Safety & Privacy at LP AI Tutor

LP AI Tutor is a small, independent project, not a big company product. This page is a plain-language, honest account of what LP does today — including where it falls short — not a legal document. If something here changes, we'll update this page, not just the code. For the rules you agree to when you create an account, see the Usage Policy.

Who you're talking to

The LP tutor is Claude, an AI model made by Anthropic, not a human tutor. It can be wrong, and it can sound confident while being wrong. Verify anything that really matters, especially for schoolwork, health, money, legal, or safety questions. LP is an educational tool, not professional legal, medical, financial, or mental-health advice.

What LP collects — and what it doesn't

For safety, LP is adults-only (18 and up) and asks you to create a free account before your first tutor response — a one-time emailed sign-in link or Google sign-in, no password ever. The only thing stored on our servers today is your account record: your email, sign-in method, account ID, and when you linked it (see Accounts, guest identity, and deletion below). Everything else about your learning — name, goal, flashcards, quiz history, chat history, XP, and streaks — currently lives only in your browser, on your device. We don't see it, store it on our server, or sell it.

Your chat history is local-only: it lives only in your browser and is never stored on our servers. That's a permanent promise, not just a description of today: it stays true even after cloud sync (below) ships, because chat history is deliberately excluded from sync, on every device, forever.

When you send a message to the tutor, that message and a short summary of your learning context (your stated goal, skill level, interests, flashcards you keep forgetting, recent quiz topics, and your active learning path — no chat history beyond a short recent window) is sent to Anthropic's API to generate a reply. We never send Anthropic your email or any identifier tied to your identity — requests carry only a one-way hashed token used for abuse monitoring. Anthropic's standard API terms govern that exchange, and under Anthropic's commercial API terms, your conversations are not used to train any model. Having an account changes none of this — the same message and context are sent either way. Your use of LP is also governed by Anthropic's Usage Policy; our Usage Policy explains the data flow and the acceptable-use rules.

LP uses privacy-respecting product analytics (screen views, feature usage) that never include your message text, quiz content, name, or goals — only counts and categories. Analytics also records whether a session is signed in or not — again just a category, never your email or any other identifying detail. If analytics isn't configured for a given deployment, none of this is collected at all.

Accounts, guest identity, and deletion

Before you create an account, every visitor to LP — including someone who's about to be told they can't enter yet — is invisibly issued an anonymous authentication token the instant the page loads. It carries no name, email, birthdate, or other personal information; its only jobs are letting our server apply fair usage limits on our AI budget and, when you sign in, carrying your session into your new account. It's never shown anywhere in the app.

Adults (18 and up) turn that anonymous token into a real, free account — no password, ever — using a one-time emailed sign-in link or Google sign-in. This is required before the first tutor response: it's a safety measure, so that use of LP is tied to an accountable identity rather than being fully anonymous. It stays free, and you can delete it at any time from Settings (deleting it signs you out, so you'd sign in again to keep learning). Accounts aren't offered to anyone under 18, and because an account is required to get a response, LP is adults-only (18 and up) for now — see The age check below, and COPPA, plainly.

Here's exactly what's stored server-side when you have an account, by Firebase Authentication (a Google Cloud identity service LP operates): your email, which sign-in method you used, your account ID, and when you linked it. That's the whole account record today — no chat messages, cards, quiz history, or goals are stored there.

Your one-time sign-in link email, and any feedback you submit through the app, are delivered by Resend, a third-party transactional email service — the same kind of role Anthropic plays for tutor responses. Resend sees the email address you're sending to and the message content of that one email; it does not have access to your account record, chat history, or learning data.

An account is also the foundation for cloud sync — carrying your progress across devices — which is being built next and is not live yet. When it ships, your learning progress (cards, learning paths, quiz progress, streaks, and XP) will be stored on our servers so it can follow you to another device, and we'll update this page to say so plainly when that happens. Two things will never be part of that sync, on any device, ever: your chat history and any crisis-banner event. Those are permanent design decisions, not current limitations.

You can delete your account at any time from Settings. Deletion is real and server-verified, not just "clear your browser": our server permanently deletes your Firebase Authentication account record and everything stored under it (including synced learning progress, once sync exists). It does not delete anything saved on this device — your cards, XP, streaks, and chat history stay exactly where they are unless you separately use "Reset everything," also in Settings. Those are two intentionally separate actions.

How content safety works

Right now, only adults (18 and up) can enter LP. Children under 13 are stopped by the age check before any profile is created, because LP has no parent-consent flow. And because an account is required before any tutor response and accounts are adults-only, 13-17 learners can't enter right now either — they're shown a "not yet" screen. The teen content band described here is what will protect 13-17 learners when that experience ships: for every tutor reply, the AI would be instructed to use age-appropriate limits on sexual content, self-harm or weapon detail, and substance-use instructions. These are instructions to the underlying AI model, not a separate content scanner, so it can still make mistakes.

Separately, and independent of the AI model, LP watches (only on your own device, never by sending your text anywhere else) for phrases that suggest someone may be in real distress. If it thinks it sees one, it shows a bold, impossible-to-miss banner naming real help: in the US, call or text 988 (Suicide & Crisis Lifeline); anywhere in the world, findahelpline.com; and a reminder to contact local emergency services if anyone is in immediate danger.

The distress banner is available to anyone who can reach the tutor — currently adults (18 and up). It's a simple on-device phrase check, not a clinical assessment — tuned to err toward showing the banner rather than missing someone who needs it, so it may occasionally appear when nothing is actually wrong.

It is session-only: nothing about a distress banner appearing is ever saved, logged, or reported to a parent, guardian, or anyone else. Today, no adult is notified if this happens. This is unaffected by accounts and by cloud sync: even signed in, no crisis-banner event is ever saved, synced, or attached to your account — see Accounts, guest identity, and deletion above.

The age check, and its limits

Before you can start using LP, you're asked your age.

  • Under 13: LP stops there. We don't have a parent-consent flow built yet, so rather than let a young child in without one, LP tells them plainly that this needs a parent and to check back later.
  • 13-17: not admitted right now. Because a free account is required before any tutor response and accounts are adults-only in this version, 13-17 learners are shown a "not yet" screen instead of entering. A teen experience with the right safety and parental controls is planned, tracked internally as "teen safety posture."
  • 18 and up: the only age band admitted right now. Onboarding assigns the adult content band, and a free account is required before the first tutor response (see Accounts, guest identity, and deletion above). Explanation preferences can still be changed later in Settings.

The honest limitation: this is a self-reported age, not a verified one. LP has no ID check, no parental email verification, and no way to confirm anyone is telling the truth about their age — the same trust model most consumer web apps use, but we want to say so plainly rather than imply otherwise. Real age verification and a parental-consent flow for younger learners remain open work (tracked internally as "teen safety posture").

COPPA, plainly

Children under 13 are stopped completely, before a profile of any kind — local or account-linked — is ever created. The one thing that happens for every visitor, including someone on the age-gate screen who hasn't entered an age yet, is the invisible anonymous authentication token described above. It carries no name, email, birthdate, or other personal information, and it's never linked to a blocked under-13 visitor's identity, because a blocked visitor never gets far enough to provide one.

Accounts are offered to adults 18 and up only, and — because an account is now required to use the tutor — 13-17 learners can't enter this version at all; they see a "not yet" screen rather than a profile or an account. So LP does not knowingly collect personal information from anyone under 18, and the only thing any under-18 visitor ever receives is the same invisible anonymous token every visitor gets, which carries no personal information.

That said, self-reported age is not verified age, and we're not claiming a fully audited COPPA compliance program — we're stating our actual current design honestly and will update this page as that changes.

Questions

This is a personal project. If you're a parent, educator, or reviewer with a question about how LP handles safety and privacy, the most current source of truth is always this page and the Usage Policy — we keep them updated as the product changes.

← Back to LP AI Tutor