Jump to section
Who we are, and what this document is for.
We're a small studio. This page covers everything DMV Master touches — the app, this part of our website, and the inboxes you may write to.
Nordic Theory Labs AB (the "studio", "we", "us") is the entity responsible for the personal data described in this policy. We are a company registered in Sweden, under Stockholm, Sweden — organisation details available on request. DMV Master is built for a U.S. audience, so this policy is written primarily around U.S. state privacy law (including the California Consumer Privacy Act, as amended by the CPRA), with a note on EU/UK rights where they apply to us as a Sweden-based controller.
This policy applies to:
- The DMV Master mobile application (iOS and Android).
- The pages at nordictheorylabs.com/apps/dmv-master/.
- Email correspondence about DMV Master with our support and privacy inboxes.
If something on this page is unclear, that's a bug. Write to privacy@nordictheorylabs.com and we'll rewrite the offending paragraph.
What we collect, and the reason we collect it.
The minimum we need to make the thing work, billed where required, and measured in aggregate so we can improve it. No advertising IDs. No selling or sharing your personal information. Ever.
Visiting this page
When you load this page, your browser tells our host (Cloudflare) the usual things — your IP address, the page you requested, your user-agent, and the time. Cloudflare keeps these access logs for a short rolling window for security and to debug outages. We don't tie them to any identifier of you.
The website itself does not run any web analytics on this page beyond a basic pageview counter (Google Analytics via `gtag.js`, aggregate only) — no Facebook Pixel, no TikTok Pixel, no ad retargeting.
Writing to us
If you email support@, privacy@, hello@, or any other inbox we publish, we receive your message, your email address, and whatever else you tell us. We use it to answer you and to run the studio — that's it. We keep threads for two years, then archive or delete them.
Using DMV Master
The app is local-first. Your selected state, study progress, quiz answers, wrong-answer log, flashcard schedule and stats live in a SQLite database on your device. We don't see them, and there is no account or login.
On first launch the app creates a random subscriber ID and registers it with RevenueCat (our subscription-management subprocessor), whether or not you ever buy anything. If you buy a subscription, Apple or Google handles the transaction, depending on whether you installed from the App Store or Google Play, and RevenueCat receives an opaque purchase identifier, your subscription state, your platform, and your country — never your name, email, or card. We use this to verify your subscription is active and to see which subscription screens work.
If the app crashes, Sentry receives a crash report and stack trace so we can fix the bug, tagged with that same random subscriber ID so a crash can be matched to a subscription problem. There is no name, email, or other directly identifying information in these reports.
Cookies, local storage, and other small stowaways.
We set one strictly-necessary cookie to remember your interface language, and a standard aggregate analytics cookie. No ad trackers.
Below is the full list of things we store in your browser on this page. If we ever add something to this table, the version number at the top of the page bumps and the change is noted in section 10.
We do not load Facebook Pixel, TikTok Pixel, Hotjar, or any other behavioral-advertising tracker. We do not run advertising. We do not embed third-party fonts beyond Google Fonts, which is loaded directly from fonts.googleapis.com and may briefly see your IP — see section 06 for how that's handled.
DMV Master — the specifics.
The app works fully offline. There is no account or login. Apple or Google handles payments via the App Store or Google Play; RevenueCat verifies your subscription state; Sentry receives crash reports; Google Analytics for Firebase receives pseudonymous usage events. That is all that leaves your device.
Data stored on your device
Your selected state (e.g. California, Texas, Florida, New York), quiz attempts, answers, timing, flashcard intervals, your chosen study mode, language, theme, and notification preferences. Everything is stored in the app's local SQLite database and is removed when you delete the app.
Subscriptions
Subscriptions are sold through the Apple App Store or Google Play, depending on your platform. Apple or Google sends us a signed receipt or purchase token containing an opaque purchase ID. RevenueCat processes this on our behalf to confirm the subscription is active and to manage entitlements; it does not receive your name, email, billing address, or card number.
Alongside the random subscriber ID, RevenueCat also receives three labels so we can compare conversion: your app language, which version of the subscription screen you were shown, and the license type you picked during setup. On iOS, if you installed DMV Master by tapping an Apple Search Ads ad, Apple provides an AdServices attribution token that tells RevenueCat which campaign led to the install; it identifies the campaign, not you, and requires no tracking permission. Apple's, Google's, and RevenueCat's privacy policies cover their handling.
Crash & error reports
If the app crashes or hits an unexpected error, Sentry receives a crash report and stack trace so we can ship a fix, tagged with the random subscriber ID described above. Screenshots are not attached. These reports do not contain your name, email, study answers, or any other directly identifying information.
Usage analytics
The app sends usage events to Google Analytics for Firebase so we can see which features actually help people pass — for example which screens you open, when a practice test is started or finished, and when a subscription screen is shown or a purchase completes. Each event carries a random app-instance identifier that Firebase generates on install, plus your device model, operating system and app version, app language, and an approximate region derived from your IP address (Google does not store the IP address itself).
That identifier is not linked to your name, email, or any advertising identifier: the app does not collect the iOS advertising identifier (IDFA) or the Android advertising ID, and Google Analytics' advertising-personalization signals are switched off. We use these events only in aggregate, for product decisions. Test builds, including TestFlight, send the same events.
Diagnostics
The app does not phone home for any other reason. It never contacts a server of our own: the question bank ships inside the app and is updated only through App Store and Google Play updates.
Who else touches the data.
A handful of companies, each doing one job. No data brokers, and nobody receives your data to target ads at you — ever. We do not sell or share your personal information.
The following service providers ("subprocessors") may process limited data on our behalf. We have a Data Processing Agreement or equivalent terms with each:
If we add or change a subprocessor, this list updates and the change is noted in the version history at the bottom of the page.
International data transfers.
DMV Master is a U.S. product used mostly by U.S. residents, but the company behind it is Swedish. Data may cross the Atlantic in both directions, handled under standard safeguards.
Because the studio itself is based in Sweden, some processing happens in the EU (for example, this website's email correspondence). Because DMV Master's users, and most of its infrastructure providers (Apple, Google — including Google Analytics for Firebase — RevenueCat, Sentry, Cloudflare), are U.S.-based, most processing for the app happens in the United States.
Where personal data is transferred between the EU and the US, the transfer is covered by either:
- The EU–US Data Privacy Framework, where the recipient is certified under it.
- Standard Contractual Clauses approved by the European Commission (2021/914), for everyone else.
You can request more detail on how a specific transfer is handled by writing to privacy@nordictheorylabs.com.
How long we keep things.
As briefly as we reasonably can. Server logs go after a month. Emails go after two years. Financial records we keep longer, because Swedish bookkeeping law requires it of the company regardless of which product the revenue came from.
Your rights, in plain words.
Wherever you live, you can ask us to show you, fix, or delete what we have. California and other U.S. states add a few specific rights below. Use any of them by writing one sentence to privacy@. We answer within 30 days (45 for California requests, as CCPA allows).
The rights above are drawn from the California Consumer Privacy Act as amended by the CPRA. We do not sell or share personal information as those terms are defined by California law, and we do not use or disclose "sensitive personal information" beyond what's needed to run the app. If you believe we've mishandled a request, you may also contact the California Attorney General's office. If you're in another U.S. state with its own privacy law (Virginia, Colorado, Connecticut, Utah, and others), we apply the same practices to your request. If you're in the EU/EEA/UK, these same eight rights map onto your GDPR rights, and you may additionally complain to the data protection authority in your country, or to Sweden's Integritetsskyddsmyndigheten (IMY) where we're based.
About children using our products.
DMV Master is intended for prospective drivers working toward a learner's permit or license — most U.S. states start this process at 15 or 16. We do not knowingly collect personal information from children under 13.
Learner's permit eligibility varies by state and is generally in the teenage years. DMV Master is rated for a general audience in the App Store and Google Play because it contains no objectionable content, but its purpose is aimed at users old enough to be pursuing a driver's license.
In line with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13, and the app does not require an account, so there is no sign-up flow that could collect a child's information in the first place. We rely on Apple's "Ask to Buy" and Family Sharing controls on iOS, and on Google Play's Family Library and supervised-account controls on Android, for parental oversight of subscriptions. If you believe a child has provided us data, write to privacy@nordictheorylabs.com and we will delete it.
How this document changes.
Material changes are announced in the app and at the top of this page for two weeks. Editorial fixes (typos, restructure) are quietly applied. Every version is below.