transiently and are not used to train Deepgram's models.
Resend Transactional emails · United States
Your email address and the emails we send you, such as sign-in codes, our replies to your help requests and weekly progress summaries.
Sentry Error monitoring and safety/feedback review · United States
Sanitised error events (request bodies for AI routes are stripped; emails are redacted), plus your sanitised feedback comments when you rate a response.
Mixpanel Product usage analytics · United States
Pseudonymous usage events tied to the account, not the individual child profile: page paths, event names, and categorical or numeric properties only (such as subject codes, quiz scores, subscription state). No name, email, or learner-typed content.
Google Advertising conversion measurement (Google Ads) on our marketing website and the web app · United States
Click identifiers (such as gclid), first-party measurement cookies (such as _gcl_aw), IP address, and basic browser metadata. Used to measure whether visits from our advertising lead to signups.
Meta Advertising conversion measurement and audience building (Meta Pixel and Conversions API, for Facebook and Instagram ads) on our marketing website and the web app · United States
From your browser: page paths, IP address, and basic browser metadata, plus Meta's own cookies and any click identifier carried across from an ad. When an account is created we also send Meta one server-side record of that signup, so the same signup is not counted twice and can still be measured if the browser tag is blocked. That record contains a one-way scrambled (hashed) form of the registration email address and of the internal account number, together with the IP address, browser details and Meta's own cookies from the browser that registered. The hashing is done before anything is sent, and it is one-way: Meta uses it only to check against accounts it already holds. We never send a child's name, age, year level, school, subjects, questions, uploaded work, results, or anything else about their learning. Used to measure whether visits from our advertising lead to signups, and to build advertising audiences.
Browser push services Study-reminder delivery in a web browser, via your browser's own push service (Apple, Google, Mozilla, Microsoft) · United States
If you turn on study reminders, an anonymous push subscription (an endpoint your browser generates) and the notification itself - a short title and message only, with no learning content. Used solely to deliver reminders you have opted into; the message is encrypted so the delivery service cannot read it, and we hold no account with these services.
Apple and Google notification services Study-reminder delivery in the PocketTutor app (Apple Push Notification service, Firebase Cloud Messaging) · United States
If you turn on study reminders in the app, an anonymous device identifier for that install and the notification itself - a short title and message only. Unlike the browser push above, an app notification is not encrypted end-to-end, so Apple or Google can read the short title and message they deliver on our behalf. It is used solely to deliver reminders you have opted into.

If you choose to invite another person via a referral link, the invitation page shows your first name so that they know who the invitation is from. You can turn that off in your account, and the page then says "A friend" instead.

05

How we keep AI tutoring safe

We mitigate risks related to AI-generated content in several layered ways, including:

  • Crisis routing. If a learner's message suggests distress, self-harm, suicide, abuse, an eating disorder, or bullying, PocketTutor immediately shows the learner an appropriate response with details on how to access support, such as Kids Helpline (1800 55 1800), Lifeline (13 11 14), 1800 RESPECT, Butterfly Foundation, and the eSafety Commissioner, and signposts them to talk to a trusted adult.
  • Content filtering. Learner messages are checked by a content-moderation service against categories that indicate inappropriate content before they reach the tutor. If a message is flagged, the tutor declines to respond.
  • Age-appropriate output. The tutor is calibrated to the learner's year level. It is instructed not to produce inappropriate content.
  • Reporting. Every AI response carries a thumbs-down with an "Inappropriate" category. Any reports are reviewed by our team.
06

Children (under 13) and parents

Signing up

PocketTutor is built for Australian learners in Foundation through Year 12. At signup we ask which year level the learner is in:

  • If the chosen year is Foundation–Year 6, the learner cannot create their own account. We direct them to a parent or carer who can set up a household account and add the child as a learner profile.
  • If the chosen year is 7 or 8 (where students may be either side of 13), we require the learner to confirm they are 13 or older before continuing. We record the date and time of that confirmation as compliance evidence.
  • From Year 9 onwards the standard signup applies.

Parent or carer control

When a household account is set up, the parent or carer is the consenting party. They can:

  • Add or remove learner profiles for their children.
  • Set a PIN on each learner profile so the child can use the app independently.
  • Remove the PIN at any time and sign in as the child to review all chat history, quiz results, and any feedback the child has filed.
  • Delete a learner profile at any time, which permanently and immediately removes all of that learner's data.
  • Set a topic blocklist for each learner profile.

Changing who holds the account

If a learner created their own account and later wants a parent or carer to take it over, they can invite that adult to become the account holder. Nothing changes unless the adult accepts the invitation.

When they do:

  • The learner keeps their profile and everything in it - chat history, progress, flashcards and study plan. It moves across to the new account holder's account. Nothing is deleted.
  • The adult becomes the consenting party for that household, with the same abilities set out above - including billing, learner profiles, PINs and topic blocklists.
  • We email the learner at each step, including when the transfer completes. Those emails show the receiving address only in a partly hidden form.
  • We keep an internal record of each step: the date, what happened, and a partly hidden email address.

A learner who receives one of those emails and did not ask for the transfer can tell us using the link in the email.

07

Cookies, analytics & advertising

Strictly necessary storage. We use cookies and browser local storage that are essential to keep you signed in and to remember your preferences (such as theme and sidebar state).

Analytics. We use a product-analytics service (Mixpanel) to understand how the app is used, in a pseudonymous form (see the table above). This helps us improve the service.

Advertising. On our marketing website (getpockettutor.com.au) and in the web app (app.pockettutor.io) we load two advertising tags. Google's advertising tag sets first-party measurement cookies to record that you arrived from one of our Google Ads and to attribute whether that visit led to a signup. Meta's Pixel sets Meta's own cookies and reports pages visited to Meta. Neither tag is loaded in the PocketTutor mobile apps.

Measuring signups with Meta. When a new account is created we send Meta a matching record of that signup from our own servers as well as from the browser, so one signup is counted once even when the browser tag is blocked. What that record contains, and what it never contains, is set out in the Meta row of the table above.

08

International transfers

Some of our processors are based outside Australia (see the table above for the country of each). When we share your data with them, it leaves Australian jurisdiction.

09

How long we keep your information

We keep your account and learning data for as long as your account is active, so PocketTutor can remember your progress over time.

  • A parent or carer can delete a learner profile at any time. This permanently and immediately removes that learner's chat history, quiz results, study plans, and related data.
  • To close an entire household account, or to request a copy of the data we hold about you or a household member, contact us at hello@getpockettutor.com.au and we will action your request.
  • If a learner transfers their account to a parent or carer, we keep the record of that transfer, and the learner's original sign-in details, so that a transfer can still be checked or queried afterwards.
10

How we keep your information safe

We apply industry-standard security measures including encryption in transit, restricted access controls, and monitoring for unusual activity. Payment data is handled directly by our payment provider and never stored on our servers. No system is perfectly secure; if we become aware of a data breach affecting your personal information, we will notify you and the relevant authorities in line with the Privacy Act 1988 (Cth).

11

Your privacy rights

Under Australian privacy law you have the right to access the personal information we hold about you, correct it if it is inaccurate, and request that we delete it.

  • You can update most of your information directly in the app.
  • You (or a parent/carer) can delete individual learner profiles yourself in the app.
  • To close your whole account or request a copy of your data, email us at hello@getpockettutor.com.au and we will action it.

If you are not satisfied with how we have handled your information, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

12

Updates to this policy

When we make a material change to this policy - for example, when we add a new provider, change how long we keep your data, change where it is stored, or change how we handle children's data - we will show you a banner the next time you sign in and ask you to acknowledge the new version before continuing.

13

Contact us

For any privacy-related questions, contact us at hello@getpockettutor.com.au or via the Help & Feedback section in the app.