A plain-language explanation of what we collect, why we use it, who can access it, and how your college stays in control.
Last updated: 31 August 2026
Student data uploaded by a college is used to provide Tutorops to that college. We do not sell student data, use it for advertising, or make one college's records available to another college.
Only what the product needs. Everything below is either uploaded by your college or produced by the platform.
Name, student ID or roll number, department or branch, batch and graduation year, CGPA, number of backlogs, and college email address if you include it. A phone number column is accepted but is never exported or shown to recruiters.
Assessment answers and scores, skill levels derived from those answers, readiness scores per job role, skill gaps, and intervention plans and their status.
The placement officer's name, email address, phone number if provided, and a hashed password. College name, type, city, state and approximate size.
A session cookie to keep you signed in. An audit log recording significant actions — sign-in, imports, exports, payment events — with the acting user and the IP address the request came from. Standard web server logs kept by our hosting provider.
No student home addresses, family details, identity numbers, photographs, biometric data, health information or financial information. Tutorops has no field for any of these and no tracking or advertising cookies.
No student data is sent to an external AI provider today. Readiness scores, eligibility, skill levels, gap severity and intervention plans are calculated by deterministic arithmetic inside Tutorops. No language model takes part in any of them.
The one AI feature we are building reads a recruiter's job description into a draft requirement list. When that ships, the text sent to the AI provider is the job description itself — no student records, names or scores — and a person at your college confirms the result before anything is saved. If that ever changes, this notice changes with it before the feature goes live.
Read the scoring method →Student records are isolated by college. Users signed in to one college cannot reach another college's students, scores or exports through the application. We use access controls and tenant-level isolation on every query to enforce this.
Tutorops never sends student information to a recruiter. A shortlist file is created only when someone at your college generates one, and you choose what to do with it. The export contains name, student ID, department, batch, CGPA, backlogs, readiness and skill evidence. Phone numbers and personal email addresses are excluded by an allow-list in the code — not by a setting that can be switched on.
Tutorops relies on a small number of providers to operate: our hosting provider, who stores the database and serves the site; Razorpay, which processes subscription payments and receives your billing details, not student data; and email delivery for account messages such as password resets. Our pages also load fonts from Google's font service, which means Google can see the IP address of a visiting browser. Providers process information only as needed to deliver their service.
Each student receives a unique link containing a random token, so students do not need to create an account. A link belongs to one student and one assessment, and can be submitted once — after submission it shows that student's result and cannot be used to answer again.
We keep your college's data for as long as your account is active and we need it to provide the service, and after that for as long as required for security, accounting or dispute resolution. If a subscription lapses, the account falls back to the free plan and your data stays where it is — nothing is deleted automatically.
Your college can ask us to delete its data at any time. Write to privacy@tutorops.com from an official college address and we will confirm when it is done. You can also ask for a copy of what we hold, or for a correction to it.
Passwords are stored as one-way hashes and never in readable form. Password reset links are stored hashed, expire after an hour and work once. Every database query uses parameterised statements, forms are protected against cross-site request forgery, and every tenant-owned query is filtered by college. Significant actions are written to an audit log. Traffic is served over HTTPS.
We describe what we actually do rather than using phrases like "bank-grade security". Our security practices are set out in full here →
For privacy questions, access or deletion requests, or any concern about student information, write to privacy@tutorops.com. Institutions that need a written data processing agreement can request one at the same address.
Upload your student list. Run your first baseline. See who is ready, who is not, and why. Two minutes to set up, no credit card, no sales call.