Privacy Policy
Last updated:
The short version
- You have no account with us. We do not know your name or email address unless you send it to us yourself.
- Your bookmarks, settings and full study history stay on your device. Which question you answered, and whether you got it right, is also counted as usage statistics.
- Ads run only after you agree. Usage statistics and crash reports run without asking, because we rely on our legitimate interest — you can object at any time.
- We use identifiers that carry no name but do recognise the same device. That is personal data, and we treat it as personal data.
- We do not sell your data and we do not feed it to any AI system.
1. Who is responsible for your data
The data controller is Filip Kowalski, trading as Nomadic Studio, publisher of the Prawo Jazdy GO app and the prawojazdygo.pl website (together, "the Service").
Filip Kowalski (Nomadic Studio)
c/o Coworking Minds
Carrer Ferrers 1
07510 Sineu, Islas Baleares
Spain
For anything concerning personal data, write to [email protected]. We answer every request, including the ones we decline — in that case we explain why.
We have not appointed a data protection officer, because we are not required to. Requests go straight to the people who run the Service.
2. What the app processes
The app has no login and no accounts. We do not require your name, phone number or any identity document. The optional contact field in feedback is free text — fill it only if you want a reply. We do process the following.
Identifiers
None of these contains your name, but each one recognises the same device over time. That makes them personal data under the GDPR, and we treat them accordingly.
| Identifier | Where it comes from | What it is for |
|---|---|---|
| App instance ID (Firebase) | assigned automatically by Google on first launch | app usage statistics |
| Anonymous analytics ID | a random string generated on your device | counting sessions and journeys through the app |
| Anonymous subscriber ID (RevenueCat) | assigned by our subscription provider | checking an active subscription, preventing abuse |
| Advertising identifier — Advertising ID (Android) or IDFA (iOS) | assigned by the operating system; you can reset or disable it in device settings | serving ads, only after you agree |
One link we should state plainly
We pass our Google analytics identifier to the subscription provider so a purchase can be connected to how the app was used beforehand. It tells us which features lead people to subscribe. In practice it means purchase data and usage data can be joined together within a single device.
Usage data
- in-app events: session start and end, screens opened, learning sessions started and finished, mock exam results, Survival mode, the 5-minute mode, bookmarks added, explanations viewed
- onboarding choices: language, licence category, whether you attend a driving school, reminder settings
- purchase events: subscription screen shown and dismissed, the reason you picked for declining (from a fixed list, no free text), purchase, purchase restored, amount and currency
- each answer you give: the number of the question, whether the answer was correct, and the time — sent as a usage event, so this part of your study history exists on our side too
- how many ads you watched, and how many questions you answered in a session and on the day
- subscription status: active or none
Technical data
- device model, operating system version, platform
- app version and build number
- device language, region and time zone
- IP address — visible to any server the app connects to; we use it only to determine the country and to prevent abuse, and we do not store it in our statistics
Question difficulty statistics
When you answer a question we send the question number and whether the answer was correct. No identifier of any kind is attached — not yours, not your device's. There is no way to work out who answered. It exists only to count which questions learners find hardest and to build the list of most-missed questions.
Purchases and subscriptions
Payments are handled by the App Store and Google Play. We never see or store card numbers or payment details. We receive which product was bought, when it expires, whether it renews automatically, and whether a free trial was used.
Where an install came from
If you installed the app after clicking an ad, the store passes us campaign parameters — the source, campaign and ad group. Before anything leaves your device, the app discards every parameter except a known list of campaign tags. This goes only to our subscription provider and serves one purpose: judging which advertising is worth paying for.
Notifications
Study reminders are created and shown by your own device, at the time you choose. We do not send push notifications from a server and we hold no push token for your device.
Crash reports
When the app crashes or hits an unexpected error, it sends a report to Firebase Crashlytics: the error and its stack trace, the device model, the operating system version, the app version, and an identifier for the app installation. It carries nothing you typed and nothing you studied. We use it to find and fix faults. Debug builds send nothing.
Reports and feedback
If you send feedback from inside the app, we receive your message, anything you choose to put in the contact field, the screen you sent it from, your platform and language, and two counters — how many questions you have answered and how many bookmarks you hold. If you report a wrong explanation, we receive the question and the explanation you flagged, plus your platform, language and app version. Neither report carries an identifier that links back to your device.
What the app does not do
It does not request or hold access to your location, camera, microphone, photos, contacts, calendar or health data. It does not read your clipboard. It contains no chat and no AI feature.
3. What the website processes
prawojazdygo.pl is a set of static pages. There is no login, no comment system and no advertising on it.
Visit statistics
We use an analytics tool that sets no cookies and builds no persistent visitor profile. It processes the page URL, the referring page, the page title, screen resolution, browser and operating system type, language, and your IP address — from which it derives a country and a one-off hash for the visit, without storing the address itself.
Driving school form
The page for driving schools carries a contact form. It asks for the school name, the contact person's name, an email address, optionally a phone number, the approximate number of students per year, and your message. We use this only to reply. We do not add it to any marketing list.
Hosting
The site runs on Cloudflare infrastructure. The host necessarily processes your IP address, browser headers, the requested URL and the time of the request — a page cannot be delivered or automated traffic filtered without them. It may set its own technical cookies in the process.
4. What never leaves your device
We do not send this to any server and cannot see it:
- study statistics: your error rate per question, consecutive correct answers, when you last saw a question
- bookmarks, and the questions in them
- settings: language, licence category, reminder time, offline mode, sound, haptics
- images and videos downloaded for offline study
One thing this list does not cover
The database of answers on your device is richer than anything we hold, and the study algorithm reads only that copy. But each answer also leaves as a usage event — question number, right or wrong, time — as section 2 describes. So a version of your answer history does exist on our side. Only the counters and bookmarks themselves stay purely local.
You can erase all of it at any time by clearing the app data in your system settings or uninstalling the app. The deletion is final, because we hold no copy.
System backup
On Android, app settings fall within Google's backup mechanism (Android Auto Backup). That copy goes to the user's own Google account, not to us, and Google controls it under the terms of your Google account. You can switch it off in your system settings.
5. Legal bases and purposes
Every processing operation rests on a basis in Article 6(1) GDPR:
| Purpose | Legal basis | If it is withdrawn |
|---|---|---|
| Providing the app and website, storing your settings and progress on your device | Art. 6(1)(b) — performance of a contract for digital content | the Service cannot be provided |
| Running subscriptions, verifying purchases, restoring access | Art. 6(1)(b) — performance of a contract | paid access cannot be maintained |
| App usage statistics (analytics) | Art. 6(1)(f) — our legitimate interest in knowing which features are used and where people get stuck | you can object under Art. 21; we then stop |
| Crash and error reports | Art. 6(1)(f) — our legitimate interest in a working app | you can object under Art. 21; we then stop |
| Advertising, including personalised ads, and measuring how it performs | Art. 6(1)(a) — your consent | ads still appear, but are not personalised |
| Question difficulty statistics | Art. 6(1)(f) — our legitimate interest; the data carries no identifier, so it cannot be linked to a person | — |
| Replying to a message or report you send | Art. 6(1)(f) — legitimate interest in handling correspondence you asked for | we stop handling the matter |
| Security, and preventing abuse and subscription fraud | Art. 6(1)(f) — legitimate interest | — |
What we ask for, and what we do not
Ads are the part we ask about. On first launch the app shows a consent dialog covering advertising; decline it and you see non-personalised ads instead. Usage statistics and crash reports are not covered by that dialog — they start with the app, and we rely on our legitimate interest rather than your consent. You can object to both at any time by writing to us, and every study feature keeps working either way. Neither is ever a condition of using the app or of the access you paid for.
6. Who receives the data
We do not sell, rent or trade data. We do not pass it to AI systems or data brokers. The full list of recipients follows.
Where a provider acts as our processor, it does so under a data processing agreement: it may use the data only on our instructions, must protect it to a standard no lower than this policy describes, and must keep it confidential. Where a provider is an independent controller, it decides its own purposes — its own privacy policy applies, and you can send requests about that processing to them as well as to us.
Google Ireland Ltd (Firebase Analytics)
Data: app instance ID, in-app events including each answer you give, device information, country derived from a masked IP address, purchase events
Purpose: app usage statistics. Here Google acts as a processor on our instructions — send your requests to us
Where processed: United States and other countries where Google operates data centres
Google Ireland Ltd (Firebase Crashlytics)
Data: error and stack trace, app installation identifier, device model, operating system and app version
Purpose: diagnosing crashes and errors. Google acts as a processor here as well
Where processed: United States and other countries where Google operates data centres
Google Ireland Ltd (AdMob)
Data: advertising identifier, IP address, device information, records of ads shown and clicked, diagnostic data
Purpose: serving ads and measuring their performance — only after you consent. For advertising, Google is an independent controller rather than our processor: ask Google directly about data AdMob processes, on the terms in its own policy
Where processed: United States and other countries where Google operates data centres
RevenueCat
Data: anonymous subscriber ID, purchase history and entitlement status, advertising campaign parameters, Google analytics identifier
Purpose: running subscriptions, verifying purchases, preventing abuse, measuring advertising. Acts as our processor
Where processed: United States
Apple
Data: App Store transaction data, Apple advertising attribution token, SKAdNetwork reports
Purpose: completing purchases and measuring App Store advertising. Apple is an independent controller of App Store account and payment data
Where processed: United States and European Union
Cloudflare
Data: IP address, browser headers, requested URL, request time. App statistics also reach our own servers through Cloudflare's edge, so the same technical data passes through it
Purpose: website hosting and content delivery, protection against automated traffic, and carrying app statistics to our own infrastructure. Acts as our processor for that transit
Where processed: United States, with edge servers worldwide
Umami
Data: URL, referrer, page title, screen resolution, browser and OS type, language, IP address processed transiently
Purpose: counting website visits. Acts as our processor
Where processed: European Union and United States
Tally
Data: whatever you enter in the support form we link to from the App Store
Purpose: receiving support requests. Acts as our processor
Where processed: European Union
Telegram
Data: the content of the message you send us, and whatever you choose to put in it
Purpose: delivering your report to our team — we currently use Telegram as an internal inbox. Telegram is an independent controller of its service. Prefer emailing [email protected] if you want correspondence to stay on ordinary email infrastructure; we are replacing this channel
Where processed: United Arab Emirates and other countries where Telegram operates infrastructure
Our own infrastructure
Data: anonymous identifier, in-app events including each answer you give, technical device data; separately and without any identifier — question difficulty statistics
Purpose: app usage statistics and question difficulty analysis
Where processed: European Union
Beyond this we may disclose data to public authorities where the law requires it, and to a legal successor in the event of a sale or merger. In the second case we will say so on this page before any transfer.
7. Advertising, consent, and tracking on iOS
The free version of the app shows ads, which is what keeps the questions free. Subscribing removes them.
Consent to advertising
In the European Economic Area, the United Kingdom and Switzerland, the app shows a consent dialog on first launch, provided by a Google-certified consent management platform and conforming to the IAB TCF standard. You agree separately to storing information on your device and to each advertising purpose. Declining does not block the app — you will see non-personalised ads, chosen without using your advertising identifier.
iOS: the tracking prompt
On Apple devices the system additionally asks for permission to track (App Tracking Transparency). That covers access to the IDFA and combining data from this app with data from other companies' apps or websites for advertising. If you do not allow it, the app cannot read the IDFA and ads will not be personalised. You can change your answer at any time under Settings → Privacy & Security → Tracking.
System-level controls
- Android: Settings → Google → All services → Ads — you can delete the advertising ID or turn off personalisation
- iOS: Settings → Privacy & Security → Apple Advertising, and Tracking
8. Withdrawing consent, and objecting
Advertising — withdrawing consent
You can withdraw consent to advertising at any time, and as easily as you gave it. Withdrawal does not affect processing that was lawful beforehand.
- In the app: Settings → Privacy choices — this reopens the same advertising consent dialog and lets you change any answer. The entry appears where the consent platform requires it, which in practice means the European Economic Area, the United Kingdom and Switzerland
- On iOS, additionally: System Settings → Privacy & Security → Tracking
- In writing: email [email protected]
Statistics and crash reports — objecting
These do not run on consent, so there is nothing to withdraw. You have the right to object instead, under Art. 21 GDPR. There is no switch for it in the app today — write to [email protected] and we will stop collecting for that installation. Include the analytics identifier from Settings → Analytics ID (copy it from the app) so we can find what we already hold and delete what we can identify.
Either way, study modes, mock exams, bookmarks and any access you paid for continue unchanged.
9. Transfers outside the EEA
Some providers listed in section 6 process data outside the European Economic Area, mainly in the United States. Each transfer relies on one of the mechanisms in Chapter V GDPR:
- a European Commission adequacy decision — for US providers participating in the EU–US Data Privacy Framework (Art. 45 GDPR)
- standard contractual clauses approved by the European Commission, together with a transfer impact assessment and supplementary technical safeguards, where no adequacy decision applies (Art. 46 GDPR)
The European Commission adequacy decision for the EU–US Data Privacy Framework is in force but is under appeal before the Court of Justice of the European Union. Should it cease to apply, we will move those transfers onto standard contractual clauses.
Messages via Telegram
In-app feedback and some website forms are still delivered through Telegram, whose infrastructure sits outside the EEA and which is not covered by an adequacy decision. That is a real transfer. We do not rely on the narrow Art. 49 GDPR derogations for it (those are for occasional, not systematic, transfers). Prefer [email protected] or the App Store support form until we finish moving that inbox to EU-hosted tooling.
We will provide a copy of the safeguards on request — write to [email protected].
10. How long we keep data
| Category | Retention period |
|---|---|
| Data on your device (answers, bookmarks, settings) | until you clear the app data or uninstall — your decision, not ours |
| Analytics events on our own infrastructure | kept while they still tell us how the app is used; deleted or aggregated once they do not. We apply a hard ceiling of 14 months once the automated purge is in place — until then, treat “while useful” as the rule |
| Crash and error reports | 90 days — the retention period Firebase Crashlytics applies to crash reports |
| Statistics in Firebase Analytics | 14 months — the period we have set for event-level data; only aggregate figures remain afterwards |
| Question difficulty statistics | no time limit — they contain no identifiers and are therefore not personal data |
| Subscription data at our payments provider | for the life of the subscription and 5 years afterwards, to meet tax and accounting obligations |
| Correspondence and reports | up to 24 months after the matter closes, or until claims become time-barred where a dispute is possible |
| Driving school form submissions | up to 24 months after the last contact, unless we start working together — then for the duration and any period accounting rules require |
| The record of your consent or refusal | for as long as the decision stands and 3 years after it changes, so we can show that we asked |
11. Your rights
You have the following rights against us:
- access to your data and a copy of it (Art. 15 GDPR)
- rectification of inaccurate or incomplete data (Art. 16)
- erasure — the "right to be forgotten" (Art. 17)
- restriction of processing (Art. 18)
- portability in a machine-readable format (Art. 20)
- objection to processing based on legitimate interest (Art. 21) — this is the one that covers usage statistics and crash reports; see section 8
- withdrawal of consent at any time (Art. 7(3)) — this covers advertising; see section 8
We make no decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you (Art. 22 GDPR). The question-selection algorithm runs entirely on your device and only changes the order you study in.
Send your request to [email protected]. We answer within one month. If the matter is complex we may extend that by two further months, and will tell you within the first month if we do.
A limit worth knowing about
We have no user accounts. Device-local data (answers, bookmarks, settings) you erase yourself by clearing app data or uninstalling. Analytics events are keyed only by a pseudonymous install ID — copy it from Settings → Analytics ID when you write to us. Without that ID we often cannot locate your events, which is the situation Art. 11(2) GDPR describes; we still stop collection for that install once you object. Question difficulty statistics cannot be attributed to a person by any means. Purchase and subscription records live with Apple or Google as well as our payments processor — ask the store for those too where needed.
Complaint to a supervisory authority
If you believe we process your data unlawfully, you can lodge a complaint with a supervisory authority. Because we are established in Spain, our lead supervisory authority is:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6, 28001 Madrid, Spain
aepd.es
You may also complain to the authority of your habitual residence or of the place of the alleged infringement. For residents of Poland that includes the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw — uodo.gov.pl.
12. Children and young people
The app is for people preparing for a driving licence exam. In Poland a course may start no earlier than three months before the required age, so most users are 16 or older.
Under Art. 8 GDPR and Art. 4 of the Polish Personal Data Protection Act, a person aged 16 or over can consent to information-society processing on their own. That matters here for advertising consent. Usage statistics and crash reports do not run on consent — they run on legitimate interest — so a parent who wants them stopped should object under Art. 21 (see section 8), not “withdraw consent”.
If you are under 16, a parent or guardian should give or approve consent to advertising. Study modes, mock exams and bookmarks all work without advertising consent. If you are a parent and believe your child under 16 consented to ads without your knowledge, or you want analytics stopped for their install, write to [email protected] — include the Analytics ID from Settings if you have the device.
13. Security
- all app and website connections are encrypted with TLS
- we keep no account database, so there is no password to steal
- study data stays on the device, protected by the app sandboxing built into the operating system
- only the person running the Service has access to the statistics
- we collect only what is described above — less data means a smaller consequence if anything goes wrong
No safeguard is absolute. If a personal data breach occurs that is likely to result in a high risk to your rights, we will notify the Agencia Española de Protección de Datos within 72 hours and tell you on this page and in the app.
15. Changes to this policy
We update this policy when the way we process data changes — for example when a provider is added or removed. The date of the last change appears at the top.
We will announce material changes in the app before they take effect, particularly any that need fresh consent. We never repurpose data under a consent you gave for something else; we ask again.
16. Contact
Filip Kowalski (Nomadic Studio) — publisher of Prawo Jazdy GO
c/o Coworking Minds, Carrer Ferrers 1, 07510 Sineu, Islas Baleares, Spain
Personal data matters: [email protected]
Help and questions about the app: [email protected]
Write in Polish, English, German or Ukrainian — we reply in the same language.
The Polish version of this policy is the binding one, as the Polish Language Act requires for consumers in Poland. This translation is provided for convenience; where the two differ, the Polish text governs.