🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
TutorPal

TutorPal Privacy Policy

How TutorPal handles tutor accounts, learner records, sync and family links.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Working records Local-first with authenticated backend sync
Student care Tutors control information about learners and guardians
Family pages Time-limited secret links need careful sharing
Privacy requests [email protected]
On this page
  1. Overview
  2. Data we handle
  3. How we use data
  4. Sharing and processors
  5. Storage and residency
  6. Public links
  7. Retention
  8. Security
  9. Your rights
  10. Children and minors
  11. International transfers
  12. Changes
  13. Contact

TutorPal keeps a local working database while clearly explaining the connected services needed for continuity and family coordination.

Overview

Blue Sparrow is a solo developer based in India and operates TutorPal, a local-first scheduling, student-management, lesson-pack, invoicing and family-coordination service for independent tutors. This policy explains the information TutorPal handles, why it is needed, how the mobile app and connected services work together and the choices available to you.

TutorPal is designed around data minimisation, purpose limitation, transparency and the rights provided by the EU General Data Protection Regulation, UK GDPR and other applicable privacy laws. Google sign-in is required for the tutor app. The working database is stored on the device and supported records are synchronised with Blue Sparrow's authenticated TutorPal backend for continuity and restore.

Local-first with connected services

Local-first describes how the working app behaves; it does not mean that all records stay only on the device. Sign-in, sync, public pages, email, push, subscriptions, support and crash reporting involve the providers described below.

Data we handle

TutorPal may handle these categories:

  • Google and Firebase account information, including a Firebase user identifier, email address, display name, profile image URL, provider details and authentication timestamps.
  • Tutor profile and business information, such as display name, subjects, teaching preferences, contact details, service area, biography, credentials, public-profile choices, branding and selected logo.
  • Student and guardian information entered by the tutor, including names, contact details, tags, notes, goals, homework, scheduling context and relationship preferences.
  • Lesson records, recurring slots, calendar blocks, attendance and status, cancellations, reschedule requests, follow-up notes, reminders and automation choices.
  • Lesson-pack balances, policies, policy text and acknowledgements, message and document templates, invoices, payment-status labels, payment-profile details, PDF documents and reports.
  • Public-link information such as tutor and student display names, lesson timing, pack or policy context, submitted parent or guardian actions, acknowledgement name and timestamps.
  • Device and service information such as a device identifier created by TutorPal, sync cursors, app version, notification settings, Firebase Cloud Messaging token, delivery state, request identifiers and security logs.
  • Purchase and entitlement information handled by Google Play, RevenueCat and Blue Sparrow's subscription services, such as product, receipt, transaction, renewal, Premium status and expiry. Blue Sparrow does not receive full payment-card details.
  • Support or feedback information you deliberately submit, including reply email, optional name and subject, message, app and platform details and a request reference.
  • Crash and error information sent to Firebase Crashlytics in release or profile builds, which may include stack traces, app and device details, technical identifiers and surrounding diagnostic state.

TutorPal's in-app business analytics are calculated from tutoring records for the tutor's own dashboard. The app does not include the Firebase Analytics SDK. TutorPal does not include a generative-AI integration that sends student records, lesson notes, messages or invoices to an AI provider.

How we use data

Information is used as reasonably necessary to:

  • Authenticate the tutor and associate the correct local workspace, backend records, devices and Premium entitlement.
  • Store, display, edit, search, synchronise and restore supported tutor, student, lesson, pack, policy, note, goal, template and calendar records.
  • Generate invoices, reports, exports, payment requests and delivery history.
  • Create and operate tutor-directed session, policy, family-snapshot and public-profile pages.
  • Receive family actions, show them in the tutor inbox and send operational push notifications when enabled.
  • Send invoices, reports or support messages when the tutor requests delivery.
  • Process and restore purchases, prevent entitlement abuse and support account deletion.
  • Protect connected services, diagnose failures, maintain reliability and meet applicable privacy, consumer, security and record-keeping obligations.

TutorPal does not sell or rent personal information, create an advertising profile or use student records for targeted advertising.

Sharing and processors

Blue Sparrow does not share information for independent advertising. Limited information may be processed by:

  • Google Sign-In and Firebase Authentication for tutor identity and session credentials.
  • Firebase Cloud Messaging and the Blue Sparrow push gateway for device tokens and operational notifications.
  • Firebase Crashlytics for release diagnostics and crash reports.
  • Blue Sparrow's TutorPal API, PostgreSQL storage, file storage and web frontend for sync, invoices, public profiles, family links, support and other connected features.
  • Blue Sparrow's mail relay and its configured delivery provider when the tutor requests an invoice, report, support message or other operational email.
  • Google Play, RevenueCat and Blue Sparrow subscription services for purchases, receipts and entitlements.
  • A recipient's browser, email, SMS, WhatsApp, sharing application or communications provider when the tutor chooses to share content or a link through that channel.
  • Operating-system providers for local notifications, file or image selection, sharing, app storage and device backup behaviour.
  • Infrastructure, security or professional service providers where reasonably necessary to operate, protect or meet obligations relating to TutorPal.

These third-party providers process information under their own terms and privacy notices, and may use infrastructure outside the tutor's region. Blue Sparrow may also disclose limited information when legally required or reasonably necessary to address fraud, abuse or a serious security threat.

Storage and residency

The working TutorPal database is held in the app's private storage using Drift and SQLite. It is local-first but is not described as independently encrypted by TutorPal. Device locks, operating-system protections and device-backup settings therefore remain important.

After sign-in, supported records are synchronised through the authenticated TutorPal API to Blue Sparrow-controlled infrastructure. This includes supported tutor, student, contact, scheduling, pack, policy, template, note, goal, inbox and automation records. Invoice PDFs, public tutor branding and related delivery records can also be stored by connected services when those features are used.

Blue Sparrow intends its controlled primary synchronized content to remain in European Union infrastructure. Production datacentre placement, off-site backup location and retention controls still require release evidence, so this is not a promise that every copy or every provider-held item remains exclusively in the EU.

Project documentation records a Firestore database configured in the eur3 multi-region. The current Flutter app does not use Firestore as its tutoring-record sync database. That Firestore setting does not establish the processing location of Firebase Authentication, Firebase Cloud Messaging, Crashlytics, Google Play, RevenueCat, mail delivery or other providers.

Public links

TutorPal can create no-login session, policy and family-snapshot pages, plus an optional public tutor profile. Session pages can show selected lesson and policy context and accept confirmation, cancellation or reschedule requests. Policy pages can show a policy summary and accept an acknowledgement name. Family snapshots can show selected upcoming lesson, pack and policy context.

Each private family page uses a high-entropy token in its URL. TutorPal stores a cryptographic hash of that token on the backend, but anyone who receives the complete URL may be able to open the page until it expires or is revoked. Tutors should share links only with intended recipients and should revoke or replace a link if it is exposed. Browsers, messaging services and recipients may retain the URL outside TutorPal.

Public-page services may process limited request information, including network address, timing, route, rate-limit state and hashed-token diagnostics, for delivery and abuse prevention. Link records include creation, last-sent, expiry, revocation and response information. Expiry prevents normal access but does not itself prove immediate removal of the backend record.

Known deletion gap

The current automated account purge does not include family-snapshot link records. A snapshot may therefore remain available until its configured expiry unless it was revoked earlier. Contact [email protected] for manual handling while this implementation gap is being corrected.

Retention

Local records remain until the tutor deletes them, signs out through a flow that clears the local workspace, clears app storage or uninstalls the app. Operating-system backups may affect what uninstalling removes and whether device data can later return.

Synced account and tutoring records are kept while needed to provide the connected workspace. Public-link records are governed by their expiry and revocation state, but expired records may remain in storage until an applicable cleanup or account-data process removes them. Invoice, email, push, support, subscription, security and diagnostic records are kept only for delivery, reconciliation, abuse prevention, reliability and applicable operational obligations, then removed or de-identified under the relevant process. Exact production schedules for public-link and backup cleanup are still being verified.

The in-app deletion flow first asks for recent Google authentication, requests deletion of supported TutorPal backend data, removes the current FCM token on a best-effort basis, deletes the Firebase Authentication user, clears the local workspace and signs out. The backend intentionally keeps a minimal account-deletion marker to prevent unintended recreation. As disclosed above, family-snapshot link records are not yet included in that automated purge. Provider records controlled by Google Play, RevenueCat, email or communications providers follow their own retention and account controls. Deleting a TutorPal account does not cancel a Google Play subscription.

Security

TutorPal uses proportionate safeguards including Firebase authentication, recent reauthentication for deletion, HTTPS, authenticated API requests, access controls, high-entropy public-link tokens, hashed server-side link tokens, rate limiting and app-private local storage. Blue Sparrow limits operational access to the solo operator and providers that need information for their assigned purpose.

TutorPal sync is not described as end-to-end encrypted. Connected services must process readable records where needed to synchronise data, render a requested page, prepare a document, deliver a message or provide support. No device, transmission or service can be guaranteed completely secure. Protect the Google account and device, review public links before sharing and avoid recording unnecessary sensitive information.

Your rights

Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, obtain a portable copy, delete it, restrict or object to processing, and withdraw consent where consent is the basis. You may also have a right to complain to a local data-protection authority. Applicable protections can include the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy laws, Brazil's LGPD, Canada's privacy laws and comparable rules elsewhere.

TutorPal provides local review and editing, exports, notification controls, public-link management and in-app account deletion. Some provider-controlled information must be managed through the relevant Google, Google Play, RevenueCat, browser or communications-provider controls.

To exercise a privacy right, email [email protected] with TutorPal in the subject and enough information to identify the relevant account or request. Blue Sparrow may request proportionate verification and will respond within the period required where you live. Ordinary requests are not charged, although clearly excessive or repeated requests may be handled as applicable rules permit.

Children and minors

TutorPal is intended for adult tutors and tutoring businesses. It is not a student account, classroom social network or child-directed app. Students and guardians do not create TutorPal app accounts merely by appearing in a tutor's records or opening a family page.

Tutors may record information about students who are minors. The tutor or tutoring business decides what learner information to enter and share and is responsible for an appropriate basis, required notices, parent or guardian permissions, access controls and age-appropriate handling. Use only information reasonably needed for teaching and administration. Avoid adding unnecessary health, disability, family, safeguarding or other highly sensitive details to free-text notes or messages.

Parents or guardians should contact the responsible tutor first to correct teaching records or manage a shared link. They may also contact [email protected] where Blue Sparrow assistance is needed. If Blue Sparrow learns that child information was provided without an appropriate basis, it will take proportionate steps with the responsible tutor to restrict or remove it.

International transfers

TutorPal's device database remains on the tutor's device unless it is synchronised or a connected feature is used. Blue Sparrow-controlled primary sync content is intended for EU infrastructure subject to the production-evidence qualification above. Firebase Authentication, Cloud Messaging, Crashlytics, Google Play, RevenueCat, mail, communications and other providers may process limited information in other countries or regions.

Where transfer safeguards are required, Blue Sparrow and relevant providers rely on appropriate contractual, adequacy or other lawful mechanisms and apply data-minimisation and security controls. EU users receive the protections required by the EU GDPR, but Blue Sparrow does not claim that every TutorPal datum or provider operation remains exclusively in the European Union.

Changes

This policy may change when TutorPal, its providers or applicable requirements change. Material updates will be presented in the app or on the website where appropriate, and the updated date will be revised. Earlier processing remains covered by the version applicable at that time unless a change must apply sooner for security or compliance reasons.

Contact

Blue Sparrow is the developer and privacy contact for TutorPal. For privacy questions, rights requests, public-link concerns or account-data deletion, email [email protected]. For general help, email [email protected]. Product and policy information is available at https://bluesparrow.dev.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.