Skip to main content
ATPL Training logoATPL Training

Privacy Policy

Effective date: 5 August 2026

1. Introduction

ATPL Training (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use:

  • our website at atpltraining.io and its subdomain app.atpltraining.io (collectively, the “Website”); and
  • our iOS mobile application, ATPL Training, available on the Apple App Store (the “App”),

together referred to as the “Platform.” By using the Platform you agree to the practices described here. If you do not agree, please stop using the Platform and delete the App.

2. Data Controller

ATPL Training is the data controller for personal data processed through the Platform. Our contact details:

Email: info@atpltraining.io

ATPL Training
Tallinn, Estonia

For users in the European Economic Area, the lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). You may also lodge a complaint with your local data protection authority.

3. Information We Collect

3.1 Information You Provide

  • Account Data: Email address and authentication credentials when you register via email, Google Sign-In, or Apple Sign-In. We do not store passwords — authentication is handled by Supabase Auth.
  • Profile Data: Display name, avatar, target exam date, and in-app preferences.
  • Payment Data: Subscription plan selection and billing details, processed exclusively by Stripe (Web) or Apple In-App Purchase / RevenueCat (iOS App). We never store full card numbers or raw IAP receipts.

3.2 Information Collected Automatically

  • Study & Exam Data: Exam attempts, individual question responses, scores, subject performance, LMS lesson completion, flashcard review grades (FSRS algorithm), and study streaks.
  • Device & Technical Data: IP address, device type and model, operating system version, app version, unique device identifiers (not advertising identifiers — see Section 11), screen dimensions, and crash stack traces.
  • Usage Analytics: Screen views, feature interactions, session duration, and in-app navigation — collected only after you grant analytics consent (web cookie banner; iOS analytics are described in Section 10).

3.3 iOS App — Additional Data Points

When you use the iOS App, we additionally collect or process:

  • Push Notification Token: A device token generated by Apple (APNs) to deliver study reminders and streak alerts. Stored only if you grant notification permission in iOS Settings.
  • In-App Purchase Receipt: Apple-issued purchase receipts are shared with RevenueCat (our subscription management provider) to verify and activate your subscription. See Section 7 for RevenueCat details.
  • App Diagnostics: Crash reports, ANR events, and performance traces captured by Sentry (crash monitoring). Reports include device model, iOS version, app version, and the stack frame where the crash occurred. Personally identifiable data is minimised — Sentry captures your user ID (not email) only when you are logged in.

3.4 Visitors Without an Account

Parts of the Website work without registering — for example the ten-question demo on our question bank page and the mobile-app early-access form. If you ask us to email you something, we collect:

  • Contact Data: The email address you type into the form. We do not ask for your name and no account is created for you.
  • Result Data: The score, subject and per-question outcome of the demo session the email reports on — the same information already on your screen.
  • Consent Record: Whether you ticked the optional marketing box, and the date and time you submitted the form. We keep this as our record that consent was given, as required by GDPR Art. 7(1).
  • Anti-Abuse Data: A one-way hash of your IP address, your browser user agent, and the page you arrived from, used only to rate-limit the form so it cannot be used to send mail to people who did not ask for it. We do not store the raw IP address.

Two separate things happen, and you choose them separately. Submitting the form sends you one email with your result. The marketing box is a second, independent choice: it is unticked by default, it is never required, and ticking it also adds you to our study-tips and product-update list. Leave it unticked and you receive the result email and nothing else.

Every marketing email carries a one-click unsubscribe link. Unsubscribing takes effect immediately, and we then keep your address on a suppression list so that we do not contact you again. To have your address erased entirely, email info@atpltraining.io — you do not need an account to exercise any of the rights in Section 18.

4. How We Use Your Data

  • Service Delivery: Providing the question bank, exam simulator, LMS, spaced-repetition review, AI coaching, and community features across both the Website and App.
  • Personalization: Tailoring study recommendations, identifying weak subjects, and scheduling flashcard reviews based on your performance.
  • Subscription Management: Processing and activating subscriptions, managing billing, handling refunds, and restoring purchases across devices.
  • Communications: Sending transactional emails — welcome, password reset, receipts, and the single result email for the public question-bank demo — via Resend, and optional push notifications (study reminders, streak alerts) via your iOS device.
  • Marketing: Sending study tips, feature announcements and occasional offers by email, only to people who have separately and explicitly opted in, and only until they unsubscribe. We never add you to this list as a side effect of creating an account, buying a subscription, or asking for a demo result — each of those has its own unticked box, and leaving it unticked changes nothing else about your account.
  • Crash & Error Resolution: Using Sentry diagnostic data to identify and fix bugs and crashes.
  • Platform Improvement: Aggregating anonymised usage data to prioritise new features and improve performance.

5. Legal Basis (GDPR)

For users in the EEA, UK, or Switzerland, we rely on the following legal bases under the General Data Protection Regulation (Regulation (EU) 2016/679):

  • Contractual Necessity (Art. 6(1)(b)): Delivering the services you requested — account creation, study data, subscriptions.
  • Legitimate Interests (Art. 6(1)(f)): Crash monitoring, fraud prevention, and aggregated analytics to improve the Platform.
  • Consent (Art. 6(1)(a)): Analytics cookies on the Website; optional push notifications on iOS; emailing you the result of the public question-bank demo when you ask us to; and, as a separate and independently given consent, marketing email. You may withdraw any one of these at any time without affecting the others.
  • Legal Obligation (Art. 6(1)(c)): Retaining payment records as required by Estonian tax and accounting law.

6. Data Sharing & Sub-processors

We do not sell your personal data. We share data only with the following processors, each bound by GDPR-compliant Data Processing Agreements:

ServicePurposeData SharedPlatform
SupabaseDatabase, auth, file storageAccount & study dataWeb & iOS
StripeWeb payment processingPayment & billing detailsWeb
RevenueCatiOS IAP & subscription mgmtApple IAP receipts, user ID, subscription statusiOS
Apple (IAP)In-app purchase processingPurchase receipts, pricingiOS
ResendTransactional & opted-in marketing emailEmail address, demo result summary, marketing consent statusWeb & iOS
OpenRouterAI coaching (routes to models)Anonymised exam questions & chat messagesWeb & iOS
SentryError & crash monitoringDevice info, stack traces, user IDWeb & iOS
PostHogProduct analytics (consent-gated)Screen views, feature usage, device typeWeb & iOS
Expo (EAS)App build & update deliveryApp binary, OTA update manifestiOS
VercelWeb hosting & CDNIP address, HTTP request logsWeb

7. RevenueCat & In-App Purchases (iOS)

On the iOS App, subscriptions are managed by RevenueCat (revenuecat.com). When you make a purchase, Apple transmits an encrypted receipt to RevenueCat on our behalf. RevenueCat uses that receipt to:

  • Verify the purchase and activate your subscription tier.
  • Sync your subscription status across devices when you tap “Restore Purchases.”
  • Manage renewals, cancellations, and billing grace periods.

RevenueCat stores your anonymised user ID (a UUID generated by our system) and subscription state. It does not receive your name or email address. RevenueCat’s privacy policy is available at revenuecat.com/privacy.

All in-app purchases are processed by Apple. Apple’s privacy practices for payment data are governed by Apple’s own Privacy Policy.

8. Push Notifications (iOS)

The App may request permission to send push notifications. We use Apple Push Notification service (APNs) to deliver:

  • Study reminders (e.g., daily streak alerts).
  • Subscription renewal notices.

Your APNs device token is stored securely in our database and is never shared with advertising networks. You can disable notifications at any time in iOS Settings → Notifications → ATPL Training. Disabling notifications does not affect your ability to use the App.

9. Crash Reporting & Diagnostics

The App uses Sentry (hosted on Sentry’s EU infrastructure) for crash reporting and performance monitoring. When the App crashes or encounters an error, Sentry automatically captures:

  • Device model, iOS version, and App version.
  • Stack trace of the error (code location, not screen content).
  • Your user ID (a UUID) if you are logged in at the time of the crash.
  • App state at time of crash (which screen you were on).

Crash reports do not contain passwords, payment information, or exam question content. Data is retained in Sentry for up to 90 days. You cannot opt out of crash reporting as it is necessary for maintaining a stable, safe application (GDPR Art. 6(1)(f) legitimate interest). You can request deletion of Sentry data linked to your user ID by contacting us at info@atpltraining.io.

10. Analytics

We use PostHog (EU cloud) to understand how the Platform is used and to prioritise features.

Website: PostHog analytics are consent-gated. The library initialises with capture disabled by default; it activates only after you accept analytics cookies via the cookie banner. You may withdraw consent at any time by clicking “Manage Cookies.” See our Cookie Policy for details.

iOS App: PostHog analytics capture is enabled by default in the App. Captured events include screen views, feature interactions (e.g., “started exam,” “graded flashcard”), session length, and device type. No personal study content (e.g., specific answers) is included in analytics events. If you wish to opt out of in-app analytics, contact us at info@atpltraining.io and we will disable capture for your user ID.

PostHog’s privacy policy: posthog.com/privacy.

11. Advertising Tracking & IDFA

We do not use your device for cross-app advertising tracking. The App does not:

  • Request the Apple Advertising Identifier (IDFA).
  • Display third-party advertisements.
  • Share your data with advertising networks or data brokers.
  • Build advertising profiles or fingerprint your device.

The App will not present an App Tracking Transparency (ATT) prompt because we do not perform cross-app tracking.

12. App Permissions (iOS)

The App requests the following iOS system permissions:

PermissionWhy It Is NeededRequired?
NotificationsStudy reminders and streak alertsOptional
Photo Library (read)Uploading a profile photo from your Camera RollOptional

The App does not access your camera, microphone, location, contacts, calendar, health data, or any other device sensors. Declining any optional permission does not affect core App functionality.

13. App Store Privacy Details

In compliance with Apple’s App Store requirements, the following summarises the privacy nutrition labels declared for the ATPL Training iOS App:

Data Used to Track You

None. We do not track you across apps or websites owned by other companies.

Data Linked to You

CategoryData TypePurpose
Contact InfoEmail addressAccount & authentication
IdentifiersUser IDAccount management, crash attribution
PurchasesPurchase history, subscription statusSubscription management (RevenueCat / Apple IAP)
Usage DataProduct interaction (screens visited, features used)Analytics (PostHog), App improvement
DiagnosticsCrash data, performance dataCrash reporting (Sentry)

Data Not Linked to You

CategoryData TypePurpose
DiagnosticsAggregated performance metrics (app launch time, memory usage)Platform performance optimisation

14. International Transfers

Our primary infrastructure (Supabase, Vercel, PostHog, Sentry) is hosted in Europe. RevenueCat processes data in the United States under Standard Contractual Clauses (SCCs). Where data is transferred outside the EEA, we ensure adequate safeguards are in place pursuant to GDPR Chapter V.

15. Data Retention

  • Account & Study Data: Retained for the lifetime of your account. Deleted within 30 days of an account deletion request.
  • Demo Result Emails (no account): Your email address and the result summary are kept for 12 months, so we can answer a query about a message we sent, then deleted.
  • Marketing List: Retained until you unsubscribe. After you unsubscribe we keep your email address and the date on a suppression list indefinitely — that record exists solely so we can honour your objection under GDPR Art. 21(3) and never email you again.
  • Usage Analytics: Retained in PostHog for up to 12 months, then anonymised.
  • Crash Reports: Retained in Sentry for 90 days.
  • Push Notification Tokens: Deleted when you delete your account or revoke notification permission.
  • Payment Records: Retained for 7 years to comply with Estonian tax and accounting regulations.
  • Server & Access Logs: Up to 90 days.

16. Cookies

The Website uses cookies and similar technologies. For a detailed breakdown of every cookie we use — including names, providers, purposes, and durations — and how to manage your preferences, please read our Cookie Policy.

In summary:

  • Essential: Authentication session tokens managed by Supabase (required for login and platform functionality).
  • Functional: Preferences such as theme (light/dark mode).
  • Analytics: PostHog, Vercel Analytics, and Google Analytics usage data — only active after you accept analytics cookies via the cookie banner.

The iOS App does not use browser cookies. Local storage and authentication tokens in the App are managed through Apple’s Keychain and UserDefaults.

17. Data Security

We implement industry-standard safeguards: TLS 1.2+ encryption in transit, AES-256 encryption at rest in Supabase, row-level security (RLS) policies ensuring users can only access their own data, bcrypt-hashed passwords via Supabase Auth (OAuth tokens are never stored), and Stripe PCI DSS compliance for payment data. The iOS App communicates exclusively over HTTPS. In the event of a personal data breach, we will notify the Estonian Data Protection Inspectorate within 72 hours and, where the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by GDPR Articles 33 and 34.

18. Your Rights

Under the GDPR and applicable data protection law, you have the right to:

  • Access (Art. 15): Request a copy of the personal data we hold about you.
  • Rectification (Art. 16): Correct inaccurate data (many fields are editable directly in your account settings).
  • Erasure (Art. 17): Request deletion of your account and personal data (“right to be forgotten”). Note: payment records are retained as required by law.
  • Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Restriction (Art. 18): Request that we limit processing of your data in certain circumstances.
  • Objection (Art. 21): Object to processing based on legitimate interests.
  • Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting lawfulness of prior processing.

To exercise any of these rights, email info@atpltraining.io. We will respond within one month (extendable by two further months for complex requests, in which case we will inform you within the first month). You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate at aki.ee or with your local supervisory authority.

iOS account deletion: You can delete your account directly within the App at Account → Danger Zone → Delete Account, as required by Apple App Store Guidelines. Alternatively, email us at info@atpltraining.io.

19. Children

The Platform is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at info@atpltraining.io and we will delete that data promptly.

20. Changes to This Policy

We will notify you of material changes to this policy by email (to the address associated with your account) or via a prominent notice on the Website and in the App. The effective date at the top of this page reflects the latest revision. We encourage you to review this page periodically. Your continued use of the Platform after changes take effect constitutes acceptance of the revised policy.

21. Contact Us

For any privacy-related questions, data requests, or complaints:

Email: info@atpltraining.io

ATPL Training
Tallinn, Estonia

Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) aki.ee