Data Policy
How lesson data is handled, who processes it, what schools control, and what we never do with it.
Last updated March 1, 2026 · Santi Open University Ltd.
Scope
This policy sits alongside the Privacy Policy and goes deeper on one thing: the lesson data produced when you learn with Santi Tutor. If the two ever conflict, the Privacy Policy governs.
What counts as lesson data
- The questions you ask, in text, voice or as a photograph of a page.
- The board: every stroke, its timing, and the final rendered state.
- The chat and voice transcript for the session.
- Generated notes, practice questions and your answers to them.
- Derived signals: topics covered, mastery estimates, weak-topic queue, tokens consumed.
Data flow for a single lesson
- Your question is received over an encrypted connection and stored against your account.
- The question, plus the relevant part of your lesson history, is sent to the AI models that plan the explanation.
- Mathematical steps are verified symbolically before any stroke is drawn.
- The board streams to your device and is written to your library.
- Token usage is recorded against your plan.
What we do not do
- We do not sell lesson data, or share it with advertisers or data brokers.
- We do not allow model providers to train on your lesson content. This is a contractual prohibition, not a setting.
- We do not use lesson content in marketing without your explicit, separate permission.
- We do not build advertising profiles, and we never do so for learners under 18.
How we improve the service
We look at aggregated, de-identified patterns: which topics generate the most repeat questions, where lessons get abandoned, which explanations get flagged as wrong. This informs how subjects are taught on the board.
A small number of sessions may be reviewed by trained staff when you report a problem, or when abuse detection flags an account. Reviews are logged, justified and limited to what is needed.
Institution-controlled data
Where an institution provides Santi Tutor, that institution is the controller and decides:
- Which staff roles can view learner lessons and progress.
- The retention period for lesson data, within the limits we support.
- Whether assessment mode is enforced, and whether attempts are logged for teachers.
- The data-residency region, where a specific region is contracted.
Sub-processors
We use a small set of sub-processors for cloud hosting, AI inference, email delivery, payments, error monitoring and support tooling. Each is bound by written terms covering confidentiality, security and deletion. The current list is available on request, and institutions are notified of material changes before they take effect.
Retention and deletion
- Delete an individual lesson and it is removed from your library immediately and purged from backups within 30 days.
- Delete your account and all lesson data is purged within 30 days, except records we must keep for tax or legal reasons.
- Institution data is deleted or returned within 60 days of contract termination, at the institution's choice.
Getting your data out
Account → Privacy → Export data produces a machine-readable archive of your lessons, transcripts, notes and progress. Individual lessons also export to PDF and Markdown. If an export fails or you need a format we don't offer, email privacy@santitutor.com.
Questions about this document? Write to privacy@santitutor.com. Other policies: Privacy Policy, Terms of Service, Security, Cookie Policy.