Data processing

Last updated 2 September 2026

These terms apply whenever you use Halgo to keep records about your students. They form part of the terms of service and take effect when you first put a student into Halgo.

You are the controller: they are your students, you decide what to record and why. Halgo is your processor: it does what the product does, on your instruction, and nothing else with that data.

What Halgo is instructed to do

Your instructions are the actions you take in the product. Halgo processes your students’ personal data to: store their records; schedule and mark lessons; track payments and balances; generate homework, exercises and practice cards from your material; answer your questions in chat about your own students; and give a student or parent their own read-only access. The separately consented lesson transcription workflow is not configured on the live service today; it will be an additional instruction only if it is enabled later.

Halgo will not process that data for anything else. It is not used to train models, not sold, not rented, not used to advertise, and not shared with another tutor. Halgo does not contact your students on its own initiative — exactly one message can ever reach a student, a balance reminder, and it stays off unless you switch it on.

Kinds of data, and whose

Data subjects: your students, and where a student is a child, their parent or guardian.

Categories: name; optionally date of birth, email, phone, address and a parent’s name and phone; lesson times and attendance; free-text notes and goals; homework, board content and practice answers; mastery estimates; payments and balances. Lesson transcripts and summaries are a planned category, but the workflow that would create them is not configured on the live service today.

The free-text fields are the ones to think about. Halgo does not restrict what you type into a lesson note, so whether a health condition or a family circumstance ends up in Halgo is your decision, not the product’s.

Sub-processors

Halgo uses the following, each under its own terms. This list is complete as of the date above; the shorter list shown inside the product is not.

Railway

API and PostgreSQL database hosting.

Cloudflare R2

Object storage: uploaded PDFs, page images, generated files, audio.

Vercel

Web application hosting.

Clerk

Tutor authentication.

Anthropic

Language models: reading textbooks, writing exercises and cards, grading, chat.

Voyage AI

Text embeddings for exercise similarity.

ElevenLabs

Speech synthesis for listening exercises.

Resend

Email delivery.

Stripe

Tutor subscription payments.

LiveKit

Would carry real-time audio and video for in-product calls. Not configured on the live service today.

Recall.ai

Meeting transcription, if you switch it on. Not configured on the live service today.

Google

Calendar synchronisation, if you connect it.

Pexels

Stock imagery for practice cards.

PostHog

Product analytics, and session replay of a consenting tutor’s own screens — which captures students’ names as rendered text. Screens belonging to students and parents are excluded from analytics entirely. Declining the banner switches both off.

Sentry

Error reporting.

You will be told before a new sub-processor starts handling student data, and you may object by telling Halgo to stop and closing your account.

Cloudflare Turnstile protects the anonymous invite form on the public site, but is not a sub-processor of the student records covered by this agreement: it receives network, browser and device signals from the prospective tutor and no student data. That separate processing is described in the privacy notice.

What is sent to the AI providers, and what is not

One boundary in the code decides this, and every model call passes through it. It removes email addresses, phone numbers, postal addresses, dates of birth, IBANs and card numbers before a request leaves.

It does not remove names, exercise text or lesson notes, because those are the material the model is being asked to work on. Two honest limits: an unlabelled date or address written without a cue word can survive the filter, and images — textbook page renders, exercise crops, files you attach in chat — are sent as they are and cannot be redacted at all.

Requests to Anthropic carry a zero-retention header. It is Halgo’s assertion, not a documented Anthropic mechanism, and no response is checked to confirm it was honoured. It is stated here as what Halgo sends, not as a guarantee about what Anthropic keeps.

Helping you answer your students

When a parent or student asks you for a copy of their data or for it to be deleted, you answer — and Halgo gives you the tools in the product. Each student’s page has an export and an erasure, and the erasure shows exactly which records will go and which will remain before you confirm.

Halgo will not act on a request made directly by a student or parent without your instruction. If one reaches Halgo, they are pointed back to you.

The limits of erasure, so you can answer accurately when asked. It removes Halgo’s database rows and stored files. It does not rewrite the hosting provider’s backups, which expire on their own schedule; it does not recall emails already delivered; it does not remove lessons already written into your Google Calendar; and it does not instruct any sub-processor to delete anything of its own. Some rows are retained with identity removed — the erasure record itself, and accounting entries — and the screen names them first.

Retention

Halgo keeps your students’ data until you erase it or close your account. There is no automatic deletion by age and no retention schedule; nothing expires on its own. Deciding how long to keep a former student’s records is yours to make, and Halgo will not make it for you by quietly deleting them.

Security measures

Access between tutors is separated at the database itself: a request begins with no permission and earns only the caller’s own rows, so a query missing its filter returns nothing rather than another tutor’s students. Credentials are stripped from logs and error reports. Uploaded files are reachable only through short-lived signed links. Tokens that grant access — invite links, share links — are stored hashed and encrypted rather than in the clear.

What is not the case, stated so you are not relying on it: Halgo adds no encryption at rest of its own beyond those tokens, so at-rest protection is whatever Railway and Cloudflare provide; thirteen tables sit outside the database-level separation for recorded reasons; and the separation is not a defence against a compromised database credential.

Only the founder has administrative access to production. There are no other staff.

When you withdraw a student’s access

Revoking a file you gave a student stops new access immediately, but a download link already issued keeps working for up to five minutes while it expires. If that matters for a particular file, remove the file rather than only revoking the link.

Breaches

If Halgo becomes aware of a personal data breach affecting your students, you will be told without undue delay and given what is known — what happened, which data, and what is being done — so you can meet your own obligation to notify. Halgo will not notify your students or a regulator on your behalf; that decision is yours as controller.

Transfers

Halgo does not pin processing to a region. The database and API run in Europe today; object storage is distributed by Cloudflare; and the AI providers are reached at their global endpoints, so processing can take place outside the EEA under those providers’ own transfer mechanisms. If your own obligations require EEA-only processing, Halgo cannot currently give you that.

Ending

When you close your account, export what you want to keep first. Ask at hello@halgo.app and your data and your students’ data will be erased, subject to the limits set out above.