Privacy Policy
Version 1 · July 2026 · Adrian's Math Tuition, Singapore
This policy explains what personal data the AdrianMath student portal collects, why, and the rights parents and students have over it. Most portal users are under 18, so accounts are created only with a parent or guardian's explicit consent, given at account setup via an invite sent to the parent's email.
What we collect
- Account details — the student's name, school level, login email, and the parent's email and consent record.
- Practice work — answers and working the student submits for feedback, the AI feedback given, scores, and topic/error tags.
- Lesson information — schedule and progress records Adrian already keeps as your tutor, shown to the student in their dashboard.
Why we collect it
Solely to run the portal: grading practice work, showing progress over time, and personalising feedback to the student's recurring weak spots. We do not sell data, use it for advertising, or share it beyond the processors listed below.
Who processes it
- Anthropic (Claude API) — grades submitted work. Submissions are sent without the student's name, and Anthropic does not train on this data.
- Google (Gemini API) — reads the page image once more after grading to find where each answer sits, so ticks and comments land in the right place. No name is sent, and Google does not train on API data.
- Supabase — database, login system and the private file store for submitted pages and marked copies, hosted in Singapore (encrypted at rest; files are readable only through a signed-in session).
- Vercel — website hosting.
- Fly.io — hosts the marking service and the Telegram bot (Singapore region).
- Telegram — if you choose to use the bot, your messages and photos pass through Telegram under its own terms. Telegram is optional; everything is also available on this site.
- Resend — transactional email (invites, password resets).
- Dropbox — Adrian's own teaching materials only (notes, worksheets). Student submissions and marked copies are not stored there.
How it's protected
Each student's data is isolated at the database level — an account can only ever read its own records. Access from our systems uses least-privilege credentials, traffic is encrypted in transit, and student work is never written to server logs.
Your rights
From the portal's Settings page you can download all of the student's data or delete the account — deletion permanently removes the account, all practice work, and feedback. You can also email us to access, correct, or delete data, or to withdraw consent (which ends portal use). Inactive practice data is periodically purged.
Contact
Data protection is handled by Adrian Fong (tutor and data protection officer). Questions, corrections, or complaints: message Adrian directly or email ablnon@hotmail.com. If we ever become aware of a data breach affecting your child, we will notify you and, where required, the PDPC.