Controller and contact
The controller of personal data is Alexey Strokin, the operator of iapps.by. Send questions, requests to exercise your rights, and deletion requests to pdd@iapps.by.
This policy applies to the mobile app, its AI assistants, case studies and their review, synchronization of learning statistics, support, and related web pages.
Independent app and official sources
Questions and other referenced materials come from official sources of the Ministry of Transport of the Czech Republic, including the IS eTesty system. Czech Driving Test 2026 is an independent educational app.
Data stored on your device
Basic use of the app does not require an account or Firebase Authentication. Test results, favorite questions, settings, practice history, draft case-study answers, and conversation history may be stored locally on your device.
When iCloud is available, the app may store only random identifiers of submitted case studies and other supported synchronization data there. The case-study answers themselves are not stored in iCloud; the identifier is used to retrieve the status and result from our backend on another device with the same iCloud account. We do not receive your name, email address, or iCloud account credentials.
Resetting statistics or clearing history in the app removes the corresponding local data. It does not automatically delete analytics or security records already received by the server.
Technical, analytics, and purchase data
When you launch and use the app, we automatically process technical and usage data for operation, security, product analytics, and troubleshooting. This includes a random installation identifier, app and operating system versions, language, device type, event time, sessions, screens and features used in the app, learning results and progress summaries, diagnostic data, and an approximate country inferred by the service provider.
The random identifier is stored on your device and allows events to be associated with the same installation across subsequent launches. This data is pseudonymous, not automatically anonymous. Learning statistics may also be sent to our backend to track learning progress and provide supported personalized features, including a study plan you request.
To verify premium access, we may process a random identifier, the product identifier including the selected RO, ZPZ, or ZD program, subscription or purchase status, transaction date, and campaign attribution data. We do not receive your payment card details or App Store account password; Apple processes the payment.
We use Google Firebase Analytics and Amplitude to measure usage and improve app features, Firebase Crashlytics to diagnose errors, Firebase App Check to verify app requests, and RevenueCat to verify purchases and premium access and handle related attribution. The categories of data processed vary according to the purpose of each service.
When you view a question with a video, the app may load the video directly from the Ministry of Transport's official eTesty website. The operator of that source may receive your IP address, the time of the request, and technical data that your device normally transmits when loading internet content.
Case studies and manual review
This optional feature is intended for the transport operator professional competence program (ZD). After your explicit confirmation, the app sends a random submission identifier, the selected case-study identifier, question identifiers, your written answers, and limited technical app context. The full official assignment is not sent from the app; the backend retrieves it by its identifier from our secure storage.
We store the answers, review status, scores or written assessments, reviewer comments, review time, and the authorized reviewer's audit record in Firebase. Access is restricted to a limited group of authorized people through a separate section of the internal CMS. The reviewer's internal notes are not shown to the user.
If you request a notification of the result and allow notifications in system settings, we process a device token for Firebase Cloud Messaging and Apple Push Notification service. You can change this permission at any time in device settings; without it, you can still retrieve the status when you open the app.
The submission is not linked to a user account in the app. We use only a random identifier to locate it. Do not include your name, contact details, vehicle registration numbers, employer details, or other personal or confidential information in your answers.
AI assistants
Before sending the first AI request, the app asks for your explicit permission to share data. When you voluntarily use a question explanation or the road-rules assistant, our backend processes the conversation text and, depending on the situation, the question and answer text, explanations, question identifier and topic, a rule reference, a textual image description, or the question image itself.
For a paid AI case-study review that you manually request, the backend retrieves your saved answers using the random identifier and adds the official assignment and questions from server storage using the content identifier. This context and your subsequent conversation are sent to the OpenAI API. The AI assessment is only interim learning feedback and does not replace human review or the result of an actual examination.
The request also includes the app version, language, reported premium access status, a request identifier, and a random installation identifier for security and rate limits. For a request about a personal study plan, the backend may add a limited learning progress summary, such as readiness, weak topics, and recent results. This summary is not retrieved for general questions about road rules.
The assembled request is sent through Google Firebase to the OpenAI API to generate an answer. OpenAI API inputs and outputs are not used to train models by default unless the API customer explicitly opts into sharing. OpenAI may normally retain content and metadata in security logs for up to 30 days, or longer if required by law or to protect the service.
Do not send names, addresses, phone numbers, email addresses, identity documents, payment details, health data, or confidential information about yourself or another person in messages.
Purposes and legal bases
We verify purchases and premium access, provide the features you request, manually review submitted case studies, and provide related support on the basis of performance of a contract under Article 6(1)(b) GDPR.
Product analytics and diagnostics are used to evaluate feature usage, identify errors, and improve the app. For this processing, we rely on legitimate interests under Article 6(1)(f) GDPR. We also rely on our legitimate interest in protecting the service and its users for security, abuse prevention, and the protection of rights. You can object to processing based on legitimate interests as described below.
Content is shared with OpenAI for optional AI features on the basis of your consent under Article 6(1)(a) GDPR. You can withdraw consent in AI settings; withdrawal does not affect the lawfulness of earlier processing. Mandatory retention or disclosure required by law is based on Article 6(1)(c) GDPR. This does not affect any separate legal requirements for storing data on, or accessing data from, your device.
Recipients and international transfers
Depending on the feature used, data may be processed by Apple, Google Firebase including Firebase Cloud Messaging, Amplitude, RevenueCat, OpenAI, our infrastructure and support providers, authorized internal case-study reviewers, professional advisers, or public authorities where required by law.
When sharing user data, we require third parties to provide the same or an equivalent level of protection as this policy and the App Store rules. For providers acting as our processors, contractual terms must restrict processing to agreed purposes and ensure confidentiality, security, and assistance with the exercise of rights. A reference to a provider's policy does not replace our obligations as controller.
Some providers may process data outside the Czech Republic or the European Economic Area. In that case, we rely on a legally recognized mechanism, such as an adequacy decision, standard contractual clauses, and supplementary safeguards.
You can request information about the safeguards used for a specific transfer and how to obtain a copy by contacting pdd@iapps.by.
Provider information: https://firebase.google.com/support/privacy, https://amplitude.com/privacy, https://www.revenuecat.com/privacy/, https://openai.com/policies/privacy-policy/, and https://www.apple.com/legal/privacy/.
Retention and security
Records of individual AI requests and responses on our backend, including stored context and pseudonymous technical data, have a retention period of 90 days from creation. They are used for diagnostics, security, and analysis of AI operation. After this period, they are scheduled for automatic deletion; technical deletion takes place asynchronously. This period is separate from the OpenAI retention described above and does not apply to local history on your device or to the copy of an AI assessment stored with a case study.
We retain case-study submissions, answers, manual assessments, and any copy of an AI assessment during the review and the subsequent provision of the result through the submission identifier. Completing a review or deleting a local draft does not itself remove the submission from the server. You can request deletion using the procedure below; further retention may be necessary to resolve a specific dispute or comply with a legal obligation.
Purchase records are retained according to the need to verify and restore purchased access, handle complaints, and comply with applicable legal obligations. Retention of analytics, diagnostic, and synchronized learning data depends on the record type, the relevant service's retention settings, and the processing purpose. Aggregated data that can no longer be linked to a specific installation may be retained for longer. You can request specific information about the retention of records we can associate with you as part of an access or deletion request.
We use reasonable technical and organizational measures, including access restrictions, app verification, and pseudonymous identifiers. However, no method of transmission or storage can be guaranteed to be absolutely secure.
Your rights
To the extent provided by the GDPR, you may request access, rectification, erasure, restriction of processing, and data portability, object to processing based on legitimate interests, and withdraw consent. Contact pdd@iapps.by; to locate pseudonymous records, we may request the random installation or submission identifier made available to you by the app, rather than an identity document unless one is necessary.
You can withdraw consent to share data with AI under AI settings → Data sharing with the AI service → Withdraw permission. New requests will not be sent to AI until you allow sharing again. Withdrawal does not itself delete previously stored data or local history and does not change processing for the other purposes described in this policy.
The AI settings → Request AI data deletion option prepares an email containing the installation identifier. You must send the request; this is not immediate automatic deletion. If an email app cannot be opened, write directly to pdd@iapps.by. You can use the same contact to request deletion of other data, including analytics records or case studies; for a case study, include the submission identifier if you have it.
We respond without undue delay, normally within one month. If an extension is necessary in circumstances permitted by law, we will inform you within the first month of the reason and the extension. Our response will explain the scope of the deletion performed, any data we must retain, and the reason for retaining it. We will obtain the necessary cooperation from our processors; data processed independently by Apple for your account and payments is also subject to Apple's procedures for exercising rights.
You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, https://uoou.gov.cz/.
Neither AI feedback nor manual case-study review has legal effect or constitutes an official examination result. We do not use personal data for solely automated decision-making that would have legal or similarly significant effects on the user.
Children and changes to this policy
The app is not intended to collect personal data from children. Where a legal guardian's consent is required to process a minor's data, the app should be used only with that consent.
We may change this policy when the app, providers, or legal requirements change. We will publish the current version on this page with a new date.