Skip to main content
Docet

Privacy policy

This policy explains what information Docet handles, why we handle it, and the choices available to you when you use our service.

Last updated: September 17, 2026

01

Information we handle

When an organization uses Docet, we may handle account details such as name, email address, role, and location assignments; organization details such as locations and billing configuration; and operational information entered by that organization, including student records, schedules, attendance, mastery ratings, session notes, voice memos, invoices, and uploaded curriculum assets.

Public inquiry forms may collect a child's name, grade, and subjects; a parent or guardian's name, email address, and phone number; a message; and a keyed hash of the submitter's IP address for abuse prevention.

We also receive authentication events, IP address, browser and device information, audit events, and error and performance reports. Docet does not collect date of birth, home address, health data, or government identifiers about students.

02

How we use information

We use information to:

  • Provide scheduling, records, communication, billing, and account features.
  • Authenticate users, enforce role and location access, and prevent misuse.
  • Send invitations, service messages, invoices, and approved progress communications.
  • Improve reliability, troubleshoot problems, measure product usage, and provide support.
  • Meet legal obligations and protect the rights, safety, and security of Docet and its users.

03

Organization-controlled information

The tutoring organization that invites you or enters operational records generally controls the student, family, staff, and session information it places in Docet. That organization decides what information to enter, who can access it, how long it should be retained, and when records should be archived.

If you have a question about information held by a tutoring organization, contact that organization first. You may also contact us at support@docet.org and we will help route the request.

04

Service providers and sharing

We share information with the following processors under instructions and confidentiality obligations:

Neon (Postgres)
Purpose: Application database. Personal data received: All application records including student names, notes, attendance, mastery, transcripts, invoices, and audit log.
Neon Auth
Purpose: Authentication. Personal data received: Name, email, password, verification codes, and sessions.
Google
Purpose: Optional OAuth sign-in, via Neon Auth. Personal data received: Google account identity when a user chooses it.
Cloudflare R2
Purpose: Object storage. Personal data received: Voice memos, curriculum files, and organization logos.
Our hosting provider
Purpose: Application hosting and content delivery. Personal data received: Information needed to serve the Docet application.
Resend, or the organization's own SMTP server
Purpose: Transactional email. Personal data received: Recipient email, subject, and message body.
Groq
Purpose: Voice transcription and AI drafting. Personal data received: Voice-memo audio; a student's first or preferred name, session dates, attendance, mastery ratings, transcripts of single-student sessions, and retention score/band in prompts, without payment information. This processing occurs only when the organization has enabled AI, which is off by default.
Stripe
Purpose: Subscription and invoice payments. Personal data received: Billing contact name, email, billing address, payment, and invoice records.
Sentry
Purpose: Error and performance monitoring. Personal data received: Scrubbed error reports and traces for reliability monitoring; student and parent data is not intentionally sent.

We may also disclose information when required by law, to respond to a valid legal process, to investigate abuse, or to protect people and the service. We do not sell personal information.

05

Voice memos and AI drafting

An organization may choose to upload a voice memo for transcription. Voice audio and the session data described above are sent to Groq for transcription and drafting. AI processing is off by default and occurs only after an organization owner enables it. Transcripts and AI-generated drafts are stored as part of that organization's records and are subject to its access settings.

Parents can unsubscribe from AI progress digests using the unsubscribe link in each digest. Docet's workflow is designed so parent-facing AI content remains a draft until an authorized team member approves it. Do not use AI output as the sole basis for a high-impact decision about a student; review it in context before acting on it or sharing it.

06

Retention and security

When an organization is deactivated, its data is purged 90 days after deactivation. Archived leads are deleted after 365 days, and lead IP hashes are removed after 24 hours. Retention scores are kept for 180 days, and expired invitations are deleted after 7 days. Owners can permanently erase a student record from Students → student → Erase.

We use access controls, tenant scoping, encryption in transit, audit records, and other safeguards designed to protect information. Custom SMTP connections require STARTTLS or SSL. No service can promise absolute security, so please protect your credentials and report suspected unauthorized access promptly.

07

Your choices

You can review and update certain account information through Docet. To ask about access, correction, deletion, export, or another privacy matter, email support@docet.org. Deletion and export requests are handled manually; there is no self-serve export today. Requests about records a tutoring organization controls are routed to that organization.

08

Updates and contact

We may update this policy as Docet changes. We will post the current version here and update the date above. Material changes will receive reasonable notice where appropriate.

Read the Terms of service and Cookie policy for related terms. Privacy questions can be sent to support@docet.org.

09

Children's information and our role

Docet is a service provider processing student records on the instruction of the tutoring organization that holds the relationship with the family. That organization is responsible for giving parents or guardians notice and obtaining any legally required consent, including for AI features and voice memos.

Docet uses student information to calculate retention scores from attendance, mastery trend, recency, and overdue-invoice status. These scores help owners and directors identify students who may need support; they are visible to authorized staff and retained for 180 days. Docet does not use student information for advertising or to train AI models.

10

Your privacy rights

Residents of US states with comprehensive privacy laws, including California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states, may request access, correction, deletion, or a portable copy of their personal information and may appeal a refusal. Send requests to support@docet.org. We will respond within 45 days. Requests about records a tutoring organization controls are routed to that organization.

Docet does not sell personal information, share it for cross-context behavioural advertising, or use it for profiling that produces legal effects.