Privacy Policy
Meridian is a day counter for tax residency and visa limits. It is built so that your travel history stays on your phone.
Effective 12 September 2026
This Privacy Policy is issued by Damir Zhambylov, operating as Meridian ("we," "us," "our"), and describes how we handle personal information when you use the Meridian iOS app or these support pages.
The short version. There is no account and no login. Your locations, trips, day counts and document dates are stored only on your device and are never sent to us — we have no server that receives your travel history. Three limited categories may leave your device: subscription data handled by Apple and RevenueCat, anonymous app-usage events sent to TelemetryDeck, and crash and diagnostic data sent to Firebase Crashlytics. None includes a country from your travel history, travel date, raw coordinate, trip details or document details.
Contents
- Who we are
- What the app collects, and where it goes
- Third parties
- International data transfers
- What we do not do
- Legal bases for processing (EU/UK)
- Categories of personal information
- Your rights and how to exercise them
- California "Shine the Light"
- Do Not Track
- Security
- Children
- EEA/UK representative & data protection officer
- Other regions
- Changes to this policy
- Contact
Who we are
Meridian is developed and published by an individual developer based in Kazakhstan, trading as "Meridian." There is no separate corporate entity. For any privacy question, write to morua@meridiantracker.app — that is the only contact address we use, for privacy requests as well as general support.
What the app collects, and where it goes
| Data | Why | Where it goes |
|---|---|---|
| Location | To tell which country you are in and count the day | Stays on device. Accurate readings may wait briefly in a protected, backup-excluded queue; after a successful local save, the coordinates are discarded |
| Photo metadata | To rebuild your past trips at first launch | Stays on device. Only the date and country are kept |
| Trips & rules | The day counts the app exists to produce | Stays on device |
| Document dates | Passport and visa expiry reminders | Stays on device |
| Subscription identifier & device info | To unlock paid features and restore purchases | Apple and RevenueCat — see Third parties |
| How you use the app | To see where people get stuck and fix it | TelemetryDeck — screens and steps only, never a country or a date |
| Crash and diagnostic data | To diagnose crashes and reliability problems | Firebase Crashlytics — technical crash details and installation identifiers, never travel history |
Location
With your permission, Meridian monitors significant changes in your location so it can detect when you cross a border — including while the app is closed, which is the only way a day count stays correct if you do not open the app for weeks.
Each accurate location reading is matched against country borders on your device, using a border dataset bundled inside the app. No network request is made to resolve your position, and the app works with no connection at all. To prevent a background restart or temporary database error from losing a border crossing, an accurate reading may be stored briefly in a protected queue on your device until it has been converted to a day and country and saved successfully. This temporary queue is excluded from backups. Raw coordinates are never transmitted or logged, and they are deleted after successful processing, an explicit terminal discard, turning off Auto-Tracking, or Delete All Data. The travel history then keeps only the day and country.
You can decline location access, or grant it only while the app is open. The app remains usable: you can add and edit trips by hand. With "While Using" access rather than "Always," days you spend without opening the app will not be counted, and the app tells you so.
Photo library
If you allow it, Meridian reads the date and location tags attached to photos in your library in order to reconstruct where you have been. This runs entirely on your device.
The app does not open, view, analyse, copy or upload your images. It reads the metadata, matches each location to a country on the phone, and keeps only a list of days and countries. You review and correct that list before anything is saved.
The app asks for access to the whole library rather than letting you pick individual photos because it needs to sample dates across years of history to reconstruct a timeline; picking photos one by one would not produce a usable result. If you grant access to selected photos only, the app will work with just those and the reconstructed history will be correspondingly incomplete.
What you enter yourself
Passport countries, trips, rules, and document types with their issue and expiry dates. Meridian never stores scans, photographs or images of documents, and never asks for a passport or document number — only the type, country and dates you type in. This is a permanent design decision, not a limitation of the current version.
Notifications
Reminders about approaching limits and expiring documents are scheduled locally on your device. These are not push notifications — nothing is sent through a push server, and no device token is collected or transmitted for this purpose.
Storage and sync
All of your long-lived data is stored in a local database on your device. This version of Meridian does not sync to iCloud or anywhere else, so your data exists only on the phone where you entered it. The local database is included in your device backups if you have those enabled, under Apple's terms; the temporary raw-location queue described above is specifically excluded from backups. If cloud sync is added in a future version, this policy will be updated before it ships.
Because nothing is held on a server we control, retention of the data above is not set by us — it is stored until you delete it (Settings → Delete All Data) or delete the app.
Third parties
Apple
Purchases are processed by Apple through the App Store, with Apple acting as merchant of record — your payment method and billing details are held by Apple, not by us; we never see or collect them. If you join a beta through TestFlight, Apple also collects the email address associated with your Apple ID to send the invitation, and may collect crash reports or feedback you choose to submit. Apple's handling of this is governed by Apple's Privacy Policy.
RevenueCat
Meridian uses RevenueCat to manage subscriptions and to restore purchases across your devices. When you open the paywall or make a purchase, RevenueCat receives a randomly generated anonymous identifier for your installation, your purchase receipt, and basic device and platform information such as OS version and country. It does not receive your name, email address, location, trips or any other content from the app. See the RevenueCat Privacy Policy.
TelemetryDeck
Meridian uses TelemetryDeck, a privacy-focused analytics service based in Germany, to understand how the app is used — which onboarding step people stop at, which screen they open, whether a permission was granted, and how many trips the photo import recovered.
These events describe your use of the app, never your travel. No country, no date, no city, and no trip is ever sent. Where a count would be revealing it is grouped into a range rather than reported exactly. TelemetryDeck receives a randomly generated identifier for your installation so repeat visits can be counted as one person; it is not the advertising identifier and cannot be tied back to you. Nothing is used for advertising, which is why the app never asks permission to track you. See the TelemetryDeck Privacy Policy.
Firebase Crashlytics
Meridian uses Firebase Crashlytics, a service provided by Google, to find and fix crashes and reliability problems. When the app crashes or records a technical failure, Crashlytics may receive a crash stack trace, the app version, device model and operating-system details, crash state, timestamps, and randomly generated installation identifiers. This is app-functionality diagnostic data: it is not used for advertising or tracking across apps.
Meridian deliberately sends only fixed diagnostic stage codes for the non-fatal failures it records. It does not attach a country, travel date, raw coordinate, trip, rule, document, file name, file path or underlying error text. Firebase states that Crashlytics keeps crash traces and associated identifiers for 90 days before beginning removal from live and backup systems. See Privacy and Security in Firebase.
International data transfers
Apple and RevenueCat are US-based companies; TelemetryDeck is based in Germany; and Firebase Crashlytics runs on Google's global infrastructure. If you are in the EU, UK, Switzerland or another region outside the United States, the limited subscription and diagnostic information described above may be transferred to and processed in the United States or other countries where those providers operate. Each provider is responsible for appropriate safeguards under its own privacy terms. We do not operate a travel-data server ourselves: your trips, location history, rules and documents remain on your device and are not part of these transfers.
What we do not do
- No advertising, and no advertising identifiers.
- No tracking of you across other apps or websites. The app does not ask for App Tracking Transparency permission because it has nothing to track you with.
- No analytics collection of your travel data. We do measure how the app itself is used — see TelemetryDeck — but no country, date or trip is ever part of that.
- No cookies, web beacons, or similar tracking technology on this website or in the app.
- No selling or sharing of personal information with data brokers, advertisers, or anyone else's marketing.
- No account, so no email list and no password to leak.
Legal bases for processing (EU/UK)
If you are in the EEA, UK or Switzerland, we process the limited information described above only when we have a valid legal basis:
- Consent — for location and photo library access, given through the system permission prompt. You can withdraw this at any time in iOS Settings, which stops the related processing going forward.
- Performance of a contract — processing your subscription identifier and receipt to provide the Meridian Pro features you purchased.
- Legitimate interests — understanding anonymous app usage, diagnosing crashes and reliability problems, and helping RevenueCat prevent fraudulent purchases, where these interests do not override your own rights and interests.
- Legal obligations — where we are required to cooperate with a lawful request from a regulator or court.
Categories of personal information
For reference, here is every category of personal information under California's definitions, and whether it applies to Meridian:
| Category | Examples | Applies? |
|---|---|---|
| Identifiers | Name, email, IP address, unique device or account identifiers | Yes — an anonymous installation identifier and IP address logged by our hosting provider. No name or email is collected by the app. |
| California Customer Records data | Name, signature, address, passport/driver's licence number, financial account info | No — we collect passport country, never a passport number, and never financial account details. |
| Protected classification characteristics | Gender, age, race, national origin, marital status | No |
| Commercial information | Purchase history, financial details | No — Apple and RevenueCat hold your transaction record; we do not. |
| Biometric information | Fingerprints, voiceprints | No |
| Internet or network activity | Browsing history, interactions with apps or ads | Limited — anonymous events about your use of the app (screens, onboarding steps). No browsing history, no ad interactions, and these pages carry no analytics at all. |
| Geolocation data | Device location | Yes, on-device only — see above. Never disclosed to any third party. |
| Audio, electronic, visual information | Photos, audio or video recordings | No — photo metadata only; images are never read or stored. |
| Professional or employment information | Job title, work history | No |
| Education information | Student records | No |
| Inferences | Profiles built from collected data | No — we do not build profiles or make inferences about you. |
| Sensitive personal information | Health, precise geolocation used for profiling, etc. | Precise location is processed on device only to determine a country and is never transmitted or used for profiling. |
Your rights and how to exercise them
Because your data lives on your device, you are in direct control of most of it:
- Delete everything — Settings → Delete All Data inside the app. This removes trips, rules, passports and documents immediately and permanently. There is no copy on our side to request.
- Correct anything — every day, trip and document is editable in the app at any time.
- Withdraw permissions — location and photo access can be revoked at any time in iOS Settings.
- Export — paid users can export trips and reports as PDF or CSV.
Depending on where you live, you may also have the right to know what we hold about you, request a copy, request correction or deletion, and not be discriminated against for exercising these rights. We do not sell or share personal information (as those terms are defined by the CCPA/CPRA), so there is nothing to opt out of on that front — but you can still ask, and we will confirm this in writing.
To exercise any of these rights for the limited data we or our processors hold (see Third parties), write to morua@meridiantracker.app. We will acknowledge your request within 30 days.
If you are not satisfied with our response, you may appeal by replying to the same email, or escalate directly:
- UK: Information Commissioner's Office — ico.org.uk/make-a-complaint
- EEA: your national data protection authority
- Switzerland: the Federal Data Protection and Information Commissioner
- South Africa: the Information Regulator — enquiries@inforegulator.org.za
- US: your state Attorney General
California "Shine the Light"
California Civil Code Section 1798.83 lets California residents ask, once a year, what personal information we have disclosed to third parties for their own direct marketing purposes. We do not disclose personal information for this purpose. The limited disclosures described here are to Apple and RevenueCat for subscriptions, TelemetryDeck for anonymous product analytics, and Google Firebase for crash diagnostics — all to operate and improve Meridian, not for their direct marketing. If you would still like to submit a request, write to morua@meridiantracker.app.
Do Not Track
Some browsers send a "Do Not Track" signal. Because this app and these pages carry no cookies, trackers, or advertising technology to begin with, there is nothing for such a signal to switch off — we do not respond to it because it has no effect either way.
Security
Meridian's architecture is itself a security measure: because your trips, location and documents never leave your device, there is no server-side database of that information to be breached. On your device, the app's data is protected by iOS's own file-level encryption and app sandboxing. Network connections for subscription handling, anonymous product analytics and crash diagnostics use HTTPS, as does this website. No security measure is perfect, and we cannot guarantee that unauthorised access will never occur, but the design of the app is intended to keep the amount of information at risk as close to zero as possible.
Children
Meridian is not directed at children and is not designed to appeal to them. By using the app, you represent that you are old enough to hold a valid passport or ID in your own right. We do not knowingly collect personal information from anyone under the age required by their local law. If you believe a child's information has reached us, write to morua@meridiantracker.app and we will delete it.
EEA/UK representative & data protection officer
We have not appointed a formal representative in the EEA or UK, or a data protection officer. As a sole developer whose processing is limited, on-device, and does not involve large-scale monitoring or special category data, we believe this falls within the exemptions available under Article 27 GDPR and its UK equivalent. All privacy matters are handled directly at morua@meridiantracker.app.
Other regions
If you are in Australia or New Zealand, we process your information consistently with the obligations of the Privacy Act 1988 (Australia) and the Privacy Act 2020 (New Zealand) — in practice, this means the same data-minimisation approach described throughout this page: nothing beyond what is needed to run the app, and no disclosure beyond what is described in Third parties.
Changes to this policy
If this policy changes in a way that affects how your data is handled, the effective date at the top will change and the updated version will be published here before the change reaches the app.