Privacy
Last updated September 21, 2026. This notice covers the CDL Permit Prep website and CDL-branded iOS and Android apps. It does not cover DMV Prep or third-party websites you open.
Website
The website stores practice progress and preferences in your browser. It does not require an account. The current website build does not load Google Analytics. It does not send study answers or learner activity to Google Analytics or another learner analytics service.
Cloudflare delivers and protects this website. It may process connection and request data, such as your IP address and request metadata. See the Cloudflare Privacy Policy.
Mobile apps and Firebase
Earlier CDL Permit Prep app versions used Google Firebase Analytics. Historical Analytics reports include app screens, onboarding, study activities, and question interactions. The linked Firebase and Google Analytics property includes multiple data streams. Its current project-level reports do not let us match every event to a specific platform or distributed app version. The study event schema included app version, app-instance identifiers, device and operating-system details, and selected study settings such as state, test track, and language. It was designed not to send names, email addresses, passwords, user IDs, or free-form text. App-instance identifiers can still distinguish an app installation.
Earlier app versions also included Firebase Crashlytics. When a crash report is generated, Crashlytics may process crash traces, app and device details, and installation identifiers. Google says Crashlytics starts removing crash traces and associated identifiers after 90 days. See Firebase privacy and security.
On September 20, 2026, this Firebase Analytics project was set to retain event data for 2 months and user-level data for 14 months, with the user-data period reset by new activity. These settings do not remove most aggregated standard reports, which may remain separately.
CDL app builds now being prepared disable Firebase Analytics and automatic Crashlytics reports. Those builds have not been released. While automatic Crashlytics collection is off, crash reports stay on the device unless a later build enables collection. The builds still include Google Firebase SDK components that may send limited, unlinked SDK diagnostics, such as log-cache size and dropped-log counts, to help maintain SDK quality. See Firebase's Apple-platform data collection details. Until an updated app is available and installed, an earlier installed version may still send data as described above. The website and current local CDL app builds do not send learner analytics.
Local storage and deletion
Detailed answers, bookmarks, and study progress are stored on your device or in your browser; the CDL apps do not require an account to study. Clear browser storage to remove website data. On Android, clear the app's data; on iOS, delete the app to remove locally stored study data. Device backups may restore data. We do not currently provide an in-app or self-service control to delete Firebase Analytics events sent by earlier app versions. Those events follow the retention settings above.
Optional account and progress sync
Accounts are optional; you can study without one. If you create an account, you consent to this processing when you create it (basis: consent).
What we collect. Google Firebase Authentication holds your email address and sign-in method and assigns a Firebase user ID (uid). Our account store keeps only: the uid (taken from your verified sign-in token), the study-progress and settings fields your app syncs (fields.<key>.value) with each field's timestamp (fields.<key>.at), the profile's created and updated times, and, after a deletion request, a record of the uid with its deletion and purge times. We do not store your name, phone number, contacts, location, free text, answer text, licence numbers, date of birth, or medical data.
Why. Only to sync and restore your study progress across devices. We do not use it for advertising or tracking, and we do not sell it.
Processors. Google Firebase Authentication (sign-in) and Cloudflare (D1 storage and service delivery).
Retention. We keep your profile while your account is active. After a deletion request, we delete it within 30 days; backups are kept for at most 35 days.
How to delete. In the app, open the Account screen and choose Delete account, or follow the steps at https://cdlpermitprep.org/account/delete.
Account recovery. Email support@cdlpermitprep.org; we respond within 7 days.
Third-party services and links
Google provides Firebase services used by earlier app versions. See Google's Firebase privacy information. Links to manuals and other sources open third-party sites that follow their own privacy policies.
We do not sell study data or use it for targeted advertising.
Contact
For privacy questions, email support@cdlpermitprep.org or visit CDL Permit Prep Support.
