Privacy Policy
LicencePass ("Learn. Practise. Pass.") helps you prepare for the driving licence theory test in Saudi Arabia, the United Arab Emirates and Pakistan. It is published by MUCO Apps ("we", "us", "our").
We built LicencePass to work offline and to keep your study data on your phone. This policy explains what information the app handles, where it is stored, who helps us run the service, and the choices and rights you have. Some features described here are marked Planned: they are not in the app yet, and we describe them now so you know how they will work. Features in the app today are marked Now.
Lessons, signs, practice and mock exams run on your device with no connection needed.
Your answers, scores and mistake bank are stored encrypted on your device.
Signing in with Apple or Google is optional and only backs up your progress across devices.
No data brokers, and you can delete your account and data at any time.
Contents
- Who we are & scope
- Information we handle
- What we do not collect
- How we use information
- Sign in with Apple & Google
- Backend & content downloads
- Service providers
- In-app purchases
- Advertising
- Notifications
- Sharing & disclosure
- International transfers
- Data retention
- Deleting your data & account
- Your privacy rights
- Children's privacy
- Security
- Changes to this policy
- Contact us
1Who we are & scope
MUCO Apps is the developer of LicencePass and the data controller for the personal data described in this policy. This policy applies to the LicencePass mobile apps for iOS and Android, to our backend services, and to this website. It does not cover third-party services that have their own policies, such as the App Store, Google Play, or Apple and Google account services.
LicencePass is an independent study aid. It is not affiliated with, endorsed by, or operated by any traffic authority, driving school, or government body (for example the Saudi General Directorate of Traffic (Muroor), UAE traffic authorities, or Pakistan's National Highways & Motorway Police).
2Information we handle
2.1 Stored only on your device Now
To work offline, LicencePass saves the following locally on your device, encrypted with AES-256. The key is kept in your device's secure storage (iOS Keychain or Android Keystore):
- Preferences: country (market), language, theme, chosen test authority, optional test date, and reminder settings;
- Study progress: questions answered and whether they were correct, category accuracy, spaced-repetition (mistake bank) state, bookmarks, chapters read, daily streak, and mock-exam results;
- A learner number: a random 5-digit number shown on your in-app "learner permit" card. It is generated on your device and does not identify you;
- Downloaded content: question packs and sign images for your market, so they work offline.
This information does not leave your device unless you choose to sign in (Section 2.3).
2.2 Anonymous app identifier Now
When your device is online, LicencePass checks for updated questions and downloads the full question bank for your market. To authorise these downloads, the app automatically creates an anonymous account identifier on our backend. This is a random ID with a session token and contains no name, email or phone number. We use it to authorise downloads, protect the service against abuse, and, if you later sign in, to connect your account to this installation.
2.3 Optional account and progress backup Planned
If you choose Sign in with Apple or Sign in with Google, we receive and store:
- Your email address. With Sign in with Apple this can be a private relay address if you choose "Hide My Email";
- Your name, if the provider shares it (Apple shares it only the first time, and only if you allow it);
- The account identifier issued by Apple or Google, used to recognise you when you sign in again;
- Your synced study data: the progress listed in Section 2.1, mock-exam history, and profile preferences (market, test authority, language, test date, reminder time). This lets you continue on a new phone or reinstall without losing progress.
Signing in is never required to use LicencePass. We do not receive your Apple ID or Google password.
2.4 Question reports Planned
If you use "Report an error" on a question, we receive the question reference, the reason you pick (for example "wrong answer" or "typo"), any note you write, the app version, and your anonymous or account identifier. We use reports only to correct content. Please do not include personal information in the note.
2.5 Purchases Planned
If we introduce optional paid features, purchases are processed by Apple or Google (see Section 8). We receive purchase confirmations (product, transaction ID, date, country, and whether the purchase is active or refunded). We never receive your card or bank details.
2.6 Notifications Planned
If you allow notifications, your device receives a push token that we store with your platform, market and language so we can send content-update alerts and the study reminders you ask for (see Section 10).
2.7 Advertising data Planned
LicencePass shows no ads today. If we add ads in the future, our advertising partner may process device and advertising identifiers as described in Section 9.
2.8 Technical and support data Now
- Connection logs: like any online service, our backend and content-delivery providers automatically process your IP address, request time, and basic device and app details to deliver content, keep the service secure, and diagnose faults. These logs are kept only briefly (see Section 13).
- Support messages: if you email us, we receive your email address and whatever you choose to tell us.
3What we do not collect
- We do not access your contacts, photos, camera, microphone, or precise location. Your market is chosen by you (or suggested from your device language setting) and is never taken from GPS.
- We do not ask for your national ID, Iqama or Emirates ID, CNIC, driving licence number, or payment details.
- There are currently no analytics or advertising trackers in LicencePass, and we do not track you across other companies' apps or websites.
4How we use information
| Purpose | Data used | Legal basis (EU/UK GDPR) |
|---|---|---|
| Deliver lessons, practice, exams and offline question packs | On-device data, anonymous identifier, connection logs | Performance of our contract with you (the Terms) |
| Back up and sync progress across your devices | Account and synced study data | Contract (you asked for it by signing in) |
| Provide and restore paid features | Purchase records | Contract, and legal obligations (tax and accounting) |
| Correct content errors | Question reports | Legitimate interest in accurate study material |
| Keep the service secure and prevent abuse | Identifiers, connection logs | Legitimate interest in security |
| Send content-update alerts and study reminders | Push token, preferences | Consent (you can turn this off at any time) |
| Show ads, if introduced | Advertising data | Consent for personalised ads; legitimate interest for non-personalised ads |
| Answer support requests | Support messages | Legitimate interest / contract |
Readiness scores, weak-area detection and the adaptive "Smart Test" are calculated on your device using fixed rules. LicencePass does not use your data to train AI models and makes no automated decisions with legal or similarly significant effects on you.
5Sign in with Apple & Google Planned
Sign-in is offered only so you can back up progress and use it on more than one device. When you sign in:
- Apple authenticates you and gives us a signed token with your Apple account identifier and email address (or a private relay address). Apple's handling of your data is covered by the Apple Privacy Policy. You can stop using Sign in with Apple for LicencePass in your Apple ID settings (Sign-In & Security → Sign in with Apple).
- Google authenticates you and gives us a signed token with your Google account identifier, email address, name and profile picture URL. We request only the basic
openid,emailandprofilepermissions; we do not access your Gmail, Drive, contacts or other Google data. See the Google Privacy Policy; you can remove LicencePass's access at myaccount.google.com/connections.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
6Backend & content downloads Now
Everything you study works offline. We use a backend for only three things:
- Content: to check for and download updated question banks and sign images for your market. These downloads are one-way. Your answers and progress are not uploaded as part of them.
- Optional backup: if you sign in, your study progress is saved to your account so it can be restored on another device.
- Features that need a server: such as verifying purchases, question reports, and notifications, when these are available.
Our backend runs on Supabase (database and authentication). Content files are delivered through Cloudflare R2. Access to your records is restricted by row-level security, so each account can read only its own data, and all traffic is encrypted in transit (HTTPS).
7Service providers
We use the following providers to run LicencePass. They act on our instructions (as "processors") or, where noted, under their own policies:
| Provider | What it does | Status |
|---|---|---|
| Supabase, Inc. | Backend database, authentication (anonymous, Apple and Google sign-in), server functions | Now |
| Cloudflare, Inc. (R2) | Storage and delivery of question packs and images | Now |
| Apple (App Store, Sign in with Apple) | App distribution, sign-in, payment processing: under Apple's own policy | Now / Planned |
| Google (Google Play, Google Sign-In) | App distribution, sign-in, payment processing: under Google's own policy | Now / Planned |
| RevenueCat, Inc. | Validates App Store and Google Play purchases and keeps track of what you have unlocked | Planned |
| Google Firebase Cloud Messaging | Delivers push notifications | Planned |
| Google AdMob | Serves ads, if ads are introduced | Planned |
We will update this list before we start using a new provider that processes personal data.
8In-app purchases Planned
LicencePass is currently free. In the future we may offer optional one-time purchases (for example a lifetime unlock of extra features for a market). If we do:
- Payments are handled entirely by the Apple App Store or Google Play under their terms and privacy policies. We never see or store your card, bank, or billing address details.
- We (through RevenueCat) receive purchase information: product, transaction ID, purchase date, store country and currency, price, and refund or cancellation status. We use it to unlock what you bought, to restore purchases on new devices, to prevent fraud, and for our accounting and tax obligations.
- If you are signed in, purchases are linked to your LicencePass account so they follow you across devices. Otherwise they are linked to your anonymous identifier and can be restored with the store's "Restore Purchases" feature.
- Refunds are handled by Apple (reportaproblem.apple.com) or Google Play (Google Play refund policy).
9Advertising Planned
LicencePass shows no ads today. If we introduce ads, we will use Google AdMob, and:
- Ads will never appear between questions or on question and exam screens.
- AdMob may collect your device advertising identifier (Android Advertising ID, or the iOS IDFA only if you allow tracking), IP address and approximate location derived from it, device and app information, and ad interactions. It uses these to serve, limit and measure ads and to prevent fraud, as described in How Google uses information from apps that use its services.
- iOS: we will ask for your permission (App Tracking Transparency) before any tracking. If you decline, you will only see non-personalised ads. You can change this in
Settings → Privacy & Security → Tracking. - Android: you can reset or delete your advertising ID in
Settings → Google → Ads(orSettings → Privacy → Ads). - EEA, UK and Switzerland: a consent message will let you accept or refuse personalised ads before any are shown.
- Where an optional "watch an ad to unlock" feature is offered, watching is always your choice.
10Notifications Planned
LicencePass will ask before sending notifications. Study reminders you set are scheduled on your device. Content-update alerts are sent through Firebase Cloud Messaging using your device's push token. You can turn notifications off at any time in the app or in your device settings; the push token is deleted with your account.
11Sharing & disclosure
We do not sell your personal information, and we do not share it with data brokers. We disclose information only:
- To the service providers in Section 7, to run the app on our behalf;
- When you choose to share something, for example a progress or "exam ready" card through your phone's share sheet;
- If required by law, a valid legal request, or to protect the rights, safety and security of our users, the public or us;
- As part of a merger, acquisition or sale of the app, in which case this policy continues to protect your information and we will tell you about any change of controller.
12International transfers
Our providers may store and process data on servers outside your country, including in the European Union and the United States. Where the law requires (for example the EU/UK GDPR, Saudi Arabia's Personal Data Protection Law, or the UAE Personal Data Protection Law), we rely on appropriate safeguards such as the providers' Standard Contractual Clauses or data processing agreements, and we transfer only the minimum data needed to provide the service.
13Data retention
| Data | How long we keep it |
|---|---|
| On-device data | Until you delete it in the app or uninstall LicencePass. We never hold a copy unless you sign in. |
| Anonymous identifier | While the app is in use. Identifiers inactive for 12 months may be deleted. |
| Account and synced progress | Until you delete your account. It is then removed from our live systems, and backup copies expire within 30 days. |
| Question reports | Up to 24 months, to review and correct content. On account deletion the report is unlinked from your account. |
| Purchase records | As long as needed to provide what you bought and as required by tax and accounting law (typically up to 7 years), even after account deletion. |
| Push tokens | Until notifications are turned off, the token stops working, or the account is deleted. |
| Connection and security logs | Short-term, generally no longer than 90 days, unless needed to investigate abuse. |
| Support emails | Up to 24 months after the conversation ends. |
14Deleting your data & account
You can delete everything at any time. No reason is needed, and deleting your account does not cancel purchases you already own through Apple or Google.
- Delete your account in the app: open
Settings → Account → Delete account. This permanently deletes your LicencePass account, synced progress, exam history, profile and push tokens from our servers, and signs you out. - Request deletion without the app: if you no longer have the app installed, email pakmuco.apps@gmail.com from the email address linked to your account (or give us your Apple private relay address) with the subject "LicencePass account deletion". We will confirm and complete the deletion within 30 days. See also Support → Delete your account.
- Remove on-device data: uninstall LicencePass. On Android you can also use
Settings → Apps → LicencePass → Storage → Clear data. - Disconnect sign-in: you can also revoke LicencePass in your Apple ID settings or at myaccount.google.com/connections. This stops future sign-ins but does not delete data we already hold; use step 1 or 2 for that.
If you never signed in, your progress exists only on your device, so uninstalling the app deletes it. Your anonymous identifier holds no personal data, and you can also ask us to delete it.
15Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent at any time. These rights come from laws such as:
- EU/UK GDPR, including the right to complain to your local data protection authority;
- Saudi Arabia: the Personal Data Protection Law (PDPL), overseen by SDAIA;
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data;
- Pakistan: applicable data protection and electronic-crimes laws;
- California (CCPA/CPRA) and other US state privacy laws. We do not sell personal information. If personalised ads are introduced, you can opt out of "sharing" for targeted advertising through the controls in Section 9.
To exercise any right, email us (Section 19). We may need to confirm that the account is yours, and we will respond within 30 days (or sooner where the law requires). We will not treat you differently for using your privacy rights.
16Children's privacy
LicencePass is designed for people preparing for a driving licence, typically aged 16 and over. It is not directed to children under 13 (or under the minimum age of digital consent in your country, such as 16 in parts of the EU), and we do not knowingly collect their personal data. Sign-in and any future personalised advertising are not intended for children. If you believe a child has given us personal data, contact us and we will delete it.
17Security
- Study data on your device is encrypted with AES-256-GCM, with the key held in the iOS Keychain or Android Keystore.
- All communication with our backend and content storage uses HTTPS (TLS).
- Downloaded question packs are checked against a cryptographic checksum (SHA-256) before use.
- Server access is restricted per account by row-level security; secret keys stay on the server and are never shipped in the app.
No system is 100% secure, but we work to protect your information and will notify you and the relevant authorities of a breach where the law requires.
18Changes to this policy
We will update this policy when features marked Planned go live, when we add a provider, or when the law changes. We will revise the "Last updated" date and, for material changes, tell you in the app before the change takes effect. Where the law requires your consent to a change, we will ask for it.
19Contact us
Privacy questions or requests
MUCO Apps, developer of LicencePass
Email: pakmuco.apps@gmail.com
Support: Help & Support · Terms: Terms of Use
This policy is written in English and may be translated for convenience; if versions differ, the English version applies.