Security
Overview
Effective August 27, 2026
This page describes the practical measures Plumes uses to protect accounts, personal data, tutoring sessions, and the people who use the platform. Security is treated as an ongoing practice, not a one-time setting.
Because students and tutors share information through Plumes, we combine technical safeguards with clear roles and responsibilities. Everyone who uses the platform plays a part in keeping accounts and data safe.
This text is designed to be practical and safety-first. It describes our intended practices and is not a guarantee, a certification, or a substitute for independent security or legal review tailored to your specific situation.
1. Data Protection
Data sent between your browser and Plumes is encrypted in transit using HTTPS. Account, profile, and booking data is stored in a managed Postgres database with encryption at rest provided by our hosting infrastructure, and the contents of your messages are additionally encrypted at the application layer, so they are stored as ciphertext rather than plain text.
We rely on established cloud providers for hosting, storage, and authentication, and we configure access so that data is reachable only through authorized application paths rather than open public access.
We aim to collect only the data needed to operate the service and to limit who can access it. Database access rules restrict records to the users and roles entitled to see them.
2. Account And Access Security
Sign-in is handled through a managed authentication service, and you can sign in with your email or a supported provider such as Google. You are responsible for keeping your credentials private and for signing out on shared devices.
Sessions are maintained with secure cookies, and access is checked on every protected request. We apply rate limiting and authorization checks on the server so that requests are validated before any data is returned.
Plumes uses role-based access. Students, tutors, and administrators each see only the features and data appropriate to their role, and administrative actions are restricted to authorized accounts.
3. Sessions And Communications
Online sessions use secure in-app video generated for each booking. Access is limited to the session’s participants and to anyone the tutor invites with a session link, and it is only open for a short window around the scheduled time rather than being a permanently open room.
Online sessions connect the two participants’ devices directly to each other where the network allows it, rather than routing the call through a server. Because that connection is direct, each device may learn the other’s network (IP) address, as it does in any direct video call. Calls that cannot connect directly are carried by a relay service instead.
Sessions can be recorded by the tutor — online sessions as audio or, on eligible plans, audio and video, and in-person sessions as audio. When a session is recorded, the recording is used to produce a transcript and, on eligible plans, AI-generated notes, an agenda, and a student progress assessment. This processing uses third-party AI services, some of which are located outside Canada; the resulting recordings, transcripts, and notes are stored with a Canadian cloud provider and made available only to the participants of that session. See our Privacy Policy for details.
Messaging and file sharing are intended for legitimate tutoring use. Do not share malware or unlawful content, and only upload files you have the right to use. Misuse may lead to account restrictions after review.
4. Student Safety And Minors
Use by a minor should be supervised by a parent, guardian, or authorized institution where required. The minimum age for opening each type of account is set out in our Terms of Service.
We aim to minimize the personal data associated with student accounts and to limit its visibility to the tutors involved in a learning arrangement.
If you believe a minor's information has been exposed or that an account is being misused, contact us using the details below so we can review the situation promptly.
5. Reporting A Concern And Contact
If you discover a vulnerability or a potential security issue, please report it to us privately rather than sharing it publicly. Responsible disclosure helps us protect users while a fix is prepared.
When reporting, include enough detail to reproduce the issue, such as the steps taken, the affected page or feature, and the time it occurred. Please do not access, modify, or delete data that is not yours while investigating.
Security questions and reports can be sent to the contact address below. We review reports and aim to respond with appropriate next steps.