Theorio

Privacy Notice

Effective date: 15 August 2026

Last updated: 15 August 2026

The official language of this notice is English. Translations, if provided, are for convenience only.

1. Summary

Theorio is a study service for the UK driving theory test, operated by Arda Future Limited. This notice explains what personal information we collect, why we use it, who we share it with, how long we keep it, and what rights you have.

We are the data controller for the personal information we process about you. We comply with the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

In short: we use your information to run your account and adapt your practice, we do not sell it, we do not run advertising tracking, and we do not currently send marketing emails. If we ever do, it will only be because you asked us to.

2. Who we are and how to contact us

Theorio is operated by Arda Future Limited, a company registered in England and Wales. Arda Future Limited is the data controller.

Data controller: Arda Future Limited
UK Company Number: 17133300
Registered office: 24 Bishops Close, Richmond, London TW10 7DF, United Kingdom
Privacy contact: info@theorio.co.uk

3. Information we collect

We collect and use the following categories of information:

Account information

Your email address, display name, and password. Passwords are hashed by our authentication provider (Supabase) and are never stored or accessible to us in plain text. We also record whether your email address has been confirmed.

Profile and preferences

Preferred language, country of origin (optional), planned exam date (optional), and your preference for service emails. Used to run and personalise the service.

Learning information

Your answers to practice questions, diagnostic test results, topic-level performance scores, hazard perception attempts (including the timing of your clicks during a clip), and your progress through the learning journey. Used to adapt the difficulty and topic mix of your practice.

AI study summary

A study coach summary generated for you after a mock test is stored against your account so it does not have to be regenerated each time you visit.

Subscription information

If you subscribe to a paid plan, we store your plan, the dates it started and runs to, whether the subscription is currently active or a payment has failed, and the customer and subscription identifiers issued to us by Stripe. Payment itself happens on Stripe's own hosted pages: we do not receive or store your full card number, security code, or bank details.

When a payment succeeds, we also keep a short payment record containing the amount, the currency, the time Stripe confirmed the payment, and an opaque reference we generate ourselves for that payment. That reference is not derived from your identity or from any Stripe identifier. We keep this record to run and support your subscription, for accounting and fraud prevention, and — only if you have accepted analytics cookies — to count completed purchases in aggregate. The record itself is a financial and operational record: we keep it whether or not you accept analytics cookies. What consent controls is whether anything is sent to Google Analytics.

Email delivery information

To send you service emails we pass your email address, the subject and body of the message, and any account context the message needs (such as your display name) to our email provider.

Technical and error information

When something goes wrong, a technical record — such as the error message, a stack trace, the page path, and general browser and operating system information — is sent to our error-monitoring provider. Our servers also keep standard web access records containing your IP address, browser user-agent, the address requested, and a timestamp. We do not use fingerprinting or behavioural tracking for advertising.

Analytics information

If — and only if — you accept analytics cookies, Google Analytics collects usage information about how the site is used. See section 7.

Messages you send us

If you email us for support or to exercise a right, we hold that correspondence and anything you include in it.

4. Why we use information, and our legal bases

Under UK GDPR Article 6, we rely on the following legal bases:

  • Contract (Art. 6(1)(b)) — to create and run your account, provide the practice questions and adaptive learning features, send the service emails described in section 5, and provide and bill a paid subscription if you choose one.
  • Legitimate interest (Art. 6(1)(f)) — to detect and diagnose errors, to keep the service and our servers secure, to prevent fraud and abuse, and to understand and improve how the service works. We balance this against your interests, and you can object (see section 11).
  • Consent (Art. 6(1)(a)) — for optional analytics cookies, and — if we ever introduce them — for optional marketing emails. You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — to keep the records we are required to keep, for example for tax and accounting purposes, and to respond to lawful requests.

5. Service emails

Service emails are the messages we have to send so that your account works. They are not marketing. We send them on the basis of our contract with you, and you cannot opt out of them while you have an account — but you can close your account.

  • confirming your email address when you register;
  • resetting your password when you ask us to;
  • a welcome message when your account is set up;
  • a reminder if your email address has not been confirmed;
  • telling you if a subscription payment has failed, so you can fix it.

6. Optional marketing emails

Theorio does not currently send optional marketing emails.

We are describing this here so you know in advance what would happen if we introduce them. If we do:

  • We would only send them to people who have actively opted in by ticking an unticked box or turning on a setting. Silence is never consent.
  • We would not rely on the “soft opt-in” exception for existing customers, even though the law allows it in some cases.
  • Having an account, having a subscription, practising questions, or completing the 28-question check is not consent to marketing, and we would never treat it as such. Your setting for service emails is not marketing consent either.
  • If we hold no record that you opted in, we treat that as no. We would never add existing users to a marketing list by default.
  • You could withdraw your consent at any time, and it would be as easy to withdraw as it was to give.
  • Every marketing email would carry an unsubscribe link that works without signing in — no password, no account needed. The link would stay valid for 90 days.
  • When you unsubscribe, we would keep a minimal do-not-contact record so we can honour your choice — see below.

Do-not-contact records

If you opt out, the safest thing we can do is remember that you opted out. To do that we keep a one-way, keyed fingerprint of your email address rather than the address itself. That fingerprint is pseudonymous, not anonymous: it is still personal information, and this notice and your rights still apply to it. We keep as little as we need to recognise that you asked not to be contacted.

We may also record an address as do-not-contact if messages to it bounce repeatedly or are reported as spam. Those records exist to protect delivery and security and are not removed by opting back in. We would not start sending marketing to you again without a fresh, explicit opt-in from you.

7. Cookies and analytics

We use two categories of cookies:

  • Functional cookies — set by Supabase to keep you logged in. These are necessary for the service to work and are set without consent under the PECR “strictly necessary” exemption.
  • Analytics cookies — set by Google Analytics only after you explicitly accept them. Until you accept, the Google Analytics script is not loaded at all. We use Google’s consent mode: all consent signals start as denied, and accepting analytics cookies grants only analytics_storage. Advertising storage, advertising user data and advertising personalisation are never granted in this app, and we run no advertising tags. We do not use analytics for advertising profiling.

If you accept analytics cookies and you then complete a purchase, a purchase event — the amount, the currency and the opaque reference described in section 3 — is included in what Google Analytics receives from your browser, so that completed purchases can be counted. If you do not accept, nothing about that purchase is sent to Google: there is no server-side route that reports purchases to Google Analytics on your behalf, and none of the analytics consent signals are granted.

You can change or withdraw your choice at any time using the Cookie settings control in the site footer. Withdrawing stops further analytics collection and removes Google Analytics cookies (_ga, _ga_*) from this browser on a best-effort basis. Cookies set by other providers for sign-in or payments are not affected.

Analytics information is kept in line with the retention settings configured in the analytics account, and we review those settings periodically.

8. Service providers and recipients

We use the following providers. Each is engaged under a data processing agreement, and each only receives the information it needs for its part of the service. We do not sell your personal information.

  • Supabase — account authentication and database hosting. Data processing addendum.
  • Stripe — payment processing and subscription management for our paid plans. Checkout and the billing portal are hosted by Stripe, so card details are entered on Stripe’s pages and not on ours. Stripe also acts as a controller in its own right for some purposes, such as fraud prevention and legal compliance. Data processing agreement.
  • Resend — delivery of the service emails listed in section 5. Receives the recipient address, the message, and the account context the message needs. It is not used for marketing. Data processing agreement.
  • Sentry — error and performance monitoring. See section 3 for what a technical record contains, and below for how we reduce what is sent.
  • Anthropic — the Claude large language model, used to generate the study coach summary. The learning context needed to write the summary may be sent. We do not send payment information or marketing preferences to Anthropic.
  • Google Analytics — usage analytics. The Google Analytics script is only loaded after you explicitly accept analytics cookies; before that, no request is made to Google.
  • Hostinger — hosting and infrastructure provider for the servers that run the site. Privacy policy.

How we limit error monitoring

We do not use session recording or replay of any kind. Our monitoring is configured not to attach personal data by default, and events are filtered before they leave our servers so that values such as email addresses, tokens, session cookies, credentials and account identifiers are redacted. Technical details such as the error, the stack trace, the page path and general browser and operating system information can still be present, because that is what makes a fault diagnosable.

9. International processing and safeguards

Some of our providers operate outside the United Kingdom, and your information may be processed outside the UK — in particular by providers based in, or with operations in, the United States.

Where information leaves the UK, we rely on the safeguards approved for UK transfers — the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — or on a UK adequacy or data bridge finding where one applies to that provider. The exact mechanism is set out in each provider’s data processing agreement, linked in section 8.

You can ask us for more information about the safeguards in place by emailing info@theorio.co.uk.

10. How long we keep information

We keep information for as long as we need it for the purpose we collected it for. Where we cannot give a fixed period honestly, we give the criteria we use instead.

Account, profile and learning information

Kept for as long as your account is open. You can ask us to close your account and delete your information by emailing info@theorio.co.uk. Deletion is handled by us on request — it is not an automatic process — and it may not cover records we are required or permitted to keep, such as records needed for tax and accounting or to deal with a legal claim.

Subscription and payment records

Kept for as long as needed to provide and support the subscription, and after that for as long as required by applicable tax, accounting and other legal obligations, or as reasonably necessary to establish, exercise or defend legal claims. The short payment record described in section 3 is kept on the same basis. Because it is a financial and operational record rather than an analytics record, it is not deleted if you decline analytics cookies or later withdraw that consent.

Service email records

Kept for as long as we need them to deliver the service and to investigate delivery problems. Records held by our email provider are also subject to that provider’s own settings and policies.

Analytics information

Only collected if you consent. Kept in line with the retention settings configured in the analytics account and for no longer than we need it, and we review those settings periodically.

Error monitoring records

Kept in line with the configuration of our monitoring account and only for as long as reasonably necessary for security and troubleshooting.

Web server access records

Rotated and deleted on our servers on a rolling schedule, typically around 14 days. We keep them for security and to operate the service.

Marketing preferences and consent records

We do not currently send marketing emails. If we introduce them, we would keep a record of your choice and of when and how you made it, for as long as we need it to act on your choice and to show that we acted lawfully.

Unsubscribe links

An unsubscribe link would stay valid for 90 days from the date the email is sent. After that the link stops working. The underlying record may be kept beyond that point where it is still needed for security, auditing, or to show that we honoured an opt-out; how and when those expired records are cleared is governed by a separate cleanup policy.

Do-not-contact records

Kept for as long as the opt-out applies and we need it to honour that opt-out, and reviewed periodically to confirm it is still needed and still accurate. This is a minimal, pseudonymous record. Closing your account does not automatically remove it, and a request to erase your data will not always remove it either — because its only purpose is to stop you being contacted again.

Messages you send us

Kept for as long as we need them to answer you, to complete any follow-up, to deal with fraud or security issues, and where necessary for legal claims or obligations.

Backups

Our own and our providers’ backups are kept in line with the relevant backup policies and only for as long as there is an operational or legal need. Information deleted from the live service can persist in a backup until that backup is cycled out.

11. Your rights

Under UK GDPR you have the following rights in relation to your personal information:

  • Access (Art. 15) — request a copy of the information we hold about you.
  • Rectification (Art. 16) — correct inaccurate or incomplete information.
  • Erasure (Art. 17) — ask us to delete your information.
  • Restriction (Art. 18) — ask us to limit how we use your information.
  • Portability (Art. 20) — receive your information in a common format.
  • Objection (Art. 21) — object to processing we carry out on the basis of legitimate interest.
  • Objection to direct marketing (Art. 21(2)) — an absolute right. If you object to direct marketing we must stop, with no exceptions and without you giving a reason.
  • Withdrawing consent (Art. 7(3)) — where we rely on your consent, you can withdraw it at any time, and it must be as easy to withdraw as it was to give.

Withdrawing consent stops the processing going forward. It does not make what we did before you withdrew unlawful.

Not every right applies in every situation — which rights you can use depends on the legal basis we rely on for that particular processing, and some rights have exceptions in law. If a right does not apply we will tell you why.

To exercise any of these rights, email info@theorio.co.uk. We will respond within one month. We may need to ask you for information to confirm your identity before we act, so that we do not disclose your data to someone else.

12. Automated personalisation

We use your practice results, your topic scores and your diagnostic results to automatically choose which questions and suggestions you see next, and to generate an AI study summary after a mock test. This is automated personalisation, and it is profiling in the sense the law uses that word.

It is not a decision with a legal or similarly significant effect on you. It does not set your price, decide whether you can have an account, decide anything about your driving theory test, or affect any legal right. All it changes is what the app shows you next.

You can ask us to explain how it works, and you can object to it — email info@theorio.co.uk.

13. Children and young people

Theorio is for people aged 16 and over. Learner drivers aged 16 and 17 are a real part of who this service is for, and this notice is written to be understood by them.

We aim not to collect information from anyone under 16. To be straightforward with you: we ask you to confirm your age in our Terms, but we do not currently run an age check when you register, and we do not have a parental consent process. If you are under 16, please do not create an account. If you think a child under 16 has created one, email info@theorio.co.uk and we will delete it.

We do not send marketing emails to anyone, and that includes young people. Marketing is not switched on for any age group.

14. Changes to this notice

We may update this notice from time to time. When we do, we will change the “Last updated” date at the top and, where changes are material, notify account holders by email. If we ever start using your information for something new, we will tell you before we do it.

15. Complaints to the ICO

If you are not satisfied with how we have handled your personal information, please tell us first so we can try to put it right. You also have the right to complain to the UK Information Commissioner's Office, and to seek a remedy through the courts.

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
ico.org.uk

16. Contact

For any privacy-related question, or to exercise a right, email info@theorio.co.uk.