Fidius · Terms · All languages

Privacy Policy

Last updated: 23 August 2026 · Contact: admin@fidius.app

Who we are

Fidius (https://fidius.app) is a web application for private tutors and their students. It provides lesson scheduling, student records, payments and receipts, and tutor subscription billing.

This Privacy Policy applies to https://fidius.app and the Fidius web app. It is available without an account at https://fidius.app/privacy and as this static English page at https://fidius.app/privacy.html

Google user data we access

You can sign in to Fidius with Google (openid, email, and profile). Google tells us your verified email and name so we can match an existing Fidius account or let a new tutor finish registration. We do not store Google Sign-In access or refresh tokens. Connecting Google Calendar is a separate, optional step for tutors only.

If a tutor chooses Connect Google Calendar, Fidius requests the OAuth scope https://www.googleapis.com/auth/calendar.events.readonly (read-only access to Calendar events). We do not request Gmail, Drive, Contacts, or any write/delete Calendar scopes.

Google user data we access: (1) OAuth refresh and access tokens that prove the tutor granted that scope; (2) the Google account email associated with the connection, used only to show which account is connected; (3) event title, start time, end time, and related event metadata from the tutor’s primary Google Calendar, only for a date range the tutor selects in Fidius when they run an import.

We do not create, update, or delete events in Google Calendar. We do not access the tutor’s full Calendar history on an ongoing background sync — import runs only when the tutor starts it.

How we use Google user data

We use Google Sign-In data (verified email and name) only to authenticate you on Fidius. We use Calendar user data solely to provide the Calendar import feature the tutor requested: show a preview of events inside Fidius, and, if the tutor confirms, create matching lesson records on the tutor’s Fidius schedule.

Google user data is not used for advertising, analytics products sold to others, credit scoring, or to determine eligibility unrelated to Fidius. We do not use Google user data to train generalized AI or ML models.

Google Calendar event data is never sent to Google Cloud Vision, OpenAI, Anthropic, or any other AI/ML provider. Fidius does not call Google Photos APIs and does not call Google Workspace APIs other than Calendar events (read-only). Optional optical character recognition (Google Cloud Vision) runs only on receipt images that a tutor or student uploads to Fidius. Those images are not Google Calendar or Google Photos API user data and are never mixed with Calendar OAuth tokens or event metadata.

OAuth tokens are used only to call Google Calendar APIs for that tutor’s import and to refresh access while the tutor keeps the connection enabled.

Sharing, transfer, and disclosure of Google user data

We do not sell Google user data. We do not share, transfer, or disclose Google user data to other tutors, to students, or to advertisers.

We do not share Google user data with third parties except: (1) infrastructure processors that host Fidius (server and encrypted storage) and that process data only on our instructions to operate the app; (2) Google itself, when we call Google Calendar APIs with the tutor’s token; (3) when required by law, regulation, or a valid legal process; (4) with a service provider the tutor asked us to involve for a support ticket, and only as needed to fix that issue.

Imported Fidius lessons are visible in the tutor’s Fidius account (and to a student only if that lesson is assigned to them as a Fidius lesson). We do not give students access to the tutor’s Google Calendar or OAuth tokens.

Data protection mechanisms

Fidius is served over HTTPS/TLS in transit. Personally identifiable fields (email, phone), tutor bank details, and Google OAuth refresh and access tokens (sensitive credentials) are stored at rest with AES-256-GCM encryption — not as plaintext in the database. Access to production systems is limited to operators who maintain the service.

We do not store a full copy of the tutor’s Google Calendar. After an import, we keep only the Fidius lesson records the tutor confirmed. Tokens are stored only while Google Calendar remains connected.

Human access to Google user data is not allowed for research, ads, or product training. A person may see such data only if the tutor asked for support and it is needed to fix the issue, we are required by law, or the data is aggregated so it cannot identify a person — consistent with Google’s Limited Use requirements.

Retention and deletion of Google user data

OAuth tokens are retained only while the tutor’s Google Calendar connection is active. The tutor can disconnect at any time in Fidius (Profile → Google Calendar → Disconnect). Disconnecting deletes the stored Google tokens from our servers. The tutor can also revoke access at https://myaccount.google.com/permissions

Event metadata used for an import is not kept as a separate Google Calendar archive. Lessons the tutor imported become ordinary Fidius lesson records and are retained according to the tutor’s Fidius account (until the tutor deletes those lessons or the account).

You can delete your Fidius account in Profile (two confirms; tutors download a backup first). To ask us to erase remaining Google-derived data, email admin@fidius.app. We will delete or anonymize that data unless we must keep a limited record to meet a legal obligation.

Limited Use and Google API policy

Fidius’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy

Other Fidius data

We process account data (name, email, password hash), lesson and payment records, and optional profile information to provide the service. Operators who maintain Fidius can see account metadata in the admin console, including when a tutor last signed in; we do not record page-by-page activity or session replay. Email and phone are stored encrypted at rest (AES-256-GCM). Bank details a tutor saves for students are encrypted separately; students see a mask until they request the full number, and each reveal is logged. Passwords are stored as hashes, never as text. We use cookies or tokens needed to keep you signed in and to protect forms.

To measure marketing effectiveness we may load the Meta (Facebook) Pixel on https://fidius.app. It can collect technical data such as IP address, device/browser information, pages viewed, and conversion events (for example registration or subscription). Meta uses this to show and optimize ads on Facebook and Instagram. You can limit ad tracking in your Meta account settings and browser controls. Fidius does not use Yandex Metrika or session replay (webvisor).