🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
DrivePilot

DrivePilot Privacy Policy

How DrivePilot protects local teaching records and handles optional sync, recovery and sharing.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Local source of truth The on-device database is encrypted and remains usable offline
Connected features Sync and encrypted Drive recovery are optional Premium tools
Shared links Treat every lesson-summary or invoice link as confidential
Privacy requests [email protected]
On this page
  1. Overview
  2. Data we handle
  3. How we use data
  4. Sharing and processors
  5. Storage and residency
  6. Cloud and backups
  7. Public links
  8. Retention
  9. Security
  10. Your rights
  11. Children and minors
  12. International transfers
  13. Changes
  14. Contact

This policy explains DrivePilot's local-first workspace, connected services, public links and the choices available to instructors and other affected people.

Overview

Blue Sparrow is a solo developer based in India and operates DrivePilot for independent driving instructors and small driving schools. This policy explains what the mobile app, optional connected services, enquiry pages and tokenized sharing pages handle, how the information is used and the choices available to you. DrivePilot follows data-minimisation, purpose-limitation, transparency and rights principles supported by the EU General Data Protection Regulation and other applicable privacy rules.

DrivePilot is local-first, not exclusively offline. Its encrypted on-device database is the source of truth. Google sign-in, workspace synchronization, push messages, public enquiries, hosted lesson summaries and invoices, support, purchases, updates and optional Google Drive recovery use the connections described below.

Instructors generally decide why and how learner, guardian and business records are entered and shared. For those records, the instructor or driving school is normally the relevant organisation responsible for appropriate notices, permissions, accuracy and recipient choices. Blue Sparrow handles connected copies as a service provider for that instructor while separately deciding how account, security, purchase and support information is handled.

Data we handle

Depending on the features you use, DrivePilot may handle:

  • Instructor and workspace details such as Firebase identifier, Google account email, display name, business name, business contact fields, service area, currency, tax settings, branding and preferences.
  • Learner and guardian records such as name, contact information, pickup details, availability, transmission preference, experience level and notes entered by the instructor.
  • Teaching records such as schedules, attendance, lesson duration, private notes, learner-facing summaries, next focus, skill ratings and package balances.
  • Billing records such as quotes, invoice lines, prices, taxes, status, payment method labels, external payment instructions, PDFs and hosted-invoice metadata. DrivePilot does not receive learner payment-card credentials or bank-login details.
  • Files and images the instructor chooses to attach or import, and CSV, JSON or PDF files the instructor asks DrivePilot to create.
  • Public enquiry information deliberately submitted by a prospective learner, including name, optional email or phone, contact preference, postcode, preferred times, transmission, experience level and optional note. The service may temporarily use the requesting IP address for rate limiting and security.
  • Tokenized lesson-summary activity, including link state, expiry, views, acknowledgement timestamps and the browser user-agent recorded with summary events. Hosted-invoice activity can include link, file and download-event metadata.
  • Device and service information such as device identifier and name, platform, app version, Firebase Cloud Messaging token, authentication and request identifiers, synchronization state, service logs and security events.
  • Google Play and RevenueCat purchase information such as product, receipt, transaction, subscription and entitlement status. Blue Sparrow does not receive full payment-card details.
  • Support or email information you choose to submit, including contact details, message content, attachments and delivery metadata.

DrivePilot does not need precise device location, contact-book access, SMS content, call history, microphone recordings or advertising identifiers for its current features. It does not sell personal information or build a cross-app advertising profile. Image import occurs only when you choose a supported file or image action.

How we use data

Information is used only as reasonably necessary to:

  • Provide learners, lessons, schedules, skill tracking, packages, invoices, exports and instructor settings.
  • Authenticate an account, manage a workspace and synchronize supported records across authorized devices when connected access is enabled.
  • Create encrypted recovery checkpoints or restore one when the instructor requests it.
  • Publish, display, acknowledge, revoke and expire selected lesson summaries and hosted invoices.
  • Receive public enquiries and notify the relevant instructor workspace.
  • Deliver optional push messages and operational email.
  • Process purchases, restore entitlements and enforce the access level associated with the offer.
  • Answer support requests, diagnose failures, prevent abuse, rate limit public endpoints and protect the service.
  • Meet applicable privacy, consumer, accounting and operational requirements.

DrivePilot does not sell or rent personal information and does not use it for targeted advertising. Firebase Analytics is not included in the current app. Firebase Crashlytics collection is disabled by default and can run only in a non-debug build where the release configuration explicitly enables it; if enabled, limited crash, device and diagnostic information is sent to Firebase to investigate reliability problems.

Sharing and processors

Blue Sparrow does not disclose instructor or learner information for independent advertising. Limited information may be processed by:

  • Google and Firebase for Google sign-in, Firebase Authentication, push-message transport, optional Crashlytics diagnostics, Google Drive recovery, Google Play distribution and billing.
  • Blue Sparrow's DrivePilot API and infrastructure providers for optional workspace synchronization, public enquiries, hosted summaries and invoices, service security and account-deletion requests.
  • The Blue Sparrow notification gateway and Firebase Cloud Messaging for workspace notifications and sync nudges that are enabled.
  • RevenueCat and Google Play for purchases, receipts, renewal, cancellation and entitlement delivery.
  • Blue Sparrow mail and support delivery services when an instructor sends support or invoice email.
  • The operating system and applications selected when an instructor saves, opens, prints or shares an attachment, invoice, report or export.

These third-party providers process limited information under their own terms, controls and privacy notices. Blue Sparrow may also make a limited disclosure where required by applicable rules or reasonably needed to address fraud, abuse or a serious security threat.

Storage and residency

Core workspace records are held in an encrypted SQLite database on the instructor's device. Optional synchronized records, hosted files, enquiries and link events are handled by the DrivePilot API. Blue Sparrow-controlled synchronized DrivePilot content is intended to remain in European Union infrastructure, subject to verification of the production datacentre, backups, retention workers and operational configuration. This is a qualified infrastructure commitment, not a claim that every DrivePilot-related datum stays exclusively in the EU.

Google, Firebase, RevenueCat, Google Play, notification, mail, support and user-selected file services can process limited information in other regions under their own infrastructure and transfer arrangements. Blue Sparrow support access may occur from India when needed to answer a request or operate the service.

Cloud and backups

Cloud workspace synchronization is optional and requires an eligible signed-in plan. It can include learner and guardian details, pickup information, lessons, private and learner-facing notes, skills, packages, invoices, payment instructions, enquiries, attachments, preferences, workspace settings and audit information. Local records remain the app's working source of truth while supported changes synchronize with the API.

Google Drive recovery is a separate optional feature. DrivePilot requests access only to its hidden Drive app-data area, not general access to visible Drive files. A checkpoint contains an encrypted physical copy of the local database and an encrypted manifest. DrivePilot creates a separate random backup master key, protects recovery access with a passphrase-derived key and verifies an uploaded checkpoint before publishing it. The recovery passphrase is not sent to Blue Sparrow or Google.

Drive stores opaque encrypted checkpoint objects, but Google controls their physical region and infrastructure. DrivePilot attempts to retain the newest three checkpoints, up to eight weekly checkpoints and up to twelve monthly checkpoints. Cleanup is best effort, so an older object may remain until a later successful cleanup or explicit deletion. Protect the recovery passphrase; Blue Sparrow cannot reconstruct it for you.

Exports, attachments and PDFs saved or shared through the device become ordinary user-controlled files. The chosen destination and recipient control their copy, and deleting DrivePilot cannot retrieve a file already sent elsewhere.

Public links

DrivePilot can create high-entropy tokenized links for lesson summaries and hosted invoices. Lesson-summary pages can display the learner's first name, lesson date and duration, the selected summary and next focus, and can accept an acknowledgement. Hosted-invoice pages can display invoice file information and provide the PDF. Anyone who receives a working URL can access its selected content until it expires or is revoked, so instructors must verify recipients and avoid sharing more than needed.

Token values are stored as hashes on the service. Tokenized lesson-summary and hosted-invoice pages instruct search engines not to index or follow them, but this does not replace careful sharing. A lesson-summary link expires after seven days by default unless configured otherwise and can be revoked. Expired or revoked lesson-summary records and their events are intended to be removed by a retention process; production operation of that process remains subject to verification. Hosted invoice expiry and revocation depend on the options used when the link is created.

Public enquiry pages are designed for prospective learners to find and contact an instructor. Information submitted there becomes an enquiry record in the instructor's connected workspace. Do not submit unnecessary sensitive information in the free-text note.

Retention

Local records remain until the instructor deletes them, completes the local deletion flow, clears app storage or uninstalls in a way that removes app data. Exports and recipient copies have independent lifecycles. Optional Drive checkpoints follow the rolling, best-effort schedule described above and remain in the authorized Google account until cleanup or successful explicit deletion.

Connected workspace, enquiry, hosted-file, public-link, mail, notification, purchase, security and support information is retained while reasonably needed for the relevant feature, service integrity, applicable records or a verified deletion process. No fixed production period is promised where the live cleanup evidence has not been verified. Google Play, RevenueCat, Firebase, Google Drive and other provider records also follow provider controls and applicable requirements.

The in-app account-and-data action first attempts to delete Drive recovery objects, then sends an account-deletion request to the DrivePilot API and removes the local database, recovery profile, archive binding and device key after the required steps succeed. The current API records the request and revokes lesson-summary links; the audited implementation does not establish that all synchronized workspace records, hosted invoice links or files, Firebase Authentication records, mail records or shared-workspace content are immediately erased. Email [email protected] to follow up on connected-service deletion. Deleting data or signing out does not cancel a Google Play subscription; cancel it separately through Google Play.

Security

DrivePilot uses proportionate safeguards including an encrypted local database, a random device key, biometric access where enabled, disabled Android backup, HTTPS, authenticated API requests, encrypted push-token storage, high-entropy public-link tokens stored as hashes, scoped Drive access, encrypted recovery checkpoints and server access controls. Uploaded checkpoints are read back and verified before publication.

Protect the device, Google account, recovery passphrase, public URLs, external payment instructions and exported files. Remove access for a lost device and revoke a shared link when appropriate. No device, transmission, passphrase or connected service can be guaranteed completely secure.

Your rights

Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, receive a portable copy, delete it, restrict or object to processing, and withdraw consent where consent is the basis. You may also have a right to contact your local data-protection authority. These protections include, where applicable, the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy rules, Brazil's LGPD, Canada's privacy rules and comparable requirements elsewhere.

Instructors can edit records, control notifications, revoke supported links, export information, manage Drive recovery and start account deletion in the app. Learners and other people whose information was entered by an instructor should normally contact that instructor first; Blue Sparrow will assist a verified instructor or respond directly where required.

Email [email protected] with DrivePilot in the subject and enough detail to identify the relevant account or request. Blue Sparrow may request proportionate verification and will respond within the period required where you live. Provider-held copies or subscriptions may also need to be managed through Google Play, Google Drive or the relevant provider account.

Children and minors

DrivePilot is intended for professional instructors and is not directed to children as account operators. An instructor may record a minor learner's details, optional guardian contact, pickup information and teaching progress. The instructor is responsible for the notice, permission or other valid basis required where the learner lives, for collecting only information needed for instruction and for sharing summaries only with an appropriate recipient.

DrivePilot does not invite children to create learner accounts. Public lesson summaries can show a learner's first name and selected progress content to anyone holding the link. Use extra care for a minor, confirm the recipient and revoke a link when it is no longer needed. Contact [email protected] if you believe a child's information has been provided or shared inappropriately.

International transfers

Blue Sparrow-controlled synchronized content is intended for EU infrastructure subject to the production verification described above. Google, Firebase, RevenueCat, Google Play, notification, Drive, mail, support and user-selected file providers may process limited information outside the instructor's, learner's or recipient's country.

Where safeguards are required for an international transfer, Blue Sparrow and relevant providers rely on appropriate contractual, adequacy or other lawful mechanisms and apply data-minimisation and security measures. EU users retain the protections required by the EU GDPR when a necessary provider connection crosses a regional boundary.

Changes

This policy may change when DrivePilot, its providers or applicable requirements change. Material updates will be presented in the app or at https://bluesparrow.dev where appropriate, and the updated date will be revised. Earlier handling remains subject to the version applicable at that time unless a change must apply sooner for security or compliance.

Contact

Blue Sparrow is the developer and privacy contact for DrivePilot. For privacy questions, rights requests or account-deletion follow-up, email [email protected]. For general help, email [email protected]. Product and policy information is available at https://bluesparrow.dev.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.