LLektobox

Privacy Policy

Last updated: July 29, 2026

This Privacy Policy explains how Yevhen Hrynchak, a Ukrainian sole proprietor (ФОП) ("Lektobox", "we", "us") collects, uses, and protects personal data when you use our CRM/LMS platform for private tutors and language schools.

1. Two roles: account data vs. student data

When your organization (tutor or school) signs up, we act as the data controller for your own account data — name, email, billing details, and usage/log data.

When your organization enters information about students into Lektobox (names, contact details, session notes, progress, quiz results, uploaded files), we act as a data processor on your behalf — you (the tutor or school) are the controller for that data and are responsible for having a lawful basis to collect it, including any consent required from students or their parents/guardians where students are minors.

2. What we collect

  • Account data: name, email address, password hash, organization/branch membership, role.
  • Billing data: plan, subscription status. Card and payment details are collected and processed directly by our payment provider — we do not store full card numbers.
  • Customer Data entered by your organization: student profiles, courses, curricula, scheduled sessions, quiz results, notes, and files you upload.
  • Technical data: IP address, browser/device information, and usage logs for security and reliability.

3. How we use data

We use account and technical data to provide, secure, and improve the Service, communicate with you (e.g. billing or product notices), and comply with legal obligations. We process Customer Data only as instructed by your organization, to operate the features you use (scheduling, progress tracking, quizzes, etc.) — not for our own marketing purposes.

4. Sub-processors

We share data with a limited number of service providers who help us run Lektobox, including: cloud hosting/infrastructure, email delivery (for notifications and invites), and our payment provider (payment processing and billing). If you connect the optional Google Calendar integration, Google also processes your calendar data as described in Section 5 below. Each is bound by contractual data-protection obligations.

5. Google Calendar integration (Google user data)

If a teacher chooses to connect their Google Calendar, Lektobox requests Google's calendar.events OAuth scope — read/write access to calendar events only, not the broader scope that would allow creating, deleting, or managing entire calendars. We use this access to:

  • Create, update, and cancel events in that Google Calendar corresponding to lessons scheduled in Lektobox, so the teacher sees their teaching schedule in their personal calendar.
  • Read the teacher's existing calendar events to detect scheduling conflicts with the teacher's other commitments. For events that did not originate in Lektobox, we store only the busy time range (start and end time) — never the event's title, description, location, or attendees.

OAuth tokens are encrypted at rest. Disconnecting the integration immediately revokes our access with Google and deletes the stored tokens. This data is used solely to provide the calendar-sync feature described above — never for advertising, and never sold or shared with any third party except as needed to provide the Service (e.g. our hosting provider) or as required by law. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. AI-assisted lesson generation

Lektobox offers an optional feature that lets a teacher generate draft lesson content using OpenAI's API. The only information sent to OpenAI is the lesson/course title, the free-text teaching brief the teacher types in, and metadata (title, description, declared type) of any media links the teacher supplies — never Google Calendar data or any other Google user data. Per OpenAI's API Data Usage Policy, data submitted through its API is not used to train OpenAI's models by default.

7. Data retention

We retain account and Customer Data for as long as your organization has an active account, and for a limited period afterward to allow reactivation and to meet legal/accounting obligations, after which it is deleted or anonymized.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Account holders can exercise these rights directly in the app for account data; requests concerning student data should generally go through the tutor/school organization that controls it, or you may contact us at evgeniy.python.developer@gmail.com and we will route the request appropriately.

9. International transfers

Data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.

10. Security

We use industry-standard measures — encryption in transit, access controls, and hosting provider security practices — to protect data against unauthorized access, loss, or misuse. No system is 100% secure, and we cannot guarantee absolute security.

11. Children's data

Lektobox itself is intended for use by tutors, schools, and their staff. Student profiles (including those of minors) are entered and managed by the tutor/school organization, which is responsible for obtaining any required parental/guardian consent under applicable law (e.g. GDPR, COPPA) before entering a minor's data.

12. Cookies

We use essential cookies/local storage required for authentication and core functionality. We do not use third-party advertising cookies.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice.

14. Contact

For privacy questions or requests, contact us at evgeniy.python.developer@gmail.com.