passline · NMLS Prep

Privacy Policy

Effective August 29, 2026 · Applies to the NMLS Prep app for iOS and to passline.app

The short version

1. Who we are

NMLS Prep is published by passline ("we", "us"). This policy explains what data the NMLS Prep app for iOS (the "app") and the website at passline.app (the "site") handle, and what we do with it. It is written to be read, not skimmed past; it is also short because we handle very little.

2. No account, no sign-in

The app has no accounts. You do not register, sign in, or give us an email address to use it. We do not know who you are, and we have no profile of you anywhere.

3. Data stored on your device

Everything the app records about your study lives in the app's own database on your phone:

None of this is sent to us. You can erase all of it at any time with Settings → Erase all progress in the app, or by deleting the app.

4. iCloud sync

Some versions of the app keep the same data in your private iCloud database as well, so it follows you to a new phone. The app shows this in Settings under "Storage" ("Synced with iCloud"). This uses Apple's CloudKit service: the data is stored under your Apple Account, encrypted by Apple, and is not visible to us. We have no key to it and no way to read it.

Apple's handling of iCloud data is described in the Apple Privacy Policy. You can turn iCloud off for the app in iOS Settings → your name → iCloud → Apps Using iCloud. "Erase all progress" also removes the iCloud copy when sync is on.

5. Purchases

90-Day Access and Lifetime Access are sold through Apple's App Store as in-app purchases. Apple processes the payment; we never receive your name, address or payment details. The app checks your purchase with Apple on the device to decide whether access is active. "Restore purchases" asks Apple to re-send that record to your device. We do not run our own purchase server.

Refunds are handled by Apple under Apple's terms (reportaproblem.apple.com). We can see anonymous sales totals in App Store Connect; those figures are not tied to any person we can identify.

6. Requests the app makes to our servers

The app works offline. When it is online it makes two kinds of request to our content server, which runs on Amazon Web Services (Amazon S3 and CloudFront):

Content updates

At most once an hour the app asks whether a newer, verified set of questions exists. The request contains no identifier: only the version tag of the content it already has, so the server can answer "nothing new". If there is an update, the app downloads it. We use this so that a corrected question reaches you without an App Store release.

Anonymous counters

At a handful of moments (the check was started or finished, a result page was shown, a purchase was completed, a session or mock exam was finished, a regulation source was opened) the app sends a request whose whole content is the name of that moment, for example diagnostic-finished. There is no device identifier, no user identifier, no cookie, no session id and no other property. We count these requests to learn how many people reach each step of the app. Two events from the same person cannot be linked to each other, and none can be linked to you.

What the server logs record

Like any web server, CloudFront writes an access log for each request: the time, the path requested, the IP address the request came from, and the device's user-agent string (roughly, "iPhone, iOS 26"). We use these logs for the counts above and to detect abuse. We do not combine them with any other data, and we do not use them to identify you. They are deleted automatically after 90 days.

The counters are switched off entirely in test builds, and the app sends nothing at all to us while it is offline.

7. Reminders and notifications

If you turn on the daily reminder, the app schedules local notifications on your phone. They are created and delivered by iOS on the device; no server is involved, and we do not use push notifications. The app asks iOS for notification permission the first time you turn the reminder on. You can change this at any time in the app's Settings or in iOS Settings → Notifications.

8. Email and question reports

Contacting us is by email, at support@passline.app. When you report a question from inside the app, the app opens a draft in your mail app addressed to us. The draft contains the question's id, the category you picked (wrong answer, unclear, rule changed, typo, other) and anything you type. Nothing is sent until you send it, and you can edit the draft first.

When you email us we receive your email address, the message, and whatever your mail app adds. We use this only to answer you and to fix the app or a question. Email to support@passline.app is forwarded by Cloudflare to our mailbox at our email provider.

9. This website

passline.app is a set of static pages. It sets no cookies, runs no analytics, loads no fonts or scripts from third parties, and has no forms. It is served by Cloudflare, which keeps standard access logs (time, page, IP address, browser) for a short period for security and capacity. Links to the App Store and to apple.com take you to Apple, whose own policy then applies.

10. Third parties

The only companies that handle anything on our behalf are:

WhoWhat they doWhat they see
AppleApp distribution, in-app purchases, iCloud, notifications, ratingsYour Apple Account and purchases, under Apple's own policy
Amazon Web ServicesServes question content and receives the anonymous countersStandard access logs (IP address, path, time, user agent)
CloudflareServes this website and forwards email addressed to support@passline.app to our mailboxStandard access logs; email in transit
Our email providerStores and lets us answer email you send to support@passline.appYour email and its contents

We do not use advertising networks, analytics SDKs, crash-reporting services, attribution services or social plug-ins. We do not sell, rent or share personal data with anyone for their own purposes, and we do not "share" data for cross-context behavioral advertising as that term is used in California law.

11. How long we keep things

12. Your choices and rights

Because we hold no account and no profile, most rights are exercised on your own phone:

Depending on where you live (for example California, other U.S. states with privacy laws, the United Kingdom or the European Economic Area) you may have rights to access, correct, delete or port personal data, to object to or restrict certain processing, and to complain to a supervisory authority. You can exercise them by email; we will not treat you differently for doing so. We do not sell personal data and we do not use it for targeted advertising, so there is nothing to opt out of.

Where a legal basis is required, ours is: performance of our agreement with you (delivering the app and content updates), our legitimate interest in understanding how the app is used and in keeping it secure (the anonymous counters and server logs), and your consent where you contact us. Our servers are in the United States; if you use the app from elsewhere your requests are handled there.

13. Children

The app is for people preparing for a professional licensing exam and is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has sent us personal data by email, contact us and we will delete it.

14. Security

Data on your device is protected by iOS device encryption and the passcode or biometrics you set. iCloud data is encrypted by Apple in transit and at rest. Connections to our servers use HTTPS. Content updates are signed, and the app refuses any update whose signature does not verify. Because we hold so little, there is little to lose; we still take reasonable steps to keep what we do hold (support email, server logs) secure and limited.

15. Changes to this policy

If we change what the app or the site does with data, we will update this page and its effective date. If a change means the app would start collecting something it does not collect today, we will say so plainly in the app before it happens.

16. Contact

Questions about privacy, or a request under this policy: support@passline.app. Put "Privacy" in the subject and we will answer within 30 days.