Privacy Policy
Last updated: · version 1.0
This policy describes what the Site and the application actually do with your data as of the date above.
This English version is provided for convenience. Only the French version is legally binding.
Who is responsible for your data
The data controller is Mathieu Soysal, publisher of the Site (see the legal notice), reachable at contact@teacher-and-me.com. No data protection officer has been appointed.
This policy covers the website teacher-and-me.com, the application reached from it and the public pages it generates (blog, level test, path catalogue). It describes what the Site actually does with your data as of the date at the top of the page.
Tutors, students and who is responsible for what
The Site has two kinds of users: tutors (independent teachers), who create paths of exercises, and students, who follow them. Everyone creates their own account on the same sign-in page; the role is chosen at sign-in and can be changed at any time.
For accounts, sign-in, security, audience measurement and the general running of the Site, the publisher is the data controller.
A tutor who enrols a student on a path (by e-mail address), writes exercises, reads their students’ progress or sends them messages decides why and how that data is used in their own teaching. For that teaching data the tutor is the controller and Teacher and Me processes it on the tutor’s behalf, as a processor, for the sole purpose of providing the service. A written data-processing agreement (Article 28 GDPR) is available on request at contact@teacher-and-me.com. The tutor is answerable for the lawfulness of the data they enter about their students, including the parental authorisation required for students under 15 (see “Minors”).
The data we process
Account
E-mail address, display name (by default the part of your e-mail address before the @; editable in Settings), role (tutor or student), the “hide my profile” option, creation date and a technical id. We record no date of birth, phone number, postal address or photo.
Sign-in and security
- E-mail code: a 6-digit code, stored hashed, valid 10 minutes. On the very first sign-in with an unknown address, the account is created immediately for that address, without first verifying the mailbox; code verification applies from the next sign-in on. Only use an address you own.
- Google account: Google sends us your e-mail address and display name; we keep no other data from your Google account.
- Passkey: credential id, public key, signature counter, transport type, creation and last-use dates. The private key never leaves your device.
- Session: an access token valid 15 minutes, kept in memory, and a single-use refresh token valid 7 days, stored in your browser’s local storage and, hashed, on our servers. No password is ever requested or stored for your account.
- No IP address is stored in our databases. IP addresses are used transiently by Cloudflare to rate-limit requests and protect the Site against abuse, and appear in its technical logs (see “How long we keep data”).
Teaching content (tutors)
Paths, lessons and exercises (questions, choices, expected answers, explanations, optional YouTube link), audio clips you record or upload (stored inside the exercise itself), the list of your enrolled students and of the e-mail addresses you invited, messages sent, paths published in the public catalogue.
Learning activity (students)
Exercises completed, position in the path, experience points, activity streak, time spent, number of attempts, answers typed (including wrong answers and the transcripts of pronunciation exercises), skipped exercises, a timestamped attempt log, the availability you declare for bookable lessons, your exam goal (exam, date, target level). The tutor of a path sees all of this for the students enrolled on that path; you can erase your progress at any time, and your tutor can erase your progress on their paths.
Pronunciation exercises
Your microphone audio is transcribed in your browser; the recording is never sent to our servers. Only the transcript and the score are sent. On first use your browser downloads the speech-recognition model from Hugging Face’s and jsDelivr’s servers, which then see your IP address.
Messages
Tutors can send messages (congratulations, encouragement) to the students enrolled on their paths: content, sent date, read date. There is no student-to-tutor messaging. Each party can delete their own messages; a tutor can also delete the messages of a student they teach.
Public path catalogue
When a tutor publishes a path in the public catalogue, its title, description, README, language, level, skills and audience are shown publicly, with the tutor’s name unless they enabled “hide my profile”. Reviews (stars and text) are shown without a name, as a verified acquirer; comments are shown with the name chosen when posting; reports (reporter, reason, note) stay internal. The catalogue’s public pages are regenerated at every update of the Site and once a day, so a removal reaches them within 24 hours.
Welcome questionnaire (tutors)
When you first set up the tutor area, three answers (role, number of students, goal) are kept in your browser and sent to analytics as event properties.
Technical data
Cloudflare keeps technical logs of a share of requests (one in 5): IP address, requested URL, request and response headers and metadata. Our error logs contain no name or e-mail address.
Why, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service: accounts, paths, progress, messages, catalogue, offline use | account, teaching content, learning activity, messages, browser storage | performance of the contract (the terms of service); for teaching data, the instructions of the tutor acting as controller |
| Securing accounts and the Site: codes, tokens, passkeys, rate limiting, logs | sign-in data, IP address (transient, logs) | legitimate interest in the security of the service |
| Sending the sign-in e-mails | e-mail address | performance of the contract |
| Teaching assistant (tutors) | your questions, the anonymised context of your paths and students | performance of the contract, at your request |
| Handling your feedback and automatic error reports | comment, account e-mail address, technical data you tick | legitimate interest in fixing and improving the service |
| Audience measurement, session recording, heatmaps | see the dedicated section | consent (Article 82 of the French Data Protection Act); see the dedicated section for the actual situation as of the date above |
| Answering your requests and honouring your rights | your request, your e-mail address | legal obligation |
No data is sold, rented or used for advertising. We send no newsletter and no marketing e-mail.
Teaching assistant (artificial intelligence)
Tutors have an assistant that answers their questions about a student’s or a path’s results and can suggest changes to a path, applied only if the tutor approves them. Students have no access to it. It runs on Cloudflare Workers AI, with the @cf/mistralai/mistral-small-3.1-24b-instruct model and, beyond a monthly quota or when that model is unavailable, @cf/meta/llama-3.1-8b-instruct-fast.
- What is sent: your question and a context (at most 16,000 characters) built in your browser from the path’s titles and content, statistics and wrong answers. Your students’ names are replaced with “Student A”, “Student B” and so on before anything is sent; the application reminds you of this every time.
- What is kept: the context is neither stored nor logged by our servers. The question and the answer of each exchange are kept, limited to the last 24 messages per discussion, until you clear them (“New conversation”). Usage counters (token counts) are kept per tutor.
- Where: discussions are stored in a North American region of Cloudflare (United States); the models run on Cloudflare’s global network.
- Use by the provider: under its published terms, Cloudflare does not use this content to train models or improve its services, and does not make it available to any other customer.
- No decision with legal or similarly significant effects is made automatically: the assistant suggests, the tutor decides.
Audience measurement, session recording and heatmaps (PostHog)
The Site and the application use PostHog. As of the date of this policy, this is what actually happens:
- a
ph_phc_uNHEKAjjPRnUcjLzTWRka6QiYonjCTW3E7AD4E3YCtHb_posthogcookie, valid 365 days, is set on the.teacher-and-me.comdomain as soon as you arrive on the Site, together with local-storage and session-storage keys (see the table below); - page views, load times and browser performance metrics are measured;
- clicks and interactions with the pages are collected automatically (“autocapture”);
- browsing sessions are recorded (“session replay”), including the browser console messages;
- click heatmaps are produced;
- after you sign in, events are tied to your account’s technical id and your role, never to your name or e-mail address; that link is broken when you sign out;
- your IP address is sent to PostHog with every event.
In the application, the content of input fields is masked in the recordings; the rest of what is shown on screen (for example your students’ names, the content of your paths or your messages) may appear in them. On the public pages (home, blog, level test) PostHog applies its default masking: input fields masked, visible text recorded.
These trackers are not strictly necessary to run the Site: under Article 82 of the French Data Protection Act they require prior consent. As of the date above, the Site shows no consent banner and offers no setting to refuse them. You can prevent them by blocking or deleting the cookies and storage of the teacher-and-me.com domain in your browser, or with a content blocker: the Site and the application work normally without them. This page does not load PostHog.
The data is hosted by PostHog, Inc. on its European cloud in Frankfurt (Germany) and travels through the subdomain tele.teacher-and-me.com, a relay provided by PostHog and served by Cloudflare. PostHog keeps events for up to 7 years and session recordings for up to 90 days.
Feedback, bug reports and automatic reports
The application’s feedback button (and, for tutors, the automatic report sent when the assistant fails) records your comment, the date, the type of feedback, your account’s e-mail address, attached automatically when you are signed in, and, only if you tick the corresponding boxes, your screen size and browser description. This record is kept 14 days in a Cloudflare storage space.
Your comment is then rewritten by an AI model (@cf/mistralai/mistral-small-3.1-24b-instruct) instructed to remove personal information and posted as a ticket in a private GitHub repository. If that automatic anonymisation fails, the comment is posted as is. Your e-mail address is never sent to GitHub.
E-mails
We only send service e-mails: the sign-in code, and nothing else. They are sent from no-reply@teacher-and-me.com through Cloudflare Email Service. There is no newsletter and no marketing e-mail. The Site sends no invitation e-mail: a tutor who invites a student shares the link themselves, from their own mail client. The “e-mail me my results” form of the level test currently sends no message and does not transmit the address entered.
Recipients and processors
Your data is shared only with the providers below, which either process it on our behalf (processors) or are contacted directly by your browser at your request (independent third parties, responsible for their own processing).
| Provider | Role | Functions | Data location | Transfers outside the EU |
|---|---|---|---|---|
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107 European entity: Cloudflare France SAS, 6 place de la Madeleine, 75008 Paris privacy policy | Processor | hosting of the Site and its API; databases and file storage; running the AI models (assistant, anonymisation of feedback); sending the sign-in e-mails; technical logs and abuse protection; relaying the analytics traffic | databases in its European regions (details below); global network for delivery, security and AI | EU-U.S. Data Privacy Framework certification and European Commission standard contractual clauses |
| PostHog, Inc. 2261 Market St. #4008, San Francisco, CA 94114 privacy policy | Processor | audience measurement, session recording, heatmaps | Frankfurt (Germany), through Cloudflare’s global network | EU-U.S. Data Privacy Framework certification and European Commission standard contractual clauses |
| GitHub, Inc. 88 Colin P. Kelly Jr. St., San Francisco, CA 94107 European entity: GitHub B.V., Prins Bernhardplein 200, 1097JB Amsterdam privacy policy | Processor | receiving anonymised feedback (private tickets) | United States | EU-U.S. Data Privacy Framework certification and European Commission standard contractual clauses |
| Google United States privacy policy | Independent third party | signing in with a Google account, at your request; thumbnails of the YouTube videos a tutor links | United States | not applicable: your browser contacts it directly, at your request |
| Hugging Face, Inc. United States European entity: Hugging Face SAS, 9 rue des Colonnes, 75002 Paris privacy policy | Independent third party | downloading the speech-recognition model | United States | not applicable: your browser contacts it directly, at your request |
| jsDelivr (cdn.jsdelivr.net) privacy policy | Independent third party | downloading the speech-recognition model | not stated by the provider | not applicable: your browser contacts it directly, at your request |
| Ko-fi Labs Limited Suite 501, The Nexus Building, Broadway, Letchworth Garden City, Herts, SG6 9BL (company no. 11087704) privacy policy | Independent third party | donations, on its own platform | United Kingdom | not applicable: your browser contacts it directly, at your request |
Where your data is hosted
Our databases are spread over the following Cloudflare regions (D1 and R2), as configured on the date above:
| Data | Region |
|---|---|
| Accounts and sign-in | Eastern Europe |
| Paths, exercises, enrolments, catalogue | Eastern Europe |
| Progress and exam goals | Western Europe |
| Messages | Eastern Europe |
| Assistant discussions | Eastern North America |
| Feedback (files) | Western Europe |
Accounts, content, progress, messages and feedback are therefore located in the European Union; the assistant discussions are located in the United States.
AI models run on Cloudflare’s global network, with no choice of region. Technical logs and abuse protection are processed by Cloudflare in its European and US data centres. Analytics are hosted in Frankfurt and relayed by Cloudflare’s global network. The anonymised feedback tickets are hosted by GitHub in the United States.
For these transfers outside the European Union, Cloudflare, PostHog and GitHub rely on their EU-U.S. Data Privacy Framework certification and on the European Commission’s standard contractual clauses, incorporated in their data-processing agreements (links in the table above).
How long we keep data
| Data | Retention |
|---|---|
| Account, teaching content, progress, messages, catalogue activity | for the life of the account; immediate deletion at your request (Settings → delete my account); no automatic deletion of inactive accounts |
| Technical restore points of the databases | 30 days |
| Sign-in codes | 10 minutes |
| Session tokens | access: 15 minutes; refresh: 7 days (expired tokens purged daily) |
| Assistant discussions | last 24 messages per discussion, until the tutor clears them; erased on request when the account is deleted (see “Your rights”) |
| Pending invitations | until the student enrols, the tutor withdraws the invitation or the path is deleted |
| Feedback (with e-mail address) | 14 days; the anonymised ticket is kept |
| Cloudflare technical logs | 7 days, for one request in 5 |
| Analytics | cookie: 365 days; events: up to 7 years; session recordings: up to 90 days |
What the Site stores in your browser
The Site itself sets no cookie. The application stores in your browser what it needs to work, including offline; PostHog and, when it is triggered, Cloudflare’s bot protection add their own. “Necessary” marks what is essential to the service you ask for.
| Key | Type | Purpose | Lifetime | Necessary |
|---|---|---|---|---|
tm.refreshToken | local storage | refresh token of your session (single-use, rotated every time it is used) | 7 days | Yes |
tm.lastUser | local storage | instant display of your profile at start-up (id, e-mail, name, role) | until you sign out | Yes |
tm.lastRole | local storage | last role chosen, offered by default on the sign-in page | until you clear the site data in your browser | Yes |
tm.passkeyHint, tm.passkeyPromptSeen | local storage | records that a passkey exists on this device | until you clear the site data in your browser | Yes |
tm.teacherOnboarding.v1.<id> | local storage | teacher onboarding: steps seen and your three answers to the welcome questionnaire | until you clear the site data in your browser | Yes |
paths-v4, studentProgress-v4, messages-v1, pendingInvitations-v1, studentDirectory-v1 | local storage | offline copies of your data: paths and exercises, progress, messages, invitations, your student directory | until the account is deleted (kept after a plain sign-out) | Yes |
outbox-v1 | local storage | queue of changes made offline, sent when the network is back | until you clear the site data in your browser | Yes |
assistant:recent:<id> | local storage | last five discussions opened with the assistant (type, id, date) | until you clear the site data in your browser | Yes |
tm.googleOauth | session storage | state of the Google sign-in in progress | for the life of the tab | Yes |
tm.rootReloadOnce, pwa-install-dismissed, pwa-standalone-tracked | session storage | interface flags (one-time reload, install banner) | for the life of the tab | Yes |
tam.placement.v1 | session storage | progress and answers of the level test, without identity | for the life of the tab | Yes |
workbox-precache (Cache Storage) + service worker | browser cache | application files, for offline use | until the next update of the application | Yes |
transformers.js model cache (Cache Storage) | browser cache | speech-recognition model downloaded on first use of the microphone | until you clear the site data in your browser | Yes |
ph_phc_uNHEKAjjPRnUcjLzTWRka6QiYonjCTW3E7AD4E3YCtHb_posthog | cookie | PostHog analytics: visitor id, session id, properties | 365 days | No |
ph_phc_…_posthog, ph_phc_…_posthog__flags, ph_phc_…_posthog__surveys | local storage | PostHog analytics: visitor id, session id, properties | until you clear the site data in your browser | No |
ph_phc_…_window_id, ph_phc_…_primary_window_exists, ph_phc_…_posthog | session storage | PostHog analytics: visitor id, session id, properties | for the life of the tab | No |
cf_clearance, __cf_bm, cf_chl_rc_* | cookie | Cloudflare bot protection, when it is triggered | 30 minutes of inactivity | Yes |
The offline copies of your data stay on the device after a plain sign-out and are only erased when the account is deleted or when you clear the site data in your browser. On a shared device, clear the site data after use.
Security
All traffic is encrypted (HTTPS). Your account has no password: sign-in relies on a single-use code, your Google account or a phishing-resistant passkey. Codes and refresh tokens are stored hashed; access tokens expire after 15 minutes and refresh tokens are single-use. Every change to a path is checked server-side: only its author can edit it. Cloudflare rate-limits requests per IP address and protects the Site against bots.
Minors
Tutors must be adults. Students may be minors: they are invited by their tutor, who confirms, before inviting a student under 15, that they hold the authorisation of the holder of parental responsibility. We collect no age data and ask students only for what is needed to follow their exercises. A parent or legal guardian can write to contact@teacher-and-me.com at any time to access, correct or erase their child’s data.
Your rights
You have the right to access, rectify and erase your data, to restrict or object to its processing, to data portability, and to give instructions about your data after your death. Where processing relies on your consent, you can withdraw it at any time.
From the application
- Delete my account (Settings): immediate deletion of your account, your paths (including those published in the catalogue, with their reviews), your enrolments, your progress and goals, your messages, your passkeys and your sessions; your catalogue comments are anonymised and hidden; the local copies are erased from the device used.
- Download my data (Settings): a JSON file with your profile, your paths (ids, titles, dates) or your progress and enrolments, and your messages. This export does not yet include the content of your exercises, your invitations, your assistant discussions or your catalogue activity: write to us for a complete export. Tutors also have per-student CSV exports.
- Edit my name, hide my profile, erase my progress, delete my messages, clear an assistant discussion: in Settings and the relevant screens.
What account deletion does not cover yet
- your assistant discussions and usage counters: they are not yet erased automatically with the account; we erase them on request;
- the feedback you sent us (it contains your e-mail address): erased automatically after 14 days;
- the analytics data tied to your account’s technical id: we ask PostHog to erase it on request;
- pending invitations addressed to your e-mail on other tutors’ paths: erased on request;
- the technical restore points of our databases, kept 30 days, then expired.
By e-mail
For any other request, write to contact@teacher-and-me.com from your account’s e-mail address (or with proof of identity). We answer within one month. If you believe your rights are not respected, you can lodge a complaint with the French supervisory authority, the CNIL, or with the authority of your country of residence.
Changes to this policy
The version in force is the one published at this address; its date and version number are at the top of the page. Every change to the Site that alters how your data is processed is reflected here on the same date. Only the French version is binding.