Law 25 — Québec

Privacy policy

Last updated: 24 September 2026
About this English version. Permis 101’s legal documents are written in French. This English text is provided so you can read them in your own language; if the two ever differ, the French version at permis101.com/confidentialite/ is the one that prevails.

The short version: your data stays with you.

Permis 101 is built to work without knowing anything about you: no account, no advertising, no profile. Your study progress lives on your device and, when iCloud is available, in your own iCloud — or, on Android, in your Google Account’s backup — never on our servers. What we receive is limited to anonymous usage statistics, the question reports you choose to send, anti-fraud fingerprints when a purchase is verified (section 4), and the technical metadata every server receives. This page is the complete inventory, item by item.

1 · No account

The app never asks you to create an account: no email address, no password, no phone number, no profile. There is no user database on our side — nothing to breach, nothing to sell.

2 · What lives on your device

Everything the app knows about your studying stays local. Specifically, it keeps on your device — your iPhone or iPad, or, on Android, your phone:

None of this is sent to our servers. Delete the app and the local data goes with it.

If you set a test date, the app can offer up to four reminders around it (7 days, 3 days and 1 day before, then the day after). These are local notifications, scheduled and shown by your device itself from the date it keeps: no notification service, no device token, no server — nothing is sent or received. They can be turned off in the app's settings or the device's.

3 · iCloud sync and Android backup

On iPhone and iPad, when your device is signed in to iCloud, syncing happens automatically: your practice log, your first name, your situation, your test date and your self-declared results are also copied into your own iCloud — the private space Apple provides you, which we cannot access. That is what lets you pick your progress back up on your other devices. This data never passes through our servers — we have none for your data. The app has no switch for this syncing: it follows your iPhone’s iCloud settings, and if iCloud isn’t available the app simply works locally.

Worth knowing: deleting the app erases the local data, but not the copies already in your iCloud — those stay in your Apple Account, under your control, and are reused if you reinstall the app. To get rid of them entirely, write to us (section 13) and we will tell you how.

On Android there is no syncing: the app copies nothing from one device to another. It relies on Android’s automatic backup instead: if backup is turned on in your phone’s settings, the system copies, from time to time, your practice log, your first name, your situation, your test date and your self-declared results into your Google Account’s backup — the private space Google provides you, which we cannot access — and puts them back when you set up a new phone with the same account. Android decides when the backup happens and when it is restored, not the app; the app has no switch for it, it follows your phone’s settings, and if backup is turned off the app simply works locally. This data never passes through our servers. Never part of the backup: the local purchase marker (Google Play is what attests the purchase — section 4), the downloaded question bank (it downloads again) and the anonymous-statistics data (the random identifier described in section 5 is specific to each installation).

Worth knowing there too: deleting the app on Android erases the local data, but not the backup already in your Google Account — it stays under your control, in your phone’s backup settings, and Android may reuse it if you reinstall the app.

4 · Purchase and proof of purchase

The full unlock is bought through your device’s store — the App Store on iPhone and iPad, Google Play on Android: Apple or Google handles the payment. We never receive your name, your address or your payment details. To deliver the complete question bank, the app presents our server with a proof of purchase, which contains no name, no address and no payment data.

In both cases our server answers the app with an access token valid for about ten minutes. The transaction number or purchase token itself is not kept, and there is no record on our side of who bought what.

To prevent and detect fraud — for example a proof of purchase copied and then published, which would let anyone download the question bank — the server does keep a minimal trace of each verification:

These fingerprints serve one purpose: spotting the abusive use of a single proof of purchase from an abnormal number of networks — fraud prevention and detection within the meaning of Law 25. They are deleted automatically at most 90 days after the last verification, whichever the store. Restoring a purchase also goes entirely through Apple or, on Android, through Google.

5 · Anonymous statistics

To know which parts of the app are useful and to catch bugs, the app sends anonymous usage events. The complete list:

With the single exception of the system crashes described above, the properties attached to these events are only numbers, yes/no values and closed choices — never the identifier of a question, never free text, never your first name, never your test date. These events are processed by PostHog, hosted in the European Union (Frankfurt, Germany). Concretely:

You can decline these statistics: in the app, open Settings and turn off “Share anonymous statistics”. The app then stops collecting anything at all — usage events as well as error and crash reports — and does not resume at the next launch. Your choice stays on your device; it is not reported to us.

One caveat, on iPhone and iPad, for the same technical reason as the last point above: if the app closes abruptly while statistics are turned off, PostHog’s native module may still write a crash report on your device — it is written beyond our reach and we cannot prevent it. Nothing leaves while statistics stay off; if you ever turn them back on, that report may be sent along with the others. On Android the app installs no module of that kind: nothing is written while statistics are off.

6 · Question reports

If you use “Report this question” in the app, we receive exactly three things: your comment (optional), the identifier of the question and the version of the content — nothing else, and no device or personal identifier is attached. The report is anonymous: do not write personal information into it. If you do anyway and want it removed, write to us (section 13). Reports are kept for as long as it takes to check and correct the question, then at most 24 months, before being deleted.

7 · Server metadata

Like any online service, our server (used only for proof of purchase, the question-bank download and question reports) sees the IP address of the requests it receives. It appears in temporary technical logs and is used to limit abuse (rate limiting); those traces are erased automatically within hours or days and are never connected to your studying — the server does not know who is studying what. The server is hosted with Fly.io (Toronto, Canada) and its database with Neon (United States); that database contains only question reports, temporary anti-abuse counters and the purchase-verification fingerprints described in section 4.

8 · This website

permis101.com is a static site: no cookies, no analytics scripts, no fonts loaded from a third party. The site is served by Cloudflare, our host, which handles the network requests needed to deliver the pages — as any web host does.

This site’s “App Store” links carry a campaign tag — the name of the page you leave from, written into the link’s address — which Apple counts in aggregate in the statistics it provides to developers. Nothing is stored on or read from your device, and we receive no individual data: only per-campaign totals, produced by Apple under its own privacy rules.

This site’s “Google Play” links, where there are any, work the same way: a campaign tag (“referrer”) written into the link’s address, which Google counts in aggregate in its developer console. On Android the app never reads that tag: it does not query the Android service that would let it recover the tag after installation, and all we receive from Google are totals.

9 · Processors and providers

No other third party receives data. No data is sold, rented or shared for advertising purposes.

10 · Retention

11 · Your rights (Law 25 and GDPR)

Permis 101 aims at compliance with Law 25 (Québec) and the GDPR (the operator is established in Europe) in the simplest way there is: by holding almost no personal information. You have the right to request access to the information we hold about you, its correction or its deletion — in practice there is normally nothing to hand over, since your study data is with you. If you have a question, a request or a concern, write to us (section 13) and we will answer within thirty days. You can also contact the Commission d’accès à l’information du Québec.

12 · Privacy officer

The person responsible for the protection of personal information is Julien Courbebaisse, the operator (section 13), reachable at soutien@permis101.com.

13 · Operator and contact

Permis 101 is developed and operated by Julien Courbebaisse, a self-employed operator (autónomo) registered in Spain (NIE: Y8924027H) — a postal address is provided on request. For any question about this policy or about your data: soutien@permis101.com, or the Support page. The terms of use complete this policy.

14 · Changes

If this policy changes, the new version will be published here, with its update date. This policy is written in French. Where a translation is offered, it is provided for convenience: in case of any discrepancy, the French version prevails.