Apto

Privacy Policy

Last updated: 13 September 2026

1. Data controller

Apto is a free app for preparing Spain's DGT theory exams, developed and published by Serhii Bets, a private individual, who is the controller of your personal data under the General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 on Personal Data Protection (LOPDGDD).

Contact for any privacy matter: support@apto.blog

2. Principles

Data Purpose Legal basis
Anonymous account: a technical identifier created automatically when you open the app (Firebase Authentication) Running the app and protecting the service Performance of the service you request (Art. 6(1)(b) GDPR)
Linked account (optional): identifier, email and, if the provider supplies them, name and profile photo of your Google or Apple account Keeping your account when you change devices Performance of the service (Art. 6(1)(b)) — only if you choose to link
Record of legal document acceptance: which document, which version, in which language and when you accepted it Being able to show which terms you accepted Legal obligation and accountability (Arts. 6(1)(c) and 7(1) GDPR)
Push message history (if you enable push): messages received and device token (Firebase Cloud Messaging) Sending you news and letting you read them again Consent (Art. 6(1)(a))
Usage analytics (Firebase Analytics): events such as "test completed", without the content of your answers Understanding which features are used and improving the app Consent (Art. 6(1)(a))
App feedback (optional): the text you write, the technical account identifier, app version, platform, languages, licence category and number of completed tests (Firestore) Fixing problems and improving the app Legitimate interest in improving the service (Art. 6(1)(f)); you choose to send it
Crash and performance reports (Firebase Crashlytics, Sentry): technical error data, device model, OS and app version Finding and fixing errors Consent (Art. 6(1)(a))
Technical security and configuration data (Firebase App Check, Remote Config): installation identifiers and verification that the app is genuine Preventing abuse and adjusting the app without a new release Legitimate interest in the security and operation of the service (Art. 6(1)(f))

Only on your device (never sent to us): your test answers, statistics, streak, achievements, bookmarks, settings and the app lock state. Biometric checks (Face ID, fingerprint) are performed by your operating system; Apto has no access to biometric data. Streak reminders are local notifications that do not pass through any server.

We make no automated decisions with legal effects on you and do no profiling.

Analytics, error reports and push messages are off until you accept them (welcome screen or Settings). You can withdraw consent at any time in Settings; this does not affect processing that took place before.

5. Processors and international transfers

Provider Service Location
Google Ireland Ltd. / Google LLC Firebase: Authentication, Firestore, Analytics, Crashlytics, Cloud Messaging, App Check, Remote Config Database stored in the European Union (eur3 region); some services may be processed outside the EEA
Functional Software, Inc. (Sentry) Error and performance reports, only with consent May be processed outside the EEA
Apple / Google Sign in with Apple or Google, if you choose it Under their own policies

Where a provider processes data outside the European Economic Area, it does so with GDPR safeguards: an adequacy decision (EU-U.S. Data Privacy Framework) or the European Commission's standard contractual clauses.

We do not share your data with third parties unless required by law.

6. How long we keep data

7. Your rights

You have the rights of access, rectification, erasure, objection, restriction of processing and portability, and the right to withdraw consent.

If you believe your data has not been handled properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

8. Minors

In Spain, from the age of 14 you can give your own consent to the processing of your data (Art. 7 LOPDGDD). If you are under 14, a parent or legal guardian must authorise analytics and push messages; the rest of Apto's features need no data that identifies you.

9. Security

Communication with our servers is encrypted, database access is restricted by security rules, and each user can only read their own data.

10. Changes to this policy

If we change this policy in a meaningful way — for example, if Apto offers paid features in the future — we will tell you inside the app before the change applies.

11. Contact

Serhii Bets — support@apto.blog