Privacy Policy
Last updated: 14 May 2026
Stamps ("the app") is operated by Ata Saygin ("we", "us"). This policy explains what data the app handles and why.
Data we collect
- Account identifiers. When you sign in with Apple or Google, we receive a stable user identifier (
sub) and optionally your email address and display name, as permitted by you during sign-in. We use these only to create and authenticate your account.
- Your trip data. When you are signed in, the trips you create (country, entry date, exit date, optional cities and notes) are synced to our server so they are available on your other devices.
- Your visa data. When you are signed in, any visas you record (issuing country, free-form type label, validity window, day cap, entry cap, note) are synced to our server so your visa portfolio also appears on every device you sign into. Visas are stored under the same account-deletion rules as trips.
- Your settings. When you are signed in, your in-app preferences (nationality, notification preferences, warning threshold) are synced to our server.
- Authentication tokens. Short-lived access tokens and long-lived refresh tokens are stored on your device's Keychain and on our server (as a hash) so you stay signed in.
- Audit log. We record authentication events (sign-in, sign-out, account deletion) along with the request IP address and user-agent string to protect against abuse. Audit entries are retained for 90 days.
Anonymous analytics
The app includes a usage-analytics layer powered by Countly running on a private server we operate. It is on by default so we can see how the app performs in the real world and fix crashes quickly. You can turn it off at any time under Settings → Privacy → Share anonymous usage data.
What we send:
- Feature taps (e.g. "trip created", "CSV imported") so we can see which features are used and where people get stuck.
- Crash reports and performance metrics so we can fix bugs we would otherwise never hear about.
- A randomly generated device identifier maintained by the Countly SDK. It is not linked to your Apple or Google account, your email, your name, or your trip data. Uninstalling the app generates a new one on reinstall.
What we never send: your email, name, trip countries, cities, notes, dates, or any other content you enter into the app. Events carry only the feature name and coarse labels (e.g. action: created, planned: true).
We do not use advertising SDKs, and we do not track you across other apps or websites. NSPrivacyTracking is set to false in our privacy manifest.
Data we do not collect
- We do not collect location data.
- We do not access your contacts, photos, camera, or microphone.
- We do not fingerprint your device.
- If you use the app as a guest (without signing in), no trip data or settings leave your device. Anonymous analytics still run unless you turn them off in Settings → Privacy.
Subscription purchases
Stamps offers an optional paid upgrade (Stamps Pro) sold through the App Store.
- Apple handles billing. When you purchase a subscription or start the free trial, Apple processes the payment. We do not receive and do not store your payment method, card number, billing address, or Apple ID password.
- What we see. We read your current subscription status locally on your device via StoreKit (
Transaction.currentEntitlements). This lets the app know whether to unlock Pro features. The status stays on your device and is not sent to our server.
- What Apple shares with us. App Store Connect provides us with aggregated, anonymised sales and subscription reports (for example "N trials started last week"). These reports do not identify you.
- Offer codes. If we issue a press or partner offer code and you redeem it, Apple redeems it against your Apple ID; we do not see which code you redeemed.
Calendar access (optional)
If you turn on Settings → Calendar → Sync trips to Calendar, the app asks iOS for permission to write to your Calendar. When granted, each trip you create is added to a calendar of your choice as an all-day event, and the app keeps that event in sync when you edit or delete the trip.
- One-way only. We write events the app creates. We do not read any other events in your calendar and do not send any calendar data to our server or to third parties.
- You stay in control. You can change the target calendar, turn sync off at any time, and optionally remove all events we previously added. Revoking Calendar access in iOS Settings stops the sync immediately.
Where data is stored
- App data on your device is stored in your iOS app container and in the Keychain.
- Synced data is stored in a Postgres database operated by Neon (EU region) and transits through our API hosted on Vercel. All traffic is TLS-encrypted.
How to delete your data
Open Settings → Delete account inside the app. This permanently removes your account, all synced trips, all synced visas, all settings, and all refresh tokens from our server. The deletion is immediate and irreversible. Trips and visas stored locally on your device remain on your device; you can remove them by deleting the app.
You can also sign out without deleting your account (Settings → Sign out), which clears your session from this device but keeps your synced data available for future sign-ins.
Children
The app is not directed at children under 13, and we do not knowingly collect data from them.
Changes to this policy
If we change this policy we will update the date above and, for material changes, notify users inside the app before the change takes effect.
Contact
Questions or requests about your data: atasaygin13@hotmail.com