Skip to main content
Admissions are openCall +880 1758-395001 for Standard VI to A Level-A2 Cambridge classes.

Privacy Policy

Website, Platform, and complete student, staff, faculty, and administrative MCP connector.

Last updated: 27 August 2026

1. Scope and operator

This policy explains how Samim's Tutorial handles information through this website, the Samim's Tutorial Platform, and the optional Model Context Protocol (MCP) connector. The connector lets an authenticated user ask an approved AI client to use Platform tools on that user's behalf.

Questions, access requests, or complaints can be sent through our contact page.

2. Information we process

  • Student and guardian account data: names, registration identifiers, contact details, enrollment relationships, and account-security status.
  • Academic and assessment data: programmes, batches, routines, lecture sessions, notices, attendance, exams, marks, grades, report cards, and feedback.
  • Staff and administrative data: staff identity, roles, permissions, attendance corrections, leave records, and authorized academic or administrative actions.
  • Security and operational data: OAuth grants, client identifiers, audit outcomes, timestamps, and bounded diagnostic information needed to protect and operate the service.

3. Why we process it

  • Provide teaching, enrollment, attendance, assessment, communication, and administrative services.
  • Authenticate users and enforce live role- and permission-based access.
  • Carry out a user-requested MCP tool call, including confirmed staff or administrative actions.
  • Prevent abuse, investigate incidents, maintain idempotency, and keep a privacy-safe audit trail.
  • Meet applicable legal, safeguarding, accounting, and institutional obligations.

4. OpenAI, Anthropic, and MCP data flow

The optional connector can be used from compatible clients including OpenAI products and Anthropic Claude. When enabled, the client sends the tool name and the minimum arguments needed for the user's request to our MCP server. The server returns the authorized result to that client. The client provider may process the prompt, tool arguments, and result under its own terms and privacy policy.

Samim's Tutorial does not give either provider a service account or unrestricted database access. OAuth identifies the user; mcp.read and mcp.write scopes, live roles, ownership checks, and domain permissions are enforced for every list and call. Tools not authorized for the current user are withheld or rejected.

5. Sharing and service providers

We share information only when needed to operate the service, complete an authorized request, protect users, or meet an applicable obligation. This may include hosting, communications, security, and user-selected AI providers. We do not sell student, guardian, or staff personal information and do not use the connector as an advertising channel.

6. Retention and deletion

Records are retained only for as long as needed for the relevant educational, administrative, safeguarding, security, contractual, or legal purpose. The period varies by record type and institutional obligation. OAuth grants and refresh tokens can be revoked by disconnecting the connector; operational records may remain where required for integrity, dispute handling, security, or law. Contact us to request access, correction, or deletion; we will explain any record we must retain.

7. Your choices and controls

  • Do not connect an AI client unless you want it to process the request and authorized result.
  • Review requested OAuth scopes and approve only the access you need.
  • Disconnect the connector in the AI client and sign out of Platform to revoke ongoing access.
  • Ask us to review, correct, export, restrict, or delete information where applicable.
  • Staff, faculty, and administrators must use privileged tools only for authorized institutional work.

8. Children and student information

Our services include students who may be under 18. Student information is used for legitimate teaching and institutional purposes and is limited by account ownership, enrollment, role, and permission checks. Guardians should contact us if they need help understanding or correcting a student record. The connector is not directed to children who do not have an authorized Platform account.

9. Security and changes

We use HTTPS, OAuth authorization code with PKCE, short-lived access tokens, live authorization, explicit mutation confirmation, idempotency protection, rate limits, and redacted audit records. No system is risk-free. We may update this policy when the service, providers, or obligations change; the current version will remain published here.