Is It Safe to Use AI for Tutoring?
Yes for lesson planning, no with student details: never paste a child's name, school or SEN diagnosis into a consumer AI. Anonymise first.
Here is the short answer. AI is safe for the teaching work, but not for a child's details. You can plan a lesson, build a worksheet or draft a progress note with an AI. It never needs a student's real name, school or diagnosis to do that. Most of your students are minors, and children's data carries extra legal protection. A learning difficulty like dyslexia or ADHD is health data, which is even more sensitive. So anonymise names and schools before the prompt, and never paste a diagnosis tied to a name.
Most of your students are children
Think about what sits in your tutoring records. A student's full name. Their school. Their year or grade. A parent's phone number and email. Maybe a note about how the child learns best. Each line looks small on its own. Together, they identify a specific child with ease.
Children's data gets extra protection by design. In the US, COPPA (the Children's Online Privacy Protection Act) governs personal information collected from children under 13. It is enforced by the FTC (Federal Trade Commission). Online services must give parents notice and get verifiable parental consent first. A tutor pasting a young child's details into a third-party AI puts that data into an outside service.
The UK draws the line even wider. The Children's Code, from the ICO (Information Commissioner's Office), protects anyone under 18. It rests on a simple idea: the best interests of the child come first. It expects data minimisation and high privacy by default. In plain terms, collect and expose as little student data as you can.
Learning difficulties are health data
This is the point most tutors miss. A learning difficulty or a diagnosis is health data. Dyslexia. ADHD. Autism. A special educational needs (SEN) note. Under the UK and EU GDPR, health data is 'special category data' under Article 9.
Special category data carries a general ban on processing. You need extra safeguards to touch it at all. A note like 'has ADHD' tied to a named child is exactly this. It sits in the highest-risk tier the law defines.
The bar is much higher than for a phone number. To process special category data lawfully, you need two things. A lawful basis under Article 6. And a separate Article 9 condition, usually explicit consent. Pasting a diagnosis tied to a name into a consumer AI clears neither on its own.
A tutor's file mixes three kinds of data
Here is what makes tutoring records unusual. They combine three sensitive types at once.
- Children's data — a name plus school plus grade points to one specific child.
- Special-category health data — SEN notes and diagnoses like dyslexia, ADHD or autism.
- Adults' personal data — parent and guardian names, phone numbers and email addresses.
No single line feels dramatic. The mix is what raises the stakes. A tutor holds the highest-sensitivity combination in one place.
| You might think | The reality |
|---|---|
| “A first name in a prompt is harmless” | Name plus school plus grade identifies one child precisely |
| “'Has ADHD' is just a helpful note” | It's special-category health data under Article 9 of the GDPR |
| “Only under-13s get special protection” | COPPA covers under-13s; the UK Children's Code covers under-18s |
| “Parent contacts aren't a concern” | They are adults' personal data under the GDPR |
The fix: anonymise before the prompt
Good news: AI stays genuinely useful for tutoring. It can plan a lesson. It can build a worksheet. It can draft a progress summary or a message to a family. For all of that, it works fine on de-identified text. Replace the student's name and school with neutral placeholders first.
Two habits do most of the work. First, swap names and schools for tokens before you send. Second, never paste a diagnosis or an SEN note tied to a name. Add vetted tools and parental consent where needed. Treat every student record as children's data. This lowers the risk. It is good practice, not a guarantee of full legal compliance.
- 1Spot the student details: names, schools, grades, parent contacts.
- 2Replace names and schools with reversible tokens, in the browser.
- 3Keep any diagnosis or SEN note out of the prompt entirely.
- 4Send only the de-identified text to the AI.
- 5Restore the real names locally when you use the reply.
That's what ONYRI Sanitize is built for. The engine detects sensitive data — student names, schools, contacts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI sees tokens, never the children you teach. You keep the help, and you keep faith with the families who trust you.
Frequently asked questions
- Is it safe to use AI for tutoring?
- Yes for the teaching work, no with student details. AI can plan lessons, build worksheets and draft progress notes on de-identified text. But never paste a child's name, school or diagnosis into a consumer AI. Most students are minors, and children's data gets extra protection. A diagnosis is special-category health data under Article 9 of the GDPR. Anonymise names and schools first, and keep diagnoses out of the prompt.
- Can I paste a student's name or diagnosis into ChatGPT?
- Better not. A name plus school plus grade identifies a specific child, and children's data carries extra protection under COPPA and the UK Children's Code. A diagnosis like dyslexia or ADHD is special-category health data under Article 9 of the GDPR. Replace names and schools with tokens, and never paste a diagnosis tied to a name.
- Can AI help me plan lessons without student data?
- Yes. AI can build a worksheet, plan a lesson or draft a progress summary from de-identified text. Swap the student's real name and school for neutral placeholders first. The AI does the teaching work on the shape of the task, never on the child's identity.
Sources & references
- Complying with COPPA: Frequently Asked Questions (parental consent for children under 13; what counts as a child's personal information) — US Federal Trade Commission (FTC)
- Introduction to the Children's Code (protections for under-18s; best interests of the child; data minimisation by default) — UK Information Commissioner's Office (ICO)
- What is special category data? (health data under Article 9; general prohibition and stricter safeguards) — UK Information Commissioner's Office (ICO)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.