Last updated: 5 September 2026
Privacy policy
This policy explains how TeoriGuiden ApS processes personal data in TeoriGuiden for iPhone/iPad and Android, on teoriguiden.dk and when you contact us. Features may vary between platforms.
1. Who is responsible for your data?
- Data controller
- TeoriGuiden ApS
- Company registration (CVR)
- 45649016
- Address
- Nordre Fasanvej 165, 2. th, 2000 Frederiksberg, Denmark
- teoriguiden@gmail.com
2. Data, purposes and legal bases
Account and sign-in
When you sign in with Apple or Google, we process a user ID, sign-in method, account creation and last sign-in times, and profile information provided by your sign-in provider, including your name and email address. Apple may provide a private relay address. The sign-in provider and Firebase handle authentication; we do not receive your Apple or Google password.
The information is used to create and manage your account and link sign-in methods. The legal basis is performance of the agreement for the app's account features under GDPR Article 6(1)(b). Without the necessary sign-in information, we cannot provide an account and synchronisation.
Progress and local storage
The app stores data such as test results, ongoing tests, answers, marked questions and settings locally on your device, depending on the platform and feature. When you are signed in, your best scores for theory, topic and road sign tests and the update time are stored in Cloud Firestore, linked to your user ID, so that progress can be synchronised.
The legal basis for account-linked storage and synchronisation is GDPR Article 6(1)(b). Local app data is used to remember your choices and let you continue practising.
Purchases and access to content
On iPhone/iPad, purchases are processed through Apple's App Store. The app processes product and transaction identifiers, purchase times, any revocation and the duration of access. Access information is also stored in Firebase under your account. We do not receive your full payment card details. Current iOS access periods do not renew automatically.
The Android version can read existing access; purchasing through Google Play is not yet available. Processing to provide and restore purchased access is based on GDPR Article 6(1)(b). Where information forms part of legally required accounting records, it is processed under Article 6(1)(c).
Feedback and support
When you submit feedback in the app, we store your message, time, platform and information about the relevant screen or question. The feedback feature does not automatically add an account ID or email address, but the message may contain personal data you enter yourself. For email enquiries, we process the sender's address, message and any attachments.
We use the information to answer enquiries, correct errors and improve learning content. Support relating to your agreement is processed under GDPR Article 6(1)(b); other feedback under Article 6(1)(f), based on our legitimate interest in helping users and correcting errors. Providing feedback is voluntary. Do not send passwords, Danish civil registration numbers (CPR) or payment card details.
Technical operation and crash reports
We use Firebase Authentication, Cloud Firestore and Cloud Storage for sign-in, storage and image delivery. These services also process technical information such as IP addresses, client information and timestamps when the app connects. The purposes are to provide the service and prevent abuse, based respectively on GDPR Article 6(1)(b) and (f).
The iOS version includes Firebase Crashlytics for technical crash reports. Reports may include installation identifiers, app and operating system versions, device information and technical traces of a crash. The purpose is to identify and fix crashes. The Android version does not use Crashlytics. Neither app version uses Firebase Analytics or advertising SDKs.
We do not sell personal data or use it for targeted advertising. We do not make automated decisions that produce legal or similarly significant effects for you. Calculating test scores is part of the app's practice features.
Website visits
The website is hosted on GitHub Pages. GitHub may process your IP address and technical information about your visit to deliver the website and maintain its operation. Our website contains no analytics tools, advertising pixels or code that sets cookies. Our purposes are to provide information and support and protect the website under GDPR Article 6(1)(f).
3. Who receives data?
- Google/Firebase: sign-in, account data, progress, access information, feedback, content delivery and iOS crash reporting. Google processes Firebase customer data on our behalf under the services' data processing terms. See Firebase privacy and security information.
- Apple and Google as sign-in providers: authentication through your chosen account. Apple also handles App Store purchases. These providers are also independent controllers for processing within their own account and store services. See Apple's privacy policy and Google's privacy policy.
- GitHub: website hosting and technical visitor data. See GitHub's privacy statement.
- Email providers: transmission and storage of support emails.
- Authorities and advisers: only where necessary for a legal obligation or to establish, exercise or defend a legal claim.
4. Processing outside the EU/EEA
Our providers may process data outside the EU/EEA, including in the United States. Google's and GitHub's published terms describe use of the EU-U.S. Data Privacy Framework for covered transfers to certified US recipients, and standard contractual clauses where applicable. The transfer basis depends on the particular service and recipient. Contact us for information about the relevant safeguards and a copy of them.
5. How long is data retained?
- Account, progress and access: retained while your account exists so you can use it and return to your progress. When an account is deleted, the account and associated progress and access documents are removed from the app's active systems. See the deletion section below.
- Local data: stored on your device until reset or removed. Uninstalling the app does not delete your cloud account. Your device's own backups are controlled by your Apple/Google settings.
- Feedback and support: retained while the enquiry or error correction is being handled, and afterwards only for as long as its content is necessary for follow-up or documentation of a specific case. Personal data must be deleted or anonymised when that need ends. Feedback without an automatic account ID is not automatically located during account deletion; contact us with information that can identify the message.
- Firebase Authentication: Google states that logged IP addresses are kept for a few weeks, and that other authentication data is removed from live systems and backups within 180 days after deletion is initiated.
- Crashlytics: Google states that crash reports and associated identifiers are retained for 90 days before removal from live systems and backups begins.
- Legal obligations and claims: necessary accounting records are retained under applicable bookkeeping rules. Information about a specific dispute may be retained until it is finally resolved and relevant claims are time-barred. This does not justify retaining all your app data.
6. Delete your account or request deletion
On iPhone/iPad, go to Profile → Account → Delete account (Profil → Konto → Slet konto). On Android, select Profile → Delete account (Profil → Slet konto). Follow the confirmation in the app; you may need to sign in again.
You can also request deletion without access to the app by emailing teoriguiden@gmail.com. State that you want your TeoriGuiden account and associated data deleted, and provide your account email address and sign-in method. Never send your password. We may ask for the information necessary to verify your identity.
Read about the consequences and exceptions on Delete account. Deleting your TeoriGuiden account does not delete your Apple or Google account and does not automatically refund purchases.
7. Your rights
Under data protection rules, you may have rights of access, rectification, erasure, restriction and data portability. You can object to processing based on our legitimate interests. Where processing is based on consent, you can withdraw it at any time; this does not affect the lawfulness of earlier processing.
Email teoriguiden@gmail.com. We respond to requests without undue delay and normally within one month of receipt. If the law permits an extension for a complex request, we will notify you and explain why within the first month.
You can complain to the Danish Data Protection Agency (Datatilsynet) if you believe our processing breaches the rules.
8. Security and changes
The app communicates with Firebase over encrypted connections. Do not share your account or sign-in information with others.
We update this policy when our processing changes. The date at the top shows the latest update. For material changes, we provide relevant information in the app or by other appropriate means.