About this English version. Permis 101’s legal documents are written in French. This English text is provided so you can read them in your own language; if the two ever differ, the French version at
permis101.com/confidentialite/ is the one that prevails.
The short version: your data stays with you.
Permis 101 is built to work without knowing anything about you: no account, no advertising, no profile. Your study progress lives on your device and, when iCloud is available, in your own iCloud — or, on Android, in your Google Account’s backup — never on our servers. What we receive is limited to anonymous usage statistics, the question reports you choose to send, anti-fraud fingerprints when a purchase is verified (section 4), and the technical metadata every server receives. This page is the complete inventory, item by item.
1 · No account
The app never asks you to create an account: no email address, no password, no phone number, no profile. There is no user database on our side — nothing to breach, nothing to sell.
2 · What lives on your device
Everything the app knows about your studying stays local. Specifically, it keeps on your device — your iPhone or iPad, or, on Android, your phone:
- your practice log: every question you answered, right or wrong, with its date, and your mock-test results — this is where the readiness score comes from;
- your local profile: the first name you enter (optional), your situation (first attempt, exchanging a foreign licence, or a retake — and which sections you are retaking, if any), and your test date if you set one;
- the real test result you declare yourself in the app, if you choose to;
- a local marker recording that the purchase is unlocked, and the downloaded question bank.
None of this is sent to our servers. Delete the app and the local data goes with it.
If you set a test date, the app can offer up to four reminders around it (7 days, 3 days and 1 day before, then the day after). These are local notifications, scheduled and shown by your device itself from the date it keeps: no notification service, no device token, no server — nothing is sent or received. They can be turned off in the app's settings or the device's.
3 · iCloud sync and Android backup
On iPhone and iPad, when your device is signed in to iCloud, syncing happens automatically: your practice log, your first name, your situation, your test date and your self-declared results are also copied into your own iCloud — the private space Apple provides you, which we cannot access. That is what lets you pick your progress back up on your other devices. This data never passes through our servers — we have none for your data. The app has no switch for this syncing: it follows your iPhone’s iCloud settings, and if iCloud isn’t available the app simply works locally.
Worth knowing: deleting the app erases the local data, but not the copies already in your iCloud — those stay in your Apple Account, under your control, and are reused if you reinstall the app. To get rid of them entirely, write to us (section 13) and we will tell you how.
On Android there is no syncing: the app copies nothing from one device to another. It relies on Android’s automatic backup instead: if backup is turned on in your phone’s settings, the system copies, from time to time, your practice log, your first name, your situation, your test date and your self-declared results into your Google Account’s backup — the private space Google provides you, which we cannot access — and puts them back when you set up a new phone with the same account. Android decides when the backup happens and when it is restored, not the app; the app has no switch for it, it follows your phone’s settings, and if backup is turned off the app simply works locally. This data never passes through our servers. Never part of the backup: the local purchase marker (Google Play is what attests the purchase — section 4), the downloaded question bank (it downloads again) and the anonymous-statistics data (the random identifier described in section 5 is specific to each installation).
Worth knowing there too: deleting the app on Android erases the local data, but not the backup already in your Google Account — it stays under your control, in your phone’s backup settings, and Android may reuse it if you reinstall the app.
4 · Purchase and proof of purchase
The full unlock is bought through your device’s store — the App Store on iPhone and iPad, Google Play on Android: Apple or Google handles the payment. We never receive your name, your address or your payment details. To deliver the complete question bank, the app presents our server with a proof of purchase, which contains no name, no address and no payment data.
- On the App Store, the proof is signed by Apple: it contains a transaction number assigned by Apple — an identifier only Apple can connect to a person. Our server checks the signature itself, without sending anything to Apple.
- On Android, the proof is a purchase token issued by Google Play, which Google does not sign. To make sure the purchase exists, our server sends that token to Google — to its developer service (the Google Play Developer API, hosted in the United States) — and Google answers whether the purchase is valid. Unlike Apple’s verification, this is therefore a communication from our server to Google; it contains only the token, an identifier only Google can connect to a person, and nothing about your studying.
In both cases our server answers the app with an access token valid for about ten minutes. The transaction number or purchase token itself is not kept, and there is no record on our side of who bought what.
To prevent and detect fraud — for example a proof of purchase copied and then published, which would let anyone download the question bank — the server does keep a minimal trace of each verification:
- a cryptographic fingerprint of the transaction’s identifier — the Apple transaction number or, on Android, the Google Play order number (failing that, the purchase token): a code computed with a secret key kept outside the database. The fingerprint cannot be turned back into the identifier, let alone into a person;
- a network indicator derived from the IP address: a fingerprint of the originating network, computed the same way — never the address itself;
- the environment of the transaction (a real purchase, or Apple’s or Google’s test environment), a verification counter and dates.
These fingerprints serve one purpose: spotting the abusive use of a single proof of purchase from an abnormal number of networks — fraud prevention and detection within the meaning of Law 25. They are deleted automatically at most 90 days after the last verification, whichever the store. Restoring a purchase also goes entirely through Apple or, on Android, through Google.
5 · Anonymous statistics
To know which parts of the app are useful and to catch bugs, the app sends anonymous usage events. The complete list:
- first install, opening, update and the app going to the background (the standard lifecycle events);
- repeated taps (“rage clicks”), on iPhone and iPad only: if you tap the same spot on the screen several times in quick succession, PostHog’s native module sends an event containing the position of the tap on screen and the technical name of the host screen — never the content displayed, never what you are studying, never what you type (the keyboard and text fields are excluded from this detection). We use this event to find buttons that appear not to respond, so we can fix them. On Android this detection does not exist;
- onboarding: started, situation chosen (one of the three only: first attempt, exchanging a foreign licence, or a retake), completed;
- the app’s language changed — during onboarding or in settings: the event carries the language now active (French or English, one of the two only). It replaces the older “interest expressed in an English version”, a bare counter with no properties, which app versions predating the language choice still send. The end of onboarding also records, once, the language you finished it with — the same closed value (French or English), including when you keep the French offered by default;
- how you heard about the app, if you choose to answer the question asked at the very end of onboarding. One answer, never required, from twelve closed choices (App Store, Google Play — the app only offers your own device’s store —, a Google or web search, TikTok, Instagram, Facebook, YouTube, an AI assistant such as ChatGPT or Claude, someone you know, an online group or forum, a driving school, other) — it is the app’s only attribution tool: no advertising install tracking exists. Skipping the question sends nothing at all — a missing answer is not data — and no identifier accompanies the answer beyond the random installation identifier described below;
- studying: practice session, review, mock test, scenario trainer and sign quiz — each one “started” and “finished”, with the number of questions and correct answers; for practice, also the section chosen (or “all”), endless mode (yes or no) and whether it is a retry of your mistakes (yes or no); for the mock test, the verdict per section;
- free bank exhausted: the practice screen reports that no free questions are left to practise — we count how often that screen is reached, with no further detail;
- readiness-score explanation opened: the event carries the verdict shown at that moment (ready, almost, or not yet — one of the three only), never the score itself nor the per-section detail;
- purchase: unlock screen shown (and from which door), purchase started, purchase completed — these events, like the three that follow (purchase failed, cancelled, pending), also carry which variant of the unlock screen was shown (one of two, drawn at random once per installation and kept on the device only); restore requested, with its outcome — one of three only: purchases restored, nothing to restore, or failed;
- purchase failed, with the cause — chosen from a closed list of eight: purchases disabled on the device, store unavailable (the App Store or, on Android, Google Play), product not found, network, server busy, server error, verification refused, purchase already pending. Never the error message itself — and the same unlock-screen variant;
- purchase cancelled: you close Apple’s or Google’s payment sheet without buying — the event says only which door of the app the sheet had been opened from, and which unlock-screen variant; purchase pending: an authorization request (for example a parent’s approval) is under way — the same two properties, the door and the variant, nothing else;
- unlock recovered: an interrupted purchase, a family-approval request approved later or, on Android, a pending payment confirmed later, that completes with no screen waiting on it. This event carries no properties;
- the real test result you declare yourself (passed, failed or not taken yet — and, if failed, which sections) — the same event whether you answer from the statistics screen, from the day-after reminder or on the first app open after the date; iCloud sync becoming active (on iPhone and iPad);
- test date and reminders: test date set — the event only says how far away it is, in one of four bands (0 to 7 days, 8 to 30, 31 to 90, more than 90), never the date itself; the date question deferred (“Later”, with no properties); notification permission requested, with the answer (yes or no); reminders scheduled, with their count (0 to 4); reminder tapped, with which of the four (7 days, 3 days or 1 day before, or the day after) — never the time;
- sharing: the “Share my result” button tapped after a passed mock test (the gesture only — never the destination you choose, never the content shared);
- invitation to rate the app: two events. The first reports that one of five planned moments has been reached for the first time on this installation — a mock test passed, all three sections turned “ready”, half the bank covered together with a week’s study streak, a practice session of at least eight questions passed at 75% or better (a practice session — never the onboarding mini-quiz), or a real test you declare passed; it carries which of the five, and nothing else. The second reports that the app actually asked the system — iOS, or Google Play on Android — to show its rating prompt, which does not happen every time: the app allows itself at most one request per version (patch updates reopen none) and at least sixty days between two. That one carries no properties. Neither says whether the prompt appeared, nor whether you rated the app: the system decides, and it does not tell us. The app never asks after a failure or a session that went badly;
- screenshots, on iPhone and iPad only: if you take a screenshot while the app is on screen, iOS notifies the app and we count the event, with a single detail — the broad area of the app involved (practice, mock test, review, scenarios, signs, statistics or other). Never the image itself, which the app has no access to, and never the question displayed. That counter tells us how much the content is being copied by screenshot; it blocks nothing and warns you of nothing. On Android the app does not count screenshots;
- error and crash reports: when an error occurs in the app, we receive its type (the technical name of the error, for example “StateError”) and an anonymous fingerprint — a short code computed from the message and the call stack. The message itself, file paths and the content of the screen are removed on your device, before anything is sent. One exception: if the app closes abruptly (a crash at the iOS system level), the report is produced by PostHog’s native module and sent at the next launch; that one is written beyond our reach and therefore escapes this filtering. It is a technical report — call stack and program state at the moment of the crash — not a record of your studying: the app attaches none of your progress, your answers or your first name to it. On Android, the equivalent is an unhandled error in the app’s Java layer (rare: most of the app is written in a language whose errors go through the filtering described above); that report is produced by PostHog’s Android module and likewise escapes this filtering. Crashes at the level of the Android system itself are not captured by the app.
With the single exception of the system crashes described above, the properties attached to these events are only numbers, yes/no values and closed choices — never the identifier of a question, never free text, never your first name, never your test date. These events are processed by PostHog, hosted in the European Union (Frankfurt, Germany). Concretely:
- no personal profile is created;
- events carry a random identifier specific to the installation, attached to no identity — there is none;
- every event also states the app’s installation channel — one of six closed choices: App Store, TestFlight (the trial builds we run ourselves), Google Play, direct install (an installation made outside a store — on Android, our own test runs), a development build, or undetermined. That label lets us exclude our own test runs from the statistics, so they are never counted as real usage;
- no “autocapture” of interactions — with the single exception of the repeated-tap detection described above, on iPhone and iPad — no screen or session recording;
- the app collects no location data and asks for no access to your contacts; on PostHog’s side, inferring the country or city from the IP address (“GeoIP”) is disabled in the project;
- nothing is used for advertising or sold to anyone.
You can decline these statistics: in the app, open Settings and turn off “Share anonymous statistics”. The app then stops collecting anything at all — usage events as well as error and crash reports — and does not resume at the next launch. Your choice stays on your device; it is not reported to us.
One caveat, on iPhone and iPad, for the same technical reason as the last point above: if the app closes abruptly while statistics are turned off, PostHog’s native module may still write a crash report on your device — it is written beyond our reach and we cannot prevent it. Nothing leaves while statistics stay off; if you ever turn them back on, that report may be sent along with the others. On Android the app installs no module of that kind: nothing is written while statistics are off.
6 · Question reports
If you use “Report this question” in the app, we receive exactly three things: your comment (optional), the identifier of the question and the version of the content — nothing else, and no device or personal identifier is attached. The report is anonymous: do not write personal information into it. If you do anyway and want it removed, write to us (section 13). Reports are kept for as long as it takes to check and correct the question, then at most 24 months, before being deleted.
7 · Server metadata
Like any online service, our server (used only for proof of purchase, the question-bank download and question reports) sees the IP address of the requests it receives. It appears in temporary technical logs and is used to limit abuse (rate limiting); those traces are erased automatically within hours or days and are never connected to your studying — the server does not know who is studying what. The server is hosted with Fly.io (Toronto, Canada) and its database with Neon (United States); that database contains only question reports, temporary anti-abuse counters and the purchase-verification fingerprints described in section 4.
8 · This website
permis101.com is a static site: no cookies, no analytics scripts, no fonts loaded from a third party. The site is served by Cloudflare, our host, which handles the network requests needed to deliver the pages — as any web host does.
This site’s “App Store” links carry a campaign tag — the name of the page you leave from, written into the link’s address — which Apple counts in aggregate in the statistics it provides to developers. Nothing is stored on or read from your device, and we receive no individual data: only per-campaign totals, produced by Apple under its own privacy rules.
This site’s “Google Play” links, where there are any, work the same way: a campaign tag (“referrer”) written into the link’s address, which Google counts in aggregate in its developer console. On Android the app never reads that tag: it does not query the Android service that would let it recover the tag after installation, and all we receive from Google are totals.
9 · Processors and providers
- Apple — on iPhone and iPad: payment and purchase restoration (App Store); iCloud, as the provider of your personal space.
- Google — on Android: payment and purchase restoration (Google Play); the Google Play Developer API (United States), to which our server sends the purchase token for confirmation (section 4); Android backup, as the provider of your personal space (your Google Account).
- PostHog (European Union, Frankfurt) — anonymous usage statistics and error reports.
- Fly.io (Toronto, Canada) — hosting for the app’s server.
- Neon (United States) — the server’s database (question reports, anti-abuse counters, purchase-verification fingerprints).
- Cloudflare — hosting for this website.
No other third party receives data. No data is sold, rented or shared for advertising purposes.
10 · Retention
- Study data: on your devices and, depending on the device, in your own iCloud or in your Google Account’s backup, under your control — we hold no copy of it.
- Proof of purchase: the access token expires after about ten minutes; the Apple transaction number is not kept; Google purchase token: not kept — sent to Google for confirmation, then discarded.
- Purchase-verification fingerprints (anti-fraud, section 4): at most 90 days after the last verification.
- Question reports: at most 24 months.
- Technical logs and anti-abuse counters (IP addresses): erased automatically, within hours to days.
- Anonymous statistics: kept by PostHog in aggregate form, with no identity to connect them to.
11 · Your rights (Law 25 and GDPR)
Permis 101 aims at compliance with Law 25 (Québec) and the GDPR (the operator is established in Europe) in the simplest way there is: by holding almost no personal information. You have the right to request access to the information we hold about you, its correction or its deletion — in practice there is normally nothing to hand over, since your study data is with you. If you have a question, a request or a concern, write to us (section 13) and we will answer within thirty days. You can also contact the Commission d’accès à l’information du Québec.
12 · Privacy officer
The person responsible for the protection of personal information is Julien Courbebaisse, the operator (section 13), reachable at soutien@permis101.com.
13 · Operator and contact
Permis 101 is developed and operated by Julien Courbebaisse, a self-employed operator (autónomo) registered in Spain (NIE: Y8924027H) — a postal address is provided on request. For any question about this policy or about your data: soutien@permis101.com, or the Support page. The terms of use complete this policy.
14 · Changes
If this policy changes, the new version will be published here, with its update date. This policy is written in French. Where a translation is offered, it is provided for convenience: in case of any discrepancy, the French version prevails.