Tutor Chat
EN简中繁中日本VIIDKOTH

Effective date: 2026-08-16

Privacy Policy

How Tutor Chat collects, uses, and protects your data.We process data only as needed to provide accounts, security, AI learning, membership, and support. You can request access, correction, export, or deletion by email.
1. Who We Are2. Data We Collect3. How We Use Data4. AI and Third-Party Services5. Cookies and Local Storage6. Retention7. Your Rights8. Children9. International Processing and Security10. Changes

1. Who We Are

Tutor Chat provides English learning, AI tutoring, vocabulary context, grammar explanations, exam drill, writing, speaking, text summary, and related membership services across Web, iOS, macOS, and Android.

Privacy requests can be sent to xmf29202589@gmail.com. General support requests can be sent to xmf29202589@gmail.com.

2. Data We Collect

  • Account data: nickname, email, password hash when a password is set, login state, role, language, theme, and security tokens.
  • Verification and security data: email codes, password-recovery records, stable account identifiers and verified email supplied by Google or Apple, Passkey public keys and device labels, login time, session cookies, CSRF cookies, IP address, approximate country inferred from IP, device context, and basic logs. We do not receive a Google or Apple account password.
  • Learning data: study records, questions, answers, accuracy, chat messages, AI feedback, review history, word lists, grammar points, writing submissions, and text summaries.
  • Speech and video data: recordings, transcripts, speech features, user-submitted video links, subtitles, term occurrences, video/book materials, and notebooks.
  • Podcast data: Podcast Index search terms and directory identifiers, publisher RSS URLs and metadata, subscriptions, episode playback position, transcript candidates, learning materials, and term timestamps. Ordinary listening does not permanently copy audio to our servers.
  • Membership data: Apple in-app purchase or manual activation products, plans, transaction identifiers, status, purchase/expiry/revocation dates, and validation results.
  • Bring Your Own Key (BYOK) data: API provider, connection label, model identifier, service URL, verification status, capability information, and the encrypted API key. We do not return the complete key to a client after it is saved.

3. How We Use Data

  • Create and protect accounts, restore sessions, prevent abuse, block unauthorized access, and assist initial interface-language selection.
  • Generate learning content, AI explanations, personalized review, speaking/writing feedback, and progress tracking.
  • Process membership access, subscription status, payment confirmation, support, and administrator actions.
  • Maintain product reliability, diagnose errors, improve learning workflows, and comply with legal obligations.

4. AI and Third-Party Services

When you choose Google or Apple sign-in, that provider sends us a signed identity credential, a stable account identifier, and any verified email or name you authorize it to share. We do not store Google access or refresh tokens. An Apple authorization credential is encrypted server-side only so authorization can be revoked when you unlink or delete the account. Your device or credential provider keeps each Passkey private key; we store only the public key and non-sensitive device information needed for verification.

To generate explanations, feedback, transcription, speech, or learning materials, we may send necessary content to configured AI, speech, email, payment, hosting, and database providers, such as OpenAI, DeepSeek, Qwen/Tongyi-related services, Apple App Store, email providers, YouTube, Bilibili, or equivalent providers. Podcast searches send the query to Podcast Index; show, episode, artwork, audio, and official transcript data come from publisher RSS feeds or external hosts linked by those feeds.

Podcast playback normally connects to the publisher audio URL and may use our controlled proxy after a direct playback failure. We download and submit podcast audio to a configured transcription provider only after you request a learning material and confirm any required ASR quota. Temporary audio caches are removed under the retention period shown in the product.

YouTube browsing and playback use the YouTube website and official embedded player. We attempt to create learning material only after you tap Enter Vocabulary Context Room. If ASR has been approved and enabled, temporary audio needed for processing is isolated and deleted promptly after processing completes.

When you select your own model, we decrypt the corresponding key on the server only for that request and send the prompts, chat content, and related learning data needed for the task to your selected API provider. That provider processes data and bills usage under its own terms, privacy policy, and account settings.

The initial BYOK release enables LLM profiles only. Separate ASR, TTS, and speech-evaluation profiles are reserved for a future release. Until those entries are enabled, voice features continue to use our configured system services, and we do not collect voice API keys merely because the data model reserves them.

We do not sell personal data. Providers may process data only as needed for service delivery, security, compliance, and support.

YouTube Terms of ServiceGoogle Privacy PolicyApple Privacy Policy

5. Cookies and Local Storage

The Web product uses login cookies, refresh cookies, CSRF cookies, a restricted legal-session cookie, interface language cookies, and local storage for language and theme preferences. These are used for login, security, legal confirmation, and interface preferences, not for sale or cross-site advertising.

The YouTube page in the iOS App uses persistent cookies in the system WKWebView so you may sign in to YouTube and keep that session across pages and launches. Tutor Chat does not read, export, upload, or store your Google username, password, credentials, or cookie contents. You can clear YouTube/Google website data from the App's YouTube page.

6. Retention

Account and learning records are generally kept until the account is deleted, you request deletion, or the service no longer needs them. Transaction, tax, security, and audit records may be retained as required by law, platform rules, and dispute handling.

When you delete a BYOK connection, we delete its stored encrypted credential and model profiles. Non-secret event records required by law or security audit may be retained. Existing sessions locked to that connection can no longer continue with that model.

7. Your Rights

You may manage login methods and sessions under Login & Devices, or request access, correction, export, or deletion by emailing xmf29202589@gmail.com. If you decline updated terms, the product leaves only sign-out, data-export, and account-deletion actions available. Email requests should include your account email or nickname and the requested scope; we will verify the request and respond within a reasonable period.

If your location grants additional rights, such as objection, restriction, or withdrawal of consent, we will handle those requests under applicable law.

8. Children

The product is not directed to children under 13. If you believe a child provided personal data without guardian consent, contact us so we can delete the relevant information.

9. International Processing and Security

Data may be processed outside your location depending on our providers and infrastructure. We use reasonable technical and organizational safeguards, but no system can guarantee absolute security.

10. Changes

We may update this policy as the product, law, or providers change. Material changes may be communicated through in-product notices, webpage updates, or other reasonable methods.

Contactxmf29202589@gmail.comxmf29202589@gmail.com
Related document: Terms of Service
Back to Home