Legal

Privacy Policy

Last updated June 13, 2026

This policy explains what we collect when you use clss, why we collect it, who processes it on our behalf, and the choices you have. The short version: we collect what the product needs to work, we don't sell your data, and we don't run advertising trackers.

1. What we collect

  • Account. Name, email, password (stored as a hash by our auth provider), role, country, timezone, and date of birth. For students aged 13–17, a parent or guardian email.
  • Profile. What you choose to add — photo, bio, subjects, languages, and for tutors: rates, availability, credentials, and identity-verification documents.
  • Activity. Bookings, sessions, reviews, group-class enrollment, waitlist entries, and reported issues.
  • Messages. Your message threads, including automated flagging of contact-information exchange (a safety feature — flagged messages may be reviewed by our team).
  • Class recordings. Where recording is enabled for a session, the audio/video of that class.
  • Technical. Logs and error reports needed to keep the service running (IP address, browser type, crash diagnostics). No advertising or cross-site trackers.

2. How we use it

  • Running the product: matching, booking, the live classroom, messaging, email notifications.
  • Safety: tutor verification, contact-info flagging, reviewing reported sessions, protecting minors.
  • Service health: debugging errors, preventing abuse, securing accounts.
  • Email: transactional messages (confirmations, reminders, receipts) always; product updates only if you opted in, and every one has an unsubscribe.

We do not sell personal data, and we don’t use it for third-party advertising.

3. Who processes data for us

clss runs on a small set of infrastructure providers, each processing data under their own contractual safeguards:

  • Supabase — database, authentication, and file storage.
  • LiveKit — live classroom video/audio and class recordings.
  • Resend — transactional email delivery.
  • Vercel — application hosting.
  • Sentry — error monitoring.
  • Stripe — payment processing, once payments launch.

4. Children

clss is not for children under 13, and we block signups below that age. Students aged 13–17 may use clss with parent or guardian consent; we collect a parent email at signup for that purpose. Parents and guardians can contact admin@clss.io to review or request deletion of their child’s data.

5. Recordings

When a session is recorded through the platform, the recording is accessible only to that session’s participants under the access rules shown in the product, and to clss for safety and quality review. Recordings are stored in our file storage with access-controlled, expiring links and are deleted on their published retention schedule or when the underlying session data is deleted.

6. Retention and deletion

We keep data for as long as your account exists. Deleting your account in Settings cancels future sessions and removes your profile and personal data from the live product; residual copies in encrypted backups age out on the backup schedule. Some records we must keep longer where the law requires it (for example, payment records once payments launch).

7. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA, and similar), you may have rights to access, correct, export, restrict, or delete your personal data. You can do most of this directly in Settings; for anything else, email admin@clss.io and we’ll respond within 30 days. We don’t discriminate against you for exercising privacy rights.

8. Cookies and local storage

  • Auth cookies keep you signed in. They are essential — the product doesn’t work without them.
  • Local storage remembers preferences like your theme choice and in-progress onboarding drafts, on your device only.
  • No advertising cookies, no cross-site tracking, no analytics that identify you.

9. Security

All traffic is encrypted in transit. Data access is enforced row-by-row at the database layer, classroom access is verified server-side per participant, and recordings use expiring signed links. Two-factor authentication is available in Settings. No system is perfectly secure — if we learn of a breach affecting your data, we’ll notify you as the law requires.

10. Where data lives

clss is operated from the United States and our providers store data primarily in the US. If you use clss from elsewhere, your data is transferred to and processed in the US under our providers’ standard contractual safeguards.

11. Changes to this policy

We’ll update this policy as the product evolves and note the date at the top. For material changes — like the launch of payments — we’ll notify you by email or in-product first.

12. Contact

Privacy questions or requests: admin@clss.io.