CivicsTorch (“the app”, “we”, “our”) is an offline-first study app for the U.S. naturalization civics test, published by SAY Studio Say, an individual developer. This policy explains what information the app collects, why, who it is shared with, and the choices and rights you have.
Contact for privacy questions or requests: vsaytech@gmail.com
We (the developer) do not operate any server and do not directly receive your personal information. The data below is collected by Google SDKs embedded in the app, under Google’s own privacy terms, when the relevant feature is active and (in the EU/UK) after you consent.
When ads are enabled, Google’s AdMob SDK may collect the advertising identifier and other device identifiers, your IP address (and coarse location derived from it), ad interactions (impressions, taps), and device/diagnostic information. By default the app requests non-personalized ads; personalized ads are served only where you consent. Ads appear only in the free tier — never during a mock interview or mid-question.
When enabled, Firebase Analytics collects aggregate, non-identifying usage signals — limited by design to identifiers, categories, and counts (e.g., a study session finished, a question answered, a mock completed). It may include an app-instance identifier, device/diagnostic info, and coarse (country/region) location. Analytics is off by default and runs only after consent. Anonymous “helper” study sessions are tagged with a per-session throwaway identifier never linked to a persistent one.
When enabled, Crashlytics collects crash stack traces, exception type, device state, model, and OS version to help fix defects. It is consent-gated and off by default. The app is built so that no text you type is ever included in crash reports, and a filter additionally scrubs email-like and long-digit patterns.
To honor your privacy choices, the app stores your consent selections (ads/analytics personalization and, in applicable U.S. states, your “Do Not Sell or Share” choice), used only to remember what you chose.
Android’s built-in Auto Backup may copy your on-device learning progress and preferences to your own Google Drive, controlled by your Google account and encrypted by Google. This backs up your data to your account — it does not send data to us. Ad/analytics caches and consent choices are excluded. You can disable backup in device settings.
| Purpose | Data used | Provider |
|---|---|---|
| Show ads to support a free app | Ad ID, IP, ad interactions, device info | Google AdMob |
| Understand feature usage to improve the app | App instance ID, interaction events, coarse location | Firebase Analytics |
| Diagnose and fix crashes | Crash traces, device state | Firebase Crashlytics |
| Remember your privacy choices | Consent selections | UMP |
We do not sell your data for money. Whether ad serving counts as “sharing” under some U.S. state laws is addressed in §7.
Google (AdMob, Firebase Analytics, Crashlytics, UMP), as the provider of these services, under Google’s policies:
We share with law enforcement only if required by valid legal process. There is no other backend, ad network, or data broker in the app.
If you are in the EEA or UK you have the rights of access, rectification, erasure, restriction, objection, and portability. Because we hold no personal data on any server, most requests concern data held by Google for the SDK functions above; exercise Google-side rights via your Google account and the links in §4. For anything we can action, contact vsaytech@gmail.com. Legal bases: consent for ads/analytics/crash personalization; legitimate interests in a functioning, stable app where permitted. Withdrawing consent does not affect prior processing. You may complain to your local supervisory authority.
If you are a California resident (or in a state with comparable law), you have the right to know, to request deletion, and to opt out of the “sale” or “sharing” of personal information. We do not sell your personal information for money. Serving ads via AdMob using device identifiers may be considered “sharing” for cross-context behavioral advertising, so the app provides a “Do Not Sell or Share My Personal Information” control at Settings → Privacy, which signals your opt-out to the advertising SDK via the IAB Global Privacy Platform. You may also email vsaytech@gmail.com.
We retain no personal data on any server. Data held by Google is retained per Google’s policies (§4). On-device data persists until you delete it (§9).
CivicsTorch is intended for adults and is not directed to children under 13. A neutral age gate blocks under-13 use. We do not knowingly collect personal information from children under 13; contact us and we will delete any that was provided.
The app is offline-first with no server-side account, removing an entire class of breach risk. Data in transit to Google’s SDKs is encrypted by those SDKs; on-device data is protected by Android’s app sandbox and, for backups, by Google’s encryption.
The app links to official U.S. government pages (e.g., USCIS) for authoritative content; those sites have their own policies. CivicsTorch is not affiliated with, endorsed by, or connected to USCIS, DHS, or any U.S. government agency.
We may update this policy as the app changes. Material changes update the “Last updated” date and, where required, prompt renewed consent. Continued use after an update means you accept the revised policy.
SAY Studio — CivicsTorch
Email: vsaytech@gmail.com