Privacy Policy

Last Updated: August 2026

At TutorWave, your privacy and platform security are our top priorities. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational marketplace and proprietary virtual classrooms, published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000, and the Consumer Protection (E-Commerce) Rules, 2020.

1. Information We Collect

  • Identity & Profile Data: Name, email address, phone number, Google SSO data, educational certificates, LinkedIn verification data (for Tutors), and — for Tutors, as part of identity verification — a government-issued identity document (such as an Aadhaar Card, Passport, or Birth Certificate) and its document number.
  • Student Academic & Guardian Data: For Students, we collect grade/class, education board, preferred subjects, target exam preferences, guardian name, address, and date of birth as part of registration and profile setup. This information is used to match Students with relevant Tutors and, as described in Section 6, is shown only to a Tutor once a Student enrolls in that Tutor’s subject.
  • Classroom Telemetry: Exact TutorMeet join, leave, and reconnect timestamps. This is used strictly to verify session attendance for our automated payment-release and refund system.
  • Classroom Engagement Data: For sessions conducted via TutorMeet, we record attendance duration against the 5-minute validity threshold, and session-level participation indicators (e.g., whether both parties remained connected for the scheduled duration) used to power tutor analytics and the attendance/refund system described in our Terms of Service. We do not analyze session audio or video content for engagement scoring.
  • Live Engagement & Gamification Data: During a TutorMeet session, we record a Student’s poll votes, Q&A questions asked (including the text of the question), and question upvotes, each linked to the Student’s account, the session, and the relevant subject. These actions earn points that contribute to a live leaderboard visible to other participants in that session, and are retained as part of your account’s learning-activity data for as long as your account remains active (see Section 10).
  • Payment Data: We do not collect or store your card, UPI, or bank details. All payment information is collected and processed directly by our payment partner, Razorpay, under Razorpay’s own security and compliance standards (PCI-DSS).
  • Communication Data: Platform messages sent through TutorChat are subject to automated data-loss prevention (DLP) filtering to detect and block sharing of unauthorized off-platform contact details or payment handles.
  • Device, Usage & Push Notification Data: IP address, browser/device type, and app usage logs, collected for security, fraud prevention, and service improvement. For users of our mobile app, we also collect a device push-notification token, used solely to deliver session reminders and account alerts.
  • Learning Activity Data: For students, we generate and store learning-activity data from AI session notes, including test/quiz answers and scores, flashcard review history and spaced-repetition scheduling, achievement progress, and overall progress analytics.
  • Reports & Invoices: Tutors can generate and export attendance, revenue, and student-analytics reports from their dashboard; these may only be shared with a student’s parent/guardian. Students can generate and download invoices for their own purchases.
  • Ratings & Reviews: Students can rate and review tutors after a completed session. Reviews may be shown publicly on a tutor’s profile using an anonymized or privacy-preserving display name rather than the reviewer’s real name.
  • Chat Presence & Activity Data: Online/last-seen status, typing indicators, message read receipts, message-edit history, and message reactions are visible to the other participant(s) in a TutorChat conversation, not only stored internally by us. In a Tutor-created group/class chat, this activity — along with shared messages, files, and participant names — is visible to every member of that group, including other enrolled Students, not TutorWave staff alone.
  • Contact & Support Data: If you submit our Contact page or otherwise reach out for support — including as a visitor who has not created an account — we collect the name, email address, and message content you provide, solely to respond to and resolve your enquiry.

2. Cookies & Tracking Technologies

We use essential cookies and similar browser storage — such as authentication session tokens — to keep you signed in and to remember basic preferences like light/dark theme. We do not use cookies or similar technologies to serve third-party advertising, and we do not sell information collected this way. You can control or clear cookies through your browser settings at any time, though doing so may sign you out of the Platform or affect features that depend on them.

3. Live Session Audio/Video — No Recording

TutorWave’s TutorMeet classroom, powered by LiveKit’s real-time video and audio infrastructure, facilitates real-time, live audio/video communication between tutor and student, transmitted directly over our TutorMeet infrastructure for the duration of the session only. We do not record, save, store, or process session audio or video in any form. No transcript, recording, or AI-generated notes are created from your sessions.

The TutorMeet classroom also includes TutorBoard, a live collaborative whiteboard synced in real time over Socket.IO, which the tutor uses to draw and share visual explanations while students view along live. Whiteboard content — including any drawings or images placed on it — is never saved, recorded, or stored on our servers. It exists only for the duration of the live session, the same as session audio and video.

4. TutorChat Messages & Files

TutorChat, our in-platform messaging tool built on real-time Socket.IO infrastructure, supports one-to-one conversations between a tutor and a student, and tutor-created group chats for an entire class or batch. This is separate from the live video classroom described above.

  • Content we process: Text messages, voice recordings, emoji reactions, pinned messages, and any PDFs, images, or video files that tutors or students choose to share through TutorChat.
  • Who can contact whom: Only tutors can start a new conversation, create or manage a group, or pin a message. A tutor can only search for and message students who have purchased one of their subjects. Students cannot independently search for or start a chat with a tutor or another student, but can reply once a tutor starts a conversation with them.
  • Group chat visibility: Messages, shared files, and participant names in a tutor-created group/class chat are visible to every member of that group — including other enrolled students in the same batch — not only to TutorWave staff.
  • PDF surfacing: PDFs shared in a class chat are stored so they can automatically appear in each enrolled student’s dashboard as study material. Images, videos, and voice recordings are stored so they remain accessible within the chat, but are not surfaced on the dashboard.
  • Deletion: Any participant can delete a message or shared file at any time; once deleted, it is removed from the conversation for everyone, though a brief operational backup copy may persist for a limited period before final removal.
  • This is distinct from session recording: storing a file someone deliberately uploads to TutorChat is not the same as recording a live TutorMeet class — we still never record, save, or process live session audio/video, as described above.
  • All TutorChat content is subject to the same automated DLP filtering described in Section 1 (Communication Data), to detect and block unauthorized off-platform contact details or payment handles.

5. AI Session Notes

After a session ends, a tutor may upload a PDF (one per session). Our system generates a written summary and practice questions from that PDF only — never from session audio or video. The tutor can review and edit the generated questions before publishing. Once published, enrolled students can view the AI-generated notes, answer the practice questions, and access the original uploaded PDF.

6. Profile & Data Visibility

  • Students see only relevant tutors: a student can view a tutor’s profile only if that tutor teaches a subject the student has selected. A tutor’s Trust Score and Performance Score (ratings, sessions conducted, and total teaching hours) are shown on their profile only to these matched students.
  • Verification documents are never public: identity documents and educational verification documents collected from tutors are used only for internal verification. They are not displayed on any public profile and are not disclosed to students.
  • Tutors see limited data, only for their own students: once a student enrolls in one of a tutor’s subjects, that tutor can view the student’s name, class, email, phone number, guardian name, address, date of birth, and enrolled subject. Tutors cannot view this information for students who are not enrolled with them.

7. Administrator Access

Authorized TutorWave personnel may internally access account, verification, session, attendance, and payment records solely to operate the Platform, investigate policy violations, resolve disputes, and comply with legal obligations. This internal access does not change the visibility limits between tutors and students described in Section 6.

8. How We Protect Your Data

Your data is secured using industry-standard encryption in transit and at rest. Our video infrastructure and website run on secure Oracle Cloud (OCI) instances, and our database is hosted on MongoDB Atlas. We do not sell your personal information, attendance logs, or account data to third-party advertisers.

9. Data Sharing & Third Parties

We share data only with essential partners required to operate TutorWave, each bound by confidentiality and data-processing agreements:

  • Razorpay — for payment collection, refunds, and tutor payouts. Razorpay is an RBI-regulated payment aggregator; your payment instrument details are handled entirely by Razorpay and are not visible to or stored by TutorWave. Tutor payouts are processed entirely through Razorpay’s escrow infrastructure and held for the full 4-week package cycle before release. Tutors registered for Razorpay Route can view full payout history on Razorpay’s own dashboard; this data is also mirrored on the tutor’s TutorWave dashboard. Tutors who provide only bank details receive an admin-processed manual transfer funded from the same escrow, also reflected on their TutorWave dashboard. TutorWave never custodies these funds itself.
  • Cloudinary — our file and media storage provider. Profile pictures, identity and educational documents, and any PDFs, images, videos, or voice recordings uploaded to the Platform or shared via TutorChat are stored with Cloudinary. This content is not shared by us with any other third party.
  • LiveKit — our real-time video and audio infrastructure provider, powering the TutorMeet classroom. Session audio/video is relayed live through LiveKit’s infrastructure for the duration of a session only and is never recorded or stored, by LiveKit or by us.
  • Sentry — for error monitoring, so we can detect and fix technical issues on the Platform.
  • Cloud hosting providers — for database storage and live TutorMeet relay infrastructure (session audio/video passes through this infrastructure in real time only, and is not stored).

Some of our infrastructure partners may process data on servers located outside India; where this occurs, we ensure such transfers comply with the DPDP Act. We do not share your data with third parties for their own marketing purposes.

10. Refunds & Data Retention

  • All payments and refunds are processed directly by Razorpay. Approved refunds (e.g., for a verified Tutor No-Show or Abnormal Duration event) are credited back to your original payment method (source account/card/UPI), subject to standard bank and payment network processing timelines. TutorWave does not hold customer funds outside of Razorpay’s regulated payment/escrow flow, and does not operate a stored-value wallet.
  • Account/profile data: retained while your account is active, and for a limited period after deletion to allow account recovery.
  • Live engagement & gamification data: poll votes, Q&A questions and upvotes, and points earned during TutorMeet sessions are retained as part of your account’s learning-activity data for as long as your account is active, and for a limited period after deletion consistent with our general account-data retention above.
  • Attendance and transaction logs: retained for a minimum of 8 years where required for tax, accounting, and financial dispute-resolution purposes under Indian law, even after account deletion.
  • Session audio/video: not recorded or stored at any point — transmitted live between tutor and student only, for the duration of the session.
  • TutorChat messages and shared files: retained for the duration of your account, so that shared PDFs, images, and videos remain accessible in the relevant chat and dashboard, and for a limited period after account deletion for moderation and dispute-resolution purposes.

11. Children’s Data

If you are under 18 years of age, you may only use TutorWave with the involvement and verifiable consent of a parent or legal guardian, who must create or supervise the account. We do not knowingly process a child’s personal data for behavioral monitoring, tracking, or targeted advertising. Parents/guardians may contact our Grievance Officer to review, correct, or request deletion of a child’s data at any time.

12. Your Rights

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you.
  • Correct or update inaccurate or incomplete data.
  • Request erasure of your personal data.
  • Withdraw previously given consent at any time (withdrawal does not affect processing already carried out, and may limit your ability to use certain Platform features).
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • File a complaint with the Data Protection Board of India if you are unsatisfied with our response.

You can exercise most of these rights directly from Profile Settings, or by emailing us at officialwebxstudio@gmail.com. Note that certain attendance and transaction logs may be retained after account deletion as described above.

In accordance with the Information Technology Act, 2000, complaints to our Grievance Officer are acknowledged within 24 hours and resolved within 7 days. For any privacy-related questions, contact officialwebxstudio@gmail.com. We may update this Policy from time to time; material changes will be notified via email or in-app notice.