Privacy Policy
Esta es la política de privacidad de Mr. Driver’s Ed, y está en inglés. El texto en inglés que aparece abajo es el que rige. Si tiene preguntas sobre él, escríbame a support@mrdriversed.com y le respondo en español.
Mr. Driver’s Ed is built to need as little of your data as possible. You can use the entire study app without an account, and by default nothing you do in the app leaves your device. This policy explains the three ways data can exist, two of which are optional and off until you choose them.
The short version
| Category | What | Where | Default |
|---|---|---|---|
| Studying | Questions answered, progress, streaks, scores | Your device only | Always on-device |
| Optional guardian account | Guardian email + password (sign-in) | Google — Firebase Authentication, United States | Off until you create an account |
| Optional guardian account | Learner display names, synced progress | My servers (AWS, United States) | Off until you create an account |
| Optional anonymous usage stats | Nine milestone counts, no identifiers | My servers, as aggregate counters only | Off until you turn it on |
The app shows no ads, contains no advertising SDK and no analytics or crash-reporting SDK of mine, does not track you across apps or websites, and never sells or shares personal data. It does include sign-in libraries from Google, which are listed in section 5 along with what they may collect.
1. Studying (no account)
All study data — your answers, spaced-repetition state, streaks, exam results — is stored in a local database on your device. It is not transmitted to me. Downloading a state’s question bundle is an anonymous file download from my content network, which has access logging deliberately turned off. You can export a copy of your study data or erase all of it at any time in Settings & privacy.
2. Optional guardian account and sync
A parent or guardian (an adult — creating an account requires attesting you are 18 or older) may create a free account to sync a learner’s progress across devices and see it on a dashboard. If you do, I store:
- Guardian email address and password — to sign you in.
- Learner display names — names you choose to label learners on your dashboard (a first name or nickname is enough; it’s only used to label the dashboard).
- Synced study progress — spaced-repetition state and practice-attempt history for each learner.
- A self-reported official-test result — if a learner records passing the real DMV test, the date, the state, and which test it was sync so the guardian dashboard can show it. Nothing verifies it and no state is contacted; it is what the learner typed.
Two providers hold different halves of this, and both process it in the United States. Signing in runs on Firebase Authentication, a Google service, so your email address and password are stored by Google, and Google records the IP address and the app/browser user agent of sign-ups and sign-ins to prevent abuse (it keeps those logs for a few weeks). Learner display names and synced study progress are stored with Amazon Web Services. Both encrypt the data in transit and at rest, and it is used only to sign you in and provide sync and the guardian dashboard — never for advertising, profiling, or sale. A second guardian can join only by redeeming a single-use invite code created by the learner’s owner, and the owner can revoke that access at any time.
Teen devices have no account. A guardian pairs a teen’s device using a one-time code. The teen’s device gets a limited token that can sync only that one learner’s progress. I do not ask the teen for a name, an email, or any account information. The device does send its model name (for example “iPhone” or “Pixel 8”) when it is paired, so a guardian can tell paired devices apart on the dashboard; nothing else about the device is collected. A guardian can unlink the device at any time, which cuts off its access immediately.
Export and deletion. In the app you can export a learner’s synced data and delete a learner — deletion removes every synced record for that learner from my servers. Deleting your guardian account (Settings & privacy → Account & sync → Delete my account) removes the account and every learner you own, including their synced data; learners you merely co-oversee belong to their owner’s household and are untouched. On-device data is separately erasable in Settings & privacy. Full deletion instructions, including how to request it by email if you no longer have the app installed.
3. Optional anonymous usage stats
Settings & privacy contains a switch called “Share anonymous usage stats.” It is off by default. If you turn it on, the app sends at most nine one-time milestone events: started studying, passed a practice exam, reached the readiness threshold, shared a pass, reported passing the real DMV test, left a tip, changed the study language (the event does not say which language), set the phone up as a parent’s, and paired with a parent’s account. Each event contains only the milestone name, the state being studied (e.g. “AR”), and the platform (“ios” or “android”) — no user ID, no device ID, no account link, and no study content. A phone set up as a parent’s has no state, because it never downloads a state’s questions; those events send the placeholder “ZZ”, which is not a state. My server stores these only as daily aggregate counters (for example, “how many devices passed a practice exam on this date”); it is technically incapable of describing an individual device. Turning the switch off stops sending and discards anything queued.
4. Children’s privacy
Mr. Driver’s Ed is designed for teen permit-seekers and their parents. On first launch the app asks an age question. If a user self-identifies as under 13, the app runs in offline-only mode: accounts, sync, device pairing, and usage stats are all unavailable, and I collect nothing from that device. Guardian accounts must be created by an adult. Learner sync is enabled by the guardian — the guardian controls what syncs and can delete it at any time (see section 2). I do not knowingly collect personal information from children under 13; if you believe a child has provided me personal information, write to support@mrdriversed.com and I will delete it.
5. Service providers
I use two data processors, and both process in the United States:
- Google — Firebase Authentication. It stores guardian email addresses and passwords and performs the sign-in itself. This applies to every guardian account, including one created with an email address and a password — not only to accounts that use a “Sign in with Google” button. Google states that Firebase Authentication runs only from US data centres, that it logs the IP address and user agent of authentication requests to prevent abuse and keeps those logs for a few weeks, and that when I delete a user it removes the data from its live and backup systems within 180 days. Google also collects diagnostic information about how its sign-in code is running on the device — as part of operating the service, and for Google’s own analytics. Google’s own declaration says that this diagnostic data is not linked to your identity and is not used to track you. None of it reaches me; I cannot see it or query it.
- Amazon Web Services — hosting. It stores learner display names, synced study progress, and the anonymous usage counters.
The app also includes Google’s own sign-in libraries so that the “Sign in with Google” button can open a native Google sheet rather than a web page — Google’s GoogleSignIn-iOS library on iPhone and iPad, and Android’s built-in Credential Manager with Google Identity on Android. They run only if you tap that button, and if you never do, they are never contacted. When you do, you are signing in to Google, so Google handles that step under its own privacy policy; all I receive back is the sign-in token and the email address that becomes your account, exactly as described in section 2. Sign in with Apple works the same way where it is offered — Apple handles that step under its own privacy policy, through the system’s own dialog rather than a library I bundle, and I receive only what is needed to create your session.
Apple requires every library bundled in an iPhone or iPad app to publish what it may collect, and Google’s published declaration for its iOS sign-in library covers a wider surface than this app uses: your name, email address and phone number, an approximate (city-level) location, your Google user ID, a device identifier, and general usage data — some of it for Google’s own analytics. Google’s declaration for the Firebase Authentication library adds the diagnostic data described above, which it marks as not linked to your identity. All of it is collected by Google, for signing you in, and none of it reaches me beyond the email address in section 2. This app never asks you for a phone number or your location, and has no code that reads either. Both declarations also state that the libraries do no tracking and contact no tracking domains. Because Apple shows the App Store the sum of what an app and its libraries declare, both lists appear on this app’s App Store privacy label, and I have declared them there rather than leave them out.
The app stores (Apple App Store, Google Play) may show you the listing and handle installs, ratings prompts, and in-app review dialogs under their own policies. If you leave an optional tip, Apple or Google processes that payment under its own terms and I never see or receive your payment details — the app keeps no receipt and stores no purchase history, and nothing about a tip reaches my servers except the optional “left a tip” milestone count in section 3, and only if you turned usage stats on. There is no advertising SDK in the app, and I have added no analytics or crash-reporting SDK — the app bundles Firebase’s authentication library and Google’s sign-in libraries described above, with no Firebase Analytics and no crash reporting.
6. Data retention
I keep each category of data only as long as it serves the purpose it was collected for, and nothing is retained indefinitely — every category has a deletion path or an automatic expiry:
- On-device study data (purpose: your studying) — stays on your device until you erase it in Settings & privacy.
- Guardian account and synced learner data (purpose: sign-in, sync, and the guardian dashboard) — kept while the account or learner exists, deleted when you delete the learner or the account (see section 2). Deletion is immediate in the live systems. Disaster-recovery backups age out on their own afterwards: up to 35 days for the sync database, and Google states that Firebase Authentication clears a deleted user from its live and backup systems within 180 days.
- Sign-in security logs (purpose: preventing abuse of sign-up and sign-in) — the IP address and user agent Google records with each authentication request; Google states it keeps these for a few weeks. I cannot query them and they are not linked to anything in the app.
- Anonymous usage counters (purpose: aggregate feature-use counts; contain no personal data) — expire automatically after about 13 months.
7. Your choices and rights
Everything above is user-controllable in the app: study without an account, export data, erase the device, delete learners and the account, and keep usage stats off. Depending on where you live you may have additional legal rights (access, correction, deletion, portability); write to support@mrdriversed.com and I will honor them.
8. Changes
If this policy changes, I will update it at this URL and update the effective date. A material change to what is collected will be called out in the app’s release notes.