Privacy

Privacy notice

Draft of 2026 09 17. Read by counsel, who returned no blockers. Still a draft, and not in force.

A review is not the same thing as a signature. This text stops being a draft when somebody says the final words are final, and nobody has.

This draft was written from Camito's own Processing Inventory, which lists every data flow the product is specified to have, and from the Legal Surface Specification, which says what shape these documents take and why. Where the inventory records that something is not yet known, this draft says so in the same place rather than filling it with a number that sounds right.

Corrected on 2026 09 17 against the app's own source code. The first version of this draft described the product the inventory specified. Somebody then read the code, and nine of the things described here were things the app does not do. Every sentence below now matches the app that is actually built, and where the app is smaller than the plan this page says so.


In short

  • Camito is a study app. It teaches road rules and tests you on them.
  • We collect what it takes to run that: your account, whether you are subscribed, a little about how the app is used, and a crash report when it breaks.
  • Your lessons, scores and progress stay on your phone. In this version of the app they are not uploaded anywhere at all.
  • We never see your card. Apple and Google take the payment and tell us only whether you are subscribed.
  • There is no advertising, no advertising identifier and no tracking. Camito does not ask iOS for permission to track you, because it has nothing to track you with.
  • We do not sell your personal information and we do not share it for cross-context behavioural advertising.
  • You can delete your account, and everything in it, from inside the app.
  • If something here is unclear, write to us at [email protected].

Who is responsible for your data

Camito is operated by Mimi Studio d.o.o., a company registered in Slovenia and based in Ljubljana. Mimi Studio d.o.o. decides what is collected and why, so in the language of European data protection law it is the controller of everything described on this page.

OpenThe exact registered address and the company and tax identifiers are held once in the Portfolio Publisher Profile and are not reproduced here from memory. This is a lookup rather than a question: copy them from that profile, so that the address in this notice, in the App Store listing, in the Google Play listing and in the Terms is one address rather than four.

Because Mimi Studio d.o.o. is established in the European Union, it does not need a separate representative in the Union.

OpenWhether a United Kingdom representative is required under Article 27 of the UK GDPR, and who it would be, is a live question rather than a formality: the company is established in the EU and not in the UK, and the UK is a Launch Territory. Counsel, before the first UK visitor is offered the app.

You can reach us about anything on this page at [email protected].

Who Camito is for, and how old you have to be

You must be at least 13 years old to use Camito. If you are under 18, you must have your parent or guardian's permission to use it. The Terms say the same two numbers in the same words, and the app's store rating is 4+.

Camito is not directed at children under 13 and we do not knowingly collect personal information from anyone under 13. If we learn that we hold information about a child under 13, we delete it.

OpenHow a parent or guardian gives that permission, and what Camito records about it, has not been designed or built. In parts of the European Economic Area the age at which a young person can consent on their own is 14, 15 or 16 rather than 13, which means that in those countries a parent has to consent for some of what is described below and not for the rest. The per-country analysis is partly done and partly not: Spain and Italy are 14, France is 15, the Netherlands and Germany are 16, and Poland, Czechia, Austria and every other member state are not yet established. Counsel decides what this notice must say, and the product has to build the mechanism before any of those countries is opened.

What we collect, why, and what happens to it

Your account

What Your email address, and a password that is stored only as a hash
Why To know it is you, and to attach your subscription to a person rather than to a handset
Basis Performing our contract with you
Held by Supabase
Where OpenThe region has not been chosen, because the project has not been created. Counsel and the build lane settle this together, and it changes what this notice must say about transfers.
Kept For as long as your account exists. When you delete it, the only copy that remains is in the weekly backups, and Backups, and how long deletion really takes below says how long that is
Your control Change your email, change your password, or delete the account, all from inside the app

Email and a password, and nothing else. There is no sign in with Apple, no sign in with Google and no social login in this version of the app. If one is ever added, this section changes first.

Authentication email

The messages that carry a sign-in code or a password reset are sent for you, addressed to you, and cannot be switched off, because turning them off would lock you out of your own account. Unsubscribing from anything else never stops them. They are sent by Supabase. If we later hand the sending itself to a specialist email service, which is what the rest of our apps do, that company joins the list of processors below before it sends anything.

Before you have an account

Camito works before you create an account, so on first launch your phone makes up a random identifier for itself and keeps your work against that. It is a random number. It is not your name, not your email address and nothing anybody could read you off. It lasts as long as the app is installed and is gone when you uninstall it. It is also the name your subscription is filed under at RevenueCat, which is what lets you get your subscription back on a new phone.

One honest limitation. If you never create an account, we have no way to find your data if you later ask us to delete it, because we would have nothing to match you to. We have not solved that, and we would rather say so than pretend otherwise.

Your subscription

What Whether you are subscribed, which product, the store's transaction identifier
Why To give you access, and to give it back when you reinstall or change phone
Basis Performing our contract with you
Held by RevenueCat, Apple, Google
Where OpenNot established. No account exists at any of the three, and the region and the retention period are both terms of agreements that have not been signed.

Payment details

We never receive them. Apple and Google are the merchants for anything you buy inside the app. Your card number, your billing address and your payment history with the store are between you and the store. We are told whether you are subscribed. We are not told what you paid with.

What you do in the course

What Your score on each lesson, which questions you got right the first time, which are marked needs review, your points, your level, your unit test and mock exam results
Why This is the product. The statistics are the thing Camito promises you: honest first try performance on material it taught you
Held by Your phone, and nowhere else
Kept Until you delete the app or reset your progress

This is the part most study apps get wrong and it is worth being exact about. In this version of Camito your lessons, your answers and your scores are written to storage on your own device and are never uploaded. They do not go to our database. They do not go to our analytics. There is no event anywhere in the app that could carry a score, because we did not write one.

A later version will let your progress follow you between phones, which means sending it to our database. That is a change to what is collected, so this section changes before it ships, not after.

Which course you picked

Your jurisdiction and vehicle class. Camito needs these to show you the right road law and not somebody else's, and it keeps your progress separately for each course rather than merging them. Like your progress, these stay on your phone in this version of the app.

The questions we ask when you start

Setting up asks you three things: which country, which state or region where that applies, and which kind of vehicle. That is the course you want, it stays on your phone, and there is nothing else. Camito does not ask your age, your permit status, how far along you are, when your test is, or why you are here.

How the app is used

We count how the app is used so we can tell whether it works: that it launched, that setting up was finished, that a paywall was shown or closed, that a purchase succeeded or failed, that a reminder was scheduled, which tab was opened, that an error screen appeared. This goes to Mixpanel, along with which platform you are on and which language the app is in.

What goes with it, exactly. Mixpanel's own library adds your operating system family, browser engine and version, the size of your screen, and a random identifier it stores on your device. Camito adds the platform, the language, and a fresh random number for each event so two identical events can be told apart.

What deliberately does not go with it. Your name, your email address, your age, your progress, your scores, your answers, the course you picked, your IP address, your location or your country, the version of the app, your device model, and any text you have typed. Camito's analytics can only send a fixed list of events, each with a fixed list of fields; anything else is dropped before it leaves the phone, and the test suite proves it by trying to send a name and a latitude and checking that both disappear.

In the United States this does not need a consent banner, because it is our own measurement of our own app and carries no advertising identifiers. In the European Economic Area and the United Kingdom the rules are different and stricter.

OpenThe exact requirement in the European Economic Area depends on how each member state has written the ePrivacy rules into its own law, and those laws have not been read. Until they have, this notice cannot describe an opt out in a way that is true in a particular country, and Camito should not open a European country. Counsel, per country, before the first one opens.

OpenThe app sends its events to Mixpanel's European address. Which region the Mixpanel project itself is created in, and how long it keeps data, are both chosen when the project is created, and no project exists.

Advertising and tracking

There is none, and this is the plainest section on the page.

Camito shows no advertisements. It contains no advertising software, no attribution software and no advertising identifier. It never asks iOS for permission to track you, because there is nothing it could do with the answer. It sends nothing to an advertising network, and it joins nothing we hold to anything anybody else holds.

If Camito ever runs paid advertising it would need an advertising identifier, and on an iPhone that means the tracking permission iOS asks for. That has not been built and it is not in this app. If it is ever added, this section changes first, the app's App Store privacy label changes with it, and the permission is asked before anything is collected. None of it would affect the course, your progress or your subscription, which work on a different legal basis entirely and are never conditioned on permission to advertise.

Crashes and errors

When Camito breaks it sends us a technical report through Sentry: the type of error, the lines of our own code it happened in, which build it was and whether that build was a test one or a live one.

It carries nothing about you. Not your account, not your email address, not your name, not your device model, not your operating system version, not the screen you were on, not what you had typed and not the error's own message, which is replaced with a fixed phrase before it is sent. The report is rebuilt from a fixed list of technical fields rather than filtered, so a field nobody listed cannot escape into it.

OpenSentry's region and how long it keeps a report are both set on an organization that has not been created. Whether Sentry records the internet address a report arrives from, at its own end, is a setting on that same organization and has not been checked.

Email about your progress, and marketing

Neither exists in this version of the app. Camito sends you no newsletters, no offers and no progress reports, and there is nothing in the app that signs you up for any of them. Creating an account does not sign you up for marketing, because there is no marketing to be signed up for.

If that changes, it changes here first, and any marketing will be a separate, clearly labelled choice that starts switched off and only happens if you positively ask for it.

When you write to support

Camito has no support form, no chat and no feedback box. What it has is our email address, and tapping it opens your own mail app. So what we receive is an ordinary email from you: what you wrote, your address, and anything you chose to paste in.

Please do not send us health information. You do not need to explain a medical condition or a disability to get help with a study app, and if you mention one we will not ask for details.

Two things worth knowing, because most companies do not say them. The first is that a support conversation is filed under your email address, not under your Camito account, so deleting your account does not delete an old support conversation. Ask us and we will delete it. The second is that we have not yet fixed that, and we are recording it here rather than hoping nobody notices.

OpenWhich support system holds the conversation, which service carries the message into it, and how long it is kept are three decisions nobody has taken. The last one should be taken deliberately rather than left at a default, precisely because this is the one place people write things about themselves that we never asked for.

Study reminders

If you set a reminder to study, the schedule lives on your device and nowhere else. Camito sends no push notifications from a server, holds no push token, and receives no report of whether a reminder was shown. Uninstalling the app removes it.

Your age

This version of the app does not ask. The age rule above is a rule about who Camito is for, stated in the Terms and here, and the app does not currently collect an age to enforce it with.

When it does ask, it will store the answers to two questions, whether you are at least 13 and whether you are under 18, and not your date of birth, unless a particular country's law requires more. Your age would never be sent to any analytics or advertising service.

Backups, and how long deletion really takes

Camito's database is backed up once a week, encrypted, to private storage. The twelve most recent weekly archives are kept and older ones are deleted automatically.

This means that when you delete your account, a copy of your data can remain in our backups for up to about twelve weeks. It is not in the live service, nobody is using it, and it is deleted when the archive that holds it rolls off. We would rather tell you the real number than say "deleted immediately" and be wrong.

OpenSupabase may also run its own provider backups on its own schedule. What that schedule and its retention are has not been checked, and it is a different thing from the weekly archive above.

Server logs

Running a service produces logs: which requests arrived, when, from which internet address. DigitalOcean and Supabase hold these and they rotate in the ordinary way.

OpenHow long each of them keeps a log is not established.

This website

The website you are reading now is deliberately simple, and here is exactly what it does.

  • It is a set of static pages. It has no database, no account system and no connection to Camito's servers.
  • It sets no cookies and runs no analytics. Nothing on it counts you, follows you or reports you to anybody.
  • It loads nothing from anybody else: no script, no image, no font and no stylesheet from another site, so no third party learns that you visited. The type you are reading is a font already on your own device.
  • Two small things are stored in your browser and neither identifies anybody. The language you chose, if you chose one, so the site does not ask again. And a mark that says you have already seen the opening animation, so the second page you open does not play it at you. The first lasts until you clear your browser storage and the second until you close the tab. Neither ever leaves your browser.
  • Our hosting provider keeps ordinary web server logs, which include your internet address, as described above.

If a part of this site ever does more than that, this section changes first.

OpenCamito's account, cancellation and recovery pages are a separate application at app.camitoapp.com and have not been built. When they are, they handle signed in journeys and this notice will need a section for them. There is also a decision nobody has taken about whether Camito ever sells subscriptions through the web, which would add a payment processor and a lead capture to this notice. It is deliberately not described here as though it existed.

Who else processes your data

In this version of the app, four companies and no more.

Who What for
Supabase Accounts, and the sign-in and password reset email
Apple, Google Taking payment, and telling us whether you are subscribed
RevenueCat Keeping track of subscription state across both stores
Mixpanel How the app is used
Sentry Crash and error reports
DigitalOcean Hosting this website, and backup storage

Named because they are planned and not because they are used. An email sending service, a marketing email service, a support system, an advertising measurement service and an advertising network all appear in Camito's internal Processing Inventory as intended future flows. None of them is in this app, none of them holds anything about you today, and each one will be added to the table above, with what it is for, before it receives anything.

OpenEach company in the table needs a signed data processing agreement, a recorded region and a recorded retention period before this list is complete. None of the accounts exists yet, so none of those three facts exists yet either. This list names who we intend to use and what for, and that is as far as it can honestly go today.

Mimi Studio d.o.o. is in Slovenia, and several of the companies above are in the United States, so some of the data described on this page leaves the European Economic Area.

OpenWhich mechanism makes each of those transfers lawful, vendor by vendor, is still unanswered, and it is now blocked on one thing rather than two. The operating entity is settled. The vendor regions are not, because no account exists at any of them, and the mechanism is a term of a data processing agreement that nobody has signed. Counsel names it per vendor once those agreements are executed.

What you can do

Wherever you are, you can:

  • See and export what Camito holds about you, from inside the app.
  • Correct it, from inside the app.
  • Delete your account, from inside the app, which erases your data from the live service, subject to the backup period described above.
  • Write to us at [email protected] about any of it.

Because your progress lives on your phone in this version, the fastest way to be rid of it is to delete the app. That removes it completely and immediately, and nobody has to be asked.

If you are in the European Economic Area or the United Kingdom

You have the rights the General Data Protection Regulation gives you: access, correction, erasure, restriction, portability, objection to processing based on our legitimate interests, and withdrawal of any consent you gave. Withdrawing consent does not undo what was lawfully done before you withdrew it. You can also complain to your national data protection authority, and you do not have to come to us first.

If you are in California, Virginia, Colorado or Connecticut

You have the rights your state gives you: to know what is collected and why, to get a copy, to correct it, to delete it, and not to be treated worse for asking.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for you to opt out of on that front. If that ever changes, this page changes first and the opt out appears with it.

To use any of these rights, write to [email protected]. We may need to check that the account is yours before we act, which usually means answering from the address the account uses. If we ever say no to a request we will tell you why, and you may appeal by replying to that answer.

OpenCamito's Launch Territories are wider than these four states and wider than the European Economic Area. Which other state and national privacy regimes apply, and what each of them requires this section to say, is counsel's call territory by territory. Four states are named because those four regimes are in force and were checked. Naming fifty would be a claim nobody verified.

Things we have not solved, listed rather than hidden

  1. Deleting your account does not delete an old support conversation. It is filed under your email address, not your account. Ask us and we will delete it.
  2. Backups keep a copy for up to about twelve weeks after you delete your account.
  3. If you never made an account, we cannot find your data to delete it, because there is nothing to match you to.
  4. We have not yet confirmed exactly what RevenueCat keeps after we ask it to delete a subscriber. We ask, and we have not read the answer back against their own documentation and the signed agreement, so we will not tell you it is complete until we have.

OpenItem 4 is settled by reading RevenueCat's deletion API documentation and the executed data processing agreement, not by asking anybody's opinion. It is listed as a limitation rather than left out, because the Processing Inventory records it as not established and a notice that quietly implied otherwise would be claiming something nobody checked.

Changes

If this notice changes in a way that matters, we will say so in the app rather than quietly changing the date at the top.

Contact

[email protected]


Notes for counsel, to be removed before publication

Review status, 2026 09 17. Counsel has read an earlier draft of this text and the Terms and returned no blockers, alongside three other questions that were queued at the same time: whether a thirteen year old may lawfully be charged for a monthly subscription, New York provider licensing, and whether the California disclaimer belongs on the second paywall as well as the first. None of those came back with a blocker either. The controller is now named, which was the one thing still owed and was never a legal question.

What changed after that review, and it is substantive rather than cosmetic. The app's source code was read on 2026 09 17 and nine statements in the reviewed draft described a product that does not exist. Corrected here: progress and course choice are on the device and are not uploaded; there is no social login; there are no onboarding profiling questions; the analytics carry far less than was described and no advertising identifier at all; crash reports carry no account identifier; there is no marketing email, no progress report and no support system; the app does not ask an age; and the website stores two things in the browser rather than one. Six open questions closed as a result, not by a judgement but by reading what the code does, and this draft is shorter and more specific than the one counsel saw. It is worth a second pass on that basis.

This draft deliberately does not do several things the category usually does, and each omission is a decision rather than an oversight.

  1. No retention period is invented anywhere. Every one that is not actually known is marked open. The Processing Inventory records these as unverified because the accounts that would fix them have not been created, and a period written here would be repeated into an Apple privacy declaration and a Google Data Safety form and become a representation to a regulator that nobody checked.
  2. No vendor region is stated. Same reason. This is what still blocks the international transfer section: the controller's own country is now known, and the other end of each transfer is not.
  3. The twelve week backup latency is stated in plain words because the Processing Inventory requires it in those words, and because it is the honest end to end deletion time.
  4. The age floor is stated once, identically here and in the Terms: at least 13, and under 18 with a parent or guardian's permission. The Legal Surface Specification records that the reference product states its floor in two documents that never cross reference each other, and that Camito does not repeat that.
  5. The under 13 branch is described as a rule, not as a mechanism. An earlier draft said that telling Camito you are under 13 stops the sign up. It does not, because the app has no age question yet. The sentence was removed rather than softened. This is a product gap and it is tracked as FLOW-019: the floor is asserted in both documents and enforced nowhere, and it has to be built before the floor means anything.
  6. The state rights section covers four states, not one. The reference covers California alone. Virginia, Colorado and Connecticut are in force. Which further states apply is an open item above.
  7. Vendors that are planned are named as planned. The reviewed draft listed ten processors as though all ten held data. Five of them hold nothing, because they are not in the app. Listing a processor that has never received a byte is not a conservative disclosure, it is a false one.