About this English version. Permis 101’s legal documents are written in French. This English text is provided so you can read them in your own language; if the two ever differ, the French version at
permis101.com/confidentialite/ is the one that prevails.
The short version: your data stays with you.
Permis 101 is built to work without knowing anything about you: no account, no advertising, no profile. Your study progress lives on your device and, when iCloud is available, in your own iCloud — never on our servers. What we receive is limited to anonymous usage statistics, the question reports you choose to send, anti-fraud fingerprints when a purchase is verified (section 4), and the technical metadata every server receives. This page is the complete inventory, item by item.
1 · No account
The app never asks you to create an account: no email address, no password, no phone number, no profile. There is no user database on our side — nothing to breach, nothing to sell.
2 · What lives on your device
Everything the app knows about your studying stays local. Specifically, it keeps on your iPhone:
- your practice log: every question you answered, right or wrong, with its date, and your mock-test results — this is where the readiness score comes from;
- your local profile: the first name you enter (optional), your situation (first attempt, exchanging a foreign licence, or a retake — and which sections you are retaking, if any), and your test date if you set one;
- the real test result you declare yourself in the app, if you choose to;
- a local marker recording that the purchase is unlocked, and the downloaded question bank.
None of this is sent to our servers. Delete the app and the local data goes with it.
3 · iCloud sync
When your device is signed in to iCloud, syncing happens automatically: your practice log, your first name, your situation, your test date and your self-declared results are also copied into your own iCloud — the private space Apple provides you, which we cannot access. That is what lets you pick your progress back up on your other devices. This data never passes through our servers — we have none for your data. The app has no switch for this syncing: it follows your iPhone’s iCloud settings, and if iCloud isn’t available the app simply works locally.
Worth knowing: deleting the app erases the local data, but not the copies already in your iCloud — those stay in your Apple Account, under your control, and are reused if you reinstall the app. To get rid of them entirely, write to us (section 13) and we will tell you how.
4 · Purchase and proof of purchase
The full unlock is bought through the App Store: Apple handles the payment. We never receive your name, your address or your payment details. To deliver the complete question bank, the app presents our server with a proof of purchase signed by Apple. That proof contains no name, no address and no payment data; it contains a transaction number assigned by Apple — an identifier only Apple can connect to a person. Our server checks the signature and answers with an access token valid for about ten minutes. The transaction number itself is not kept, and there is no record on our side of who bought what.
To prevent and detect fraud — for example a proof of purchase copied and then published, which would let anyone download the question bank — the server does keep a minimal trace of each verification:
- a cryptographic fingerprint of the transaction number: a code computed with a secret key kept outside the database. The fingerprint cannot be turned back into the transaction number, let alone into a person;
- a network indicator derived from the IP address: a fingerprint of the originating network, computed the same way — never the address itself;
- the environment of the transaction (a real purchase or Apple’s test environment), a verification counter and dates.
These fingerprints serve one purpose: spotting the abusive use of a single proof of purchase from an abnormal number of networks — fraud prevention and detection within the meaning of Law 25. They are deleted automatically at most 90 days after the last verification. Restoring a purchase also goes entirely through Apple.
5 · Anonymous statistics
To know which parts of the app are useful and to catch bugs, the app sends anonymous usage events. The complete list:
- first install, opening, update and the app going to the background (the standard lifecycle events);
- repeated taps (“rage clicks”): if you tap the same spot on the screen several times in quick succession, PostHog’s native module sends an event containing the position of the tap on screen and the technical name of the host screen — never the content displayed, never what you are studying, never what you type (the keyboard and text fields are excluded from this detection). We use this event to find buttons that appear not to respond, so we can fix them;
- onboarding: started, situation chosen (one of the three only: first attempt, exchanging a foreign licence, or a retake), completed;
- the app’s language changed — during onboarding or in settings: the event carries the language now active (French or English, one of the two only). It replaces the older “interest expressed in an English version”, a bare counter with no properties, which app versions predating the language choice still send;
- how you heard about the app, if you choose to answer the question asked at the very end of onboarding. One answer, never required, from eleven closed choices (App Store, a Google or web search, TikTok, Instagram, Facebook, YouTube, an AI assistant such as ChatGPT or Claude, someone you know, an online group or forum, a driving school, other) — it is the app’s only attribution tool: no advertising install tracking exists. Skipping the question sends nothing at all — a missing answer is not data — and no identifier accompanies the answer beyond the random installation identifier described below;
- studying: practice session, review, mock test, scenario trainer and sign quiz — each one “started” and “finished”, with the number of questions and correct answers; for practice, also the section chosen (or “all”), endless mode (yes or no) and whether it is a retry of your mistakes (yes or no); for the mock test, the verdict per section;
- free bank exhausted: the practice screen reports that no free questions are left to practise — we count how often that screen is reached, with no further detail;
- readiness-score explanation opened: the event carries the verdict shown at that moment (ready, almost, or not yet — one of the three only), never the score itself nor the per-section detail;
- purchase: unlock screen shown (and from which door), purchase started, purchase completed; restore requested, with its outcome — one of three only: purchases restored, nothing to restore, or failed;
- purchase failed, with the cause — chosen from a closed list of eight: purchases disabled on the device, App Store unavailable, product not found, network, server busy, server error, verification refused, purchase already pending. Never the error message itself. A purchase you cancel sends nothing at all — changing your mind is not a failure;
- unlock recovered: an interrupted purchase, or a family-approval request approved later, that completes with no screen waiting on it. This event carries no properties;
- the real test result you declare yourself (passed, failed or not taken yet — and, if failed, which sections); iCloud sync becoming active;
- sharing: the “Share my result” button tapped after a passed mock test (the gesture only — never the destination you choose, never the content shared);
- invitation to rate the app: two events. The first reports that one of four planned moments has been reached for the first time on this installation — three mock tests passed, all three sections turned “ready”, half the bank covered together with a week’s study streak, or a real test you declare passed; it carries which of the four, and nothing else. The second reports that the app actually asked iOS to show its App Store rating prompt, which does not happen every time: the app allows itself at most one request per version (patch updates reopen none) and at least sixty days between two. That one carries no properties. Neither says whether the prompt appeared, nor whether you rated the app: iOS decides, and it does not tell us. The app never asks after a failure or a session that went badly;
- screenshots: if you take a screenshot while the app is on screen, iOS notifies the app and we count the event, with a single detail — the broad area of the app involved (practice, mock test, review, scenarios, signs, statistics or other). Never the image itself, which the app has no access to, and never the question displayed. That counter tells us how much the content is being copied by screenshot; it blocks nothing and warns you of nothing;
- error and crash reports: when an error occurs in the app, we receive its type (the technical name of the error, for example “StateError”) and an anonymous fingerprint — a short code computed from the message and the call stack. The message itself, file paths and the content of the screen are removed on your device, before anything is sent. One exception: if the app closes abruptly (a crash at the iOS system level), the report is produced by PostHog’s native module and sent at the next launch; that one is written beyond our reach and therefore escapes this filtering. It is a technical report — call stack and program state at the moment of the crash — not a record of your studying: the app attaches none of your progress, your answers or your first name to it.
With the single exception of the system crash described above, the properties attached to these events are only numbers, yes/no values and closed choices — never the identifier of a question, never free text, never your first name, never your test date. These events are processed by PostHog, hosted in the European Union (Frankfurt, Germany). Concretely:
- no personal profile is created;
- events carry a random identifier specific to the installation, attached to no identity — there is none;
- no “autocapture” of interactions — with the single exception of the repeated-tap detection described above — no screen or session recording;
- the app collects no location data and asks for no access to your contacts; on PostHog’s side, inferring the country or city from the IP address (“GeoIP”) is disabled in the project;
- nothing is used for advertising or sold to anyone.
You can decline these statistics: in the app, open Settings and turn off “Share anonymous statistics”. The app then stops collecting anything at all — usage events as well as error and crash reports — and does not resume at the next launch. Your choice stays on your device; it is not reported to us.
One caveat, for the same technical reason as the last point above: if the app closes abruptly while statistics are turned off, PostHog’s native module may still write a crash report on your device — it is written beyond our reach and we cannot prevent it. Nothing leaves while statistics stay off; if you ever turn them back on, that report may be sent along with the others.
6 · Question reports
If you use “Report this question” in the app, we receive exactly three things: your comment (optional), the identifier of the question and the version of the content — nothing else, and no device or personal identifier is attached. The report is anonymous: do not write personal information into it. If you do anyway and want it removed, write to us (section 13). Reports are kept for as long as it takes to check and correct the question, then at most 24 months, before being deleted.
7 · Server metadata
Like any online service, our server (used only for proof of purchase, the question-bank download and question reports) sees the IP address of the requests it receives. It appears in temporary technical logs and is used to limit abuse (rate limiting); those traces are erased automatically within hours or days and are never connected to your studying — the server does not know who is studying what. The server is hosted with Fly.io (Toronto, Canada) and its database with Neon (United States); that database contains only question reports, temporary anti-abuse counters and the purchase-verification fingerprints described in section 4.
8 · This website
permis101.com is a static site: no cookies, no analytics scripts, no fonts loaded from a third party. The site is served by Cloudflare, our host, which handles the network requests needed to deliver the pages — as any web host does.
This site’s “App Store” links carry a campaign tag — the name of the page you leave from, written into the link’s address — which Apple counts in aggregate in the statistics it provides to developers. Nothing is stored on or read from your device, and we receive no individual data: only per-campaign totals, produced by Apple under its own privacy rules.
9 · Processors and providers
- Apple — payment and purchase restoration (App Store); iCloud, as the provider of your personal space.
- PostHog (European Union, Frankfurt) — anonymous usage statistics and error reports.
- Fly.io (Toronto, Canada) — hosting for the app’s server.
- Neon (United States) — the server’s database (question reports, anti-abuse counters, purchase-verification fingerprints).
- Cloudflare — hosting for this website.
No other third party receives data. No data is sold, rented or shared for advertising purposes.
10 · Retention
- Study data: on your devices and in your own iCloud, under your control — we hold no copy of it.
- Proof of purchase: the access token expires after about ten minutes; the transaction number is not kept.
- Purchase-verification fingerprints (anti-fraud, section 4): at most 90 days after the last verification.
- Question reports: at most 24 months.
- Technical logs and anti-abuse counters (IP addresses): erased automatically, within hours to days.
- Anonymous statistics: kept by PostHog in aggregate form, with no identity to connect them to.
11 · Your rights (Law 25 and GDPR)
Permis 101 aims at compliance with Law 25 (Québec) and the GDPR (the operator is established in Europe) in the simplest way there is: by holding almost no personal information. You have the right to request access to the information we hold about you, its correction or its deletion — in practice there is normally nothing to hand over, since your study data is with you. If you have a question, a request or a concern, write to us (section 13) and we will answer within thirty days. You can also contact the Commission d’accès à l’information du Québec.
12 · Privacy officer
The person responsible for the protection of personal information is Julien Courbebaisse, the operator (section 13), reachable at [email protected].
13 · Operator and contact
Permis 101 is developed and operated by Julien Courbebaisse, a self-employed operator (autónomo) registered in Spain (NIE: Y8924027H) — a postal address is provided on request. For any question about this policy or about your data: [email protected], or the Support page. The terms of use complete this policy.
14 · Changes
If this policy changes, the new version will be published here, with its update date. This policy is written in French. Where a translation is offered, it is provided for convenience: in case of any discrepancy, the French version prevails.