Privacy notice
The short version
- We collect what running the lessons needs, and not more.
- We do not sell data, and we do not share it for anybody else's advertising. Ever.
- Lessons are audio and a whiteboard. Nothing said in a lesson is recorded.
- You can download everything we hold about you, from Settings, in one click.
- You can have your account erased, from Settings, without asking anybody's permission.
- Analytics load only if you agree, and they are switched off entirely if you do not.
TeachCurve is the controller of the personal data described here. The rest of this page is the detail behind those six lines.
What we collect
When you create an account
- Your name, email address and password (stored only as a one-way hash — we cannot read it).
- Your date of birth, and the country and time zone you are in.
- For a student under 16: a parent or guardian's email address, and then their name and, if they give it, a phone number.
- For a tutor: the profile you write, your qualifications and experience, your photograph if you upload one, and the record of any vetting check.
As you use the platform
- Lessons booked, taught, cancelled and missed, and who was in each one.
- The whiteboard from each lesson, files shared in it, notes either side wrote, and messages typed in the lesson chat.
- Practice attempts, assignments, marks and the progress calculated from them.
- Payments made and, for tutors, earnings — we never see or store your card number.
- Emails we sent you, so that "I never got it" has an answer.
- A record of administrative actions taken on your account: what was done, by whom, and when.
Technical
The address your requests come from, used to stop somebody guessing passwords or flooding the platform, and to investigate abuse. Error reports when something breaks. Nothing here is used to build a profile of you.
Why, and on what basis
- To provide the tuition you asked for — booking, teaching, keeping the record, taking payment. The basis is the contract between us.
- To keep children safe — guardian authorisation, the checks on age, the safeguarding queue, the rule about contact details. The basis is our legitimate interest in the safety of the people using this platform, and in several cases a legal obligation.
- To keep the platform secure — rate limits, the record of administrative actions, error reports. Legitimate interest.
- To meet obligations we cannot avoid — keeping records of what was sold and to whom, for tax. Legal obligation.
- To understand how the site is used — analytics, and only with your consent. You can withdraw it at any time; see cookies below.
Where we rely on legitimate interest, we have weighed it against your privacy, and we do not do it where the balance goes the other way. That is why there is no advertising, no tracking across other sites and no profiling.
Children's data
Much of this platform is used by children, and their data gets more care rather than less.
- An account for somebody under 16 does not work until a parent or guardian has authorised it. Until they do, the child cannot sign in.
- That authorisation is recorded: who gave it, when, what they were told and which version of the terms they were shown.
- A guardian may withdraw it at any time, which switches the account off.
- A guardian may ask for everything we hold about their child, and may ask us to erase it.
- A child's data is never used for marketing, is never profiled, and is never shared with anybody outside the people listed below.
- If a tutor or anybody else tells us they believe a student is younger than their account says, we look into it, and we may require guardian authorisation before lessons continue.
What happens in a lesson
Nothing said in a TeachCurve lesson is recorded. There is no audio recording, no video recording and no transcript. There is no camera at all: the server refuses one, for everybody.
What is kept from a lesson, and why:
- The whiteboard, because it is the student's work and they should still have it in June.
- Files either side shared, for the same reason. They are scanned before anybody can open them.
- Messages typed in the chat, so that if a concern is ever raised about a lesson there is something to look at.
- Notes either side wrote afterwards. Both people can read both.
- Who joined, when, and for how long, which is what attendance and payment are calculated from.
A screen is shared only after the other person has agreed, and either side can stop it instantly. While it is happening, both screens say so. What is shown on a shared screen is not captured or stored.
Who else sees it
We do not sell personal data and we do not share it for advertising. Data reaches other organisations only here:
- Amazon Web Services — hosting, in Ireland. Our database, our files and the audio infrastructure for lessons run there.
- Stripe — payments. Card details go to Stripe and never to us.
- Google Analytics — only on the public website, and only if you agree to it. Never inside the platform, never for a signed-in student, and never with advertising features enabled.
Inside TeachCurve, access follows need: a tutor sees the students they teach, a student sees their own work, and our office sees what it must to answer a concern or run the platform. Administrative access leaves a record.
We would disclose data to law enforcement or to a child protection authority where the law requires it or where a child is at risk. That is the only circumstance in which anything here goes to anybody not listed above.
Where it is kept, and for how long
Everything is stored in the European Union, in Amazon's Ireland region. Where a supplier processes data outside the EU, it does so under the safeguards the law requires.
- Your account and your work — while your account exists, and until you ask us to erase it.
- Records of sales — kept as long as tax law requires, with the person detached from them where possible.
- Safeguarding records — kept while they may still be needed, because a concern that was closed can matter later.
- The record of administrative actions — kept, including after an account is erased. It holds ids, not contents.
- Email records and rate-limit counters — a short period, then deleted.
What you can do about it
Under the GDPR you have rights, and on this platform most of them are buttons rather than requests:
- See it and take it with you. Settings → Your data gives you everything we hold, as a file, immediately. Nobody has to approve it.
- Have it erased. Settings → Close and erase my account. It removes your account and your data. What stays is the record of sales that tax law requires, with your details taken off it, and the safeguarding record if there is one.
- Correct it. Most details are editable in Settings; ask us for anything that is not.
- Object, or ask us to restrict what we do. Tell us and we will answer.
- Withdraw consent. Where we relied on consent — analytics, and a guardian's authorisation — you can take it back, and it is as easy to take back as it was to give.
A parent or guardian can do all of these on behalf of a child whose account they authorised.
There is no automated decision-making here that has a legal or similarly significant effect on anybody. Suspensions and safeguarding outcomes are decided by a person.
Cookies and analytics
Nothing is loaded from Google until you say yes. Not the script, not a cookie, not a single request. If you choose "No thanks", the tag is never fetched and the answer is remembered.
- The public website asks once whether it may count your visit. Agreeing loads Google Analytics 4, which sets its own cookies to tell one visit from another. Advertising features are switched off permanently, not by default — we do not turn them on for anybody.
- The platform itself uses no analytics and no advertising cookies at all. It stores your sign-in token in your browser so you stay signed in, and a few preferences such as the last filter you chose. That storage is necessary for it to work and stays on your device.
- To change your mind, clear this site's data in your browser; the question is asked again on your next visit.
How it is protected
- Everything travels encrypted, and is stored encrypted.
- Passwords are stored as one-way hashes. Nobody at TeachCurve can read yours.
- A password alone never signs anybody in: a code goes to your email address every time, for every account, including ours.
- Repeated attempts to guess a password, or to flood the platform, are counted and refused.
- Files uploaded in a lesson are scanned before the other person can open them.
- Administrative actions leave a record of who did what, and when.
If a breach ever happens that is likely to put anybody at risk, we will tell the Data Protection Commission within 72 hours and tell the people affected without undue delay.
Complaining
Tell us first — use the form on the front page, or Settings if you have an account — and we will answer. If you are not satisfied, you can complain to the Data Protection Commission in Ireland, or to the supervisory authority in the country you live in. You do not have to come to us first, but we would rather you did.
This document is written to be read. If a sentence in it is unclear, that is our fault and we would like to know — tell us through the form on the front page, or from Settings if you have an account.