Privacy policy
Version of 4 October 2026, updated the same day: sync between devices enabled. This is a translation; if it differs from the Russian version, the Russian version prevails.
In short. Your trips and document details are stored on your device and in your account on our server, so they are available on all your devices. Document scans are stored on your device only. The server also keeps your email address, your name from Google and information about your sign-ins. We do not sell data, show ads or use visitor tracking. You can delete your account in the app with one button.
1. Who is responsible for your data
Apus (apus.page) is run by a private individual, German Galimov, Argentina, who is the data controller.
For any question about your data, write to [email protected].
2. What data we keep and where
Only on your device, never sent to us. Scans and photos of documents, settings. Text recognition on scans runs on your device; the scans themselves are not sent anywhere.
On your device and in your account on the server, so they are available on all your devices: trips (country, dates, passport, means of transport, notes), passports, visas, residence permits and other permits (country, type, number, dates, notes), records of overstays and entry bans, and rules you created yourself. The app sends them automatically when you change something.
On the server, only if you sign in:
- the email address, name and internal Google account identifier that Google provides when you sign in;
- your role in the service (user, reference editor, administrator, owner), the date you registered and last visited;
- information about sign-ins: when each started, when it expires, browser and device type;
- if you added sign-in with Face ID or fingerprint, the public key for that sign-in and the device type. Your fingerprint or face image never leaves your device and is not sent to us;
- a log of administrators' actions on accounts (for example, "blocked" or "role granted").
- if you turned on reminders, the device subscription address your browser provides and your reminder plan: texts such as "Thailand: 7 days left" and when to send them. The notification itself arrives empty through your browser's push service (Apple, Google or Mozilla), and the device fetches the text from our server, so those services do not see it.
Sync between devices is on for everyone who is signed in. Data on the server is not encrypted with a key of your own: it is protected by HTTPS and Cloudflare disk encryption, but it is technically accessible to the operator of the service. The operator does not browse it and accesses the database only for maintenance and fixing faults.
Checking entry rules. When you refresh a country's rules, only a pair of country codes (destination and passport) goes to our server and from there to an AI provider, with nothing about you, your dates or your documents. The answer is saved in the shared reference data.
Technical data. Our hosting provider, Cloudflare, processes IP addresses and request times to deliver the site and protect it from attacks. We keep no visitor logs of our own.
3. What we do not do
- we do not sell or rent out data;
- we do not show ads or share data for advertising;
- we do not use visitor counters, third-party analytics or trackers;
- we do not store passwords: you sign in with Google or with a passkey on your device.
4. Why we process data
- To run your account: sign-in, role, access to your data. Legal basis: performance of the terms of use you accept.
- To protect the service and accounts: sign-in records and the administrators' log. Legal basis: our legitimate interest in security.
- To comply with the law: for example, to respond to requests about your rights.
5. Who receives data
- Cloudflare, Inc. (USA): hosting of the site, server and database, email forwarding.
- Google LLC (USA): sign-in with Google, if you choose it. Google processes its data under its own policy.
- Anthropic PBC (USA): checking entry rules; receives only country codes, no personal data.
Data may therefore be processed outside your country, including in the USA. We work with providers that commit to protecting data. Data may be disclosed to public authorities only when legally required.
6. How long we keep data
- account data, trips and document details: until you delete them or delete your account;
- a sign-in: until you sign out, or up to 90 days without use;
- when you delete your account, the account record, all sign-ins, trips and document details are erased from the server immediately (they stay on your device until you delete them there); they may remain in database backups for up to 30 days, after which they disappear;
- log entries remain after an account is deleted, but are no longer linked to your email or name.
7. How data is protected
Connections use HTTPS only. Your sign-in key is kept in a cookie that page scripts cannot read; the server stores only a fingerprint of the key, which cannot be used to sign in. Administrators see users' email, name, role and last visit; they do not see your trips or documents in the app.
8. Cookies and browser storage
We use only essential cookies:
__Host-apus_sessionkeeps you signed in, up to 90 days;__Host-apus_oauthprotects sign-in with Google, lives 10 minutes.
Browser storage holds your data and app settings. There are no advertising or analytics cookies, so no consent is needed for them.
9. Your rights
Wherever you live, you can:
- find out what data we hold about you and get a copy;
- correct inaccurate data;
- delete your account in the app (Settings → Account → Delete account) or by email;
- receive your data in a portable format, on request;
- object to or restrict processing;
- complain to the supervisory authority of your country.
Send requests to [email protected]. We reply within 30 days. We may ask you to confirm that the request comes from the account holder.
Residents of Argentina: the supervisory authority under Personal Data Protection Law No. 25.326 is the Agencia de Acceso a la Información Pública (AAIP), which handles complaints about data protection breaches. Residents of the EU and the UK have rights under the GDPR, residents of Brazil under the LGPD (authority: ANPD), and residents of California under the CCPA: we do not sell or share personal information within the meaning of that law.
10. Children
You must be 16 or older to create an account. If we learn that an account belongs to someone younger, we will delete it.
11. Changes to this policy
We will announce significant changes in the app in advance. The date of the current version is shown at the top of this page.