Privacy Policy
Effective date: 5 August 2026
1. Introduction
ATPL Training (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use:
- our website at atpltraining.io and its subdomain app.atpltraining.io (collectively, the “Website”); and
- our iOS mobile application, ATPL Training, available on the Apple App Store (the “App”),
together referred to as the “Platform.” By using the Platform you agree to the practices described here. If you do not agree, please stop using the Platform and delete the App.
2. Data Controller
ATPL Training is the data controller for personal data processed through the Platform. Our contact details:
Email: info@atpltraining.io
ATPL Training
Tallinn, Estonia
For users in the European Economic Area, the lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). You may also lodge a complaint with your local data protection authority.
3. Information We Collect
3.1 Information You Provide
- Account Data: Email address and authentication credentials when you register via email, Google Sign-In, or Apple Sign-In. We do not store passwords — authentication is handled by Supabase Auth.
- Profile Data: Display name, avatar, target exam date, and in-app preferences.
- Payment Data: Subscription plan selection and billing details, processed exclusively by Stripe (Web) or Apple In-App Purchase / RevenueCat (iOS App). We never store full card numbers or raw IAP receipts.
3.2 Information Collected Automatically
- Study & Exam Data: Exam attempts, individual question responses, scores, subject performance, LMS lesson completion, flashcard review grades (FSRS algorithm), and study streaks.
- Device & Technical Data: IP address, device type and model, operating system version, app version, unique device identifiers (not advertising identifiers — see Section 11), screen dimensions, and crash stack traces.
- Usage Analytics: Screen views, feature interactions, session duration, and in-app navigation — collected only after you grant analytics consent (web cookie banner; iOS analytics are described in Section 10).
3.3 iOS App — Additional Data Points
When you use the iOS App, we additionally collect or process:
- Push Notification Token: A device token generated by Apple (APNs) to deliver study reminders and streak alerts. Stored only if you grant notification permission in iOS Settings.
- In-App Purchase Receipt: Apple-issued purchase receipts are shared with RevenueCat (our subscription management provider) to verify and activate your subscription. See Section 7 for RevenueCat details.
- App Diagnostics: Crash reports, ANR events, and performance traces captured by Sentry (crash monitoring). Reports include device model, iOS version, app version, and the stack frame where the crash occurred. Personally identifiable data is minimised — Sentry captures your user ID (not email) only when you are logged in.
4. How We Use Your Data
- Service Delivery: Providing the question bank, exam simulator, LMS, spaced-repetition review, AI coaching, and community features across both the Website and App.
- Personalization: Tailoring study recommendations, identifying weak subjects, and scheduling flashcard reviews based on your performance.
- Subscription Management: Processing and activating subscriptions, managing billing, handling refunds, and restoring purchases across devices.
- Communications: Sending transactional emails (welcome, password reset, receipts) via Resend, and optional push notifications (study reminders, streak alerts) via your iOS device.
- Crash & Error Resolution: Using Sentry diagnostic data to identify and fix bugs and crashes.
- Platform Improvement: Aggregating anonymised usage data to prioritise new features and improve performance.
5. Legal Basis (GDPR)
For users in the EEA, UK, or Switzerland, we rely on the following legal bases under the General Data Protection Regulation (Regulation (EU) 2016/679):
- Contractual Necessity (Art. 6(1)(b)): Delivering the services you requested — account creation, study data, subscriptions.
- Legitimate Interests (Art. 6(1)(f)): Crash monitoring, fraud prevention, and aggregated analytics to improve the Platform.
- Consent (Art. 6(1)(a)): Analytics cookies on the Website; optional push notifications on iOS. You may withdraw consent at any time.
- Legal Obligation (Art. 6(1)(c)): Retaining payment records as required by Estonian tax and accounting law.
6. Data Sharing & Sub-processors
We do not sell your personal data. We share data only with the following processors, each bound by GDPR-compliant Data Processing Agreements:
| Service | Purpose | Data Shared | Platform |
|---|---|---|---|
| Supabase | Database, auth, file storage | Account & study data | Web & iOS |
| Stripe | Web payment processing | Payment & billing details | Web |
| RevenueCat | iOS IAP & subscription mgmt | Apple IAP receipts, user ID, subscription status | iOS |
| Apple (IAP) | In-app purchase processing | Purchase receipts, pricing | iOS |
| Resend | Transactional email delivery | Email address | Web & iOS |
| OpenRouter | AI coaching (routes to models) | Anonymised exam questions & chat messages | Web & iOS |
| Sentry | Error & crash monitoring | Device info, stack traces, user ID | Web & iOS |
| PostHog | Product analytics (consent-gated) | Screen views, feature usage, device type | Web & iOS |
| Expo (EAS) | App build & update delivery | App binary, OTA update manifest | iOS |
| Vercel | Web hosting & CDN | IP address, HTTP request logs | Web |
7. RevenueCat & In-App Purchases (iOS)
On the iOS App, subscriptions are managed by RevenueCat (revenuecat.com). When you make a purchase, Apple transmits an encrypted receipt to RevenueCat on our behalf. RevenueCat uses that receipt to:
- Verify the purchase and activate your subscription tier.
- Sync your subscription status across devices when you tap “Restore Purchases.”
- Manage renewals, cancellations, and billing grace periods.
RevenueCat stores your anonymised user ID (a UUID generated by our system) and subscription state. It does not receive your name or email address. RevenueCat’s privacy policy is available at revenuecat.com/privacy.
All in-app purchases are processed by Apple. Apple’s privacy practices for payment data are governed by Apple’s own Privacy Policy.
8. Push Notifications (iOS)
The App may request permission to send push notifications. We use Apple Push Notification service (APNs) to deliver:
- Study reminders (e.g., daily streak alerts).
- Subscription renewal notices.
Your APNs device token is stored securely in our database and is never shared with advertising networks. You can disable notifications at any time in iOS Settings → Notifications → ATPL Training. Disabling notifications does not affect your ability to use the App.
9. Crash Reporting & Diagnostics
The App uses Sentry (hosted on Sentry’s EU infrastructure) for crash reporting and performance monitoring. When the App crashes or encounters an error, Sentry automatically captures:
- Device model, iOS version, and App version.
- Stack trace of the error (code location, not screen content).
- Your user ID (a UUID) if you are logged in at the time of the crash.
- App state at time of crash (which screen you were on).
Crash reports do not contain passwords, payment information, or exam question content. Data is retained in Sentry for up to 90 days. You cannot opt out of crash reporting as it is necessary for maintaining a stable, safe application (GDPR Art. 6(1)(f) legitimate interest). You can request deletion of Sentry data linked to your user ID by contacting us at info@atpltraining.io.
10. Analytics
We use PostHog (EU cloud) to understand how the Platform is used and to prioritise features.
Website: PostHog analytics are consent-gated. The library initialises with capture disabled by default; it activates only after you accept analytics cookies via the cookie banner. You may withdraw consent at any time by clicking “Manage Cookies.” See our Cookie Policy for details.
iOS App: PostHog analytics capture is enabled by default in the App. Captured events include screen views, feature interactions (e.g., “started exam,” “graded flashcard”), session length, and device type. No personal study content (e.g., specific answers) is included in analytics events. If you wish to opt out of in-app analytics, contact us at info@atpltraining.io and we will disable capture for your user ID.
PostHog’s privacy policy: posthog.com/privacy.
11. Advertising Tracking & IDFA
We do not use your device for cross-app advertising tracking. The App does not:
- Request the Apple Advertising Identifier (IDFA).
- Display third-party advertisements.
- Share your data with advertising networks or data brokers.
- Build advertising profiles or fingerprint your device.
The App will not present an App Tracking Transparency (ATT) prompt because we do not perform cross-app tracking.
12. App Permissions (iOS)
The App requests the following iOS system permissions:
| Permission | Why It Is Needed | Required? |
|---|---|---|
| Notifications | Study reminders and streak alerts | Optional |
| Photo Library (read) | Uploading a profile photo from your Camera Roll | Optional |
The App does not access your camera, microphone, location, contacts, calendar, health data, or any other device sensors. Declining any optional permission does not affect core App functionality.
13. App Store Privacy Details
In compliance with Apple’s App Store requirements, the following summarises the privacy nutrition labels declared for the ATPL Training iOS App:
Data Used to Track You
None. We do not track you across apps or websites owned by other companies.
Data Linked to You
| Category | Data Type | Purpose |
|---|---|---|
| Contact Info | Email address | Account & authentication |
| Identifiers | User ID | Account management, crash attribution |
| Purchases | Purchase history, subscription status | Subscription management (RevenueCat / Apple IAP) |
| Usage Data | Product interaction (screens visited, features used) | Analytics (PostHog), App improvement |
| Diagnostics | Crash data, performance data | Crash reporting (Sentry) |
Data Not Linked to You
| Category | Data Type | Purpose |
|---|---|---|
| Diagnostics | Aggregated performance metrics (app launch time, memory usage) | Platform performance optimisation |
14. International Transfers
Our primary infrastructure (Supabase, Vercel, PostHog, Sentry) is hosted in Europe. RevenueCat processes data in the United States under Standard Contractual Clauses (SCCs). Where data is transferred outside the EEA, we ensure adequate safeguards are in place pursuant to GDPR Chapter V.
15. Data Retention
- Account & Study Data: Retained for the lifetime of your account. Deleted within 30 days of an account deletion request.
- Usage Analytics: Retained in PostHog for up to 12 months, then anonymised.
- Crash Reports: Retained in Sentry for 90 days.
- Push Notification Tokens: Deleted when you delete your account or revoke notification permission.
- Payment Records: Retained for 7 years to comply with Estonian tax and accounting regulations.
- Server & Access Logs: Up to 90 days.
16. Cookies
The Website uses cookies and similar technologies. For a detailed breakdown of every cookie we use — including names, providers, purposes, and durations — and how to manage your preferences, please read our Cookie Policy.
In summary:
- Essential: Authentication session tokens managed by Supabase (required for login and platform functionality).
- Functional: Preferences such as theme (light/dark mode).
- Analytics: PostHog, Vercel Analytics, and Google Analytics usage data — only active after you accept analytics cookies via the cookie banner.
The iOS App does not use browser cookies. Local storage and authentication tokens in the App are managed through Apple’s Keychain and UserDefaults.
17. Data Security
We implement industry-standard safeguards: TLS 1.2+ encryption in transit, AES-256 encryption at rest in Supabase, row-level security (RLS) policies ensuring users can only access their own data, bcrypt-hashed passwords via Supabase Auth (OAuth tokens are never stored), and Stripe PCI DSS compliance for payment data. The iOS App communicates exclusively over HTTPS. In the event of a personal data breach, we will notify the Estonian Data Protection Inspectorate within 72 hours and, where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by GDPR Articles 33 and 34.
18. Your Rights
Under the GDPR and applicable data protection law, you have the right to:
- Access (Art. 15): Request a copy of the personal data we hold about you.
- Rectification (Art. 16): Correct inaccurate data (many fields are editable directly in your account settings).
- Erasure (Art. 17): Request deletion of your account and personal data (“right to be forgotten”). Note: payment records are retained as required by law.
- Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Restriction (Art. 18): Request that we limit processing of your data in certain circumstances.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting lawfulness of prior processing.
To exercise any of these rights, email info@atpltraining.io. We will respond within one month (extendable by two further months for complex requests, in which case we will inform you within the first month). You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate at aki.ee or with your local supervisory authority.
iOS account deletion: You can delete your account directly within the App at Account → Danger Zone → Delete Account, as required by Apple App Store Guidelines. Alternatively, email us at info@atpltraining.io.
19. Children
The Platform is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at info@atpltraining.io and we will delete that data promptly.
20. Changes to This Policy
We will notify you of material changes to this policy by email (to the address associated with your account) or via a prominent notice on the Website and in the App. The effective date at the top of this page reflects the latest revision. We encourage you to review this page periodically. Your continued use of the Platform after changes take effect constitutes acceptance of the revised policy.
21. Contact Us
For any privacy-related questions, data requests, or complaints:
Email: info@atpltraining.io
ATPL Training
Tallinn, Estonia
Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — aki.ee