Meridian

Privacy Policy

Meridian is a day counter for tax residency and visa limits. It is built so that your travel history stays on your phone.

Effective 12 September 2026

This Privacy Policy is issued by Damir Zhambylov, operating as Meridian ("we," "us," "our"), and describes how we handle personal information when you use the Meridian iOS app or these support pages.

The short version. There is no account and no login. Your locations, trips, day counts and document dates are stored only on your device and are never sent to us — we have no server that receives your travel history. Three limited categories may leave your device: subscription data handled by Apple and RevenueCat, anonymous app-usage events sent to TelemetryDeck, and crash and diagnostic data sent to Firebase Crashlytics. None includes a country from your travel history, travel date, raw coordinate, trip details or document details.

Contents

Who we are

Meridian is developed and published by an individual developer based in Kazakhstan, trading as "Meridian." There is no separate corporate entity. For any privacy question, write to morua@meridiantracker.app — that is the only contact address we use, for privacy requests as well as general support.

What the app collects, and where it goes

DataWhyWhere it goes
Location To tell which country you are in and count the day Stays on device. Accurate readings may wait briefly in a protected, backup-excluded queue; after a successful local save, the coordinates are discarded
Photo metadata To rebuild your past trips at first launch Stays on device. Only the date and country are kept
Trips & rules The day counts the app exists to produce Stays on device
Document dates Passport and visa expiry reminders Stays on device
Subscription identifier & device info To unlock paid features and restore purchases Apple and RevenueCat — see Third parties
How you use the app To see where people get stuck and fix it TelemetryDeck — screens and steps only, never a country or a date
Crash and diagnostic data To diagnose crashes and reliability problems Firebase Crashlytics — technical crash details and installation identifiers, never travel history

Location

With your permission, Meridian monitors significant changes in your location so it can detect when you cross a border — including while the app is closed, which is the only way a day count stays correct if you do not open the app for weeks.

Each accurate location reading is matched against country borders on your device, using a border dataset bundled inside the app. No network request is made to resolve your position, and the app works with no connection at all. To prevent a background restart or temporary database error from losing a border crossing, an accurate reading may be stored briefly in a protected queue on your device until it has been converted to a day and country and saved successfully. This temporary queue is excluded from backups. Raw coordinates are never transmitted or logged, and they are deleted after successful processing, an explicit terminal discard, turning off Auto-Tracking, or Delete All Data. The travel history then keeps only the day and country.

You can decline location access, or grant it only while the app is open. The app remains usable: you can add and edit trips by hand. With "While Using" access rather than "Always," days you spend without opening the app will not be counted, and the app tells you so.

Photo library

If you allow it, Meridian reads the date and location tags attached to photos in your library in order to reconstruct where you have been. This runs entirely on your device.

The app does not open, view, analyse, copy or upload your images. It reads the metadata, matches each location to a country on the phone, and keeps only a list of days and countries. You review and correct that list before anything is saved.

The app asks for access to the whole library rather than letting you pick individual photos because it needs to sample dates across years of history to reconstruct a timeline; picking photos one by one would not produce a usable result. If you grant access to selected photos only, the app will work with just those and the reconstructed history will be correspondingly incomplete.

What you enter yourself

Passport countries, trips, rules, and document types with their issue and expiry dates. Meridian never stores scans, photographs or images of documents, and never asks for a passport or document number — only the type, country and dates you type in. This is a permanent design decision, not a limitation of the current version.

Notifications

Reminders about approaching limits and expiring documents are scheduled locally on your device. These are not push notifications — nothing is sent through a push server, and no device token is collected or transmitted for this purpose.

Storage and sync

All of your long-lived data is stored in a local database on your device. This version of Meridian does not sync to iCloud or anywhere else, so your data exists only on the phone where you entered it. The local database is included in your device backups if you have those enabled, under Apple's terms; the temporary raw-location queue described above is specifically excluded from backups. If cloud sync is added in a future version, this policy will be updated before it ships.

Because nothing is held on a server we control, retention of the data above is not set by us — it is stored until you delete it (Settings → Delete All Data) or delete the app.

Third parties

Apple

Purchases are processed by Apple through the App Store, with Apple acting as merchant of record — your payment method and billing details are held by Apple, not by us; we never see or collect them. If you join a beta through TestFlight, Apple also collects the email address associated with your Apple ID to send the invitation, and may collect crash reports or feedback you choose to submit. Apple's handling of this is governed by Apple's Privacy Policy.

RevenueCat

Meridian uses RevenueCat to manage subscriptions and to restore purchases across your devices. When you open the paywall or make a purchase, RevenueCat receives a randomly generated anonymous identifier for your installation, your purchase receipt, and basic device and platform information such as OS version and country. It does not receive your name, email address, location, trips or any other content from the app. See the RevenueCat Privacy Policy.

TelemetryDeck

Meridian uses TelemetryDeck, a privacy-focused analytics service based in Germany, to understand how the app is used — which onboarding step people stop at, which screen they open, whether a permission was granted, and how many trips the photo import recovered.

These events describe your use of the app, never your travel. No country, no date, no city, and no trip is ever sent. Where a count would be revealing it is grouped into a range rather than reported exactly. TelemetryDeck receives a randomly generated identifier for your installation so repeat visits can be counted as one person; it is not the advertising identifier and cannot be tied back to you. Nothing is used for advertising, which is why the app never asks permission to track you. See the TelemetryDeck Privacy Policy.

Firebase Crashlytics

Meridian uses Firebase Crashlytics, a service provided by Google, to find and fix crashes and reliability problems. When the app crashes or records a technical failure, Crashlytics may receive a crash stack trace, the app version, device model and operating-system details, crash state, timestamps, and randomly generated installation identifiers. This is app-functionality diagnostic data: it is not used for advertising or tracking across apps.

Meridian deliberately sends only fixed diagnostic stage codes for the non-fatal failures it records. It does not attach a country, travel date, raw coordinate, trip, rule, document, file name, file path or underlying error text. Firebase states that Crashlytics keeps crash traces and associated identifiers for 90 days before beginning removal from live and backup systems. See Privacy and Security in Firebase.

International data transfers

Apple and RevenueCat are US-based companies; TelemetryDeck is based in Germany; and Firebase Crashlytics runs on Google's global infrastructure. If you are in the EU, UK, Switzerland or another region outside the United States, the limited subscription and diagnostic information described above may be transferred to and processed in the United States or other countries where those providers operate. Each provider is responsible for appropriate safeguards under its own privacy terms. We do not operate a travel-data server ourselves: your trips, location history, rules and documents remain on your device and are not part of these transfers.

What we do not do

If you are in the EEA, UK or Switzerland, we process the limited information described above only when we have a valid legal basis:

Categories of personal information

For reference, here is every category of personal information under California's definitions, and whether it applies to Meridian:

CategoryExamplesApplies?
IdentifiersName, email, IP address, unique device or account identifiersYes — an anonymous installation identifier and IP address logged by our hosting provider. No name or email is collected by the app.
California Customer Records dataName, signature, address, passport/driver's licence number, financial account infoNo — we collect passport country, never a passport number, and never financial account details.
Protected classification characteristicsGender, age, race, national origin, marital statusNo
Commercial informationPurchase history, financial detailsNo — Apple and RevenueCat hold your transaction record; we do not.
Biometric informationFingerprints, voiceprintsNo
Internet or network activityBrowsing history, interactions with apps or adsLimited — anonymous events about your use of the app (screens, onboarding steps). No browsing history, no ad interactions, and these pages carry no analytics at all.
Geolocation dataDevice locationYes, on-device only — see above. Never disclosed to any third party.
Audio, electronic, visual informationPhotos, audio or video recordingsNo — photo metadata only; images are never read or stored.
Professional or employment informationJob title, work historyNo
Education informationStudent recordsNo
InferencesProfiles built from collected dataNo — we do not build profiles or make inferences about you.
Sensitive personal informationHealth, precise geolocation used for profiling, etc.Precise location is processed on device only to determine a country and is never transmitted or used for profiling.

Your rights and how to exercise them

Because your data lives on your device, you are in direct control of most of it:

Depending on where you live, you may also have the right to know what we hold about you, request a copy, request correction or deletion, and not be discriminated against for exercising these rights. We do not sell or share personal information (as those terms are defined by the CCPA/CPRA), so there is nothing to opt out of on that front — but you can still ask, and we will confirm this in writing.

To exercise any of these rights for the limited data we or our processors hold (see Third parties), write to morua@meridiantracker.app. We will acknowledge your request within 30 days.

If you are not satisfied with our response, you may appeal by replying to the same email, or escalate directly:

California "Shine the Light"

California Civil Code Section 1798.83 lets California residents ask, once a year, what personal information we have disclosed to third parties for their own direct marketing purposes. We do not disclose personal information for this purpose. The limited disclosures described here are to Apple and RevenueCat for subscriptions, TelemetryDeck for anonymous product analytics, and Google Firebase for crash diagnostics — all to operate and improve Meridian, not for their direct marketing. If you would still like to submit a request, write to morua@meridiantracker.app.

Do Not Track

Some browsers send a "Do Not Track" signal. Because this app and these pages carry no cookies, trackers, or advertising technology to begin with, there is nothing for such a signal to switch off — we do not respond to it because it has no effect either way.

Security

Meridian's architecture is itself a security measure: because your trips, location and documents never leave your device, there is no server-side database of that information to be breached. On your device, the app's data is protected by iOS's own file-level encryption and app sandboxing. Network connections for subscription handling, anonymous product analytics and crash diagnostics use HTTPS, as does this website. No security measure is perfect, and we cannot guarantee that unauthorised access will never occur, but the design of the app is intended to keep the amount of information at risk as close to zero as possible.

Children

Meridian is not directed at children and is not designed to appeal to them. By using the app, you represent that you are old enough to hold a valid passport or ID in your own right. We do not knowingly collect personal information from anyone under the age required by their local law. If you believe a child's information has reached us, write to morua@meridiantracker.app and we will delete it.

EEA/UK representative & data protection officer

We have not appointed a formal representative in the EEA or UK, or a data protection officer. As a sole developer whose processing is limited, on-device, and does not involve large-scale monitoring or special category data, we believe this falls within the exemptions available under Article 27 GDPR and its UK equivalent. All privacy matters are handled directly at morua@meridiantracker.app.

Other regions

If you are in Australia or New Zealand, we process your information consistently with the obligations of the Privacy Act 1988 (Australia) and the Privacy Act 2020 (New Zealand) — in practice, this means the same data-minimisation approach described throughout this page: nothing beyond what is needed to run the app, and no disclosure beyond what is described in Third parties.

Changes to this policy

If this policy changes in a way that affects how your data is handled, the effective date at the top will change and the updated version will be published here before the change reaches the app.

Contact

morua@meridiantracker.app