Who is responsible for data
This Policy explains how data is processed in Uzbekistan PDD Tests Tickets 2026, on iapps.by, and on related support pages. The data controller and app provider is iapps.by / Alexey Strokin, unless a different provider is expressly identified in the app listing on App Store or Google Play.
For privacy, data deletion, and support requests, contact pdd@iapps.by.
Uzbekistan PDD Tests Tickets 2026 is an educational app for Uzbekistan traffic rules. The app is not a government service, does not represent any public authority, and is not designed to process government IDs, health data, precise location, contacts, SMS, calls, camera, or microphone data.
Data we may process
No account is required for the basic use of the app. We do not ask for your legal name, home address, identity documents, or precise location.
If you contact support, we may receive your email address, name or nickname, message text, app country, language, purchase details, screenshots, and technical information you choose to send.
The app and website may process app version, device model, operating system version, language, approximate region, installation source, website pages, referrals, usage events, errors, crash data, performance data, and technical identifiers generated by your device, app stores, or SDKs.
If paid features are available, App Store or Google Play handles payment, subscription, cancellation, and refund processing. We may receive only limited data needed to verify access, such as product ID, subscription status, purchase date, and technical transaction or receipt identifiers. We do not receive your full card number, CVC, or bank credentials.
Some app versions may use advertising, attribution, or analytics. In that case, advertising identifiers, ad interaction data, and impression information may be processed where allowed by device settings, store rules, and applicable law.
Purposes and legal bases
We use data to provide app features, verify purchase access, keep the app working, fix errors, answer requests, prevent abuse, analyze the quality of materials, and improve users' exam preparation.
Depending on the country and situation, the legal basis may be performance of a contract with the user, legitimate interest in service support and security, user consent, compliance with legal obligations, or protection of rights and legitimate interests.
Where consent is required for analytics, advertising, diagnostic SDKs, or device permissions, it should be requested in the app or through system settings. Users can withdraw or limit consent through device settings, App Store, Google Play, or available app settings.
Learning progress and product analytics
Detailed learning statistics are calculated on the device. To understand app quality and improve exam preparation, the app may also send pseudonymous learning and product events to Firebase. These may include a random installation identifier, question IDs and topics, the selected answer index and whether it was correct, question weights and bookmarks, exam attempt dates, duration and outcome, readiness estimates and weak topics, counts of local explanation threads, app version, language, premium state, notification settings, device model and operating system version.
The analytics copy does not include your legal name, email address, phone number, account credentials, or the text of locally stored explanation chats. Records are stored under a random identifier that we do not connect to a name or user account. Firebase Analytics and Amplitude may process pseudonymous usage events and properties; RevenueCat may process the same random identifier, product and subscription status, and attribution data to provide and measure premium access.
Resetting statistics or clearing chat history in the app removes the corresponding local data. It does not automatically erase server-side analytics or short-lived security records already received. You may request deletion of records that we can associate with your pseudonymous installation identifier by contacting pdd@iapps.by.
AI assistants
Before the first AI request is transmitted, the app asks for explicit permission to share the data described below with OpenAI. If you decline, no AI request is sent: the feature remains visible, and your latest message stays locally on the device with an option to review the permission later. You can grant or withdraw this permission at any time in AI settings. Withdrawal stops future AI transmissions but does not by itself delete records already stored by us or our providers; you can request deletion from AI settings or by email.
If you use the optional AI explanation or road-rules assistant, the app sends your messages and the relevant local conversation history to our Firebase Cloud Function. For explanations, it also sends the current test question, answer choices, rule references and explanations, and image file names. The original question image is not sent to the model; when available, a textual image description from our database is added on the server.
The request also includes app version, language, client-reported premium status, a request identifier, and a random installation identifier used for abuse prevention and limits. We store only a one-way hash of the installation identifier in assistant records and send a privacy-preserving hashed safety identifier to the model provider.
The Cloud Function sends the assembled prompt to OpenAI through the OpenAI API to generate an answer. OpenAI does not use API inputs or outputs to train its models by default. We request that response application state is not stored by OpenAI, although OpenAI may retain API content and metadata for up to 30 days for abuse monitoring or longer where legally required, as described in its data controls.
The full final model request and response, status, timing, and usage metadata are stored by us in Firebase for up to 90 days so authorized CMS users can investigate quality, safety, errors, and abuse. The raw installation identifier is not stored with these records. Conversation history also remains locally on your device for the app experience and can be cleared in AI settings. Do not include personal, confidential, payment, or third-party data in assistant messages.
Third-party services
For app operation, website hosting, analytics, diagnostics, payments, subscriptions, attribution, and distribution, we may use Apple App Store, Google Play, Google Firebase services, Amplitude, RevenueCat, email services, and other infrastructure providers.
When an AI assistant is used, Google Firebase processes the request through our backend and OpenAI processes the assembled prompt to generate the answer under its API terms, privacy policy, and data controls. OpenAI API inputs and outputs are not used to train its models by default unless the API customer expressly opts in. See https://openai.com/policies/privacy-policy/, https://openai.com/policies/business-terms/, and https://platform.openai.com/docs/models/default-usage-policies-by-endpoint.
These providers process data under their own policies and contracts. We select services that provide data protection measures and do not authorize providers to use app data for purposes unrelated to operation, analytics, security, support, advertising, or legal requirements.
Useful links: https://firebase.google.com/support/privacy, https://firebase.google.com/policies/analytics, https://amplitude.com/privacy, https://www.revenuecat.com/privacy/, https://www.apple.com/legal/privacy/.
Sharing and international processing
We do not sell personal data. We may disclose data to service providers, app stores, store payment processors, advisers, public authorities where legally required, and a successor in connection with reorganization or transfer of the business.
Data may be processed outside your country, including in the European Economic Area, the United States, and other countries where Apple, Google, Firebase, or our providers operate infrastructure. Where applicable law requires safeguards for cross-border transfers, we use available contractual, technical, and organizational protections.
Retention and deletion
We keep data only as long as needed to provide a feature, verify a purchase, answer a request, meet store or legal requirements, maintain security, resolve disputes, or protect rights.
Support messages may generally be kept for up to 3 years after the last communication unless a longer period is needed to protect rights or comply with law. Purchase and subscription data is primarily kept by App Store or Google Play under their rules. Aggregated statistics that do not reasonably identify a user may be kept for longer.
AI assistant requests and responses stored by us are scheduled for deletion after 90 days. Deletion may occur shortly after the expiry time because Firebase TTL processing is asynchronous. Copies temporarily retained by infrastructure providers are governed by their own security, backup, and abuse-monitoring policies.
Pseudonymous learning and product analytics are kept only as long as reasonably needed for product analysis, security, and legal obligations. Aggregated statistics that no longer reasonably identify an installation may be retained for longer.
If the app has no account, account deletion is not required. You can still request deletion of support, AI, or pseudonymous analytics data controlled by us. We may ask for the installation or support identifier needed to locate it. Data kept independently by Apple, Google, OpenAI, Amplitude, RevenueCat, or other providers is managed under their settings and policies.
Security
We use reasonable technical and organizational measures, including access limitation, infrastructure from major providers, protected transmission where applicable, and data minimization. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.
Children
The app is intended for traffic rules preparation and is not specifically directed to children. We do not knowingly seek to collect personal data from children under the digital consent age required by applicable law. If a child has sent us personal data without parental or guardian consent, contact us and we will take reasonable steps to delete it.
Your rights
Depending on applicable law, including data protection rules in the European Economic Area, Belarus, Kazakhstan, Uzbekistan, Ukraine, and Russia, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, and information about data recipients.
To exercise rights, contact pdd@iapps.by. We may ask for information needed to verify your identity and locate data. We respond within time limits required by applicable law and may refuse a request in whole or in part where the law allows it, for example for security, fraud prevention, legal compliance, or protection of rights.
You may also complain to the competent data protection authority in your country if you believe your rights have been violated.
Automated decisions and updates
We do not use personal data for decisions that produce legal or similarly significant effects for a user without human involvement.
We may update this Policy when the app, website, providers, or legal requirements change. The updated version will be posted on this page with a new date.