Privacy Policy
Effective Date: March 1, 2026
Last Updated: March 1, 2026
Introduction
Welcome to Statlas ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you understand how we collect, use, and safeguard your personal information. This Privacy Policy explains our practices regarding data collection and use for the Statlas mobile application ("App").
By using Statlas, you agree to the collection and use of information in accordance with this policy. If you do not agree with our practices, please do not use the App.
Information We Collect
1. Account Information
When you create an account using Google Sign-In, we collect:
- Email address - Used as your account identifier and for important communications
- Name - Your full name, first name, and last name for display purposes
- Profile picture - Your Google profile image URL for personalization
- Google user ID - A unique identifier from Google to link your account
We do not have access to your Google password. Authentication is handled securely through Google's OAuth 2.0 protocol.
2. Location Data
Statlas is a travel tracking application, and location data is central to its functionality. We collect:
- GPS coordinates - Latitude and longitude of your location
- Timestamps - When each location was recorded
- Accuracy data - The precision of location readings
- Altitude - When available from your device
Location Tracking Modes:
| Mode | Accuracy | When Used |
|------|----------|-----------|
| Off | N/A | No location tracking |
| Off | None | Location tracking is disabled; nothing is recorded |
| Resting | ~500 meters | Battery-efficient background tracking using Apple's significant-location and visit monitoring, plus periodic geofence refresh |
| Walking | ~10 meters | Active GPS at a walking-pace update rate |
| Driving | Best available | Active GPS at the highest update rate, for travel at speed |
Background Location: If you grant "Always" location permission, Statlas can track your location in the background to automatically log places you visit. You can change this permission at any time in your device settings.
3. Photo Library Data
With your permission, we access your photo library to:
- Read EXIF location data - Extract GPS coordinates embedded in your photos
- Read photo timestamps - Determine when photos were taken
- Upload photos - Attach photos to your visits and trips (optional)
We only access photos when you explicitly use the photo import feature or attach photos to visits. We do not scan your entire photo library automatically.
When you import photos, Statlas reads EXIF metadata (GPS coordinates, timestamps) to determine where and when photos were taken.
Your photos themselves never leave your device. No image file, thumbnail, or copy of any photo is uploaded by the import feature. Only the following is read, and only from photos that carry location data.
What is sent to our servers, and when. To record which parts of the world you have covered, the import sends us the GPS coordinate and timestamp of each geotagged photo it processes. This happens as the import runs — before you review or confirm anything, and it is not limited to photos whose suggested visits you accept. If you would rather this did not happen, do not run the photo import; nothing else in the App reads your photo library's location data.
Coordinates sent this way are used to build your coverage map and to derive the countries, regions, cities and landmarks shown in your passport. Photos with no location data are skipped entirely.
4. Travel Data
As you use the App, we collect information about your travels:
- Visited locations - Countries, regions/states, cities, airports, ports, and landmarks you've visited
- Visit details - Timestamps, descriptions, and photos you add to visits
- Trip information - Trip names, dates, descriptions, and associated visits
- Co-travelers - Friends you tag on trips (with their consent through the App's social features)
5. Usage and Preference Data
- App preferences - Your settings and configuration choices
- Achievement progress - Your progress toward travel achievements
- Level and points - Your gamification statistics
6. Subscription Information
- Purchase receipts - Transaction information processed by Apple for subscription validation
- Subscription status - Whether you have an active Pro subscription
We do not collect or store payment card information. All payments are processed securely by Apple through the App Store.
7. Phone Number
If you choose to verify your phone number, we collect:
- Your phone number - Used to send you an SMS verification code, and afterwards to let friends who have your number find you
- Verification status - Whether the number has been confirmed
Your phone number is sent to Twilio, which delivers the SMS and checks the code you enter. Phone verification is optional; nothing else in the App requires it.
8. Contacts
With your permission, and only when you start contact-based friend discovery, we read the names and phone numbers in your address book to find which of your contacts already use Statlas.
- Phone numbers are hashed on your device before they are sent. We transmit and compare one-way SHA-256 hashes, never the numbers themselves, so we cannot read the phone numbers of contacts who are not Statlas users.
- Contact names stay on your device. They are used only to label matches in the App.
- We do not upload your address book, store it, or use it for any purpose other than the matching you asked for.
9. Calendar
With your permission, and only when you ask Statlas to find bookings in your calendar, we read events from your calendars to detect travel bookings: flights, trains, buses, ferries, cruises, car hire, tours and restaurant reservations. As the App learns to recognise other kinds of booking, what we read from your calendar does not change, and neither do the rules below.
- Window read - Events from 365 days in the past to 365 days in the future. The window looks backwards as well as forwards: finding trips you have already taken is a deliberate feature, so a scan can read events from up to a year ago, not only upcoming ones.
- Read on your device - Calendar events are matched on your device by the App. We do not upload your calendar, and no third party receives your calendar contents. This includes calendars from other providers, such as a Google or Outlook account you have added in iOS Settings: Statlas reads them through Apple's Calendar framework on the device, not through any provider's API.
- Nothing leaves your device unless you accept it - Both the scan and your review of what it found happen on your device. An event we identify as a possible booking is shown to you locally; if you decline it, or never get to it, it is never sent to us. Only a booking you actively accept is uploaded. Your device does remember which suggestions you dismissed, so that a later scan stops offering you the same event again. That record is kept on your device and is not sent to us either.
- Not sent for AI processing - Calendar matching is done by a deterministic on-device parser. Calendar events are never sent to Anthropic or any other AI provider. (That applies only to emails you forward us; see section 10.)
- What we keep - Only the bookings you accept. Once accepted, a booking is stored on our servers as an itinerary record in the same way a booking you typed in yourself would be, with one difference: we record that it came from your calendar (rather than being entered by hand) so the record's origin stays clear.
10. Forwarded Email Content
If you use the booking-forwarding feature, you email a booking confirmation to us and we extract the travel details from it.
- What we receive - The entire email you forward, including its sender, subject and body. Booking confirmations commonly contain your name, postal address, phone number, record locator or confirmation number, payment summary, and full itinerary.
- Who processes it - Our inbound-email provider receives the message, and Anthropic's Claude API reads the content in order to extract the structured travel details. It is not used to train any model.
- What we keep - The extracted travel details, and the message for as long as needed to process it and to let you review what was extracted.
- This feature is entirely opt-in and operates only on emails you actively forward. We do not connect to, or read, your mailbox.
We do not collect or store payment card information from forwarded emails. Where a booking confirmation contains a partial card number, it is retained only as part of the forwarded message and is never used.
How We Use Your Information
We use the information we collect to:
1. Provide Core Functionality
- Track and display your travel history
- Build your personalized travel map
- Detect visits to countries, regions, cities, and points of interest
- Show your exploration statistics
2. Enable Features
- Calculate achievements and award badges
- Track your level and points progression
- Import travel history from photos
- Create and manage trips
3. Sync Your Data
- Synchronize your travel data across devices
- Back up your data to our servers
- Restore your data if you switch devices
4. Process Transactions
- Validate subscription purchases
- Manage your subscription status
5. Improve the App
- Understand how features are used
- Fix bugs and improve performance
Data Storage and Security
Local Storage
Your data is stored locally on your device in:
- Secure Keychain - Authentication tokens are encrypted using iOS Keychain Services
- App Storage - Visit history, preferences, and cached data are stored locally
Server Storage
For users with server sync enabled, data is stored on:
- Google Cloud Platform - Our backend is hosted on Google Cloud Run
- Encrypted transmission - All data is transmitted using TLS 1.2 or higher encryption
- Secure infrastructure - We use industry-standard security practices
Data Retention
- Active accounts - We retain your data as long as your account is active
- Deleted accounts - When you delete your account, we remove your personal data from our servers immediately, and in all cases within 24 hours (see Data Deletion Timeline below)
- Local data - Data stored on your device remains until you uninstall the App or manually clear it
Data Deletion Timeline
When you delete your account, we permanently delete all your data within 24 hours of your request. This includes:
- Your profile information (name, email, avatar)
- All visit history and location data
- Trip plans and itineraries
- Social connections (friends, blocks)
- Achievement and challenge progress
- Subscription metadata (payment details are managed by Apple and not stored by us)
Deletion is irreversible. We recommend exporting your data before deleting your account.
Data Portability
You can export all your personal data in machine-readable JSON format at any time from Settings > Account > Download My Data. The export includes your profile, visit history, trips, achievements, and social connections. This complies with GDPR Article 20 (Right to Data Portability).
Third-Party Services
We use the following third-party services (subprocessors):
| Service | Provider | Purpose | Data Shared |
|---------|----------|---------|-------------|
| Sign-In with Google | Google | User authentication | OAuth tokens (we don't receive your Google password) |
| Sign in with Apple | Apple | User authentication | Apple-provided identity token, optional name/email |
| Maps Platform | Google | Map tiles, geocoding | Viewport coordinates, search queries |
| Cloud Run / Firestore / Cloud Storage | Google Cloud | Backend infrastructure and storage | Synced user data (encrypted) |
| StoreKit 2 / App Store receipt validation | Apple | Subscription processing & entitlement verification | Transaction receipts |
| Apple Push Notification service (APNs) | Apple | Push notifications | APNs device token, notification payloads |
| Verify | Twilio | Sending and checking SMS verification codes | Your phone number, and the verification code sent to it |
| Inbound email processing | Our email-receiving provider | Receiving booking confirmations you forward to us | The full content of emails you forward, including sender, subject and body |
| Claude API | Anthropic | Reading forwarded booking emails to extract flight, stay and reservation details | The content of the forwarded email, which typically includes your name, travel dates, addresses, record locators and itinerary details |
On-Device Diagnostics (No Third-Party SDKs)
- MetricKit — the app uses Apple's on-device `MetricKit` framework via
`AnalyticsService` and `CrashReportingService` to collect aggregated
performance and crash diagnostics. These are processed locally and only
transmitted to our backend after aggregation. No data is sent to any
third-party analytics or crash-reporting provider.
What We Don't Use
- No advertising SDKs - We do not display ads or share data with advertisers
- No third-party analytics SDKs - We do not integrate Firebase Analytics, Mixpanel, Amplitude, Segment, or any similar service
- No third-party crash reporting SDKs - We do not integrate Crashlytics, Sentry, Bugsnag, or any similar service (crash data is collected on-device via `MetricKit` only)
Data Sharing
We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Limited Sharing
We may share your information only in these circumstances:
1. With Your Consent - When you explicitly choose to share, such as:
- Making trips visible to friends
- Sharing your profile with other users
- Connecting with friends in the App
2. Service Providers - With trusted providers who assist in operating our service (subject to confidentiality agreements):
- Cloud hosting providers
- Payment processors (Apple)
- Twilio, which receives your phone number in order to send and verify an SMS code when you verify your number
- Our inbound-email provider, which receives any booking confirmation you forward to us
- Anthropic, which processes the content of a forwarded booking email in order to extract the travel details from it. Forwarded email content is sent for extraction only. It is not used to train any model.
3. Legal Requirements - When required by law, such as:
- Responding to valid legal process
- Protecting our rights or safety
- Preventing fraud or abuse
4. Business Transfers - In connection with a merger, acquisition, or sale of assets (your data would remain subject to this Privacy Policy)
Your Rights and Choices
Control Your Data
You have the following rights regarding your personal data:
1. Access Your Data
- View all your travel data within the App
- Export your data (Pro feature)
2. Correct Your Data
- Edit visit information
- Update your profile details
3. Delete Your Data
- Remove individual visits
- Delete your entire account and all associated data
4. Control Location Tracking
- Change tracking modes within the App
- Revoke location permissions in device settings
- Disable background location tracking
5. Manage Privacy Settings
- Control trip visibility (public, friends-only, private)
- Manage friend connections
How to Exercise Your Rights
- In-App Controls - Most settings are available in the App's Settings section
- Device Settings - Location and photo permissions can be managed in iOS Settings
- Contact Us - For data export or account deletion requests, contact us at [email protected]
California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information we collect
- Right to delete your personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your rights
European Users (GDPR)
If you are in the European Economic Area, you have additional rights under the General Data Protection Regulation:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
Our legal basis for processing your data includes:
- Contract performance - To provide the services you requested
- Legitimate interests - To improve and secure our services
- Consent - For optional features like photo access and background location
Children's Privacy
Statlas is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete such information.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States where our servers are located. These countries may have different data protection laws. By using the App, you consent to the transfer of your information to these countries.
We ensure appropriate safeguards are in place to protect your data in compliance with applicable laws.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy in the App
- Updating the "Last Updated" date at the top of this policy
- Sending you a notification through the App (for significant changes)
We encourage you to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: [email protected]
Company:
SJReal Holdings
Summary
| What We Collect | Why | Your Control |
|-----------------|-----|--------------|
| Account info (email, name, photo) | Create and identify your account | Delete account |
| Location data | Track your travels | Adjust tracking mode or disable |
| Photo metadata | Import travel history | Grant/revoke photo access |
| Travel data | Show your progress | Edit or delete visits |
| Subscription info | Process payments | Manage via App Store |
Key Points:
- We collect only what's necessary for the App to function
- We do not sell your data or use advertising
- We do not use third-party analytics or tracking
- You can control, export, or delete your data at any time
- Your data is encrypted in transit and stored securely
*This Privacy Policy is effective as of March 1, 2026.*