← TuitionFlow

TuitionFlow

Privacy Policy

Last updated: 1 October 2026

The short version. TuitionFlow stores your classes, student roster, attendance and fee records in Google Firebase so they sync and survive a new phone. Only your account can read them. Payment slips and receipts stay on your phone. There are no ads, no analytics, and nothing is ever sold. Reminders go out from your WhatsApp, not from us.

This policy explains what TuitionFlow (“the app”) does with your information and with the information you enter about your students and their guardians. TuitionFlow is published by HeloCode Labs under the package name io.helocode.tuitionflow.

01Who this policy covers

TuitionFlow is used by tutors and tuition institutes (“you”). In the course of running classes you enter information about other people: students, who are often children, and their parents or guardians.

  • For your own account, HeloCode Labs is responsible for how your information is handled.
  • For student and guardian information, you decide what is entered and why, and HeloCode Labs stores and processes it on your behalf, only to provide the app to you.

Please enter a student’s details only with the knowledge and consent of their parent or guardian. The app asks you to confirm guardian consent when you add a student.

02Information about you

  • Sign-in: your mobile number, verified by SMS code, or your Google account’s email address and name if you sign in with Google.
  • Your profile: the name and details you enter during setup.
  • Your classes: class names, subjects, schedules, venues and fees.

03Information about students and guardians

For each student you add, the app stores what you enter:

  • the student’s name, and optionally their date of birth and your notes;
  • the guardian’s name and phone number, and whether consent was confirmed;
  • which classes the student is enrolled in;
  • attendance records: date, status, how it was marked and by whom;
  • fee records: amount, due date, status and payment method;
  • a record of receipts issued and reminders sent.

This information is used only to run your classes — attendance, fees, receipts and reminders. It is never sold, never used for advertising, and never shared with anyone other than the service providers below, who store it for us.

04What stays on your phone

  • Bank-transfer slips you photograph or choose as proof of payment are kept in the app’s private storage on your phone. They are not uploaded.
  • PDF receipts are generated on your phone and stay there until you choose to share one.
  • Attendance taken offline is queued on your phone and synced when you are back online.

05Where your data is stored

ServicePurposeWhat it receives
Firebase Authentication Signing you in Your phone number, or your Google account email and name
Cloud Firestore Storing and syncing your class records Your profile, classes, and the student, guardian, attendance and fee records listed above
Firebase Cloud Messaging App notifications A device token used to deliver notifications to your phone
Firebase Hosting The web check-in page students open from a QR code Standard web request data, such as IP address and browser type

Firebase is operated by Google, and data may be stored on servers outside Sri Lanka. Access to your records is restricted to your own signed-in account.

06WhatsApp reminders

When you send a fee or class reminder, TuitionFlow opens WhatsApp on your phone with the message filled in, addressed to the guardian’s number. You review it and send it yourself, from your own WhatsApp account. TuitionFlow has no access to your WhatsApp messages, and we do not send messages on your behalf. Messages you send are handled by WhatsApp under its privacy policy.

07QR check-in

If you use QR attendance, students scan a code that opens a web page hosted on Firebase. The page records the check-in against your class. It loads a QR-reading library from the jsDelivr content network, which, like any website, receives the visitor’s IP address and browser details. Check-in links expire.

08Permissions

PermissionWhy
InternetSigning in and syncing your records.
CameraScanning QR codes and photographing bank-transfer slips.
ContactsPicking a guardian from your contacts so you don’t have to type their number. Only the contact you choose is read; your address book is never uploaded.
PhotosChoosing an existing slip image as proof of payment. The image stays on your phone.

The app does not use your location, microphone or files.

09What we do not do

  • No advertising, and no advertising identifiers.
  • No analytics or usage tracking.
  • No selling or renting of any data, to anyone.
  • No contact from us to your students or their guardians.

10Children

TuitionFlow is used by tutors, not by children, and is not directed at them. It does hold information about students who may be under 18, entered by their tutor with their guardian’s consent. That information is used only to provide the app to the tutor. A parent or guardian who wants a student’s information corrected or removed can ask the tutor directly, or contact us.

11Retention and deletion

  • Records are kept for as long as your account exists, so that your class history is available to you.
  • To delete your account and everything in it, see delete your account and data.
  • Uninstalling the app removes the slips, receipts and offline queue stored on your phone.

12Your rights

Under Sri Lanka’s Personal Data Protection Act and similar laws elsewhere, you may have rights to access, correct and delete personal data, and to object to its processing. Guardians may exercise these rights for their child. You can ask us for a copy of your records, or for any of them to be corrected or deleted. Contact us and we will help — for student data, we will work with the tutor who entered it.

13Security

Data is transmitted over encrypted connections and stored in Google Firebase, with access rules that limit each account to its own records. No system is perfectly secure, and we will tell affected users promptly if we learn of a breach that puts their data at risk.

14Changes to this policy

We may update this policy as the app changes. The “last updated” date at the top always reflects the current version, and material changes will be announced in the app.

15Contact

HeloCode Labs
[email protected]
Sri Lanka