TutorDesk ← Home
Legal

Privacy Policy

Last updated: 13 June 2026

This policy explains what TutorDesk collects, how it's stored, and your choices. We've written it to reflect how the product actually works. In plain terms: your studio's data is yours, it's isolated to your account, and we don't sell it.

1. Who is responsible for the data

For your own account details (your email or username), TutorDesk is the data controller. For the information you enter about your students and their parents, you are the controller and TutorDesk acts as your processor — we store and process it on your instructions so you can run your tuition business. You're responsible for having a proper basis (such as consent) to record that information under Singapore's PDPA or any law that applies to you.

2. What we collect

3. How and where it's stored

Your data is stored in a Supabase (PostgreSQL) database and the app is served by Vercel. Every table is protected by row-level security, so each account can only ever read or write its own rows — one tutor cannot see another tutor's students. Connections use HTTPS. Passwords are hashed by Supabase Auth; we never see them.

4. How we use it

We use your data solely to provide and operate TutorDesk — to show your dashboard, schedule sessions, calculate insights, generate reports and process the features you use. We do not sell your data or your students' data, and we don't use it for advertising.

5. Who we share it with (sub-processors)

We rely on a small number of trusted providers to run the service:

These providers process data only to deliver their part of the service. We don't otherwise disclose your data except where required by law.

6. Retention and deletion

We keep your data for as long as your account is active. You can edit or delete individual records at any time, export everything (JSON, CSV or Excel) whenever you like, and ask for your account to be deleted. Deleting your account permanently removes your students, payments, grades, sessions, settings and billing record — this cascade is immediate and cannot be undone.

7. Your rights

Under the PDPA and similar laws you can request access to, or correction of, your personal data, and withdraw consent. Most of this you can do yourself inside the app; for anything else, contact us below. If you've entered data about your students, you're the first point of contact for their requests, and we'll support you as your processor.

8. Security

We use row-level security, encrypted transport (HTTPS), hashed passwords and per-account isolation. No system is perfectly secure, but we design TutorDesk so that a flaw in the page or a leaked public key cannot expose another tutor's data — access is enforced in the database, not just the interface.

9. Children

TutorDesk is for tutors, not for children to use directly. Information about students (who may be minors) is entered by their tutor, who is responsible for the appropriate consent.

10. Changes

We'll update this policy as the product changes and revise the date above. Material changes will be highlighted in the app or by email.

11. Contact

Questions or requests about your data? Email zhengda@sohsimple.sg.