← Back to Home
Last Updated: June 18, 2026 | Version: 1.0.0 | Package: tuition_core
Privacy Policy
1. Introduction & Data Controller
Tuition Core Inc. ("we," "us," "our") operates the Tuition Core application (mobile, web, desktop). This Privacy Policy explains our practices regarding collection, use, storage, protection, and your rights regarding personal data.
By using Tuition Core, you consent to data practices described herein. If you do not agree, do not use the Service.
Data Controller: Tuition Core Inc. | Contact: privacy@tuitioncore.com
2. What Information We Collect
2.1 Account & Authentication Data
- Email Address: Required for login, password recovery, account notifications
- Password: Hashed with bcrypt; never stored in plain text
- Full Name: Display name in profiles, reports, class lists
- Date of Birth (optional): Age verification, reporting
- Profile Picture (optional): Avatar for social features, stored on Firebase Cloud Storage
- Phone Number (optional): Guardian contact, emergency notifications
- User Role(s): Student, Guardian, Admin, Super Admin designation(s)
- Institution/Organization (optional): School/tutoring center affiliation for reporting
2.2 Educational & Academic Data
- Exam Responses: All answers submitted during exams (stored indefinitely for archive)
- Exam Scores & Results: Numerical scores, pass/fail status, percentile rankings
- Question-Level Performance: Correct/incorrect flags, time spent per question
- Attendance Records: Class attendance (present/absent/excused), attendance percentage
- Assignment Data: Submissions, due dates, feedback comments, grades
- Progress Metrics: Learning milestones, achievement badges, skill assessments
- Study Materials: Downloaded resources, bookmarked content, search history
- Exam Metadata: Time taken, attempts, review history, shuffle seed (for consistency)
2.3 Subscription & Payment Data
- Payment Method: Credit/debit card info (processed by Stripe/PayPal, NOT stored by Tuition Core)
- Billing Address: For invoicing and PCI compliance verification
- Transaction History: Purchase date, amount, currency, payment status, transaction ID
- Subscription Plan: Current tier (Free/Starter/Pro/Expert/Premium), start/end dates
- Add-on Purchases: Extra students, exams, duration extensions, ad-free add-ons
- Renewal Status: Auto-renewal enabled/disabled, payment method failures
- Invoice Metadata: Invoice numbers, tax jurisdiction, receipt PDFs
2.4 Communication & Messaging Data
- Private Messages: All text sent via in-app chat (encrypted in transit)
- Message Metadata: Timestamp, sender, recipient, read status, attachments
- Support Tickets: Your communications with our support team, resolution history
- Email Communications: Newsletters, transactional emails, promotional content
- Notification Preferences: Which notifications you've opted in/out of
- Social Posts & Comments: Content you create on the feed, engagement metrics (likes, shares)
2.5 Device & Technical Data
- Device Information: OS type, OS version, device model, app version
- Device Identifier: Unique device ID (for multi-device session management)
- IP Address: Source IP, approximate geolocation (city-level, for analytics)
- Firebase Cloud Messaging Token: FCM token per device (for push notifications)
- Usage Analytics: Screens visited, features accessed, time spent per section
- Interaction Events: Button clicks, form submissions, exam starts/completions
- Crash Reports & Logs: Error messages, stack traces, app stability metrics
- Network Metrics: Connection type, latency, bandwidth (for performance optimization)
- Firebase Analytics: Session duration, user retention, conversion funnels
2.6 Google Drive Integration Data
- Google Account Email: Associated with your Google Drive authorization
- File Metadata: File names, sizes, modification dates, file paths in Drive
- MD5 Checksums: Hashes for file deduplication and integrity checking
- Upload/Download History: Which files synced when, sync success/failure logs
- Storage Quota: Your Google Drive storage usage
- Google Authorization Token: Refresh token for persistent access (encrypted in Firestore)
2.7 Advertising Data (via Google AdMob)
- Ad Impressions: Which ads you viewed, placement, timestamp
- Ad Engagement: Clicks on ads, rewarded video completions
- Advertising ID: Google Advertising ID (AAID/IDFA) for ad targeting
- Behavioral Targeting: Inferred interests based on app usage (managed by Google)
3. How We Use Your Information
3.1 Service Delivery & Core Functionality
- Creating and maintaining your account and user profile
- Authenticating login and managing multi-device sessions
- Delivering exams, storing answers, calculating scores
- Managing student rosters with subscription-based limits (e.g., "30 students max on Starter plan")
- Enabling messaging and social feed features
- Tracking attendance, assignments, and progress
- Processing subscription payments and managing billing
- Syncing data across your devices
- Providing Google Drive file upload/download functionality
3.2 Personalization & User Experience
- Customizing dashboards and UI based on your role (Student/Guardian/Admin)
- Remembering preferences (notification settings, theme, language)
- Recommending content based on exam performance and learning patterns
- Suggesting peers for group discussions or study circles
- Showing relevant ads based on subscription tier
3.3 Analytics, Insights & Improvement
- Generating student progress reports and performance analytics
- Creating admin statistics dashboards (student counts, exam trends, payment analysis)
- Analyzing app usage to identify popular features
- Measuring user engagement and retention for product improvements
- A/B testing new features with anonymized user cohorts
- Aggregating anonymized data for industry benchmarking
3.4 Communications & Notifications
- Sending transactional emails (registration confirmation, password reset, receipts)
- Delivering push notifications (exam reminders, grade updates, class announcements)
- Sending subscription renewal reminders and expiry warnings
- Notifying admins of new student requests or exam submissions
- Sending newsletters and feature announcements (if opted in)
- Alerting guardians of student attendance or grade changes
3.5 Security, Compliance & Legal
- Detecting and preventing fraud (payment fraud, account takeover, cheating)
- Ensuring account security and preventing unauthorized access
- Logging suspicious activity for security audits
- Complying with legal obligations (court orders, law enforcement requests, tax reporting)
- Enforcing Terms & Conditions and resolving disputes
- Protecting intellectual property rights
3.6 Marketing & Engagement
- Sending promotional emails (new features, special offers, plan upgrades) — you may opt out
- Conducting surveys and collecting feedback
- Retargeting users on social media platforms (Facebook, Instagram) if consented
- Measuring ad campaign effectiveness
4. Data Storage & Security
4.1 Where We Store Data
- Cloud Infrastructure: Google Firebase & Google Cloud (primary)
- Database: Cloud Firestore with encryption-at-rest
- File Storage: Firebase Cloud Storage (exams, profiles, backups)
- Local Device Cache: Hive encrypted key-value store (settings, offline access)
- Geographic Region: Primary servers in United States; redundancy across multiple regions
4.2 Data Retention Periods
- Active Accounts: All data retained indefinitely during active subscription/Free Plan use
- Upon Account Deletion: Data marked for deletion, permanently removed after 30 days (except legally mandated retention)
- Exam Archives: Exam submissions and scores retained indefinitely for academic records
- Payment Records: Retained 7 years for tax and legal compliance
- Server Logs: Retained 30 days for security and debugging purposes
- Backup Copies: Retained 90 days for disaster recovery (then permanently deleted)
4.3 Security Measures
- Data Encryption in Transit: TLS 1.3 for all API communications (HTTPS)
- Data Encryption at Rest: AES-256 encryption on Firebase and Cloud Storage
- < Password Security: bcrypt with salt factor ≥12
- Local Device Storage: Hive encryption for sensitive cached data
- Access Controls: Role-based access control (RBAC); admins cannot access student passwords
- Multi-Factor Authentication: Optional 2FA available for high-risk accounts
- API Security: Rate limiting, input validation, CORS restrictions
- Regular Security Audits: Quarterly penetration testing, vulnerability scanning
- Incident Response: Security breach notification within 72 hours (if applicable law requires)
4.4 Your Responsibility
You are responsible for:
- Keeping your password confidential and changing it regularly
- Logging out on shared/public devices
- Reviewing FCM tokens for unauthorized devices
- Monitoring your subscription payment method for fraud
- Reporting suspected breaches immediately to privacy@tuitioncore.com
5. Third-Party Services & Data Sharing
5.1 Firebase & Google Cloud
Data is processed on Google infrastructure per Google's Privacy Policy. Google may use data aggregates for service improvement and Google product recommendations. You are subject to Google's Data Processing Agreement.
5.2 Google Drive API
When you authorize Google Drive sync, we request scope: drive.file (specific file access only). We do NOT request:
- drive.appData (hidden app files)
- drive (full Drive access)
- openid (OAuth identity)
Revoke access anytime at myaccount.google.com/permissions.
5.3 Payment Processors (Stripe, PayPal)
Credit card data is processed directly by Stripe/PayPal, NOT stored by Tuition Core. We only store:
- Last 4 digits of card
- Card type (Visa, Mastercard)
- Expiry month/year
- Billing address
Tuition Core maintains PCI DSS Level 1 compliance via payment processor.
5.4 Firebase Cloud Messaging (FCM)
FCM tokens are stored securely in Firestore and used exclusively for push notifications. Tokens are never sold or shared. You may view registered devices in Account Settings and revoke tokens anytime.
5.5 Google Analytics & Firebase Analytics
Usage data is sent to Google Analytics 4 and Firebase Analytics for aggregated insights. Firebase does NOT collect personally identifiable information (emails, user IDs linked to names). Data is anonymized at collection. You may opt out via device settings ("Share device analytics").
5.6 Google AdMob
Ad platforms (AdMob, Google Ad Manager) collect:
- Advertising ID (AAID on Android, IDFA on iOS)
- IP address
- Browser user-agent
- General location (country/region)
This is governed by Google's Advertising Policies. Manage ad preferences at adssettings.google.com.
5.7 Data Sharing Policy
We DO NOT sell your personal data to third parties. We share data only:
- Service Providers: With vendors necessary to operate Tuition Core (Firebase, Stripe, Google, SendGrid) under Data Processing Agreements requiring confidentiality and security
- Your Consent: With third parties you explicitly authorize (e.g., "Share results with [Institution]")
- Legal Requirement: With law enforcement/government upon court order, subpoena, or legal obligation
- Fraud Prevention: With fraud detection services to prevent financial crimes
- Business Transfer: In case of merger, acquisition, or asset sale, we will notify you and provide opt-out opportunity before data transfers
6. Your Privacy Rights & Choices
6.1 Right to Access
You have the right to access your personal data in a structured, commonly-used format. Submit a request to privacy@tuitioncore.com with:
- Your full name and email
- Proof of identity (copy of government ID)
We will respond within 30 days with a downloadable data export (JSON/CSV format).
6.2 Right to Correct
You may correct inaccurate data anytime via Account Settings or by contacting privacy@tuitioncore.com. We will correct inaccuracies within 15 business days.
6.3 Right to Delete (Right to be Forgotten)
You may request deletion of your account and all associated data. Process:
- Account Settings > Delete Account > Confirm
- Or email privacy@tuitioncore.com with deletion request
- Data marked for deletion; permanently removed after 30 days (unless legally required to retain)
- Backup copies deleted within 90 days
Exceptions: Exam archives and payment records may be retained if required by law or institutional policy.
6.4 Right to Data Portability
You may request your data in machine-readable format (JSON, CSV). Email privacy@tuitioncore.com to export:
- Account profile data
- Exam submissions and scores
- Attendance and grades
- Messages and posts
6.5 Right to Restrict Processing
You may restrict how we use your data (e.g., "Don't use for analytics" or "Don't send marketing emails"). Email privacy@tuitioncore.com with specifics. We will honor reasonable restrictions without affecting core functionality.
6.6 Right to Withdraw Consent
For optional data (marketing emails, analytics), you may opt out anytime:
- Email Unsubscribe: Click "Unsubscribe" link in any marketing email
- Push Notifications: Disable per device in Account Settings or OS notification preferences
- Advertising Tracking: Disable "Share Device Analytics" in OS settings
- Google Drive Sync: Revoke access in Google Account Settings
6.7 GDPR Rights (EU Residents)
If you are in the European Union, you have additional rights under GDPR:
- Right to object to automated decision-making (we don't use AI for high-impact decisions)
- Right to lodge a complaint with your data protection authority
- Right to data transfer to another provider
Our Data Protection Officer: dpo@tuitioncore.com
6.8 CCPA Rights (California Residents)
If you are a California resident, you have rights under CCPA:
- Right to know what personal data we collect, use, share
- Right to delete personal data (with limited exceptions)
- Right to opt-out of sale/sharing of data (we don't sell data)
- Right to non-discrimination for exercising CCPA rights
7. Children's Privacy (COPPA)
Tuition Core is intended for users 13+ years. We do not knowingly collect data from children under 13.
For students under 18:
- Parents/guardians may monitor student activity via Guardian role
- Parents may request data access or deletion at any time
- We comply with COPPA and applicable children's privacy laws
- If we discover a user is under 13, we immediately delete their account and notify parents
8. Notifications & Communications
8.1 Notification Types
- Transactional (Required): Registration, password reset, payment confirmations, exam invites
- Educational (Opt-in by role): Grade updates, class reminders, assignment due dates
- Administrative: Subscription renewal reminders, payment failures, security alerts
- Marketing (Opt-out available): New features, promotional offers, newsletters
8.2 Managing Preferences
- In-App: Account Settings > Notifications > toggle per notification type
- Email: "Unsubscribe" link at bottom of emails
- Device: OS Settings > Apps > Tuition Core > Notifications
8.3 Multi-Device Notifications
Each device stores its own FCM token. Notifications sent to ALL active devices unless you disable them per device. View registered devices in Account Settings > Devices.
9. Advertising & Ad Personalization
9.0 Website Advertising (Adsterra)
On tuitioncore.com, ads are served by Adsterra. Adsterra and its partners may collect and process your IP address, browser/device information, and cookie or similar identifiers to serve and measure ads, in accordance with Adsterra's Privacy Policy. You can review or manage ad personalization settings via your browser's cookie and privacy controls.
9.1 Ad Types
- Banner Ads: 320×50 or 320×100 in-app placements
- Interstitial Ads: Full-screen ads between screens (dismissible)
- Rewarded Ads: Optional video ads in exchange for in-app rewards (you can skip)
9.2 When Ads Appear
- Free Plan: Ads enabled
- Paid Plans (Starter/Pro/Expert): Ads enabled unless ad-free add-on purchased
- Premium Plan: Ad-free by default
- Yearly Billing: Ad-free for billing period
9.3 Ad Personalization & Your Choices
Google AdMob uses your Advertising ID (AAID/IDFA) for interest-based targeting. You may:
- Android: Settings > Google > Manage your Google Account > Data & Privacy > Ad settings
- iOS: Settings > Privacy > Apple Advertising > Personalized Ads (toggle off)
- Web: Visit adssettings.google.com
Opting out doesn't eliminate ads; it only makes them non-personalized.
10. Updates to Privacy Policy
We may update this Privacy Policy. Changes take effect immediately upon posting to the Service. Material changes will be announced via:
- Email notification to your registered address
- In-app alert on login
- Prominent banner on the website
Continued use after notice constitutes acceptance of updated policies.
11. Contact & Support
For privacy questions or requests:
Data Protection Contact:
Email: privacy@tuitioncore.com
Support: support@tuitioncore.com
Website: tuitioncore.com
Package: tuition_core (v1.0.0)
Response Time: 7-10 business days
Data Protection Officer (GDPR/CCPA):
Email: dpo@tuitioncore.com
Regulatory Complaints:
If unsatisfied with our response, you may lodge a complaint with your local data protection authority (EU: relevant DPA; US CA: California Attorney General).