Privacy Policy
This Policy explains what personal data Lectly handles, why it is needed, where it goes, how long it is kept, and the choices available to tutors, students, guardians, and visitors.
Effective and last updated: 18 July 2026
1. Who is responsible for your data
Lectly is a pre-launch project operated from Poland. Lectly is the controller for personal data used to run lectly.net, manage accounts, keep the service secure, communicate with users, and understand the product where optional consent has been given.
Contact: [email protected]. We have not appointed a data protection officer.
2. When Lectly is controller or processor
Tutors normally decide the educational purpose for student profiles, lessons, homework, messages, progress records, and scheduling data. For that tutor-controlled material, the tutor is responsible for the lawful basis, transparency, accuracy, and guardian permissions, and Lectly processes the material to provide the requested workspace.
Lectly separately acts as controller for each user's account, authentication, service security, support, essential communications, and optional product analytics. A tutor's own privacy notice may therefore also apply to a student. Questions about the tutor's teaching decisions should first be directed to that tutor; we will assist with requests concerning data held in Lectly.
3. Personal data we process
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email address, profile image, user and invitation IDs, authentication status | You, your tutor, and Clerk |
| Tutor profile | Subjects, teaching context, goals, student-count range, lesson-preparation preferences, language, onboarding responses | The tutor |
| Student profile | Name, email, course, level, discipline, learning language, interests, goals, requested topics | The student, guardian, or tutor |
| Educational content | Lesson topics and plans, source files, homework, answers, scores, feedback, flashcards, code, and progress | Tutors, students, and generated output |
| Communications and scheduling | Messages, notes, availability, session requests, meeting links, calendar event IDs and status | Tutors, students, and optional Google integration |
| Technical and usage data | IP address, browser and device details, page and feature use, timestamps, diagnostics, masked session replay, security events | Your browser, our servers, and PostHog when permitted |
| Waitlist and support | Email address, request details, and correspondence | You |
Lectly does not need medical records, biometric identifiers, government identifiers, payment-card details, or other special-category or highly sensitive data. Please do not enter that information into profiles, messages, source files, or AI prompts.
4. Why we process data and our legal bases
| Purpose | Legal basis under GDPR |
|---|---|
| Create accounts; deliver lessons, homework, messages, scheduling, files, and requested AI features | Performance of a contract or steps requested before a contract; for tutor-controlled records, the tutor's documented instructions |
| Authenticate users, prevent abuse, enforce limits, investigate errors, and protect users and the service | Legitimate interests in security, reliability, fraud prevention, and legal claims; legal obligation where applicable |
| Send invitations, service notices, support responses, and waitlist updates requested by you | Contract or requested steps; legitimate interests in service communications; consent where required for marketing |
| Connect Google Calendar and create Calendar/Meet events at the tutor's request | Performance of the requested service and the tutor's affirmative authorization through Google |
| Measure product use, performance, errors, and masked sessions through PostHog | Your consent; analytics stays off until accepted and can be withdrawn at any time |
| Maintain records needed for compliance, disputes, and responding to authorities | Legal obligation and legitimate interests in establishing, exercising, or defending legal claims |
Where we rely on legitimate interests, we limit the information used, consider the effect on users—especially children—and provide the objection rights described below. We do not sell personal data or use it for third-party behavioral advertising.
We do not create identified PostHog profiles or record sessions for student workspace accounts. Student-facing workspace and invitation routes keep browser analytics disabled even if an adult previously accepted analytics on the same browser.
5. How AI features use data
When a tutor asks Lectly to generate or revise material, Lectly sends OpenAI the information needed for that request. Depending on the feature, this can include the lesson topic, selected configuration, learner name and profile context, recent lesson topics, word-bank terms, tutor instructions, and source text, images, or documents the tutor selected. Student answers may be processed to generate feedback or explanations where the feature requests it.
OpenAI provides the model through its business API. OpenAI states that API inputs and outputs are not used to train its models by default. We request non-persistent Responses API processing; OpenAI may still retain limited inputs, outputs, and abuse-monitoring information for up to 30 days unless a longer period is legally required. See OpenAI's API data controls.
Lectly does not use AI output to make solely automated decisions that produce legal or similarly significant effects. Tutors are expected to review generated content and feedback before relying on it.
6. Service providers and other recipients
We disclose only the data reasonably needed for the following services. Vendor affiliates and their approved subprocessors may also process data under the vendor's contract and published subprocessor list.
| Recipient | Purpose and data | Primary location |
|---|---|---|
| EU VPS infrastructure provider | Hosts lectly.net and processes request, network, and security logs | European Union |
| Convex, Inc. | Application database, real-time backend, functions, and operational records | United States |
| Clerk, Inc. | Authentication, account profiles, invitations, and related service emails | United States |
| OpenAI, L.L.C. | AI generation using the prompt, learner context, and selected sources described above | United States and published subprocessor locations |
| PostHog, Inc. | Consent-based product analytics, performance, error tracking, and masked session replay | European Union (Frankfurt) |
| Cloudflare, Inc. | R2 storage for tutor-uploaded lesson source files and secure file delivery | European Union data jurisdiction |
| Google LLC | Optional OAuth connection, Calendar event and Meet link creation, and attendee invitations | As described by Google for the connected account |
We may also disclose data where required by law, to protect a person or the service, to establish or defend legal claims, or as part of a future organizational transaction subject to appropriate safeguards and notice.
7. Transfers outside the EEA
Our application hosting, PostHog analytics, and Cloudflare R2 file location are configured in the EU. Convex is hosted in the United States. Clerk, OpenAI, Google, and some vendor subprocessors may also process data outside the European Economic Area.
Where data leaves the EEA, we rely on an adequacy decision where available, including a recipient's valid EU–US Data Privacy Framework participation, or the European Commission's Standard Contractual Clauses with supplementary measures as appropriate. You may ask us for information about the safeguard relevant to your data.
8. How long we keep data
- Account, tutor, student, lesson, messaging, scheduling, and source records are generally kept while the related account or tutoring workspace is active, then deleted or anonymized when no longer needed for the service, users, legal obligations, or claims.
- Pending student invitation links normally expire after 7 days.
- Internal product events are designed for 90-day deletion; completed or failed AI request payloads for 30-day deletion; flashcard review history for one-year deletion; and completed student submissions for two-year deletion. Content still needed for an active lesson, pending review, account request, security investigation, or legal claim may be kept longer.
- PostHog analytics retention follows the EU project settings and is deleted sooner when required to honor a valid deletion request.
- Server and security logs are kept for a limited period based on operational need and the hosting provider's configuration.
- Vendors may keep backups or records for the periods stated in their contracts and legal notices. OpenAI's default API abuse-monitoring period is up to 30 days.
A tutor removing a student from a roster may not delete every linked lesson, message, or submission immediately. Contact us if a complete account or rights request is needed.
9. Cookies and similar storage
Essential storage is used without optional consent where it is needed to provide a feature you requested. Analytics storage is disabled unless you choose “Allow analytics.” Rejecting analytics does not reduce access to Lectly.
| Category | Examples and purpose | Typical duration |
|---|---|---|
| Essential | Clerk authentication and security cookies; lectly_locale for language; sidebar_state for workspace layout | Session to 1 year, depending on purpose |
| Consent preference | lectly_cookie_consent and PostHog's consent state remember whether analytics was allowed or refused | 180 days |
| Optional analytics | PostHog identifiers, product events, browser and device details, performance, errors, and masked session replay | Set only after consent; duration follows the PostHog configuration |
You can accept, reject, or withdraw optional analytics at any time. Withdrawal stops future browser analytics and clears or disables PostHog persistence on that browser; it does not affect processing that already occurred lawfully.
10. Children and student accounts
Lectly is designed to let tutors work with students who may be under 18. Student accounts are invitation-only. A tutor must have authority to provide the student's data, and a parent or guardian must authorize a minor's use where required.
For an information-society service offered directly to a child, if a processing activity relies on consent and the child is under 16, that consent must be given or authorized by the holder of parental responsibility. We ask under-16 users not to enable optional analytics themselves. Guardians can contact us to review, correct, restrict, or delete a child's data.
11. Your data-protection rights
Subject to the GDPR's conditions and exceptions, you may request access, correction, deletion, restriction, portability, or a copy of personal data; object to processing based on legitimate interests; and withdraw consent at any time. You also have the right not to be subject to qualifying solely automated decisions. Lectly does not currently make such decisions.
Email [email protected] from the account address where possible and describe the request. We may ask for proportionate information to verify identity and protect another user's data. We normally respond within one month and will explain if the GDPR permits an extension or refusal.
You may complain to the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych) through uodo.gov.pl, or to the supervisory authority where you live or work.
12. Security
We use access controls, authenticated accounts, encrypted transport, restricted source-file links, provider security controls, data minimization, and monitoring intended to protect personal data. No internet service can guarantee absolute security. Use a strong account password, protect your email account, and report suspected misuse to [email protected].
13. Changes and contact
We may update this Policy when the service, providers, or law changes. The current version will remain at lectly.net/privacy with its effective date. We will provide additional notice for material changes where required.
Privacy questions and requests: [email protected].