Skip to main content

Vivat Lex mobile apps

Mobile app privacy policy

Privacy information for Vivat Lex on iOS and Android. The web course has its own privacy policy.

Scope and controller

Stanislav Lynnyk, a sole trader trading as Vivat Lex, 32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom. Email: sqe1practice@gmail.com. Telephone: +447442194285.

This policy covers the Vivat Lex iOS and Android apps, including earlier listings named SQE1 Practice. It does not replace the separate Vivat Lex Web privacy policy at https://vivatlex.co.uk/privacy.

Vivat Lex Web, Vivat Lex for iOS and Vivat Lex for Android are separate products. A purchase in one product does not include access to either of the other products. Using the same email address does not transfer a purchase. Restore a mobile purchase through the store that originally billed you.

Effective: 27 September 2026.

Account, trial and purchase data

When you sign in, we process your email address, any profile name returned by your chosen sign-in provider, your app account identifier, provider identity and sign-in/security records. Google, Apple or the email verification service handles the chosen authentication method. We do not receive your Google or Apple password.

We process trial eligibility, subscription and transaction references, purchase or restoration status and access records to provide and verify the features you request and prevent abuse. For Android, Google Play notifications and APIs also provide verified order status, amounts, currency, tax, store country, renewal and refund information. Where a purchase supplies an account reference, we can link it to your app account; older purchases may not have that link. Apple or Google Play handles mobile payment. We do not receive your full payment-card number from these stores.

Study activity, diagnostics and region

The apps keep study progress and preferences on your device and process cloud account or study data where the relevant feature uses Firebase. We also process app interactions, session timing, feature use, app and operating-system versions, device/installation identifiers and technical errors or performance information.

Operational records may include a pseudonymous account, installation or session reference, foreground activity time, the sequence of broad app areas reached, sign-in and access outcomes, purchase outcomes and technical error codes. We use these records to identify where access fails and whether requested features work. Where we can verify the account link, restricted operator notifications and daily summaries may include your full account email address. These records are not anonymous if we can link them to an account.

An app region label may come from the device locale and does not establish physical location. A store country comes from Apple or Google Play and may also differ from your current physical location. Network providers and the Android advertising SDK may infer approximate location from an IP address. The apps do not request precise device location.

Optional AI Tutor

When you use AI Tutor, the prompt and relevant recent conversation history are sent through Firebase AI Logic to Google’s Gemini service. Where you ask about study material, the request can include the relevant question, answer choice or material context. Per-account usage counters support feature limits.

Avoid sending confidential client material or unnecessary personal information. AI responses may be inaccurate and are study aids, not legal advice. Google processes requests under its applicable service and data-governance terms; we do not promise that all provider records are deleted immediately after an answer.

Differences between iOS and Android

iOS uses Firebase Analytics and, in Release builds, Crashlytics for crash and reliability information. Messaging-related device tokens and Apple advertising-attribution information may also be processed by the corresponding features. The current iOS release does not display AdMob advertisements.

Android uses Firebase Analytics for app usage information. From version 2.6.13, Android also uses Firebase Crashlytics for crashes and application-not-responding diagnostics. Crash diagnostics can include app/build and operating-system information, device details and error traces. For signed-in users, we attach an internal account identifier rather than an email address. Necessary service diagnostics are separate from advertising permission and any optional diagnostic controls.

Android uses Google Mobile Ads (AdMob). Its SDK collects and shares approximate location, ad/app interactions, diagnostic information, advertising or app-set identifiers and applicable device-account identifiers for advertising, analytics and fraud prevention. Advertising behavior can depend on the app version, access and system settings. Advertising identifiers can be managed in Android settings.

App tracking permission and available privacy controls apply where presented. Permission for one purpose is not permission for unrelated processing.

Support and Telegram delivery

If you contact support by email, we receive the address and information you choose to provide. Operational events, daily activity summaries, verified purchase updates and in-app reports can pass through our backend to a restricted operator chat in Telegram so we can investigate sign-in, delivery, trial, purchase and reliability problems. Android notifications can include your full account email address when the account link is verified, session and broad app-area activity, error details, country labels and verified order status and amounts. Telegram therefore receives this information as a delivery provider.

On iOS, a submitted issue report can include your typed comment, question reference, app/build details and a masked signed-in identity. Android issue reports send structured fields such as category, question identifier, topic and description length rather than the typed description itself.

Send only information needed for the issue. Do not send passwords, one-time codes or payment-card details. Telegram is an internal delivery destination, not the public route for customer support requests.

Purposes and providers

We process necessary account, study, trial and purchase information to provide requested app services; reliability and security information to maintain them and prevent misuse; and correspondence to answer support or rights requests. Legal obligations can require some records. Optional processing uses consent where the law requires it. Legitimate interests apply only where necessary and proportionate and balanced against your rights.

Recipients include Google/Firebase for authentication, database storage, analytics, configuration, app verification, diagnostics, messaging and AI as used by the platform; Apple and Google for store services; Google AdMob for Android advertising; Telegram for operator notifications; Resend for sign-in email delivery; and Google Gmail for support correspondence. Cloudflare provides website or network delivery where used.

These providers operate globally and may process data outside your country. Applicable provider data-processing terms and transfer safeguards govern restricted transfers. You can contact us about recipients and safeguards relevant to your data. Network requests use HTTPS/TLS; no system is promised to be absolutely secure.

Retention and deletion

Account data is kept while needed for the account and associated features. A successful server account deletion removes the Firebase sign-in account and its server account record and nested data, including server-held AI usage counters. Use the deletion instructions at https://vivatlex.co.uk/mobile/delete-account.

Account deletion does not automatically cancel store subscriptions or remove historical operational logs and Telegram messages. Ordinary Google Cloud operational logs currently use a 30-day retention period; required audit logs use Google’s fixed 400-day period. Other security, trial-abuse-prevention, support, delivery and provider records may remain under their applicable retention rules or where necessary for a legal obligation or claim. Ask support about records relating to your account.

Raw Android operational event records in our Firebase database are scheduled to expire after 30 days; automatic deletion is asynchronous rather than instantaneous. This period does not apply to account records, verified financial records, messages already delivered to Telegram, or Firebase Analytics, Crashlytics and other providers’ own records, which follow their separate retention arrangements.

iOS deletion also clears the app’s main local progress and practice stores. Android account deletion does not guarantee erasure of all local study records; use the device’s app-data controls. Store records and AI-provider records are subject to the relevant provider’s retention. No universal immediate deletion period is promised.

Your choices and rights

You can choose whether to use AI Tutor or send a support report, manage applicable advertising/tracking settings, sign out, or request account deletion. Signing out does not delete an account. Manage subscriptions in the store that bills you.

Depending on applicable law, you may request access, correction, erasure, restriction or portability of your data, object to processing, or withdraw consent without affecting earlier lawful processing. Contact sqe1practice@gmail.com; we may need to verify control of the account. Mandatory response periods apply. You may complain to the UK Information Commissioner’s Office or another applicable supervisory authority.

The apps are intended for adults. We do not knowingly seek children’s personal information. If you believe a child’s information has been provided, contact us. Material policy changes will be communicated as appropriate; a new policy does not itself create consent for a new purpose.