Privacy notice
What the site stores about you
A plain-English description of the information used to run accounts, learning tools, enquiries and tutoring services.
Status of this notice
Self-drafted on 12 August 2026, and self-drafted still. This notice describes the site as it works today. It is not a claim of certification, external approval or professional legal review. No solicitor has read it. A professional review is intended during the 2026/27 academic year; until this section says otherwise, it has not happened.
Who is responsible and how to contact us
Oscar Song Tutoring is run by Oscar Song. Use the site's contact page for an access request, deletion request, correction, privacy question or complaint. The contact page is the source of truth for the current address, so this notice does not repeat a personal mailbox that is due to change.
What is collected
- Enquiries: whether the message is from a student or parent or guardian, name, email address, optional phone number, optional year group, selected subjects, optional exam board and the message. These fields are saved as an enquiry and used to reply.
- Content reports: when report storage is enabled, the site saves the reported question or notes identifier, page path, selected reason, status and time. A contact email is optional and is the only personal-information field in the report; it is used only if a reply about that report is needed.
- Free accounts: email-and-password sign-in and emailed magic-link sign-in are handled by Supabase Auth. The application stores an account ID, name, email address, year group, student role and the marketing choice made at signup. A user can later add or change profile fields such as phone number and exam board. Supabase Auth stores and verifies the password where one is used; the site database does not store a readable copy.
- Learning progress: course and tier choices, question, mechanism and card attempts, best scores, completion states, flashcard reviews, specification-point mastery, written-response progress and study streaks. Saved rows are tied to the signed-in account ID.
- First-party site measurement: the site can store limited funnel events such as page or tool use, with a page path, referring page, random browser ID and signed-in account ID where the event is not aggregate-only. Separate steering events contain only an event name, surface and optional timing value.
- Anti-abuse rate limits: public write routes process the proxy-observed IP address into a keyed hash used with counters and time windows. The limiter does not store the raw IP address.
- Tutoring records, if the tutoring service is used:profile and family links, bookings, messages, plans, homework and uploads, reports and mocks (including drafts), paper assignments and payment history needed to deliver and administer tutoring. The account data export includes only approved reports and mocks.
Guest progress on this device
Many learning tools work without an account. Their progress and preferences are kept in this browser's localStorage. They stay on that device until the browser storage is cleared. When a user signs in, supported account-backed progress is attached to that account and merged into its Supabase progress rows so it can follow the user across devices. Browser-only drafts, histories and preferences stay on that device. Browser storage does not make the site an offline app: an internet connection is still needed to reliably open or reload pages and to sync account progress.
Why the information is used
The information is used to answer enquiries, create and secure accounts, remember learning progress, provide requested resources, administer tutoring where it has been arranged, send service emails, prevent misuse, fix faults and understand which routes and tools are being used. Marketing email is optional at signup and can be stopped.
Where it is stored
Account authentication is in Supabase Auth. Enquiries, profiles, progress and linked service records are in the Supabase Postgres database; private account files use Supabase Storage. The configured Supabase project is in the London region. Guest progress is stored in the browser on the device being used. The website itself runs on Vercel.
Infrastructure and processors
- Supabase provides email-and-password authentication, the London-region Postgres database and private file storage used for accounts, enquiries, progress and tuition records.
- Vercel hosts and serves the website and processes the ordinary connection and request information needed to do that; Vercel Analytics is not integrated in the current app.
- Resend delivers transactional emails generated by the site, including enquiry notifications and account or tuition service messages.
- Cloudflare provides DNS for the domain (website traffic only, not an email service) and may process ordinary connection information while directing a request; the application records described here are not stored there.
The code also contains an optional Plausible script, but it is not enabled in the recorded production configuration. This notice and the processor list must be updated before that changes.
How long information is kept
There is no automated age-based retention or deletion schedule for enquiries, content reports, account records, synced progress, first-party measurement events or anti-abuse limiter rows. Identifiable records are kept until they are deleted through an available account flow or handled following a request through the contact page. Pseudonymous hashed anti-abuse limiter rows persist until manual pruning. Guest progress remains in localStorage until the user clears it. Shared tutoring and payment records are not automatically erased by closing one account because they can also belong to a family or the tutoring service.
Download your information
A signed-in user can choose Download my data (JSON) on the account page. The export includes Supabase Auth account metadata and the profile, progress and eligible service rows identified as that user, plus child rows belonging to those records. The account page also adds the learning progress, preferences and drafts stored for that account in the browser used to make the download. It excludes other family members' rows, tutor-private notes, reports that have not been published or approved, draft plans and homework sets, unsent gap patches and draft mocks.
Delete your account
The account page has a self-serve control that requires the user to type DELETE. The supporting database safety migration is currently staged rather than applied, so the live route stops safely before deleting anything and tells the user to retry or use the contact page.
Once that support is enabled, deletion of an unlinked free account removes its Supabase Auth sign-in and the profile, progress, account-owned learning or tutoring rows and owned avatar or homework files that are linked by deletion rules. Files are moved to private quarantine before the sign-in is removed; a daily recovery job finishes safe deletion or restoration if that storage step is interrupted. Shared messages, uploaded-homework attribution and booking-request attribution can remain with the account reference removed. A student account linked to a tutoring family is stopped for a safeguarded anonymisation review instead of erasing shared lesson history automatically. Parent deletion does not automatically remove the family's tutoring and payment history.
If you are a student
Your free account stores your name, email address, year group, course choices and learning progress so the site can remember where you got to. You can see the download and deletion controls under Your account. While self-serve deletion is unavailable, use the contact page and ask for the account to be removed. Free accounts are for people aged 13 or over. If you are under 13, ask a parent or guardian to contact us instead. For help with a safety concern, see the safeguarding page.
Your choices and complaints
You can ask for access, correction or deletion through the contact page. Depending on the information, you may also ask for restriction, portability or object to its use, and you can withdraw a marketing choice. Shared records or records that must be kept for another reason may need separate handling; the response will explain this rather than silently deleting someone else's information.
You can also complain to the Information Commissioner's Office, the UK supervisory authority.
Changes to this notice
Material changes will be dated here. The notice will be updated when a data flow, processor or deletion capability changes.