Legal
Privacy Policy
Last updated June 13, 2026
This policy explains what we collect when you use clss, why we collect it, who processes it on our behalf, and the choices you have. The short version: we collect what the product needs to work, we don't sell your data, and we don't run advertising trackers.
1. What we collect
- Account. Name, email, password (stored as a hash by our auth provider), role, country, timezone, and date of birth. For students aged 13–17, a parent or guardian email.
- Profile. What you choose to add — photo, bio, subjects, languages, and for tutors: rates, availability, credentials, and identity-verification documents.
- Activity. Bookings, sessions, reviews, group-class enrollment, waitlist entries, and reported issues.
- Messages. Your message threads, including automated flagging of contact-information exchange (a safety feature — flagged messages may be reviewed by our team).
- Class recordings. Where recording is enabled for a session, the audio/video of that class.
- Technical. Logs and error reports needed to keep the service running (IP address, browser type, crash diagnostics). No advertising or cross-site trackers.
2. How we use it
- Running the product: matching, booking, the live classroom, messaging, email notifications.
- Safety: tutor verification, contact-info flagging, reviewing reported sessions, protecting minors.
- Service health: debugging errors, preventing abuse, securing accounts.
- Email: transactional messages (confirmations, reminders, receipts) always; product updates only if you opted in, and every one has an unsubscribe.
We do not sell personal data, and we don’t use it for third-party advertising.
3. Who processes data for us
clss runs on a small set of infrastructure providers, each processing data under their own contractual safeguards:
- Supabase — database, authentication, and file storage.
- LiveKit — live classroom video/audio and class recordings.
- Resend — transactional email delivery.
- Vercel — application hosting.
- Sentry — error monitoring.
- Stripe — payment processing, once payments launch.
4. Children
clss is not for children under 13, and we block signups below that age. Students aged 13–17 may use clss with parent or guardian consent; we collect a parent email at signup for that purpose. Parents and guardians can contact admin@clss.io to review or request deletion of their child’s data.
5. Recordings
When a session is recorded through the platform, the recording is accessible only to that session’s participants under the access rules shown in the product, and to clss for safety and quality review. Recordings are stored in our file storage with access-controlled, expiring links and are deleted on their published retention schedule or when the underlying session data is deleted.
6. Retention and deletion
We keep data for as long as your account exists. Deleting your account in Settings cancels future sessions and removes your profile and personal data from the live product; residual copies in encrypted backups age out on the backup schedule. Some records we must keep longer where the law requires it (for example, payment records once payments launch).
7. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA, and similar), you may have rights to access, correct, export, restrict, or delete your personal data. You can do most of this directly in Settings; for anything else, email admin@clss.io and we’ll respond within 30 days. We don’t discriminate against you for exercising privacy rights.
9. Security
All traffic is encrypted in transit. Data access is enforced row-by-row at the database layer, classroom access is verified server-side per participant, and recordings use expiring signed links. Two-factor authentication is available in Settings. No system is perfectly secure — if we learn of a breach affecting your data, we’ll notify you as the law requires.
10. Where data lives
clss is operated from the United States and our providers store data primarily in the US. If you use clss from elsewhere, your data is transferred to and processed in the US under our providers’ standard contractual safeguards.
11. Changes to this policy
We’ll update this policy as the product evolves and note the date at the top. For material changes — like the launch of payments — we’ll notify you by email or in-product first.
12. Contact
Privacy questions or requests: admin@clss.io.