Legal

Privacy Policy

Tutora — The Four Stars

Effective Date: April 16, 2026 · Last Updated: May 12, 2026

The Four Stars ("Company," "we," "us," or "our") operates the Tutora mobile application and related services (collectively, the "Service"). Tutora is an educational platform that connects tutors with students, enabling classroom management, assignments, attendance tracking, resource sharing, and in-app messaging. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the practices described herein.

1. Information We Collect

a) Tutor Account Information. When you register as a tutor, we collect your name, email address, and authentication credentials. You may also sign in via Google Sign-In, in which case we receive your name, email, and Google account identifier. You may optionally provide a phone number and profile photo.

b) Student Account Information. When a tutor creates a student profile, we collect the student's name, and optionally their email address, phone number, guardian name, and guardian phone number. Students authenticate using a system-generated student code and PIN. Students may also sign in via phone number or Google Sign-In.

c) Classroom & Academic Data. We collect data related to classrooms (title, subject, grade, schedule), assignments (title, instructions, due dates, marks), assignment submissions, attendance records, grades, and shared resources uploaded by tutors or students.

d) Messages & Communications. Tutora provides in-app messaging between tutors and students, including one-on-one conversations and classroom group chats. We store message content, file attachments, and read status to deliver the messaging feature.

e) Files & Attachments. Tutors and students may upload files such as images, PDFs, and documents as assignment attachments, submissions, classroom resources, or chat attachments. These files are stored on our servers for as long as the associated content exists.

f) Device & Usage Data. We collect your device platform (iOS or Android), language preference, and theme preference (light or dark mode) to provide and improve the Service. We collect push notification tokens to deliver notifications.

g) Purchase Information. If you subscribe to a paid plan, payment transactions are processed by Apple App Store or Google Play Store. We receive subscription status and entitlement information but do not collect or store your payment card details.

h) Advertising Identifiers (Tutor Accounts Only). When you are signed in as a tutor, our advertising partner (Google AdMob) and its sub-processors may collect your mobile advertising identifier (Google Advertising ID on Android, IDFA on iOS), IP address, approximate (city-level) location derived from your IP, device information (model, OS version, language, time zone), and ad interaction events. We do not collect or share advertising identifiers from student accounts. See Section 12 for full details.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Authenticate your identity and manage your account
  • Enable tutors to create and manage classrooms, students, assignments, and resources
  • Facilitate communication between tutors and students via in-app messaging
  • Track attendance and academic progress
  • Deliver push notifications for messages, assignments, and classroom updates
  • Process and verify subscription purchases and enforce plan limits
  • Send transactional emails (password resets, email verification)
  • Serve advertisements to tutor accounts only (never to students), and measure ad performance and prevent ad fraud within tutor sessions
  • Improve, personalize, and expand the Service
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with legal obligations

3. Data Sharing & Third-Party Services

Except for advertising identifiers shared with our ad partner for tutor accounts (described in Section 12), we do not sell, rent, or trade your personal information. We share your data only with the following service providers who assist in operating the Service:

  • Google Firebase: Authentication, cloud database (Firestore), file storage (Cloud Storage), and push notifications (Firebase Cloud Messaging). Your data is processed on Google Cloud infrastructure.
  • Zoho Mail: Transactional emails such as password resets and email verification are sent via Zoho SMTP servers.
  • Google Sign-In: If you choose to sign in with Google, your authentication is handled by Google's OAuth 2.0 service.
  • Google AdMob (Tutor accounts only): Advertising identifiers and limited device data are shared with Google AdMob to serve advertisements within tutor-facing screens. Ads are never served to, and no ad identifiers are collected from, student accounts. See Section 12 for details.

We may also share data when:

  • Required by Law: When required by law, court order, or governmental authority.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.

4. How Tutors and Students See Each Other's Data

Tutora is designed so that tutors can manage their students and classrooms. As part of normal use:

  • Tutors can view student names, contact information, attendance records, assignment submissions, grades, and classroom activity.
  • Students can view their own grades, assignments, shared resources, and messages from their tutor.
  • Students in the same classroom may see each other's names in group chats.

5. Data Retention

  • Account data (profiles, classrooms, students) is retained for as long as your account is active.
  • Messages and chat history are retained for as long as the conversation exists.
  • Files and attachments are retained for as long as the associated assignment, resource, or conversation exists.
  • Activity logs are automatically deleted after 90 days.
  • Account deletion: You may request deletion of your account at any time. Upon deletion, your personal data will be permanently removed from our systems within 30 days.

6. Data Security

We implement industry-standard security measures to protect your data. All data is transmitted over encrypted connections (TLS/SSL). Authentication is managed through Firebase Auth, and student PINs are stored using one-way cryptographic hashing (bcrypt). File storage and database services are hosted on Google Cloud, which provides encryption at rest. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Permissions We Request

The Tutora app may request the following device permissions:

  • Camera: To take photos for profile pictures or file attachments.
  • Photo Library / Storage: To select images and files for upload.
  • Notifications: To deliver push notifications for messages, assignments, and classroom updates.
  • App Tracking (iOS, Tutors Only): On iOS, tutor accounts may see Apple's App Tracking Transparency prompt asking permission to use the IDFA for personalized advertising. You may decline; non-personalized ads will be shown instead. This prompt is never displayed for student accounts.

We do not request or access your location, contacts, calendar, or microphone. Approximate (city-level) location may be derived from your IP address by our ad partner when you are signed in as a tutor; this is not the same as device GPS location.

8. Your Rights & Choices

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data and account
  • Withdraw consent for data processing
  • Object to or restrict certain processing activities

To exercise any of these rights, use the "Delete Account" feature within the app or contact us at [email protected].

9. Children's Privacy

Tutora is an educational tool intended for use by tutors and their students. Students under the age of 18 should use the Service with the knowledge and consent of a parent, guardian, or their tutor. We do not knowingly collect personal information from children under 13 without parental or guardian consent. If we become aware that we have collected data from a child under 13 without appropriate consent, we will take steps to delete it promptly.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including countries where Google Cloud infrastructure is located. These countries may have different data protection laws. By using the Service, you consent to such transfers. We take appropriate safeguards to ensure your data remains protected in accordance with this Privacy Policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app or by email. The "Last Updated" date at the top indicates when the latest revisions were made. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

12. Advertising (Tutor Accounts Only)

Tutora displays third-party advertisements only to tutor accounts. We do not show advertisements to student accounts under any circumstance, and no advertising identifiers, ad-related cookies, or similar tracking technologies are loaded during student sessions.

a) Advertising Partner. We use Google AdMob, a service provided by Google LLC, to serve advertisements within tutor-facing screens of the app. Google and its third-party advertising partners (collectively, "ad partners") use cookies, software development kits (SDKs), web beacons, and similar tracking technologies to collect information about your interaction with ads.

b) Information Collected by Ad Partners. When you are signed in as a tutor, Google AdMob and its ad partners may collect or receive:

  • Your mobile advertising identifier (Google Advertising ID on Android, IDFA on iOS), where available
  • IP address and approximate (city-level) location derived from it
  • Device information (manufacturer, model, OS version, language, time zone, screen size, network type)
  • Ad-event data (impressions, clicks, conversions, viewability, time spent)
  • App-level signals (the fact that you are using Tutora, app version)

c) Personalized vs. Non-Personalized Ads. Depending on your jurisdiction and consent choices, Google AdMob may serve personalized ads (selected based on prior activity across apps and sites) or non-personalized ads (contextual only, based on the current app context and coarse geographic location). Non-personalized ads still use limited data such as IP address and ad-event signals to deliver and measure the ad.

d) Consent for Users in the EEA, UK, and Switzerland (GDPR). If you are located in the European Economic Area, the United Kingdom, or Switzerland, we use Google's User Messaging Platform (UMP), a Google-certified Consent Management Platform, to obtain your consent under the GDPR and the ePrivacy Directive before serving personalized ads or storing advertising identifiers on your device. You may withdraw or update your consent at any time from the in-app privacy settings, which will re-display the UMP consent form.

e) California Residents (CCPA / CPRA). Under the California Consumer Privacy Act (as amended by the CPRA), the disclosure of advertising identifiers and related signals to Google AdMob and its ad partners for cross-context behavioral advertising may be considered a "sale" or "sharing" of personal information. California residents have the right to opt out of such sharing. You may opt out by:

  • Emailing us at [email protected] to request that Google's Restricted Data Processing (RDP) be enabled for your traffic
  • Enabling "Limit Ad Tracking" or denying the App Tracking Transparency prompt on iOS
  • Enabling "Opt out of Ads Personalization" on Android

f) Apple App Tracking Transparency (iOS). On iOS, tutor accounts will see Apple's App Tracking Transparency prompt before the IDFA is accessed. If you decline, no IDFA is shared and Google AdMob will serve non-personalized ads only.

g) Children and Family Considerations. Tutora restricts advertisements to tutor accounts, which are represented to us as belonging to adults (18 or older). The app does not request ads, set advertising identifiers, or load any ad-related SDK code while a student account is signed in. Accordingly, Tutora does not knowingly serve advertisements to children, and ad requests made by the app are not directed to or designed for children.

h) Learn More and Opt Out. To learn how Google collects and uses information from apps that use its services, see Google's partner privacy policy at policies.google.com/technologies/partner-sites. You can manage your Google ad personalization settings at adssettings.google.com.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

The Four Stars
Email: [email protected]