Privacy

Your data, in plain words

OpenTutor is open source. This page says what the hosted OpenTutor at this address keeps about you, why, and who can see it. The code that does all of this is public on GitHub, so you can check it.

What we keep about you

What goes to AI models

To write the tutor’s replies, your answers and messages are sent, together with the lesson’s context and your profile, to an AI model through OpenRouter. During your free lessons this uses OpenTutor’s OpenRouter account; once you connect your own, it uses yours. OpenRouter and the model provider handle these requests under their own terms, so please don’t share anything in a lesson that you wouldn’t want an AI service to process.

If you ask for a topic that isn’t in the catalogue, OpenTutor builds a course for it. The topic’s name is searched on public sources (arXiv, Semantic Scholar, OpenAlex, Wikipedia, MIT OpenCourseWare, DuckDuckGo, YouTube through Invidious, and GitHub). The name and the level you chose go to an AI model, the same way, to write the course. Available source material, such as a Wikipedia summary, may also be included; a failed or timed-out search may contribute no results.

The example on the home page

If you try the example lesson, your answer is sent to an AI model for one reply and is not stored. To limit abuse we count replies per visitor per day, using a scrambled (hashed) form of your IP address, never the address itself. We attempt to delete old counts when the example is first used on a later day. If cleanup fails, old counts may remain until a later cleanup succeeds.

Cookies and your browser

We use cookies only to keep you signed in and to complete sign-in and OpenRouter connections safely. Page scripts can’t read them. Your browser also remembers a few small preferences, such as the colour theme, a topic you picked before signing up, and whether you’ve tried the example. The admin page, used only by the OpenTutor team, keeps its admin password in that browser. There are no advertising or analytics trackers.

Who can see it

The OpenTutor team, to run the service: for example, an admin view shows each student’s name, topics and progress. We don’t sell your data or share it with anyone else, apart from the AI processing above and the services that host OpenTutor: Supabase for the database and sign-in, and Vercel for the website.

Deleting your data

Sign in, open the learning app, choose Delete account next to Log out, and type DELETE to confirm. That deletes your sign-in (your email address and password), your profile, progress and learning notes, any topics built for you, and our copy of your OpenRouter key. It can’t be undone. In the account database we keep a marker that the account was closed, with no name or email, so it can’t be reopened; you can sign up again as a new account. To cancel the OpenRouter key itself, delete it in your OpenRouter settings. If the team set up your account for you, ask them to remove it. If any step of a deletion fails, the team finishes it by hand.

If you requested a custom topic, a pending build request at Vercel can remain after account deletion, for up to seven days after it was queued. It contains your account identifier, a topic identifier derived from its name, and build identifiers. Deleting your account stops the pending request from starting a new build, but does not immediately remove it from that queue.

Questions

Open an issue on GitHub. Please don’t put personal information in a public issue.

Last updated 28 September 2026.