Privacy Policy
Effective Date: January 28, 2026
Last Updated: September 19, 2026
Disclaimer: This app is not affiliated with or endorsed by any government
entity. It is an independent educational tool created to help users prepare for the U.S.
Citizenship Test. Test questions are based on the official USCIS Naturalization Test
materials, available at:
https://www.uscis.gov/citizenship
This privacy policy applies to the US Citizenship Test app (the
"Application") for mobile devices provided "AS IS". The Application includes an ad-supported
experience and may offer an optional subscription to remove ads (the "Subscription").
We strive to comply with applicable privacy laws, including the General Data Protection
Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA"), and we aim to process
your data lawfully, fairly, and transparently.
Language: This Privacy Policy is published in English only. The Application
itself is available in several languages; those translations are produced with the assistance
of artificial intelligence, are provided as a study aid, and may contain errors. The English
version of this policy and of the app's content is the authoritative version and controls in
the event of any discrepancy. See section 3 of the
Terms of Use for the
full translation notice.
Information Collection and Use
The Application may collect information when you download and use it. This information may
include:
-
Device and app information: device model, operating system version, app
version, language, and diagnostic information.
-
Usage information: which screens/features you use and how long you use them
(in an aggregated way).
-
Advertising information: ad impressions, advertising identifiers (such as
IDFA on iOS or Advertising ID on Android), and related data used to deliver and measure ads.
If you consent, this information may be used for personalized advertising.
-
Purchase/subscription information: purchase status, entitlement status
(e.g., "Pro / Ad‑Free"), and purchase/receipt data necessary to validate your subscription.
We do not collect precise location from your device. However, third-party services (such as ad
providers) may infer an approximate location from your IP address for fraud prevention,
compliance, and ad delivery.
Study Data Stored on Your Device
The Application stores study-related data locally on your device (e.g., progress, favorites,
selected test version, language, and settings). This data is used to provide the core study
experience. You can remove this data at any time by using the app's reset features or
uninstalling the Application.
ZIP Code / Elected Officials Feature
The Application offers an optional feature to display your elected officials (e.g., your U.S.
Representative, Senators, Governor) based on your ZIP code.
-
Local storage only: Your ZIP code is stored locally on your device and is
not transmitted to or stored on our servers.
-
Government API queries: When you use this feature, your ZIP code is sent to
public government APIs (listed below) solely to retrieve your elected officials. These
queries happen on-demand and the results are displayed in the app.
-
No tracking: We do not use your ZIP code for advertising, profiling, or any
purpose other than displaying your elected officials.
-
You can remove it: You can update or clear your ZIP code anytime in the app
settings.
Microphone / Speech Features
The Application includes optional features that use your microphone (e.g., mock interview
practice). Microphone access is requested only when needed and can be controlled in your
device settings. Speech recognition is not performed on your device: recordings are
transcribed and evaluated server-side by our AI provider, as described under "AI-Powered
Features" below.
AI-Powered Features (Premium)
The Application offers AI-powered features for premium subscribers, including AI Mock
Interview and AI-assisted reading practice. These features process your data as follows:
-
Audio transcription: When you use AI Mock Interview or AI reading practice,
your recorded audio is sent to our secure server (Supabase Edge Functions), which forwards
it to OpenAI's Whisper API for speech-to-text transcription. The audio is processed in real
time and is not stored by us; OpenAI's handling is described under
"Provider-side retention" below.
-
Answer evaluation: Your transcribed text, along with the test question and
accepted answers, is sent to OpenAI's GPT model for semantic evaluation. This determines if
your answer is correct and provides feedback. No personal identifying information is
included in this evaluation.
-
Data minimization: We only send the minimum data required for transcription
and evaluation. Audio recordings are deleted from your device after processing. OpenAI
processes data under their
Enterprise Privacy policy and does not
use API data to train their models.
-
Provider-side retention: OpenAI may retain API inputs and outputs
(including transcribed audio) for up to 30 days for abuse and misuse monitoring, after which
they are automatically deleted. We do not store your voice recordings on our own servers.
-
Your choice: Nothing is recorded until you tap the microphone (or
“Begin Interview”) yourself, and your device asks for microphone permission the
first time. You can decline that permission, revoke it later in your device’s
settings, or simply not use the voice features — every other part of the app keeps
working.
Server-Side Session Tracking
To enforce daily usage limits and prevent abuse of AI features, we store minimal session data
on our server (hosted on Supabase):
-
What we store: A pseudonymous user identifier (RevenueCat anonymous ID),
session counts per day, session type (mock interview or reading practice), number of AI
calls made, estimated processing cost, and your score.
-
What we do NOT store: Your name, email, audio recordings, transcripts,
answers, IP address, or any other personally identifiable information.
-
Purpose: This data is used solely to enforce a daily limit on AI practice
(set by the service and subject to change), monitor costs, and prevent abuse. This
processing is necessary for the performance of our service contract with you (GDPR
Article 6(1)(b)).
-
Retention: Session data is retained for 90 days for cost analysis and
dispute resolution, then may be archived or deleted.
-
Security: All server-side data is protected by Row Level Security policies.
Only our server-side functions (not the app directly) can access this data. Communication is
encrypted via HTTPS.
Your Right to Delete: You can delete all your server-side data at any time by
going to Settings → Delete My Data in the app. This permanently removes your user record,
all session history, and any cached data from our servers. This action cannot be undone.
Fraud Prevention Retention: When you request data deletion, we retain a
minimal, pseudonymous record of your daily AI usage counts (date and integer count only) for
up to 10 days. This prevents abuse of the deletion feature to circumvent daily usage limits.
This retention is permitted under GDPR Article 17(3) (fraud prevention, legitimate interest
under Article 6(1)(f)). The retained data contains no personal content, conversation history,
or identifiable information beyond a pseudonymous service identifier. It is automatically and
permanently deleted after 10 days.
Subscriptions & Payments
If you purchase a subscription, payment is processed by the platform provider (Apple App Store
or Google Play). We do not collect or store your full payment card details. We (and our
subscription provider, RevenueCat) receive limited information required to validate and manage
subscription access (for example: purchase status, entitlement status, and receipt tokens).
Cancellation: You can cancel your subscription anytime from your App Store /
Google Play subscription management settings. After cancellation, access may remain active
until the end of the current billing period.
Advertising and Personalization
The Application displays advertisements to support the free version. We use Google AdMob to
serve ads. Depending on your consent choices and location, you may see:
-
Personalized ads: If you consent, ads may be tailored based on your
interests, app usage, and device information.
-
Non-personalized ads: If you do not consent or withdraw consent, you will
still see ads, but they will not be based on your personal data.
Consent Management
We use Google's User Messaging Platform (UMP) to collect and manage your consent preferences
in compliance with applicable regulations:
-
European Economic Area (EEA), UK, and Switzerland: When you first use the
app, you will see a consent form asking for your permission to use your data for
personalized advertising (GDPR compliance).
-
United States: In applicable states (e.g., California, Virginia, Colorado),
you will see options to opt out of the sale or sharing of your personal information
(CCPA/state privacy law compliance).
-
iOS Users: You will see Apple's App Tracking Transparency (ATT) prompt
asking for permission to track your activity across other companies' apps and websites.
Managing Your Ad Preferences
You can change your consent and ad preferences at any time:
-
In-App: Go to Settings → Privacy Settings to update your consent choices.
-
Device Settings (iOS): Go to Settings → Privacy & Security → Tracking to
manage app tracking permissions.
-
Device Settings (Android): Go to Settings → Google → Ads to manage your
advertising ID and personalization preferences.
Withdrawing consent will not affect the lawfulness of processing based on consent before its
withdrawal.
Third-Party Services
The Application uses third-party services that may collect information according to their own
privacy policies. These services help provide ads, analytics, subscription functionality, and
elected official information.
Note: Some third-party services, such as Google AdMob, act as independent
data controllers for their own purposes and are responsible for their own compliance with
privacy laws. When you interact with ads, Google may process your data according to its own
privacy policy.
Subscription, Analytics, and AI Services:
Government APIs (for Elected Officials Feature):
-
Congress.gov API (Library of Congress): Used to retrieve information about
U.S. Representatives and Senators.
Congress.gov Data
-
U.S. Census Bureau Geocoder: Used to determine congressional districts.
Census Privacy Policy
-
HUD USPS Crosswalk API: Used to identify congressional districts for ZIP
codes. This product uses the HUD User Data API but is not endorsed or certified by HUD User.
HUD Privacy Policy
-
Zippopotam.us: Used to convert ZIP codes to geographic coordinates (public
API).
Disclosure of Information
The Service Provider may disclose User Provided and Automatically Collected Information:
- As required by law (e.g., to comply with legal processes such as subpoenas).
- When disclosure is necessary to protect rights, user safety, or investigate fraud.
-
To trusted service providers who assist in app operations and agree to confidentiality
terms.
Your Choices About Personal Information Sharing. We do not sell, rent, or
trade your personal information to third parties for their direct marketing purposes. However,
if you consent to personalized advertising, your advertising identifier and related data may
be shared with our advertising partners (including Google AdMob and its partners) for
interest-based advertising. You can opt out of this sharing at any time through the Privacy
Settings in the app or by adjusting your device's advertising settings.
Data Retention
Study data is stored locally on your device until you delete it (reset) or uninstall the app.
Analytics and usage data are typically retained for up to 14 months, unless required for a
longer period for security, legal, or operational reasons. Subscription-related records may be
retained by Apple/Google and RevenueCat as required for billing, fraud prevention, compliance,
and customer support.
Server-side session data (AI usage counts and cost tracking) is retained for
up to 90 days. You can delete this data at any time through the "Delete My Data" option in the
app's Settings screen. When you request deletion, all your session records and associated
personal data are removed from our servers immediately. A minimal fraud-prevention record
(daily usage counts only, no personal content) is retained for up to 10 days after deletion to
prevent abuse, then automatically purged.
Audio recordings submitted for AI transcription are processed in real time
and are not stored by us. OpenAI may retain API inputs for up to 30 days for abuse monitoring,
after which they are automatically deleted (see "AI-Powered Features" above).
You may request deletion of any support communications you send us by contacting
sendfeedbackus@gmail.com.
Your Privacy Rights
General Rights (All Users)
Depending on your location, you may have rights to:
- Access your personal information
- Request deletion of your personal information
- Correct inaccurate information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
Self-Service Deletion: You can delete your server-side data (AI session
records) directly from the app at any time. Go to Settings → Delete My Data. For deletion
of data held by third-party services (RevenueCat, Google, Apple), please contact them directly
or email us for assistance.
European Economic Area (EEA) and UK Users - GDPR Rights
If you are located in the EEA or UK, we process your personal data under one or more of the
following legal bases:
- Performance of a contract: To provide the Services you request.
-
Legitimate interests: To maintain and improve our Services, prevent fraud,
and ensure security.
-
Consent: For personalized advertising, certain analytics, and any other
processing where required by law. You may withdraw consent at any time.
- Legal obligations: To comply with legal requirements.
Personalized Advertising: In the EEA, UK, and Switzerland, we rely on your
consent as the legal basis for personalized advertising. If you do not consent or withdraw
consent, you will only see non-personalized (contextual) ads.
You may also:
- Object to processing based on our legitimate interests
- Request data portability in a structured, machine-readable format
- File a complaint with your local data protection authority
California Residents - CCPA Rights
If you are a California resident, you have the right under the California Consumer Privacy Act
(CCPA) to:
- Know what categories of personal information we collect about you
- Access specific pieces of personal information we have collected
- Delete personal information we have collected from you
- Correct inaccurate personal information
- Opt-out of the sale or sharing of personal information
- Non-discrimination for exercising your privacy rights
Personalized Advertising: If you consent to personalized ads, we share
advertising identifiers with our ad partners, which may constitute "sharing" under the CCPA.
You may opt out at any time via the Privacy Settings in the app or by using the "Do Not Sell
or Share My Personal Information" option when prompted. We do not use or disclose sensitive
personal information for purposes other than those permitted by the CCPA.
To exercise your rights, contact us at
sendfeedbackus@gmail.com.
International Data Transfers
We are based in the United States. Your information may be processed in the United States or
other countries, which may have data protection laws that differ from those in your country of
residence.
For transfers of personal data from the EEA, UK, or Switzerland to countries without an
adequacy decision, we and our third-party service providers rely on appropriate safeguards,
including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-U.S. Data Privacy Framework (where applicable)
- Other legally approved transfer mechanisms
Our key advertising and analytics partners (Google, RevenueCat) maintain their own data
transfer compliance programs. You can learn more about their safeguards in their respective
privacy policies linked above.
Children's Privacy
The Application is not intended for children. In the United States, we do not knowingly
collect personal information from children under 13 (COPPA). In the European Economic Area,
United Kingdom, and other jurisdictions where a higher age applies, we do not knowingly
collect personal information from children under 16 (or the applicable age of digital consent
in your country). If you believe a child has provided us with personal information, please
contact us, and we will take steps to delete such information.
Security
The Service Provider values your trust and is committed to protecting your data. We implement
reasonable technical and organizational measures to help prevent unauthorized access to user
data, including:
- All API communications are encrypted via HTTPS/TLS.
-
Server-side data is protected by Row Level Security (RLS) policies — only authenticated
server-side functions can access user data.
- Per-IP and per-user rate limiting to prevent abuse of AI features.
- Subscription entitlements are verified server-side on every AI request.
- Request size limits and input validation on all API endpoints.
However, no method of internet transmission or electronic storage is completely secure.
Changes to This Policy
This Privacy Policy may be updated from time to time. We encourage you to review this page
periodically. Material updates will be communicated through the app or other appropriate
means.
Effective Date: January 28, 2026
Last Material Update: September 19, 2026