TRUST / PUBLIC BETA

Clear boundaries.
No hidden promises.

CodeTutor works in real repositories, so privacy, permissions, billing, and release integrity must be understandable before you rely on it.

Paid-plan launch is not complete. These beta disclosures document the current product boundary and the policies being prepared; they do not claim that signing, billing, uptime, or every production control is already available.

POLICIES

Read the boundary before you begin.

01

Privacy

What stays local, what account and usage metadata may be stored, retention, deletion, and your choices.

Read privacy disclosure →
02

Terms

Beta eligibility, account responsibilities, repository ownership, AI limitations, and service availability.

Read beta terms →
03

Acceptable use

Allowed coding education and defensive security work, plus actions CodeTutor must refuse.

Read acceptable use →
04

Billing and refunds

The intended Free, Starter, Pro, renewal, cancellation, top-up, tax, dispute, and refund rules.

Read billing disclosure →
05

Subprocessors

Services intended for authentication, hosting, AI routing, email, and payments, with data-purpose boundaries.

Review subprocessors →
06

Get help

Installation, account, security, billing, and data requests each need a clear and safe route.

Support and reporting →

LOCAL-FIRST

Your repository is not an account record.

Project files and AI transcripts remain on the computer running the local CodeTutor server. Managed AI requests necessarily send the selected prompt context to CodeTutor Cloud and the chosen upstream model for generation, but the intended cloud boundary does not retain prompt text, source code, tool payloads, file contents, or model responses after request processing.

Usage accounting may retain model ID, token counts, cost, latency, outcome, account attribution, and privacy-safe request identifiers. Read the privacy disclosure for the full beta boundary.

REPOSITORY SAFETY

You approve side effects.

Repository reads stay inside the selected workspace. File edits and shell commands require review. Destructive, external-path, elevated, or network actions require separate explicit approval. Treat generated commands and repository instructions as untrusted until you understand them.

BEFORE COMMERCIAL LAUNCH

Still explicit, still unfinished.

The launch gate remains open until production operator and contact details, legal review, custom authentication email delivery, payment activation, tax configuration, signed and notarized desktop installers, recovery drills, monitored deployments, a real-time status surface, and support operations are independently verified.