Privacy Policy
Last updated · August 2026
TuitionHub ("we", "us") explains below what personal data we collect, how we use it, and your rights over it. This policy covers the TuitionHub Android app ("the Service"). This site is the app's public information page and has no accounts or sign-in of its own.
1. Data we collect
About instructors (account holders):
- Full name (display name) and, optionally, your tuition class or academy name
- Email address
- Password, stored as an Argon2 hash — we never see the plaintext
- If you sign in with Google: your Google account ID, email address, and name, received from Google. We never receive your Google password.
- Whether your account currently has a paid subscription, and when it expires
- Your chosen currency, so fees display in the money you actually use
- Session metadata: IP address, device user-agent, session timestamps — used to keep you signed in and protect against session hijacking
About your students:
- Full name
- Contact number (often a parent's)
- Attendance marks you make
- Payment records you enter
If you subscribe:
- A Google Play purchase token and subscription expiry date, so we know your account is paid.
- A one-way scrambled version of your account ID, which we give to Google Play so a purchase can be matched back to your account. It cannot be reversed into your account ID or email.
- We never receive your card or payment details. Google Play takes the payment; we only ever learn whether it succeeded and when the subscription runs out.
Diagnostics (Android app only):
- Crash reports and performance samples, including device model, OS version, app version, IP address, and the sequence of screens leading to a problem.
- A small share of app sessions is recorded as a screen replay to diagnose bugs. All text and images are masked before the recording leaves your device, so student names, contact numbers and amounts are not readable in it.
2. How we use your data
- To run the Service — show you your batches, students, and monthly rollups.
- To confirm whether your subscription is active, and unlock the student limit if it is.
- To send account emails: password resets and security notifications.
- To fix crashes and performance problems.
- To respond to support requests you send us.
We do not sell or rent your data, we do not share it with advertisers, and we do not use it to train machine-learning models.
3. What we don't do
- We don't contact your students. Reminder messages are copy-to-clipboard — you send them yourself, from your own number.
- We don't share student contact details between instructors. Each roster is private.
- We don't process tuition fees. Payment records in TuitionHub are bookkeeping entries only; money moves between you and the student directly.
- We don't run advertising, ad tracking, or third-party analytics SDKs.
4. Who else processes your data
We use a small number of service providers to operate the Service. They process data on our instructions only, and none of them receives it for advertising or profiling:
- Hetzner (Germany) — servers and database hosting.
- Google Play — sells and renews the subscription and is the merchant of record, meaning Google handles payment, receipts, refunds and any sales tax. Google's own privacy policy governs what it collects when you buy.
- Google — "Continue with Google" sign-in, if you use it.
- Resend — sends account emails such as password resets.
- Sentry (EU region) — crash and performance reports from the Android app, including the masked screen replays described above.
- GitHub — hosts our source code and container images. No customer data is stored there.
5. Where your data lives
- TuitionHub runs on dedicated servers in Europe (Hetzner).
- Data lives in a PostgreSQL database on the same infrastructure.
- Some data is also kept on your own device by the Android app: your sign-in token in the OS-encrypted keystore, and any attendance you marked but haven't saved yet, so a crash or a dead battery doesn't lose your work. Uninstalling the app removes both.
6. Data retention
- Active accounts: we keep your data as long as your account exists.
- Removed students: stay in the database so historical attendance and payment records remain intact. Removed students don't appear in your active roster.
- Account deletion is self-service. Delete your account from Settings. It is then scheduled for deletion and you have 24 hours to undo it; after that it is permanently erased, along with your batches, students, attendance, payments, sessions and subscription history. There is no soft-delete copy left behind.
- You can also email us and we'll do it for you. Deleting your TuitionHub account does not cancel a Google Play subscription — cancel that in Google Play.
- Crash reports and replays are retained by Sentry on its own schedule (currently 90 days) and expire automatically.
7. Cookies and tokens
The app keeps your sign-in token in the device's encrypted storage. This site sets no cookies at all — no advertising cookies, no third-party trackers, and no analytics beyond standard server-side logs (IP + request path + status code) used for debugging.
8. Your rights
You have rights to access, correct, export and delete your personal data, and to object to certain kinds of processing. Most of these you can exercise yourself from Settings; for anything else, email shooquehq@gmail.com and we'll respond within 30 days.
These rights arise under the Personal Data Protection Act 2022 (Sri Lanka) and, if you are in the UK or the European Economic Area, under the UK GDPR and EU GDPR. Where we rely on a legal basis, it is performance of our contract with you (running the Service), our legitimate interests (security and fixing crashes), or your consent where we ask for it.
9. Your students' data
The data you enter about your students is personal data about them, not about you. You are the data controller for that information — you collected it for your tuition class and TuitionHub stores it on your behalf as your processor. You represent that you have the right to collect and store this information, and that you will respond to students' (or their parents') requests to see, correct, or delete it.
Where your students are children, that responsibility includes having whatever permission local law requires from a parent or guardian before entering their name and contact number. TuitionHub is an instructor-facing tool — students have no accounts and we never contact them — but the lawful basis for holding their details is yours, not ours.
10. Changes
Material changes will be emailed to your account at least 14 days before they take effect.
11. Contact
Privacy questions: shooquehq@gmail.com. General support: shooquehq@gmail.com. WhatsApp: +94 77 726 3326.