passline · NMLS Prep
Privacy Policy
The short version
- There is no account. You never give us your name, email or password to use the app.
- Your answers, readiness, review queue and exam date are stored on your phone. If your copy of the app offers iCloud sync, they are also stored in your private iCloud. We cannot read either.
- Payments go through Apple. We never see your card.
- No advertising, no third-party analytics, no tracking, no selling of data.
- The app sends two kinds of request to our servers: a check for updated question content, and anonymous counters such as "a check was finished". Neither carries an identifier. Our server logs record the IP address for a short time, like any web server.
- If you email us, we keep the email to answer it.
1. Who we are
NMLS Prep is published by passline ("we", "us"). This policy explains what data the NMLS Prep app for iOS (the "app") and the website at passline.app (the "site") handle, and what we do with it. It is written to be read, not skimmed past; it is also short because we handle very little.
2. No account, no sign-in
The app has no accounts. You do not register, sign in, or give us an email address to use it. We do not know who you are, and we have no profile of you anywhere.
3. Data stored on your device
Everything the app records about your study lives in the app's own database on your phone:
- your answers to questions, including the free check, daily sessions and timed mock exams, with the time taken on each;
- your readiness number and its history, and the per-section numbers behind it;
- your review queue;
- settings: exam date, daily pace, reminder preference and time, and how the check-in after your exam went, if you told the app;
- a record of when you bought 90-Day Access, so the app can tell you when it ends.
None of this is sent to us. You can erase all of it at any time with Settings → Erase all progress in the app, or by deleting the app.
4. iCloud sync
Some versions of the app keep the same data in your private iCloud database as well, so it follows you to a new phone. The app shows this in Settings under "Storage" ("Synced with iCloud"). This uses Apple's CloudKit service: the data is stored under your Apple Account, encrypted by Apple, and is not visible to us. We have no key to it and no way to read it.
Apple's handling of iCloud data is described in the Apple Privacy Policy. You can turn iCloud off for the app in iOS Settings → your name → iCloud → Apps Using iCloud. "Erase all progress" also removes the iCloud copy when sync is on.
5. Purchases
90-Day Access and Lifetime Access are sold through Apple's App Store as in-app purchases. Apple processes the payment; we never receive your name, address or payment details. The app checks your purchase with Apple on the device to decide whether access is active. "Restore purchases" asks Apple to re-send that record to your device. We do not run our own purchase server.
Refunds are handled by Apple under Apple's terms (reportaproblem.apple.com). We can see anonymous sales totals in App Store Connect; those figures are not tied to any person we can identify.
6. Requests the app makes to our servers
The app works offline. When it is online it makes two kinds of request to our content server, which runs on Amazon Web Services (Amazon S3 and CloudFront):
Content updates
At most once an hour the app asks whether a newer, verified set of questions exists. The request contains no identifier: only the version tag of the content it already has, so the server can answer "nothing new". If there is an update, the app downloads it. We use this so that a corrected question reaches you without an App Store release.
Anonymous counters
At a handful of moments (the check was started or finished, a result page was shown, a purchase was completed, a session or mock exam was finished, a regulation source was opened) the app sends a request whose whole content is the name of that moment, for example diagnostic-finished. There is no device identifier, no user identifier, no cookie, no session id and no other property. We count these requests to learn how many people reach each step of the app. Two events from the same person cannot be linked to each other, and none can be linked to you.
What the server logs record
Like any web server, CloudFront writes an access log for each request: the time, the path requested, the IP address the request came from, and the device's user-agent string (roughly, "iPhone, iOS 26"). We use these logs for the counts above and to detect abuse. We do not combine them with any other data, and we do not use them to identify you. They are deleted automatically after 90 days.
The counters are switched off entirely in test builds, and the app sends nothing at all to us while it is offline.
7. Reminders and notifications
If you turn on the daily reminder, the app schedules local notifications on your phone. They are created and delivered by iOS on the device; no server is involved, and we do not use push notifications. The app asks iOS for notification permission the first time you turn the reminder on. You can change this at any time in the app's Settings or in iOS Settings → Notifications.
8. Email and question reports
Contacting us is by email, at support@passline.app. When you report a question from inside the app, the app opens a draft in your mail app addressed to us. The draft contains the question's id, the category you picked (wrong answer, unclear, rule changed, typo, other) and anything you type. Nothing is sent until you send it, and you can edit the draft first.
When you email us we receive your email address, the message, and whatever your mail app adds. We use this only to answer you and to fix the app or a question. Email to support@passline.app is forwarded by Cloudflare to our mailbox at our email provider.
9. This website
passline.app is a set of static pages. It sets no cookies, runs no analytics, loads no fonts or scripts from third parties, and has no forms. It is served by Cloudflare, which keeps standard access logs (time, page, IP address, browser) for a short period for security and capacity. Links to the App Store and to apple.com take you to Apple, whose own policy then applies.
10. Third parties
The only companies that handle anything on our behalf are:
| Who | What they do | What they see |
|---|---|---|
| Apple | App distribution, in-app purchases, iCloud, notifications, ratings | Your Apple Account and purchases, under Apple's own policy |
| Amazon Web Services | Serves question content and receives the anonymous counters | Standard access logs (IP address, path, time, user agent) |
| Cloudflare | Serves this website and forwards email addressed to support@passline.app to our mailbox | Standard access logs; email in transit |
| Our email provider | Stores and lets us answer email you send to support@passline.app | Your email and its contents |
We do not use advertising networks, analytics SDKs, crash-reporting services, attribution services or social plug-ins. We do not sell, rent or share personal data with anyone for their own purposes, and we do not "share" data for cross-context behavioral advertising as that term is used in California law.
11. How long we keep things
- Study data: on your device and in your private iCloud for as long as you keep it. We never hold a copy.
- Server access logs: deleted automatically after 90 days. Aggregate counts derived from them (numbers with no personal data) may be kept.
- Email: kept while your request is open and afterwards as a record of it. Ask us to delete a conversation and we will, unless we must keep it to meet a legal obligation.
12. Your choices and rights
Because we hold no account and no profile, most rights are exercised on your own phone:
- See your data: everything is visible in the app (your history, queue, readiness, settings).
- Delete your data: Settings → Erase all progress, or delete the app. Turn off iCloud for the app to stop syncing.
- Reminders: off in the app's Settings or in iOS Settings.
- Email: write to us to have a conversation deleted or to ask what we hold about you (which, other than email you have sent us, is nothing).
Depending on where you live (for example California, other U.S. states with privacy laws, the United Kingdom or the European Economic Area) you may have rights to access, correct, delete or port personal data, to object to or restrict certain processing, and to complain to a supervisory authority. You can exercise them by email; we will not treat you differently for doing so. We do not sell personal data and we do not use it for targeted advertising, so there is nothing to opt out of.
Where a legal basis is required, ours is: performance of our agreement with you (delivering the app and content updates), our legitimate interest in understanding how the app is used and in keeping it secure (the anonymous counters and server logs), and your consent where you contact us. Our servers are in the United States; if you use the app from elsewhere your requests are handled there.
13. Children
The app is for people preparing for a professional licensing exam and is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has sent us personal data by email, contact us and we will delete it.
14. Security
Data on your device is protected by iOS device encryption and the passcode or biometrics you set. iCloud data is encrypted by Apple in transit and at rest. Connections to our servers use HTTPS. Content updates are signed, and the app refuses any update whose signature does not verify. Because we hold so little, there is little to lose; we still take reasonable steps to keep what we do hold (support email, server logs) secure and limited.
15. Changes to this policy
If we change what the app or the site does with data, we will update this page and its effective date. If a change means the app would start collecting something it does not collect today, we will say so plainly in the app before it happens.
16. Contact
Questions about privacy, or a request under this policy: support@passline.app. Put "Privacy" in the subject and we will answer within 30 days.