Privacy and learning analytics
Last updated: 30 August 2026.
TutorLumin uses limited analytics to keep the website working, understand whether booking and payment journeys succeed, and help signed-in learners see their recent progress. We do not sell this information or use it for advertising.
Who is responsible
Henry Sheehy, operating TutorLumin, is the controller for the TutorLumin personal information described here. QuantaLumin provides the self-hosted technical platform under the same operator. Use the protected TutorLumin contact route for privacy questions or rights requests; please do not put private information in a public issue or source-code repository.
Accounts, bookings, support and payments
When you ask for an account, course, tutoring session or support, the relevant service processes the contact, account, scheduling and service information needed to provide it. Booking and registration records stay in their owning services rather than being copied into the public website or analytics store.
Payment providers process the payment details required for their method. Card details stay with Stripe; bank transfers are handled by the applicable bank. TutorLumin and QuantaLumin retain the payment reference, amount, currency and status needed to reconcile the purchase and meet accounting duties. Do not send card or bank credentials through the contact form.
Public website visits
We count ordinary page requests from our own server logs. We do not load a browser analytics tracker or set an analytics cookie. Before a pageview reaches our self-hosted Matomo service, the importer excludes bots, static files, errors, health checks and internal requests. It uses an anonymised, rotating visitor value rather than a signed-in account identity.
Signed-in learning activity
When you use supported learning activities, the site may record:
- that an activity was started or completed;
- that an assessment was submitted and its percentage score;
- a short, bounded engagement duration;
- a fixed difficulty signal chosen by you;
- the course, activity and content-version identifiers.
The site replaces your account identity with a one-way identifier that is specific to TutorLumin. The analytics service does not receive your name or email address. It rejects answers, free-text responses, keystrokes, passwords, authentication details and cookies.
Your recent activity produces a small progress summary that you can see while signed in. A percentage or difficulty signal is context for learning support; it is not an automatic grade or judgement about ability.
Booking, registration and payment journeys
Our services record coarse milestones such as a reservation being created, checkout starting, payment succeeding and registration completing. These events help us find broken journeys and view aggregate conversion counts. The analytics event does not contain card details. Learning progress and payment events must not be combined to rank a learner or decide their eligibility.
Who can see it
- You can retrieve your own recent learning-progress summary through your signed-in session.
- Tutors and educators do not currently have a production analytics dashboard or access to raw event histories.
- A small number of authorised operations staff may use protected access for service incidents, retention and verified privacy requests.
- Product reporting uses aggregate journey counts rather than learner-level browsing.
If educator access is introduced later, it must be limited to assigned learners, show only the minimum useful progress summary, and receive a fresh privacy review before release.
Retention and choices
Private learning events, their delivery receipts and progress summaries expire 90 days after the relevant event or last activity. Protected database backups are retained for up to 30 days. Matomo raw visit logs expire after 90 days; aggregate reports may remain.
Account, booking, support and financial records have different retention requirements. They are kept only for the service, dispute, safeguarding and legal/accounting periods that apply to their owning system, then deleted or anonymised. Closing an account does not require erasure of a record that must be retained to meet a legal obligation.
Why we process information
We use information needed to provide an account, course, booking or payment under our contract with you. We use limited security, public page measurement and service-improvement information for our legitimate interests in operating a safe and effective service; the short retention, pseudonyms, no-advertising rule and access limits protect learners’ interests. We retain financial records where the law requires it. We do not use consent as a condition for analytics that is necessary to provide requested progress features; optional future uses will receive their own lawful-basis review.
Sharing and international transfers
We use infrastructure and communication providers to operate the service and payment providers such as Stripe or the applicable bank to complete payments. They receive only the information needed for their role. We do not give learning analytics to advertisers or data brokers. Where a supplier processes information outside the UK, we require an applicable UK transfer safeguard and review its data-processing and subprocessor terms.
You can ask what information we hold, request a correction or restriction, or ask us to erase applicable analytics information. These rights depend on the circumstances, but requests about information collected from children receive particular care. A parent or guardian may contact us where appropriate.
Contact TutorLumin{.button.primary}
You may also complain to the UK Information Commissioner’s Office. We would appreciate the opportunity to address the concern first, but contacting us is not a condition of making a complaint.