Nomad Check
Draft — not yet in effect Items marked in red are not finalised. This document is being prepared before the app's first release.

Privacy Policy

Effective date: {{EFFECTIVE_DATE}}

Nomad Check is operated by {{LEGAL_ENTITY}}, a developer based in Taiwan. This policy explains how the Nomad Check Android app for Google Play handles your information.

Privacy contact: [email protected]

1. Data collection starts before registration

On a fresh online start, the app automatically creates an anonymous account with Supabase without waiting for you to tap a button or give consent. This happens when no existing session or previous identity is recorded and the app can read its local storage. An offline first start does not create the account at that time.

"Anonymous" means that the account has not been linked to your email or Google account. It still has a unique account identifier. Information saved under it is not anonymized.

After you complete initial setup, the app automatically uploads your saved information to Supabase. This includes your passport nationality, current city, income range, employer country, and work and sleep schedule when those details are present. You do not need to register or link an account first.

Uploads can also happen when you reopen the app or return to it. If information is already saved on your device, the app does not wait for you to finish reading the privacy page before uploading it. Labels such as "Guest" or "Not saved" do not mean that your information stays only on your device.

2. Information we collect and store

Profile and setup answers

The app stores and uploads the following profile information when present. Unanswered entries can also be sent as empty values.

InformationDetails
Nickname or display nameThe name saved in your profile. If this is empty when you link Google, the app copies your Google display name into it and uploads it.
Passport nationalityThe nationality of the passport you select.
Passport expiry dateThe expiry date you enter.
Current city and time zoneYour selected city and its time zone.
Age rangeYour answer to the under-30 question shown in the Taiwan assessment flow.
Work arrangementYour work type and work activities.
Employer informationEmployer entries and employer country. Details included within each employer entry: {{EMPLOYER_ENTRY_DETAILS}}.
Assignment in your destinationYour answer about an employer assignment in the destination.
Freelance clientsYour client status and the countries where your clients are located.
Business informationBusiness entries and whether your business has customers in the destination. Details included within each business entry: {{BUSINESS_ENTRY_DETAILS}}.
IncomeYour income range and the percentage recorded as independent of the destination.
ScheduleYour daily schedule information, work start and end times, and sleep start and end times. Further details included in the schedule entry: {{SCHEDULE_ENTRY_DETAILS}}.
Visa informationYour digital nomad visa status and visa expiry date.
Stay intentionsThe route you select for planning your stay and your desired number of days.

The app uploads the full profile, together with references to the plan you have selected as active and the plan you are considering, your account identifier, and an update time.

Current stay, future plans, and stay history

InformationWhat is sent to Supabase
Current stayThe entire current-stay record, including visa-related information stored in that record. Full item-by-item description: {{CURRENT_STAY_DATA_DETAILS}}.
Future plansDestination, destination time zone, planned arrival and departure dates, document checklist selections, and application status.
Stay historyCountry, city, a reference to any linked plan, how the record was created, planned and actual start and end dates, your stated basis for entry, any manual status override, free-text notes, and creation, update, and manual-edit times.

Future plans and stay history use selected fields for upload. The profile and current-stay record are uploaded in full. A visa detail excluded from a future-plan upload can still be uploaded if it is also stored in your profile or current stay.

Free-text notes are uploaded as part of stay history. Please avoid entering unnecessary information about yourself or other people.

Account and sign-in information

The app stores an account identifier, a record of whether you have linked an account, and sign-in session information on your device. Session information includes credentials that keep the app signed in.

If you use email sign-in or add an email to your account, your email address is sent to Supabase Auth to handle the sign-in email.

If you use Google, Google handles the authorization request. Google identity information, including your email and display name, is stored by Supabase and can be included in the session stored on your device. When your profile nickname is empty, the app also saves and uploads your Google display name as your nickname.

Additional information on your device

The app also stores city-clock selections, body-clock simulations, country-specific health-document checklist selections, the last country used for those checklists, reminder settings, dismissed notices, and ignored-conflict records that include date snapshots. It keeps local records of setup completion, saved-data versions, pending changes, and recovery or synchronization state.

These local entries are separate from the profile, current-stay, future-plan, and stay-history uploads described above. In particular, ignored-conflict records do not have an app cloud-upload path.

Diagnostic copies of unreadable data

If certain saved profile or travel data cannot be read, the app copies the original stored text, word for word, into a separate diagnostic storage entry on the same device. This can include the entire profile and its personal information.

The copy is created only if that diagnostic entry does not already exist. It is not overwritten and has no automatic expiry. There is no separate production-app button for clearing it.

3. Why the app handles information

The app uses account and session information to establish an identity, handle sign-in, and associate cloud records with that identity. It stores and synchronizes profile and travel records and retrieves them during restoration. It stores reminder settings for local notification scheduling. The diagnostic copy preserves the original text when a stored record cannot be read.

The service provides stay-day calculations, visa and compliance information, and health and emergency information. The specific uses and necessity of each profile and assessment answer, including income, employer and client details, age, and schedule information, are: {{PROFILE_AND_ASSESSMENT_DATA_PURPOSES}}.

The grounds on which we process each category of personal information, where required by the laws that apply, are: {{PROCESSING_LEGAL_BASES}}.

4. Storage locations and service providers

Provider or locationInformation and activity
Your deviceLocal profile and travel records, preferences, diagnostic copies, identifiers, and sign-in session information.
SupabaseAnonymous and linked accounts, authentication, profile and travel uploads, cloud retrieval, and account-deletion requests. Our project is in the Northeast Asia (Seoul), South Korea region.
Google sign-inAuthorization requests when you choose Google. Google returns identity information to Supabase.
Sign-in email providerEmail delivery triggered through Supabase Auth. The configured email provider and its processing location are {{AUTH_EMAIL_PROVIDER_AND_LOCATION}}.

The developer is based in Taiwan, the Supabase project is hosted in South Korea, and users can be in other countries. Information sent to that project crosses borders when your device is elsewhere. These locations do not by themselves establish the legal safeguards for a transfer.

Additional provider processing locations, subprocessors, and who can access stored information: {{PROVIDER_PROCESSING_AND_ACCESS_DETAILS}}.

When you choose Google sign-in, the Android app also checks whether the Supabase service is reachable. That check contains no profile data in its request body.

Official information links and search links open when you select them. The app does not attach its stored profile or travel records to those links.

Analytics and notification components

The app's analytics event code does not send events in the release version. No dedicated crash-reporting integration is present in the reviewed app code.

Reminders are scheduled locally. However, the notification dependency includes Google's Firebase Messaging component in Android builds. Whether that component initializes or sends information in the final Android build has not been verified. We therefore cannot confirm that it makes no network requests.

Possible Android system backups

The app's Android backup settings have not been explicitly specified. Depending on the final build and your device settings, local app information may be included in a backup associated with your own Google account. The actual scope has not been verified, including whether sign-in credentials or diagnostic copies are included.

5. Security and its limits

Connections to our Supabase service use TLS to protect information during transmission.

In the database, profile and travel information is stored as readable values. The app does not add a separate layer of encryption to those values. This describes how the app stores the data, not whether the hosting provider encrypts its underlying disks or backups; those settings have not been verified.

On the device, personal information, diagnostic copies, and sign-in credentials use storage without encryption added by the app. We do not represent these records as end-to-end encrypted.

Signing out does not remove your profile or travel records from the device. They remain accessible within the app to someone else using that device. Local content is not separated by account. A later guest edit may cause retained information to be uploaded under the guest identity.

6. How long information is kept

InformationRetention
Cloud profile and travel records{{CLOUD_DATA_RETENTION}}
Anonymous accounts and their associated information, including accounts you can no longer access{{UNLINKED_ACCOUNT_RETENTION}}
Authentication records, sign-in email records, and any provider logs{{AUTH_EMAIL_AND_LOG_RETENTION}}
Server backups and copies remaining after deletion{{SERVER_BACKUP_RETENTION_AND_DELETION}}

Signing out does not end local retention. Diagnostic copies have no automatic expiry. The linked-account deletion process includes local cleanup, subject to the verification limits below.

Ordinary synchronization can also delete live cloud records. Clearing a current stay triggers removal of its cloud record. Synchronizing future plans or stay history can remove cloud records that are absent from the local collection. This does not establish when copies in server backups are removed.

7. Deleting information

If you have linked an email or Google account

Open Settings → Login and Security → Delete my account.

The app first sends an account-deletion request to Supabase. If that request fails, the app does not start local cleanup.

After a successful server response, the app is programmed to clear its local profile and travel records, city clocks, simulations, health-document selections, reminder settings, diagnostic copies, and local sign-in information.

This local cleanup has been checked in source code and tests, but has not been verified end to end on an Android device. The deployed server deletion function and its removal of associated database records have also not been verified. We cannot confirm complete removal from all storage on that evidence alone.

Confirmed cloud-deletion scope and completion time: {{CLOUD_DELETION_SCOPE_AND_TIMING}}.

If a data-restoration failure screen covers the app, you cannot reach the in-app deletion controls while that screen remains open.

After account deletion, the app restarts its identity process. When a connection is available, this may create a new anonymous account.

If you have never linked an email or Google account

You still have an anonymous server account, but there is currently no in-app deletion entry for you. There is also no production-app route for you to clear diagnostic copies.

Signing in to an existing account does not include a cleanup step for the anonymous account you leave behind. Losing access to that anonymous identity does not itself delete its server records.

Requests outside the app

You can submit a deletion request at getnomadcheck.com/delete without reinstalling the app. That page explains what we can and cannot identify.

8. Your choices and rights

You can choose whether to link an email or Google account. Remaining a guest does not prevent cloud uploads.

The app asks for notification permission when you use its reminder controls. You can decline that permission. This choice does not control profile or travel-data uploads.

Depending on the laws that apply to you and the circumstances, you may have rights to access or obtain a copy of your personal information, correct it, request deletion, restrict or object to processing, and receive a portable copy. Where processing relies on consent, you may have a right to withdraw that consent. You may also have a right to complain to the relevant data-protection authority.

These legal rights are separate from the controls currently implemented in the app. The deletion limitations described above remain relevant.

How to submit and verify a rights request, and the applicable response times: {{PRIVACY_RIGHTS_REQUEST_PROCESS}}.

Privacy contact: [email protected].

9. Children

Nomad Check is not designed for children. The app does not currently have an age gate. Its under-30 assessment question is not an age-verification process.

10. Policy changes

How we will notify you of changes, including when the revised policy takes effect: {{PRIVACY_POLICY_CHANGE_NOTICE_PROCESS}}.

11. Contact

Operator: {{LEGAL_ENTITY}}
Location: Taiwan
Privacy contact: [email protected]