Privacy policy
Road to Permit · Version of 29 September 2026
Who we are
Road to Permit is made by Cloud Connected: Cloud Connected sp. z o.o., pl. Doktora Edwarda Łuczkowskiego 9, 22-100 Chełm, Poland, registered in the National Court Register (KRS) under number 0000863687, tax number (NIP) 5632442947. We decide how your data is used, so under the EU's General Data Protection Regulation (GDPR) we are the "controller".
Privacy contact: contact@cloudconnected.pl. Write to it about anything in this policy. For help with the app, write to contact@cloudconnected.pl.
This policy covers the Road to Permit app on iPhone, Android and the web, and our website, roadtopermit.com.
In short
- The app's first screen tells you what the app keeps and links this policy. Nothing goes to our server before you move on from it.
- You can use the app without giving us your name or e-mail address. The app keeps your progress on your device and a copy on our server, in an account without your name or e-mail address. That copy reaches a new phone or your other devices only after you sign in with Google or Apple.
- Signing in with Google or Apple is optional.
- The AI instructor is an AI, provided by Anthropic. Before your first message the app tells you what is sent and asks for your permission; it sends nothing until you agree. We don't keep the text of your messages.
- When you buy Plus on our website, Stripe takes the payment; we never see your card details.
- We don't sell your data, we don't show ads, and we don't track you across other apps or websites.
- In the app you can download a copy of your data, and delete your account and your data, at any time.
What we collect and why
Your progress and settings
What: your answers (the question, the option you picked, whether it was right, how long you took, when), your missions and practice exams, your readiness score for each day, your streak freezes, postcards and achievements. Your settings: the app language and the explanation language, the state you're preparing for, your exam date, your daily study time, your reminder time and whether smart reminders are on, the car you picked, and your device's time zone. We also keep the app version and a random ID for each installation of the app; a new one is made after you reset your progress or delete your account.
Why: to run the course, work out your study plan and your readiness, and keep your progress when you change or add a device.
Legal basis: we need this data to provide the app you asked for (GDPR Art. 6(1)(b)).
Your account
When you move on from the app's first screen, which tells you this, the app creates an account for you on our server. It has no name and no e-mail address, only a random ID. Even without a name, that ID ties your progress together, so the law treats it as personal data, and so do we. Nothing is sent to our server before that screen, and your progress is saved under the account once you finish the first setup.
The copy on our server does not work as a backup until you sign in with Google or Apple. Until then the app shows no account ID, and it marks your sign-in session to be left out of your phone's backups, so expect a new phone, or the app installed again, to start a new account; the earlier one is deleted as "How long we keep it" describes. To keep your progress when you change phones, sign in first (Settings → Account).
If you choose "Continue with Google", Google gives our sign-in service your Google account ID and your e-mail address, and also your name and profile picture, as Google's permission screen shows. We keep only your Google account ID and e-mail address, and use them only to sign you in and to warn you by e-mail 30 days before we delete an account you have not used for 24 months; see "How long we keep it" (proposed); our sign-in service removes your name and picture before it stores anything. We never see your Google password, and we don't post anything to your Google account. You can remove the app's access in your Google Account settings.
If you sign in on a device where you already had progress without signing in, we move that progress into your account and delete the account it was saved under.
Legal basis: Art. 6(1)(b).
The AI instructor
The AI instructor answers questions about traffic rules, road signs, the exam and the app. It is part of Plus, the paid version. The button that opens it reads "Ask AI instructor", and the chat is marked "AI" for as long as it is open.
Before your first message, the app tells you that the instructor is an AI, not a person, that Anthropic provides it, what is sent and what we keep, and that its answers can be wrong; then it asks for your permission. Nothing is sent until you choose "Agree"; with "Not now" nothing is sent. Your choice is saved with your account, so it applies on your other devices too, and you can withdraw it at any time in Settings; the app then asks again before your next message. If we change the provider, send it more data or use the data for a new purpose, the app asks you again.
When you send a message, the app sends it to our server with the ID of the question you're looking at (not its text), your explanation language, your device's time zone and the earlier messages of the conversation. Our server adds the question and its explanation from our own content, and sends the last six messages, yours and the instructor's, to Anthropic. Before it does, it replaces e-mail addresses, phone numbers and ID numbers in your messages with placeholders; it cannot recognise names or street addresses. With the messages goes a code made from your account ID with a key only our server has: Anthropic can use it to spot abuse, and only we can link it back to your account. We don't send Anthropic your name, e-mail address, IP address or account ID.
Please don't type names, addresses, document numbers, health details, immigration status or other sensitive information in the chat. The instructor doesn't need them, and a line under the box where you type reminds you.
We don't store the text of your messages or of the answers. On your device the conversation stays only until you close the app, reset your progress or delete your account. For each message we keep a record without any text: the date, the question ID, the language, the AI model, how many tokens it used, the cost, how long it took and how it ended. We use these records for the daily limit, to control costs and to prevent abuse, and keep them as "How long we keep it" says.
Anthropic processes your messages for us under a data processing agreement.
AI answers can be wrong. The official handbook decides. The instructor gives no legal or immigration advice; for questions about documents or status, it points you to the official website of your state's licensing agency (in Florida, FLHSMV).
Legal basis: Art. 6(1)(b) to answer you; Art. 6(1)(f), our legitimate interest in limits, costs and preventing abuse, for the records.
Exam results you report
After your exam date, the app asks how it went. Answering is optional, you can choose "Prefer not to say", and the score is optional too. We save your answer with your readiness and your chance of passing at that time.
We use it for two separate things:
- to show your result on all your devices and adjust your plan (Art. 6(1)(b));
- to check how well our readiness estimate predicts real results, so that we can make it more accurate for every learner (Art. 6(1)(f), our legitimate interest in an accurate estimate). This check never changes anything for you, and you can object to it (see "Your rights").
Technical data
When the app or the website talks to our servers, our providers record technical data: your IP address, the type of device or browser, the time, and the address requested. We use it to deliver the service, keep it secure and prevent abuse, for example by limiting how many new accounts one network can create.
Legal basis: Art. 6(1)(f), our legitimate interest in running a secure service.
Our website
When you visit roadtopermit.com, our host, Netlify, records the technical data above for every request. The free game at /play/ does not use Google Analytics.
On the public website pages, we count visits with Plausible Analytics, for every visitor and without asking, because it identifies no one. Plausible sets no cookies and stores nothing on your device. Your browser sends Plausible the address of the page, the page that sent you there, your browser, operating system and device type, and your IP address. Plausible uses the IP address to find your country and, together with your browser's details and a key that changes every day, to tell one day's visits apart; it then discards the IP address and never stores it. We see only totals, such as visits per page, per country and per source. The free game at /play/ and the apps do not use Plausible. Legal basis: our legitimate interest in knowing how people find and use our website (GDPR Art. 6(1)(f)).
On the public website pages, Google Analytics is optional. It does not load until you choose Accept analytics. If you accept, Google Analytics measures the pages you visit, the page that sent you there, and technical information such as your browser, device type and approximate location derived from your IP address. It may set analytics cookies such as `_ga` to distinguish visits. We disable Google advertising signals and do not use this data for advertising. If you reject analytics, no Google Analytics tag is loaded. Your analytics choice is stored in your browser so that we can respect it on later visits.
Legal basis: your consent (GDPR Art. 6(1)(a)); where the ePrivacy rules apply, analytics storage on your device also starts only after your consent. You can change your choice at any time with the Privacy choices control on the website.
Purchases
On our website you buy Plus from us. Stripe, our payment provider, runs the payment page: you give your card details and e-mail address, and where needed your billing address, to Stripe, not to us, and Stripe e-mails you the receipt. We send Stripe your account ID with the payment, so that Plus reaches your account. Stripe tells us which payment it was, that it was paid, and later whether it was refunded or disputed. We keep that payment's reference and state with your account ID: Plus ends if the payment is refunded or reversed.
In the Android app you buy Plus in Google Play, which handles the payment; we never see your card or bank details. Our server checks the purchase with Google and records what you bought, in which store and when.
What Plus includes, and how refunds work, is in the terms.
Legal basis: Art. 6(1)(b); the records we must keep for accounting and tax, Art. 6(1)(c).
Reminders
Reminders are scheduled by the app on your phone; we don't send them from a server. Your reminder time is saved with your study plan so that it follows you to your other devices. The web version has no reminders.
What we don't collect
We don't ask for your age, date of birth, address, phone number, documents or immigration status. We don't use your location: you choose your state and, in the office finder, your county. The app doesn't access your contacts, photos, camera or microphone. We use no advertising IDs, no analytics tools and no crash-reporting tools. If we start using a new service that receives personal data, we'll name it in this policy first.
Who receives your data
| Who | What they do for us | What they receive | Role |
|---|---|---|---|
| Supabase | Sign-in, database, server functions, logs and backups | Everything described above, and the technical data of each request | Processor |
| Netlify | Hosts our website and the web version of the app | The technical data of each request | Processor |
| Anthropic | The AI behind the instructor | Your messages to the instructor, as "The AI instructor" describes | Processor |
| Stripe | Runs our website's payment page and takes the payment | Your card details, e-mail address and billing details, which you give on Stripe's page; your account ID, from us | Processor for the payment; independent controller for its own legal duties, such as fraud prevention |
| Google Analytics (Google LLC) — only after consent on public website pages | Visit statistics for the website | As "Our website" describes | Analytics service provider; Google's own terms also apply |
| Plausible Analytics (Plausible Insights OÜ, Estonia) | Visit statistics for the website, without cookies | As "Our website" describes | Processor |
| Sign in with Google; Google Play (downloads and payments) | When you sign in with Google: that you signed in to our app. On Google Play: what Google's own policy describes | Independent controller | |
| Apple | the App Store (downloads and payments) | As Google | Independent controller |
| Microsoft (Microsoft 365, Outlook) | Our privacy and support e-mail addresses | What you write to us, with your e-mail address | Processor |
Processors work for us under data processing agreements and may use your data only to provide their service to us.
Google and Apple act on their own account, under their own privacy policies.
We don't sell your personal data and don't share it for advertising. We disclose data to authorities only when the law requires it.
The app links to official websites, such as your state agency's. When you open one, that site's own privacy policy applies.
Where your data is stored
Our providers store and process data in the United States. Google Analytics may process website analytics data in the United States and other locations under Google's terms.
Plausible stores the website's visit statistics in the EU.
We are based in the EU, so when data leaves the EU we protect it with the European Commission's standard contractual clauses or the EU–US Data Privacy Framework, depending on the provider. You can ask us for a copy of these safeguards.
How long we keep it
These periods are design decisions. A period marked “proposed” is not decided yet; until it is, the period after "today" applies.
| Data | How long |
|---|---|
| Your account and progress, if you never signed in | Deleted automatically when the app has sent nothing new for 180 days and you bought nothing. The progress on your device stays, and is saved again when the app next connects |
| Your account and progress, if you signed in | deleted 24 months after your last activity, after we warn you by e-mail 30 days before (proposed). Today: until you delete the account |
| AI message records (no text) | 90 days (proposed). Today: 13 months |
| Daily AI totals and the per-minute AI counter | 12 months after your last message (proposed). Today: 13 months |
| Our sign-in service's security records (IP address, and the e-mail address of a signed-in account) | 180 days (proposed). Today: to confirm; they are not deleted with the account |
| Server logs | at most 90 days (proposed). Today: our providers' settings, to confirm |
| Backups | at most 30 days (proposed). Today: to confirm |
| Purchase records | What you bought, and a website payment's reference and state: until you delete the account. Stripe and Google keep their own records under their policies. Accounting records: as the law requires |
| Data on your device | Until you reset your progress, delete your account or remove the app |
| The file of "Download my data" on iPhone and Android | Until your next download, a reset, a deletion or the next start of the app |
Downloading and deleting your data
- Settings → Account → Download my data gives you a file with your account and everything our database keeps for it, and what the app keeps on this device: your progress, settings and results. On a phone the app opens the share sheet, so you choose where the file goes; on the web your browser saves it. The file does not include our sign-in service's own logs of sessions and sign-in events (IP address, device type).
- Settings → Account → Delete account and data deletes your account and everything our database keeps for it at once, then clears the app on this device, the AI conversation included. What it does not delete is in the last point below.
- If you never signed in, Reset progress in Settings also deletes your data on our server. If you are offline, the app finishes it when it is back online.
- If you are signed in, Reset progress clears this device and signs it out. Your account keeps your data. The reset screen says which of the two will happen.
- Removing the app does not delete your data on our server. Delete your account first.
- Copies in our providers' backups and logs disappear when those expire. Our sign-in service's security records are not deleted with the account; see "How long we keep it".
If you never signed in, the app is how we know the data is yours: use Download my data and Delete account and data there. We don't ask for documents or an e-mail address.
Your rights
Under the GDPR you can:
- get a copy of your data, also in a machine-readable format;
- have it corrected;
- have it deleted;
- limit how we use it;
- object to the uses based on our legitimate interests;
- withdraw your consent, where we asked for it; this does not affect what we did before.
Download and delete in the app, as above; change your settings in the app. For anything else, write to contact@cloudconnected.pl. We answer within one month; if a request is complex, we may take up to two more months, and we tell you so within the first month.
You can also complain to a data protection authority, for example in the country where you live or work. Our lead authority is the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, UODO; uodo.gov.pl).
If you live in the United States
Wherever you live, you can see and change your settings in the app, download a copy of your data (Settings → Account → Download my data) and delete your account and data (Settings → Account → Delete account and data). You can write to us at contact@cloudconnected.pl about anything else, and we will answer.
The law of the state where you live may give you further rights, such as appealing our answer to a request, or letting someone you authorize make a request for you. Where such a law applies to us, we follow it. We won't treat you differently for asking.
We don't sell personal data, don't share it for cross-context behavioral advertising or use it for targeted advertising, and don't use it to profile you in ways that have legal or similarly significant effects. So browser opt-out signals such as Global Privacy Control change nothing in what we do.
Young learners
Many of our learners are teens preparing for a learner's permit, which Florida issues from 15 (other states: to confirm). The app collects the same data from them as from everyone else, and only the data this policy describes. It doesn't ask anyone's age or date of birth. It has no public profiles, no messages between users and no ads, and signing in is optional. Purchases go through the app stores, whose family features let a parent approve them.
The app is not meant for children under 13. If we learn that a child under 13 has an account, we delete its data on our server.
A parent or guardian can download or delete a teen's data in the app on the teen's device. For an account signed in with Google or Apple, they can also write to contact@cloudconnected.pl; we find the account by its sign-in e-mail address and, before we act, confirm the request by e-mail with the account's owner. An account that never signed in has no name or e-mail address a request could be matched to, so for it the app on the teen's device is the way.
Automated estimates
The app estimates your readiness, your chance of passing and your study plan automatically, from your answers. These estimates only guide your studying: they never block the app or any feature, never change a price, and we never pass them to anyone else, such as an employer, a school, a driving school or an agency. They have no legal or similarly significant effect on you.
Cookies and storage on your device
The app itself does not use analytics cookies. Plausible, which counts visits on the public website pages, sets no cookies and stores nothing on your device.
On the public website pages, if you accept analytics, Google Analytics may set analytics cookies such as `_ga` and related cookies. We do not load Google Analytics before you accept it. We store your analytics choice in the browser's local storage so that we can respect it; you can change that choice with the Privacy choices control.
The app stores data on your device, in the app's or the browser's local storage, because it needs it to work: your progress, your settings, your sign-in session and a few small preferences. None of that app storage is used to track you. On Android, the app turns the phone's backups off for this data (Google's backups and transfers to a new phone). On iPhone, the app marks its storage to be left out of iCloud and computer backups. To move your progress to a new phone, sign in with Google or Apple first (Settings → Account). In a web browser, the browser decides what it keeps.
Security
Data travels encrypted. On our server, each account can reach only its own data. The keys to our AI provider stay on our server, never in the app. Your sign-in session is stored on your device, and the app marks it to be left out of the device's backups. Anyone who can use your unlocked device can still open the app with your progress, so reset or delete in the app before you pass a device on.
Changes to this policy
When we change this policy, we update the version date at the top. If a change affects how we use your data, we'll tell you in the app before it applies.
Contact
Cloud Connected sp. z o.o., pl. Doktora Edwarda Łuczkowskiego 9, 22-100 Chełm, Poland. Privacy: contact@cloudconnected.pl. Support: contact@cloudconnected.pl.