Copilote is an iOS app that records your practice drives and helps you fill in your road book: it counts your drives and your kilometres, and gives you a summary of them to attach to it. To do that, it needs to know a little about you, and it needs to follow your position while you drive.
This page explains exactly what data we take, why, who it goes to, how long we keep it, and how to erase all of it. It is written to be read rather than skimmed: no jargon, and a whole section (6a) about the one data transfer we are still not happy about.
1. Who is responsible for your data
The "controller" — the GDPR term for the person who decides what happens to your data — is:
Antoine Vaessen, trading as CopiloteBelgium
Email: antoinevaessen@icloud.com
Email is the fastest way to reach us, and it is the channel we actually watch. If you would rather write to us by post, ask us for the postal address by email and we will give it to you.
Copilote is a one-person project, not a large group. There is no data protection officer: the law does not require one in our case, and writing to the address above means writing directly to the person who builds and runs the app.
2. The short version
- Copilote records your practice drives to build the trip summary you attach to your road book.
- To do that we need your GPS position — including when the app is in the background, because your phone sits in a mount while you drive.
- Your data lives in two places: on your phone, and on a server in Stockholm, Sweden, so inside the European Union.
- We sell nothing, we run no advertising, and we do not track you from app to app.
- You can delete your account from inside the app, in two taps. All of it goes.
- One exception we are not going to dress up: during guided practice routes, your position is sent to a free public routing server we have no contract with. The full story is here.
TABLE OF CONTENTS
- Who is responsible for your data
- The short version
- What we collect, why, and on what legal basis
- Location, and the two permissions we ask for
- Where your data is stored
- Who else receives your data
- Does your data leave the European Union?
- How long we keep things
- Your rights
- Deleting your account
- Minimum age
- If you are an accompanying driver
- Changes to this policy
- Contacting us
3. What we collect, why, and on what legal basis
The GDPR requires us to tell you, for each kind of data, why we process it and which "legal basis" we rely on. We do it category by category, because a blanket answer like "to provide and improve our services" would tell you nothing.
Three legal bases come up in this section:
- Contract (GDPR Article 6(1)(b)) — without this data, the app cannot do what you are asking it to do.
- Legitimate interest (Article 6(1)(f)) — useful for running and fixing the app, without overriding your rights. You can object to it.
- Legal obligation (Article 6(1)(c)) — where the law requires us to keep something.
Your account
What we have: your email address and your password. The password is stored as a hash by Supabase Auth — we never see it and cannot tell you what it is. If you use Sign in with Apple: your name and whichever address Apple passes on, whether that is your real address or a private relay. We also keep your first name, last name, date of birth, and session tokens to keep you signed in.
Why: to create your account, to sign you back in, and to put your name and date of birth at the top of your trip summary.
Legal basis: contract.
Your profile and preferences
What we have: your language, your light or dark theme, the avatar you picked, and consistency counters (current streak, best streak, last active week).
Why: to show the app the way you set it up, and to show you whether you are driving regularly.
Legal basis: contract.
Note: the avatar is a number pointing at a drawing that ships with the app. We store no photo of you, and the app never asks for access to your photos.
Your licence and exam context
What we have: your licence route and licence date, your region, and your exam centre.
Why: what your road book needs to contain, and which practice routes we offer, depend on your region and your centre.
Legal basis: contract.
Your accompanying drivers
What we have: for each accompanying driver you add — their first name, last name, and, if you choose to fill them in, their licence number, their relationship to you, their phone number, and an appointment date.
Why: your road book has to record who was with you on each drive.
Legal basis: contract, as far as you are concerned. For the accompanying driver themselves, who has not installed the app and has signed nothing: our legitimate interest and yours in being able to keep this road book. It is reasonable for a road book to contain the name of the person sitting next to you.
Important: this information is about someone other than you. The licence number and phone number are optional — only fill them in if you actually need them. If you are an accompanying driver reading this, section 12 is for you.
Your drives
What we have: the date, start and end time, duration, distance, odometer reading at departure and arrival, departure and arrival location, whether it was a round trip, road types, weather, traffic density, light conditions, the manoeuvres you performed, and your free-text fields: "notes", "difficulties", and, if you are in Brussels, "traffic conditions". For practice routes we also keep the circuit number and the points you reached.
Why: this is the content of your trip summary. It is what the app exists for.
Legal basis: contract.
About the free-text fields: "notes", "difficulties" and "traffic conditions" are open text boxes, and whatever you write goes in as-is. Avoid putting sensitive information there — health, opinions, or details about other people. The app does not need it, and we do not read it, but it would be stored like everything else.
Your GPS routes
What we have: the full path of each recorded drive, as a polyline — that is, the sequence of points you passed through, from start to finish.
Why: to calculate your distance automatically, fill in your departure and arrival locations, and show the map of your drive.
Legal basis: contract — this is the app's core function, the one you installed it for.
Note: a GPS trace is sensitive in practice, even though the GDPR does not put it in its "special categories". It reveals where you live, where you go, and at what time. That is why it stays on your phone and in our database in Sweden, and why it goes to no advertiser and no data broker. The single exception is described in section 6a.
Your self-assessments
What we have: the rating you give yourself per skill area, and the date you last updated it.
Why: to show you your progress and what still needs work.
Legal basis: contract.
The edit history
What we have: a record of changes to your drives — which drive, when, and which fields changed.
Why: to let your phone and the server sync without losing or duplicating a correction, and to be able to trace what changed when a figure does not add up.
Legal basis: legitimate interest — the reliability of your trip summary.
What it does not keep: the contents of your free-text fields. If you edit your "notes", your "difficulties" or your "traffic conditions", the history records that the field changed and when, but not what it said: the value is replaced with "[redacted]". Times, distances, dates and the accompanying driver are kept as they were — those are precisely what makes it possible to check that a trip summary adds up. A useful consequence for you: if you delete a drive, no free text about it survives in this history. Note though that replacing is not deleting. The history rows themselves exist until you delete your account.
Your purchases
What we have: the product identifier you bought, the App Store transaction identifier, the store, the grant, expiry and any revocation dates, and the raw signed receipt Apple passes to us.
Why: to unlock what you paid for, on all your devices, and to handle a refund or cancellation properly.
Legal basis: contract.
What we do not have: your card number. Apple takes the payment. We never see your payment methods, and could not see them even if we wanted to.
Crash diagnostics
What we have: when the app crashes, a report is sent to Sentry. It contains your device model, iOS version, app version, the technical trace of the error, and your account's UUID. We also collect performance measurements on roughly 10% of sessions.
Why: to fix bugs, and to know whether a crash affects one person or a thousand.
Legal basis: legitimate interest. You can object by writing to us.
What is stripped before sending: Sentry is configured not to collect personal information by default, and a filter actively removes, before anything leaves your phone: email addresses, authentication tokens, purchase transaction identifiers, and GPS coordinates. That filter applies to errors, to the trail of events leading up to them, and to performance measurements; if it fails, it drops the whole event rather than risk letting something through. Crashes reach us at 100%, performance measurements at 10%.
4. Location, and the two permissions we ask for
Copilote asks for two levels of location permission, and it is fair to wonder why:
- "While using the app" — to start a recording and show your position on the map while you are looking at the screen.
- "Always", meaning in the background — because while you are driving, your phone is in a mount, screen off or another app open. Without this permission, recording stops the moment you leave the app, and your distance is wrong. That is the only reason we ask for it.
You can refuse these permissions, or withdraw them later in Settings > Privacy & Security > Location Services. The app keeps working: you simply enter your drives by hand, as you would on paper.
We use your location for nothing else. No advertising, no profiling, no sharing with any ad network.
5. Where your data is stored
In two places, kept in sync with each other:
- On your phone, in a local database. That is what lets the app work in the car, with no network.
- With Supabase, which hosts our database, our account system and our server functions, on servers in Stockholm, Sweden (region
eu-north-1) — so inside the European Union.
Supabase itself runs that infrastructure on Amazon Web Services: AWS is the physical host of those Swedish servers — that is what the code eu-north-1 refers to — and not a service we send anything to ourselves. We hold no AWS account and pass it no data directly.
If you delete your account, both copies are erased.
6. Who else receives your data
We do not sell your data and we share none of it for advertising. This is the complete list of third parties that receive any of it, and exactly what each one gets:
- Supabase — database, accounts, and server functions. Receives everything described in section 3. Servers in Sweden.
- Apple — Sign in with Apple, if you use it, and in-app purchases, including receipt validation. Receives what those two functions need, and nothing more.
- Resend — sending service emails only: signup confirmation and password reset. Receives your email address. The sender is
no-reply@co-pilote.eu. No newsletter, no marketing. - Sentry — the crash and performance diagnostics, on the terms in section 3, filtering included. Servers in Frankfurt, Germany.
- Expo — over-the-air app updates. On each update check, receives technical information about your device and the installed version. No drive data.
- Open-Meteo — the weather for your drive. Receives a coordinate deliberately rounded to 2 decimal places, about 1.1 km of precision, plus a timestamp. No identifier, name or account number is attached: the request cannot show that it was you.
- FOSSGIS e.V. — route lookup during guided practice routes. That transfer deserves its own section, immediately below.
Worth stating, because this is exactly the kind of detail that leaks unnoticed: the PDF export of your trip summary is generated entirely on your phone, with no network request at all. The file passes through neither our servers nor anyone else's, and the handwriting font it uses is bundled into the app.
6a. A transfer we would rather be blunt about
When you use the guided practice route feature, the app has to calculate a route along real roads. To do that, it sends your current position to router.project-osrm.org, a free public demo server run by FOSSGIS e.V., a German non-profit association.
Concretely:
- It is sent roughly every 30 seconds, for as long as the practice session lasts.
- Your position is rounded to 4 decimal places, about 11 metres, before it leaves your phone. Route calculation cannot work with less: below that, the server risks placing you on a service road instead of the right street.
- No account identifier, name, email or number is attached to the request.
- Because FOSSGIS e.V. is established in Germany, this data stays inside the European Union.
And now the part we are not going to spin:
- This is a free public service. We have no contract and no data processing agreement with FOSSGIS e.V. So we cannot tell you what they keep, or for how long, or promise you that they protect this data the way we commit to. Writing otherwise would be false, and plenty of privacy policies write it anyway.
- A point rounded to 11 metres, sent every 30 seconds across a whole practice session, is still a trace of your movements. Rounding reduces the precision of each point; it does not make the path go away.
- Of everything in this policy, this is the transfer we like least. We are looking to replace it, either with a server we host ourselves or with a provider we hold a real contract with.
In the meantime, you stay in control: guided practice routes are the only feature in the app that contacts this server. If you do not want this data leaving your phone, do not use them. Recording your drives, calculating your distances and your trip summary all work fully without it.
7. Does your data leave the European Union?
Partly, and here is exactly what:
- Stays in the EU: Supabase, where your account and all your drives live, on Swedish servers. Sentry, on its German region, in Frankfurt. And FOSSGIS e.V., in Germany.
- Leaves the EU: Apple, Resend and Expo are established in the United States. For those transfers we rely on the safeguards in their standard service terms — the European Commission's Standard Contractual Clauses, or their certification under the EU–US Data Privacy Framework, depending on the provider. Write to us if you want the detail for a specific one.
- Open-Meteo receives a rounded coordinate with no identifier attached. In practice there is no personal data to transfer.
- FOSSGIS e.V. is the only recipient we hold no agreement with, and the only one we can promise you nothing about. It stays inside the EU. See section 6a.
8. How long we keep things
- Your account, profile, accompanying drivers, drives, GPS routes, manoeuvres, self-assessments and edit history — as long as your account exists. Erased the moment you delete it.
- Our backups — there are none. Our hosting keeps no automatic database backups, so once something is deleted it survives nowhere on our side. A deletion is immediate and permanent, with no copy left sitting around.
- Your purchases — erased with your account. Apple is the seller of record: the accounting records Belgian law requires us to keep for 7 years are Apple's payout statements, which do not identify you individually.
- Diagnostics at Sentry — 90 days, then deleted automatically.
- Service emails at Resend — for as long as it takes to send them and diagnose a failure, then according to Resend's own retention period.
9. Your rights
The GDPR gives you the rights below. Exercising them is free, and you do not have to justify yourself.
- Access — get a copy of everything we hold about you.
- Rectification — have anything wrong corrected. Most fields you can edit directly in the app.
- Erasure — have your data deleted. The delete-account button in the app does exactly that, without going through us.
- Restriction — ask us to stop processing your data without deleting it.
- Portability — receive your data in a reusable format, to take it elsewhere.
- Objection — object to the processing based on our legitimate interest, meaning the diagnostics, the edit history, and the recording of your accompanying drivers.
- Complaint — go to the supervisory authority if you believe we are processing your data unlawfully. In Belgium that is the Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels — dataprotectionauthority.be. If you live in another EU country, you can go to your own country's authority.
To exercise one of these rights, write to us at the address in section 14. We reply within one month, as the GDPR requires. If your request is complex and we need longer, we will tell you before that month is up.
10. Deleting your account
In the app: Profile > Delete my account. No need to write to us, no form, no waiting period.
What that erases, immediately and permanently:
- your account and your sign-in credentials;
- your profile: name, date of birth, licence, region, exam centre, preferences, consistency counters;
- all your accompanying drivers, including their licence and phone numbers if you had filled them in;
- all your drives, with their GPS routes, manoeuvres, notes and free-text fields;
- your self-assessments;
- the edit history;
- your purchase entitlements;
- the local copy on your phone.
If you signed up with Sign in with Apple, we also call Apple's revocation endpoint to cut the link between your Apple account and Copilote, before the erasure runs.
What lingers briefly, for completeness: diagnostics already sent to Sentry, up to 90 days. Those contain neither your email address nor your GPS coordinates, which are filtered out before sending. There is no database backup your data could resurface from later.
Any PDFs you have already exported and saved are on your device, or wherever you sent them. They are yours, and we have no way to delete them remotely.
11. Minimum age
You need to be 16 to create a Copilote account.
This is not about content: there is nothing shocking in the app. It is about law. The data processed here, a GPS trace in particular, is too sensitive for us to rely on a child's agreement alone, and 16 is the highest threshold the GDPR allows a member state to set for this kind of consent. If you are under 16, a parent or guardian needs to create and manage the account.
If we learn that an account was created by someone under 16 without that agreement, we delete it.
12. If you are an accompanying driver and your name is in someone's road book
This section is for you if you do not use Copilote, but a learner driver has added you as an accompanying driver. You have the same rights they do, even though you never installed the app.
What may be stored about you: your first name, your last name, and, if the learner filled them in, your licence number, your relationship to them, your phone number and an appointment date. We have nothing else: no email address, no location, no account in your name.
Why: a road book has to record who accompanied the learner on each drive. Legal basis: our legitimate interest and the learner's in being able to keep that road book.
How to object or have yourself removed: the fastest route is usually to ask the learner to remove you from their accompanying drivers — they can do it themselves in the app, in seconds. But you do not have to go through them: write to us at the address in section 14 and we will handle it. We will ask you to help us find the entry about you, for instance with the learner's name, because we have no other way to look you up.
13. Changes to this policy
We will update this page when the app changes. The date at the top tells you which version is current.
For an important change — a new category of data, a new recipient, or the replacement of the routing service in section 6a — we will tell you in the app or by email, not just quietly edit this page.
The French, Dutch and English versions of this policy carry equal weight.
14. Contacting us
For a question, to exercise one of your rights, or to report a privacy problem, write to antoinevaessen@icloud.com.
A person reads those messages, not a department. If your request is about your GDPR rights, say so in the subject line so it gets handled within the deadline.