Skip to content
XP TheoryXP
Features Privacy Support Terms

TheoryXP Privacy Policy

Version: V1.6
Effective date: 15 September 2026
Controller: TheoryXP Limited
Website: theoryxp.app
Privacy and support contact: support@theoryxp.app

1. The short version

TheoryXP is a UK driving-theory revision app. We use a limited amount of account, technical and learning information to provide Practice, Mock Tests, progress tracking, personalised Study Plans, Today’s Tasks, Road Signs learning and optional Recovery features.

We do not currently use in-app advertising, a dedicated third-party analytics/crash SDK or an external AI/LLM to process learner data. TheoryXP does not sell personal information and does not currently use learner data for third-party behavioural advertising or direct marketing.

The Recovery Scanner is designed so that the source image and raw OCR text are processed on your iPhone and are not uploaded to TheoryXP’s backend. Only the learning categories and related information you confirm are kept with your TheoryXP account.

Account-linked learner progress is normally kept while your account is active. If there is no recorded account activity for 12 months, the account may become eligible for automatic deletion. If we have an email address for the account, we send an advance warning and provide at least 30 days before deletion. A Guest account without an email address may not receive that warning.

You can export your account data and delete your account in the app. You can also contact us at support@theoryxp.app.

2. Who we are and where this policy applies

TheoryXP Limited is the controller of the personal information described in this policy.

TheoryXP is an independent revision product. It is not an official DVSA or DVA app and is not endorsed or approved by either agency. TheoryXP includes DVSA-licensed revision material where identified.

This policy is written for TheoryXP’s UK service, including users in England, Wales, Scotland and Northern Ireland. UK data-protection law, including the UK GDPR and Data Protection Act 2018, applies throughout the UK.

If TheoryXP later deliberately offers or targets the service into additional jurisdictions, including EEA countries, we will review the applicable privacy and representative/transfer requirements before that expansion.

3. Information we use

Account and sign-in information

Depending on how you use TheoryXP, this may include:

  • a TheoryXP/Supabase account identifier;
  • email address if you use an email-linked account;
  • Google identity information needed to complete Google sign-in;
  • an anonymous account identifier if you use Guest mode; and
  • authentication/session and account-security information.

We do not store your plaintext password in TheoryXP learner tables.

Profile and study preferences

This may include:

  • display name;
  • where you are in your learning journey;
  • theory-test date, if you provide one;
  • preferred study duration, study days and schedule preferences;
  • timezone;
  • test jurisdiction where the app needs to distinguish Great Britain and Northern Ireland content; and
  • onboarding/account-preference state.

Learning activity

This may include:

  • Practice, quiz and Mock Test sessions;
  • assigned question identifiers and order;
  • answers you select and whether they are correct;
  • timestamps and session status;
  • hint use;
  • response time and answer-change counts where recorded;
  • questions/signs you flag, save or bookmark;
  • Road Signs and video-case-study learning activity; and
  • Practice/Mock history.

Personalised learning information

TheoryXP calculates learning information from your activity, including:

  • Topic Performance states and supporting evidence;
  • weak/improving/strong/stale or insufficient-evidence status;
  • Study Plan and Today’s Tasks;
  • task outcomes and recommendation history;
  • XP/streak information;
  • readiness/pass-confidence-style summaries; and
  • limited timing/answer-change support signals used to adjust revision priority.

These are educational estimates used to guide revision. They are not official DVSA or DVA assessments and do not guarantee a theory-test result.

Technical, security and diagnostic information

TheoryXP and its infrastructure providers process limited technical information needed to authenticate users, provide the service securely, prevent abuse and diagnose faults. Depending on the service and context, this can include:

  • IP address and request/network metadata processed in Supabase authentication/API/security logs;
  • user-agent or client information associated with requests;
  • authentication, rate-limit and security-event information;
  • app version, device class/model, operating-system version, crash stack information and performance/diagnostic information where Apple makes those reports available to developers under Apple’s systems and user sharing settings; and
  • Apple-generated diagnostic identifiers that may appear in crash reports.

TheoryXP does not currently create its own persistent advertising/device identifier, use device fingerprinting for advertising, or collect precise GPS location.

TheoryXP does not need to collect your iPhone model simply to make the interface fit your screen. Responsive layout and compatibility testing can be performed without building a learner device-profile database.

Recovery Scanner

If you use Recovery Scanner:

  • TheoryXP may request camera access when you choose to photograph feedback;
  • the source image and raw OCR text are processed locally on your iPhone under the current architecture;
  • TheoryXP does not currently upload the source image or raw OCR text to its Supabase backend; and
  • categories, wrong-count/severity information and learning signals you confirm may be saved to your account so TheoryXP can target revision.

Support and privacy requests

If you contact us, we receive the information you choose to include, your contact address and normal email/routing metadata.

Please do not send passwords, one-time codes or unnecessary sensitive information in support/privacy correspondence.

Special-category information

TheoryXP does not ask for or intentionally use special-category personal information as part of its normal revision and personalisation features. This includes information revealing or concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for identification, health, sex life or sexual orientation.

A person could nevertheless choose to include sensitive information in a support or privacy message. If this occurs incidentally, we limit its use to what is reasonably necessary to deal with the communication and apply appropriate protections.

TheoryXP does not use response-time or answer-change information to infer health, anxiety, emotion, disability or another special-category characteristic.

TheoryXP also does not ask for or intentionally use criminal-conviction/offence information as part of the normal revision service. If such information is sent incidentally in correspondence, we minimise its use and do not repurpose it for learner profiling.

App Store information

Apple handles App Store payment/card processing. TheoryXP does not need your payment-card details in its learner database.

TheoryXP may receive App Store sales/accounting information and Apple-provided app analytics or crash/diagnostic information where Apple makes this available to developers under its platform controls.

4. Where the information comes from

Most personal information comes directly from you or from your use of TheoryXP.

Other sources can include:

  • Google, if you choose Google sign-in;
  • Apple, for App Store sales/accounting information and Apple-provided diagnostics/analytics made available to developers;
  • Supabase infrastructure logs generated when the app authenticates or communicates with the backend; and
  • information generated by TheoryXP from your learning activity, such as Topic Performance, Study Plans and progress/readiness summaries.

TheoryXP does not obtain an official DVSA or DVA test record through Recovery Scanner. Recovery information comes from the feedback you choose to process and confirm.

5. What you need to provide

You do not have to provide every optional profile field or use every optional feature.

Some information is necessary for a feature you choose. For example, an account identifier is needed to keep server-backed progress, an email address is needed for email-linked sign-in/account notices, and learning answers are needed to calculate progress and recommendations.

If you do not provide optional information, the related feature or level of personalisation may not be available.

6. Why we use your information and our lawful bases

We use personal information for the following purposes:

Purpose Main lawful basis
Create and maintain your account, including Guest accounts Contract where applicable; otherwise legitimate interests to provide the requested core service
Provide Practice, Mock Tests, Road Signs, video-case-study and other learning features Contract where applicable; otherwise legitimate interests to provide the requested core service
Save progress and produce Topic Performance Contract where applicable; otherwise legitimate interests to provide the requested core educational service
Personalise Study Plans, Today’s Tasks and revision recommendations Contract where applicable; otherwise legitimate interests for core educational personalisation, subject to child-user safeguards
Operate optional Recovery Scanner category-based personalisation Contract where applicable and the feature is requested; otherwise legitimate interests for the requested educational feature
Keep saved/flagged/bookmarked learning items Contract where applicable; otherwise legitimate interests to provide the requested feature
Provide XP, streaks and learner-facing progress summaries Contract where applicable; otherwise legitimate interests to provide the requested learning experience
Use limited response-time/answer-change signals as secondary personalisation inputs Legitimate interests, subject to a documented balancing assessment and child-user safeguards
Protect accounts, licensed content and service reliability; prevent abuse/rate-limit misuse Legitimate interests
Use Apple-provided analytics/diagnostics to assess app quality and faults where available Legitimate interests
Answer ordinary support requests Contract and/or legitimate interests depending on the request
Handle statutory data-rights requests, data-protection complaints and required records Legal obligation where applicable; legitimate interests for related administration
Maintain the 12-month inactivity-retention process and send account-service warnings Contract where applicable and legitimate interests/storage-limitation purposes
Maintain accounting, tax, corporate and licensing records Legal obligation and legitimate interests where applicable

Core service and younger learners

For core processing, contract is used only where the learner/account user is a party to the relevant service contract and the processing is objectively necessary to perform it.

TheoryXP may be used by people under 18, and the person using the learning account may not always be the same person who made the App Store purchase. We therefore do not assume that “contract” automatically applies to every child-user situation. Where contract is not an appropriate basis for necessary core educational processing, TheoryXP relies on legitimate interests to provide the requested core service, with extra weight given to the rights and interests of child users and the safeguards recorded in our Children’s Code/DPIA assessment.

Where we rely on legitimate interests, our interests are providing a safe, useful educational service, protecting users/licensed content, diagnosing faults and delivering proportionate learning personalisation without overriding your rights.

We do not currently rely on consent as a blanket basis for the core learning service. If we introduce optional processing for which consent is required, you will be given a genuine choice and can withdraw that consent without affecting processing that was lawful before withdrawal.

7. Personalisation and profiling

TheoryXP uses deterministic learning rules to analyse revision evidence and decide what to show or recommend next.

The system may consider correctness, recency, evidence coverage, repeated errors, hint use, Recovery signals, study preferences and limited behavioural signals such as response time or answer changes.

Response time and answer changes are secondary supporting signals. They may slightly influence revision priority, but they cannot by themselves classify a learner as Weak. TheoryXP uses minimum-evidence thresholds and relative patterns rather than treating one slow answer as proof that a learner is struggling.

TheoryXP does not use these signals to infer emotion, anxiety, mental state or health.

TheoryXP does not currently use the learner profile for behavioural advertising, pricing, access eligibility or unrelated commercial decisions.

The current learning recommendations do not make decisions that have legal or similarly significant effects on you.

8. Who receives information

We use service providers and platform services where needed to run TheoryXP:

  • Supabase — authentication, database, private storage, backend infrastructure and request/security logging;
  • Google — if you choose Google Sign-In, and for Google-hosted services used by TheoryXP where applicable;
  • Cloudflare Email Routing — receives mail sent to support@theoryxp.app and forwards it to TheoryXP’s support mailbox;
  • Resend — transactional account-service email such as inactivity-deletion warnings; and
  • Apple — App Store distribution/purchases and Apple-provided app analytics/diagnostics under Apple’s systems.

Support/privacy emails sent to support@theoryxp.app are currently routed through Cloudflare Email Routing to a Google-hosted support mailbox. Email providers necessarily receive message content, sender information and routing metadata needed to deliver and store the correspondence.

Where a provider processes personal information on TheoryXP’s behalf, we use appropriate written processing/contractual safeguards, assess its data-protection and security arrangements, and limit the processing to the service purpose. Where a provider acts as a separate controller for its own platform activity, its own privacy notice and legal responsibilities also apply. Apple and Google are examples of providers that have independent responsibilities for parts of their platform/account services.

TheoryXP requires third parties receiving user data through our chosen service arrangements to provide protections consistent with applicable law and, where Apple’s App Review rules apply, the same or equal protection described for the relevant user data in this policy.

We do not currently send learner data to an advertising network or external AI/LLM provider. We do not sell personal information.

We may disclose information where required by law or where reasonably necessary and proportionate to protect rights, users, licensed content or service security.

Corporate transactions

A “corporate transaction” means a legitimate business change such as a merger, acquisition, financing, reorganisation, sale of all or part of the business/assets, or transfer to a successor operator. If such a transaction requires personal information to be disclosed or transferred, we limit the information to what is reasonably necessary, use appropriate confidentiality/data-protection safeguards, and provide any notice required by law. A successor that becomes controller remains responsible for complying with applicable data-protection law.

9. Where information is processed and international transfers

TheoryXP’s live Supabase project is hosted in the London (eu-west-2) region.

Some suppliers operate internationally. Depending on the provider and service, information may therefore be processed outside the UK.

Where TheoryXP makes a restricted transfer of personal information, we use an applicable UK-recognised safeguard or lawful transfer mechanism, such as:

  • an adequacy regulation/recognised adequacy arrangement;
  • an applicable UK International Data Transfer Agreement/Addendum or other approved contractual safeguard; or
  • another lawful mechanism available under UK data-protection law.

Current provider arrangements are tracked internally. For example, Supabase, Resend and Cloudflare publish data-processing/transfer terms for processor services. Google and Apple also publish their own privacy and international-transfer information for their independent services.

10. How long we keep information

Our current retention approach is:

  • Active account and learner progress: kept while needed to provide your active account/service.
  • 12-month inactivity rule: if there is no recorded account activity for 12 months, your account may become eligible for automatic deletion.
  • Email-linked accounts: we send an advance inactivity warning and provide at least 30 days before deletion.
  • Guest/no-email accounts: we may be unable to send an email warning. A Guest account that remains inactive for 12 months may therefore be deleted without an email warning.
  • Returning before deletion: refreshes the inactivity period and cancels pending inactivity deletion.
  • Uninstalling: deleting the app from your device does not itself delete your server-side account.
  • Delete Account: the in-app Delete Account control deletes the TheoryXP account and account-linked learner data from active TheoryXP systems, subject to information that must lawfully be retained. Under TheoryXP’s current Supabase Pro plan, deleted database data may remain within the provider’s normal daily-backup rotation for up to 7 days before the relevant backup expires.
  • Response-time and answer-change evidence: retained as part of the existing learner attempt history while that account history is retained. TheoryXP does not maintain a separate raw psychological/emotion profile. Derived timing/answer-change data follows the account-linked learning-data lifecycle.
  • Recovery source image/raw OCR: not retained by TheoryXP’s server under the current architecture.
  • Rate-limit/security events: matching TheoryXP rate-limit records are currently cleaned after approximately two days. Supabase’s current Pro API & Database log retention is 7 days.
  • Apple-provided analytics/diagnostics: controlled principally through Apple’s reporting systems and retention windows; TheoryXP does not currently operate a separate third-party analytics database.
  • Support/privacy correspondence: normally kept for up to 12 months after the matter is closed, unless longer retention is reasonably needed for a dispute, security investigation, regulatory matter or legal obligation.
  • Business/accounting/licensing records: kept separately for the periods required or justified for the relevant legal/business purpose.

The Hide History control is not the same as deleting learning data. Under the current implementation it hides older Practice history from that view while underlying learning evidence may remain for the learning engine.

11. Your data rights

Depending on the circumstances and lawful basis, you may have rights to:

  • be informed about how your information is used;
  • access your personal information;
  • correct inaccurate information;
  • ask for deletion;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive certain information in a portable format; and
  • withdraw consent where a particular processing activity genuinely relies on consent.

You can use Export My Data and Delete Account in TheoryXP. You can also contact support@theoryxp.app. You do not need to use legal terminology or a particular form to exercise a data-protection right.

We may ask for proportionate information to verify identity where necessary before disclosing or changing personal information. We do not ask for more identity evidence than reasonably needed for the risk involved.

We respond to valid data-protection rights requests without undue delay and normally within one calendar month. Where the law permits an extension for a complex request or multiple requests, we will tell you and explain the extension within the required period.

Your right to object: if we rely on legitimate interests for a particular use of your information, you can object. We will consider the reasons and the applicable legal test. If an objection is upheld for processing that is necessary for a particular personalised/server-backed feature, we may be unable to continue that feature for the account.

Data protection complaints

If you believe TheoryXP has handled your personal information incorrectly, email support@theoryxp.app and make clear that you are making a data-protection complaint. Please include enough information for us to understand the issue, but do not send passwords, one-time codes or unnecessary sensitive information.

We will:

  • provide a clear way to make the complaint;
  • acknowledge a data-protection complaint within 30 days;
  • investigate it without undue delay;
  • keep you informed of relevant progress where appropriate; and
  • tell you the outcome without undue delay.

You can also complain to the UK Information Commissioner’s Office (ICO) at any time. ICO complaint information is available at https://ico.org.uk/make-a-complaint/.

12. Children and younger learners

TheoryXP is likely to be used by younger learners, including 17-year-olds preparing for a car theory test.

Rather than collect full dates of birth solely to change privacy settings, TheoryXP’s current approach is to apply relevant high-privacy protections broadly to users.

Core educational personalisation is limited to helping the learner revise. TheoryXP does not use learner weaknesses for behavioural advertising, public ranking, pricing or unrelated commercial profiling.

We use a full Privacy Policy together with shorter privacy explanations. Privacy information for younger users should remain clear, prominent and easy to revisit, including at points where a feature such as Recovery Scanner or personalised recommendations uses personal information in a way that may not be obvious.

13. Security

TheoryXP uses controls including authenticated accounts, ownership checks, row-level/data-access controls, private content storage and server-only administrative operations.

We also maintain internal security/access-control requirements covering least privilege, credential/secret handling, production access, account security, release security testing and incident response.

No online service can promise absolute security. If we become aware of a personal-data incident, we will assess and contain it where appropriate, keep the required internal record, and make any notifications required by applicable law.

14. Storage/access technologies on devices and websites

TheoryXP’s iOS app uses device-side technologies needed for functions such as authentication/session handling, local app state, Google Sign-In where chosen, and on-device Recovery processing.

TheoryXP does not currently use a third-party advertising tracker or dedicated third-party analytics SDK.

UK rules on storage/access technologies can apply to mobile apps as well as websites. Where a technology requires prior consent, it will not be enabled before the required information and choice are provided. Technologies that fall within a legal exception may be used without consent where the exception applies, while still being described where data-protection transparency requires it.

The public website must likewise be assessed against the technologies actually deployed. Non-essential cookies/local storage/tracking will not be introduced silently.

15. Changes to this policy

We review this policy when our data practices materially change and at appropriate release/compliance reviews.

If we plan to use personal information for a materially new purpose, we will update the relevant privacy information and bring that change to affected users’ attention before the new processing starts where required.

In particular, a fresh review is required before introducing advertising, a dedicated analytics/crash SDK, external AI/LLM learner-data processing, precise geolocation, social/user-to-user features, a new class of sensitive information, materially different profiling or expansion into additional target jurisdictions.

We keep versioned copies so that material changes and effective dates can be identified.

16. Contact

TheoryXP Limited
Company number: 17320394
Registered office: 167-169 Great Portland Street, 5th Floor, London, London, United Kingdom, W1W 5PF
Registered in: England and Wales
Website: theoryxp.app
Privacy, support and data-protection complaints: support@theoryxp.app

XP TheoryXP

UK driving-theory revision designed around focused practice, progress and clearer next steps.

TheoryXP is an independent revision product. It is not an official DVSA or DVA app and is not endorsed or approved by either agency.

Legal

Terms of Use
Privacy Policy
Privacy at a Glance
Data & Account Rights
Licences & Acknowledgements

Help

Support
Accessibility
Privacy complaints
support@theoryxp.app

TheoryXP Limited · Company 17320394 · Registered in England and Wales