Privacy
Last updated 2 September 2026
This page covers both halves of Halgo: the public site at halgo.app, and the product a tutor signs in to. They are different in an important way, so they are separated below.
On the site, the data is yours and Halgo decides what to do with it. Inside the product, most of the data is about your students, you decide what to do with it, and Halgo acts on your instructions. The terms for that second relationship are in the data processing agreement.
Part one: the site
If you ask for an invite, you send your email address to one inbox — Halgo’s — so somebody can write back to you about a place. The request identifies which invite form you used. If you accepted optional measurement, it also includes the first permitted Halgo page and referring site and, when present, campaign parameters and advertising click identifiers. Without that choice, those attribution details are neither saved in the browser nor included in the request. They are not added to an advertising audience.
They are not stored in Halgo’s database or added to a mailing list. The message is sent only through Resend, the email provider acting as our processor, to Halgo’s inbox; once delivered it lives there until it is deleted, the same as any other email you might have sent us. Ask at hello@halgo.app and it will be deleted.
Invite-form abuse check. When you first interact with an invite field, the page loads Cloudflare Turnstile. Cloudflare reads network, browser and device signals, including your IP address, to decide whether the submission looks automated. It returns a short-lived token; Halgo sends that token and the IP address authenticated by its web edge back to Cloudflare for validation before sending the email. Halgo does not store the token or raw address from this invite path. It temporarily keeps a one-way keyed label while enforcing the rate limit. This check is necessary to keep the public form from being used to exhaust or abuse the email service, so it runs independently of the optional measurement choice below.
Optional measurement. PostHog, on its EU infrastructure, records page views and clicks only after you accept the banner. It also keeps the first landing page, referring site, campaign parameters and any advertising click identifier present in that visit, so Halgo can compare where enquiries came from. After sign-in, Halgo links those events to the account’s opaque sign-in-provider ID only after asking again for that account. This prevents one person’s browser choice from being assigned to somebody else who later signs in on the same device. Halgo does not send the tutor’s email address or other account profile fields. Like any analytics request, the connection exposes network and browser details, including the IP address, to PostHog; Halgo enables PostHog’s project-level IP-discard control so the raw address is not retained in analytics events. PostHog data is not shared with advertisers.
Accepting also permits a Google Ads tag to count a server-confirmed invite request as a conversion. Accepting by itself does not load or contact Google: Halgo loads the tag only after the inbox delivery has been confirmed. The conversion contains an opaque receipt identifier and the Halgo origin and page path. It does not contain the email, form contents, referring page, UTM campaign parameters, full query string or fragment. If the visit came from Google advertising, Halgo does give the tag the validated Google click identifier captured on that first page; without it Google cannot connect the confirmed request to the ad. Like any web request, the conversion also exposes network and browser details such as the IP address and user agent, and Google may use consented advertising-measurement storage. Advertising personalization remains off. If you decline, the tag is never loaded and no Google measurement request is sent.
Accepting also switches on session replay: a recording of what happens on screen while you use Halgo. Text you type into a field is masked, and everything else on the page is not — so if you accept for a signed-in account, a replay of that dashboard contains your students’ names as they appear on it. Your students’ own screens are excluded from analytics entirely. If that is not a trade you want to make, decline the account prompt; nothing else changes.
Sign-in cookies. If you sign in, Clerk sets a session cookie. Without it you would be signed out on every page. It is not used for advertising.
You can accept, decline or change optional measurement at any time. The button below controls this browser’s public-site measurement and Google conversion. A signed-in account has its own control under Settings → Account → Optional measurement. Revoking the relevant choice stops future PostHog capture and session replay and prevents another Google conversion. If a confirmed conversion already loaded Google code, changing the choice cannot recall the event already sent. It does not delete measurement already received; ask at the address above if you want Halgo’s copy removed.
Part two: the product — who is responsible for what
A tutor decides which students to record, what to write about them and what to keep. In data protection language the tutor is the controller and Halgo is the processor. If you are a parent or a student, the person to ask about your data is your tutor, not Halgo — and the section on requests below says what Halgo can do to help them answer you.
Halgo is the controller of one thing only: the tutor’s own account — their name, email address, sign-in and subscription state.
What the product holds about a student
Identity and contact
Name, and optionally a date of birth, email address, phone number, parent’s name and phone, and address. All of these are typed in by the tutor and none is verified. The email is often a parent’s.
Teaching records
Lessons and their times, attendance, free-text lesson notes, goals, homework, boards, practice answers and mastery estimates. The free-text fields hold whatever the tutor writes, which in practice can include health, family or learning-difficulty information.
Money
Payments recorded by the tutor, packages, and what is owed. No card numbers: Halgo never sees a student’s payment details.
A sign-in, if the tutor issues one
A student or parent who is given a link gets an account with no password and no email address of its own. The link contains a random token; Halgo stores only a hash of it. It lasts six months by default. Whoever holds the link can use the account, which is why it should be sent to the family and not posted anywhere.
Lesson recordings
Only if the tutor switches them on for that student, and only with a consent record on file. Not currently in service — see below.
Who else sees it
Halgo sends the minimum needed to do the job, and never a student’s email address, phone number, postal address, date of birth or payment details to an AI provider — those are stripped at one boundary before any request leaves. Names, exercise text and lesson notes do go, because that is the material being worked on.
Anthropic
Reads textbook pages, writes exercises and cards, answers chat. Every request carries a zero-retention header. Being straight about this: that header is Halgo’s own assertion, it is not a documented Anthropic API feature, and nothing checks that it was honoured. Treat it as intent, not as a guarantee.
Voyage AI
Turns exercise text into vectors so similar exercises can be found. No retention assertion is sent to Voyage.
ElevenLabs
Reads listening-exercise text aloud, when a tutor asks for audio.
Cloudflare R2
Stores uploaded files: textbook PDFs, page images, generated PDFs, audio.
Cloudflare Turnstile
Checks invite-form submissions for abuse using the visitor’s IP address and browser or device signals. Halgo’s server-side validation request contains no email address or form contents.
Railway
Runs the API and the database.
Vercel
Serves the web app.
Clerk
Signs tutors in.
Resend
Sends the few emails Halgo sends.
Stripe
Handles subscription payments by tutors. Not in use during the beta.
LiveKit
Would carry audio and video for the in-product call. It is not configured on the live service today, so no call media or participant log is being processed there.
Recall.ai
Would join a Zoom or Meet call to transcribe it. Not configured on the live service, so no recording is being made today.
Google Calendar
Only if a tutor connects it. Lessons are then written into that tutor’s own calendar, carrying the student’s name.
Pexels
Supplies stock photographs for practice cards. It receives the search words, not student data.
PostHog
Product analytics, and — for a tutor who accepted the banner — session replay of their own screens, which shows their students’ names as rendered text, plus first-touch campaign attribution linked to an opaque account ID. Tutor email and account profile fields are not sent. The request exposes ordinary network and browser details to PostHog, whose project-level setting discards raw IP data. Students’ and parents’ screens are excluded from analytics altogether.
Google Ads
Counts a confirmed invite request after the visitor accepted optional measurement. Halgo contacts Google only after server-confirmed delivery and sends an opaque receipt plus the Halgo origin and query-free page path. For a Google Ads visit it also supplies the validated Google click identifier needed for attribution — not the rest of the query. It does not send the email, form contents, referrer or UTM campaign parameters. Google still receives ordinary network, browser, device and online identifiers, while advertising personalization remains disabled.
Sentry
Error reports. Credentials are stripped and PII collection is off; a student’s name that appears inside an exception message is not removed by anything.
Children
Most people a tutor teaches are children, so this section is the one worth reading twice — including the parts that say Halgo does less than you might assume.
Halgo never contacts a student on its own. There are no student adverts, no marketing, no nudges. Exactly one message can ever reach a student — a balance reminder — and it is off unless both the tutor and the operator switch it on.
What a parent is asked to agree to is three specific things, each one recorded and each one withdrawable at any time from the parent’s own screen: their child having a Halgo sign-in of their own; a lesson being recorded and transcribed; and Halgo emailing the child. Withdrawing recording consent also cancels recordings already booked for that student’s future lessons.
What that consent does not cover. It is not a precondition of a tutor keeping records about a child in Halgo at all — the tutor can create and hold a student record without any consent record existing. Whether that is lawful is the tutor’s responsibility as controller, and it usually depends on a relationship the parent already has with them.
Ages are not verified. Date of birth is an optional field the tutor types, and most records do not carry one. Where it is missing, Halgo cannot tell whether a parent needs to be asked, and it does not assume one does. A parent account is created by opening an invite link — there is no password and no identity check, so anyone holding that link is treated as the parent.
A student cannot consent for themselves in Halgo, even where local law would let them. The decision sits with the tutor and the parent.
The table of consent ages by country that the product uses has not been reviewed by a lawyer. It is a default, not a legal determination.
How long anything is kept
Plainly: until someone asks for it to go. Halgo runs no retention schedule and deletes nothing because it has reached an age. Lessons, notes, transcripts, chat messages, boards, practice history and payments stay until a tutor erases the student or the account.
The exceptions are small and go the other way: a share link expires on its own schedule, and a student’s sign-in token expires after six months.
Asking for a copy, or for erasure
If you are a tutor: open a student, go to their data page, and export or erase from there. The export is a file you download; the erasure shows you exactly which records will go and which will remain before you confirm, and leaves a receipt.
If you are a parent or a student: ask your tutor. They hold the records and the controls. Halgo has no self-service request path for you, and will not act on your data without the tutor’s instruction — because acting on it would mean taking a stranger’s word about a child’s records.
If your tutor does not answer, or you believe your data is being handled wrongly, write to hello@halgo.app. Requests are answered within 30 days.
What erasure reaches, and what it does not. It removes Halgo’s own database rows and its own stored files. It does not rewrite the hosting provider’s backups, which expire on their own schedule; it does not recall emails already delivered; it does not remove lessons already written into a tutor’s Google Calendar; and it does not instruct any AI provider to delete anything. Some rows are deliberately kept and stripped of identity instead — an erasure record, and the accounting entries a tutor needs — and the screen names them before you confirm.
Deleting a tutor’s account with the sign-in provider does not by itself erase their Halgo data. Ask, and it will be done by hand.
Security, without the usual adjectives
Every request to the database starts with no permission at all and has to earn the caller’s own slice — the isolation between tutors is enforced by the database, not only by application code, so a query that forgot its filter returns nothing rather than somebody else’s rows.
What that does not cover, stated because a privacy notice that only lists strengths is not informative: it is not a defence against a stolen database credential, and thirteen tables are deliberately outside it for recorded reasons. Halgo does not add its own encryption at rest — that is a property of the hosting providers — and free-text notes are stored as written. Transport to the database and to Redis runs on the providers’ private networks.
Halgo’s own application does not derive a device or browser fingerprint. Anonymous abuse controls temporarily keep an IP address in a Redis rate-limit key, or in a process-local fallback while Redis is unavailable; the invite form keeps only the one-way keyed label described in part one. These values are not put in a profile or product record. Cloudflare Turnstile separately processes the network, browser and device signals described in part one, and a consented Google conversion exposes the browser, device and online identifiers described above; neither becomes a Halgo database profile.
Where it is
Halgo does not pin its infrastructure to a region, and it would be untrue to tell you that everything stays in the EU. The database and API run on Railway in Europe today; object storage is Cloudflare R2, which distributes automatically; the AI providers are reached at their global endpoints, which means processing can happen outside the EEA under those providers’ own transfer terms.
Changes
If Halgo starts collecting something new, this page changes before it starts, not after. The date at the top is when it last did.