1. Scope
This disclosure covers the CodeTutor CLI, TUI, desktop app, hosted browser app, documentation site, and CodeTutor-owned cloud services. It does not replace the privacy terms of an upstream model or a third-party site you choose to open.
2. Data that remains local
Repository files, local Session transcripts, tool payloads, shell output, lesson workspaces, and local lesson state stay on the computer running CodeTutor unless you deliberately export or share them. Hosted web repository access is intended to use an origin-bound pairing with a loopback local server; it is not cloud repository storage.
3. Managed AI processing
To answer an AI request, the selected prompt context and necessary repository excerpts are transmitted through CodeTutor Cloud and Vercel AI Gateway to the model you selected. The intended CodeTutor cloud design does not persist prompts, source code, file contents, tool payloads, or model responses after request processing. Upstream processing is governed by the selected provider's terms.
4. Records CodeTutor may store
- Account identity, verified email, linked sign-in methods, profile and tutor preferences.
- Learning progress you choose to synchronize; local curriculum files remain local.
- Named device sessions, last activity, revocation state, MFA and recovery metadata.
- Plan, invoices, checkout references, credit ledger entries, refunds and disputes when billing is enabled. Full card data is handled by Stripe, not CodeTutor.
- Model ID, token counts, estimated and reconciled cost, latency, outcome, client/version labels, and privacy-safe request identifiers.
- Security and fraud signals needed to protect accounts and limited Free usage.
5. Retention
- Local repositories and transcripts: until you delete them locally.
- Active account/profile and synchronized learning records: while the account is active.
- Revoked refresh sessions and security events: retained only as long as reasonably needed for abuse prevention and incident investigation.
- Billing and credit-ledger records: retained as required for accounting, tax, disputes, and legal obligations.
- Scheduled deletion: a seven-day recovery window is intended before account records are removed or irreversibly de-identified, subject to required billing/security retention.
- Opt-in diagnostics: retained for the shortest documented operational period and scrubbed of prompts, code, paths, credentials, and personal data.
6. Your controls
Use codetutor account export to request account data, codetutor account sessions to review devices, and codetutor account delete to review deletion options. You can remove local Sessions and lesson workspaces separately. These commands must show the available action before confirmation.
7. Children and regions
The commercial product is intended for people aged 16 or older and only in regions where the service may lawfully be offered. The beta is not directed to children under 16.
8. Requests and changes
Until a production privacy contact is published, do not send identity documents or confidential data through a public issue. Use the account export/deletion controls and the support route on the Trust page. Material changes will receive a new update date.