Privacy policy

A clear account of how personal information enters Pluto Academy, and how we use and protect it.

Last updated: 9 September 2026

The short version

  • We collect only what is needed to provide accounts, bookings, event registration, learning support and secure operations. We do no direct marketing and never sell your information.
  • Our operational database is in Sydney, Australia; some providers (hosting, email, analytics) process data in the United States and elsewhere. AI learning features (not yet enabled) will send the minimum necessary content about an attempt to an external AI provider only when you consent each time, and AI never decides your grades.
  • You may ask to access, correct or delete personal information, or raise a privacy question or complaint through our contact page. We respond within 30 days.

Scope and operator

This policy applies to the website, learning tools, booking, event registration and related support services provided at vvsacademy.com.au by VVS Education Pty Ltd trading as Pluto Academy (we, us or our).

It describes how we usually handle personal information. A more specific collection notice shown for a particular service should be read together with this policy.

Information we collect

Depending on the features you use, we may collect or hold the following kinds of information:

  • Account and identity information, such as name, email address, Australian mobile number, role, login and email-verification status.
  • Student profile and service information, such as study stage, course preferences and information you choose to provide to an adviser or tutor.
  • Booking and event records, such as course, tutor, delivery mode, date and time, event, Stars cost, status and necessary service notes.
  • Event participation details, such as social or gaming handles and event-specific answers you provide.
  • Tutor and staff information, such as professional profiles, teaching subjects, photos, availability and teaching feedback.
  • Stars balances and transaction records. The current website does not process real card payments.
  • Uploaded content and metadata, such as booking files, file names, sizes and upload times.
  • Communications you send through forms, support channels or WeChat.
  • Technical and security information, such as IP address, browser and device type, request time, errors and security logs.
  • Website-use information, such as public page views, tool-flow steps, whether a booking or registration completed, and report exports.

How we collect information

We mainly collect information directly from you when you register, complete a profile, book a lesson, register for an event, upload a file or contact us. A parent, guardian, school or authorised service representative may also provide information for a student.

Some technical information is generated automatically when you use the site. We may also receive service-operation records from providers that support hosting, email, storage, security and analytics.

Please do not include unrelated sensitive information in free text, uploads or support messages. If we need sensitive information, we will seek consent or rely on another lawful basis where required by applicable law.

Why we use information

We may collect, hold, use or disclose information to:

  • create and protect accounts, verify identity and provide role-appropriate features;
  • arrange and manage lesson bookings, tutor matching, reminders, feedback, Stars records and event registration;
  • respond to enquiries and provide learning, pathway or service support;
  • operate, maintain, troubleshoot and secure the site, and prevent fraud, abuse and unauthorised access;
  • understand aggregate use of public features and improve pages, tools and service flows; and
  • meet legal, accounting, dispute-resolution or regulatory obligations and protect lawful rights.

Google Analytics, cookies and local storage

When Google Analytics 4 (GA4) is enabled, Google says its default implementation may collect user counts, session statistics, approximate geolocation, browser and device information, and use a first-party cookie named _ga to distinguish browsers and sessions. Google uses IP addresses at collection time to determine approximate location and says they are discarded before data is logged in its data centres.

Our GA4 custom events are limited to aggregate behavioural trends. Paths are checked against an allowlist, dynamic routes are templated, and queries and hashes are removed. We do not send names, emails, phone numbers, social handles, tokens, user/student/tutor/booking/registration IDs, messages, GPA, raw or predicted grades, admission or matching results, booking dates and times, or upload information as custom analytics parameters.

The two deliberately retained business dimensions are public event slugs and public course codes. They come from the public site catalogue and do not identify a person. We do not use GA4 data to automatically decide admission, course eligibility or booking outcomes.

Necessary cookies and browser storage may also support login sessions, language preferences, flow state and temporary booking drafts. Blocking them may affect login or unfinished flows. We do not currently provide an in-site analytics preference control; you can block or delete cookies in your browser or use Google’s Analytics opt-out tool.

AI learning features

We are preparing AI learning features for the AI question bank (a post-attempt learning diagnosis and per-question explanations). As at the date of this policy they are not available to students. The rules below apply once they are enabled, and we will update this section at that time.

These features run only when you actively start them and confirm a notice each time; you can withdraw consent in the same place at any time. When you do, we send the minimum necessary content about that attempt to an external AI provider: the learning diagnosis sends only aggregated performance by topic, error-cause labels and short in-request references, never question text; the per-question explanation sends that question’s wording, options, your selection and the fixed solution. Neither sends your name, contact details, account ID or anything about other students; you appear to the provider under an irreversible pseudonym.

AI output is used only to explain results the server has already determined. It never decides or changes marking, correct answers or grades for objective questions, and output is checked for structure and content on our server before it is shown; anything that fails is not shown. We keep metadata for each request, a snapshot of what was sent and the result for quota control, troubleshooting and quality review, handled under the retention rules in this policy.

We will only use providers that allow us to require that request content is not used to train models, and we will name the provider, processing location and data-retention arrangement in this section before enabling the features.

Who we disclose information to

We disclose only what is reasonably necessary to provide a service, where you authorise us, or where disclosure is permitted or required by law. Recipients may include tutors and administrators responsible for the relevant student service, and service providers that process data for us. We do not sell personal information or provide it to third parties for their own marketing.

  • Vercel for website hosting, delivery and operational logs. Server-side functions run in the Washington, D.C. (United States) region; the content delivery network caches public pages at nodes worldwide.
  • MongoDB Atlas for account, booking, registration and other operational database records. The database is hosted in the AWS Sydney region (Australia).
  • Cloudflare R2 for authorised booking files and tutor media, stored and delivered on Cloudflare’s global network, which may be outside Australia.
  • Resend for verification, password-reset and service-notification emails, processed in the United States.
  • Google Analytics for controlled public-site usage data, when configured, processed by Google in the United States and other locations it operates.
  • An external AI provider, only once AI learning features are enabled and you consent each time, receiving the content described in the previous section. The provider’s name and processing location will be added here before enabling.
  • WeChat/Tencent when you choose to contact us through WeChat; that communication is also governed by the platform’s own policy.
  • Professional advisers, law enforcement, courts or regulators where authorised, necessary to protect rights, or required by law.

Overseas processing and disclosure

Our operational database is located in Australia. Server-side processing for hosting, email delivery and website analytics takes place in the United States; file storage and content delivery use global networks that may be outside Australia; once AI learning features are enabled, related content will be sent to the provider’s country (expected to be the United States). Exact locations may change with provider configuration and infrastructure; the previous section lists each provider’s current location.

Where Australian privacy law applies, we take reasonable steps to assess providers and protect information through access controls, contractual arrangements and service configuration. Contact us if you want information about the current processing location for a particular service.

Storage, security and retention

We use technical and organisational measures proportionate to the information, including access permissions, authentication, encryption in transit, password hashing, restricted file access, and separation between operational records and analytics. No internet or storage system can be guaranteed completely secure. If a data breach is likely to result in serious harm to you, we will notify affected people as soon as practicable after assessment, and notify the regulator where the law requires it.

We retain information only as long as reasonably needed to provide services, resolve disputes, maintain security, meet audit needs and satisfy legal obligations. Periods already fixed include: accounts whose email is not verified within 7 days of registration are deleted automatically; upload drafts not submitted with a booking within 24 hours are removed together with their files; a fixed retention period for AI learning-feature records will be set and published here before those features are enabled. Other periods vary by record and purpose. When information is no longer needed, we take reasonable steps to delete, destroy or de-identify it, although legal holds and backup cycles may delay removal.

Direct marketing

We send only service emails related to your account, bookings, event registrations and security. We do not send marketing messages without your consent and do not give your contact details to others for marketing. If we later offer an optional newsletter, we will ask separately and include an unsubscribe option in every message.

Children and young people

Some services are for students who may be under 18. We may require a parent or legal guardian to participate or confirm consent for purchases, bookings, AI learning features or other services where consent is needed. For a student we know to be under 15, the relevant consent should normally be given by a parent or guardian.

A parent or guardian with a question about a young person’s information, or seeking access, correction or deletion, should use our contact page and explain their relationship to the student. We may need to verify identity and authority first.

Access and correction

You may request access to personal information we hold about you or ask us to correct information that is inaccurate, incomplete or out of date. Some profile information can be updated in your account; use our contact page for other requests.

To protect accounts and student information, we may verify identity or authority before acting. Where permitted by applicable law, we may refuse all or part of a request and will explain the reason and available next steps. You may also ask us to delete an account or information no longer required, although operational, dispute, security or legal records may need to be retained.

Complaints

If you believe we have not handled personal information appropriately, use our contact page and describe the relevant account, event, date and outcome you seek. Do not send a password or reset token through a public channel.

We will acknowledge the issue, investigate it and respond within 30 days with an outcome or a request for more information. If you are not satisfied and Australian privacy law applies, you may contact or complain to the Office of the Australian Information Commissioner (OAIC).

Office of the Australian Information Commissioner (OAIC)

Changes to this policy

We may update this policy when our services, providers or legal obligations change. We will update the “Last updated” date on this page and may provide a separate website or account notice for material changes.

This policy describes our usual current practices and does not limit rights available under applicable law.

Privacy questions and requests

VVS Education Pty Ltd trades as Pluto Academy. Use our contact page for privacy enquiries, access or correction requests, and complaints.

Contact us