Who is responsible
Marvin Perzi, trading as Persie0
Angerdorf 6, 3822 Karlstein an der Thaya, Austria
persie0@protonmail.com
This policy applies to NomadRank and this policy page. It supplements the general Persie0 privacy policy; for this app, the more specific information on this page takes precedence.
Information used on your device
The app stores or processes the following information locally for the features you choose:
- offline copies and queues of account, trip and social data
- map/static datasets, cached country and currency data
- settings and a Gemini API key stored in OS secure storage
Local processing is based on Art. 6(1)(b) GDPR where it is needed to provide a requested feature. Settings that are technically necessary are stored under the necessity exception in § 165(3) TKG 2021. Local information normally remains until you delete it, clear the app's data or remove the app.
The GPS position used to suggest a nearby city remains on the device. Stored trip coordinates represent the city or destination you select, not continuous live tracking. The optional Gemini importer sends entered text and selected text or spreadsheet attachments to Google using your API key.
Permissions
NomadRank may request these device permissions:
- Precise/approximate location: suggest the nearest supported city; matching is performed against a local city database.
- Photos/files: select a profile/visited-place image or import/export trip files.
- Network: account synchronization, social features, maps, country/currency data, diagnostics and optional Gemini import.
Permissions can be changed in the operating-system settings. A feature that depends on a denied permission may then be unavailable.
Services and data transfers
The following services receive information only for the purposes described below.
Sentry (EU, standard event capture)
Find and fix defects; protect stability and security. The information involved is: Crash and performance diagnostics, including the error and stack trace, app version, device and operating-system information, technical runtime data and the network IP address visible to Sentry. Common direct identifiers are filtered before transmission, although diagnostic text may still contain information entered or displayed in the app.
Recipient: Sentry; project data hosted in the EU, subject to possible international support/access. Legal basis: Art. 6(1)(f) GDPR. You may object; do not put unnecessary personal data in free-text fields. Retention: 90 days in the configured Sentry project, then deletion; longer only for a concrete security/legal claim.
NomadRank authentication
Create, secure and sign you into a NomadRank account. The information involved is: Firebase UID, email, display name, authentication provider, tokens and security/request logs including IP; Google or Apple additionally process the sign-in data you authorize.
Recipient: Google Firebase and the sign-in provider you choose (Google or Apple). Legal basis: Art. 6(1)(b) GDPR; security/abuse prevention also Art. 6(1)(f). Retention: For the account lifetime. After account deletion, live and backup deletion follows provider cycles; Firebase states many deleted systems/backups are cleared within up to 180 days, subject to security/legal records.
NomadRank account and social backend
Provide the account, synchronization, diary, ranking and requested social features. The information involved is: UID; username/display name; email from sign-in; avatar URL; home country; membership/rank/achievements; trips and planned trips (destination/city coordinates, dates, ratings, tags, notes, costs); bucket list; friends/invites; groups; travel circles and their members/stops; server/security logs including IP. Other users may see profile/social data according to the feature.
Recipient: Persie0 and Oracle as infrastructure processor; people you befriend, invite or join in a group/circle receive the fields the feature displays. Legal basis: Art. 6(1)(b) GDPR; service security and abuse prevention Art. 6(1)(f). Social publication/sharing occurs at your request. Retention: Account content until you delete individual content or use account deletion. Operational backups rotate under provider schedules; security logs are retained only for abuse/claim needs. Portable export is available in-app.
Country/region detection
Choose regional defaults, currency, language or the appropriate consent flow. The information involved is: Public IP address, request metadata and country/region inferred from IP; no GPS location.
Recipient: The first available country-detection service named above. Legal basis: Art. 6(1)(f) GDPR (minimal regional configuration). You can override regional settings where offered. Retention: The response is used transiently or cached locally; Persie0 does not keep a server log. Providers retain request logs under their policies.
Optional Gemini trip import (bring your own key)
Extract proposed trip records and resolve destinations when you start an import. The information involved is: Your Gemini API key, entered itinerary text, selected text/spreadsheet attachments (up to the app limit), file names, prompts, candidate destination rows and generated trip extraction. The key is stored in OS secure storage; Persie0 does not receive it.
Recipient: Google AI. Persie0 is not an intermediary for the API payload. Legal basis: Art. 6(1)(a)/(b) GDPR. Optional and initiated by you. Google acts under the API account/terms tied to your key. Retention: Persie0 keeps only trip data you accept. Google retention/training depends on the paid service and account configuration; review Gemini API terms before sending personal data.
Map tiles and geographic content
Display the map area you request. The information involved is: IP, user agent, request time and requested map-tile coordinates/zoom, which can reveal the area viewed. The map provider does not receive a Persie0 account password.
Recipient: CARTO/CDN and, where directly requested, OpenStreetMap-related services. Legal basis: Art. 6(1)(b) GDPR for the requested map and Art. 6(1)(f) for efficient delivery. Retention: Persie0 does not keep tile-request logs; provider log retention applies. Local cache is cleared by the app/OS or uninstall.
Country, encyclopedia and currency lookups
Display country information, advice/static facts and exchange rates. The information involved is: IP, request metadata and the requested article/country/currency pair. No account password.
Recipient: The content/API provider requested by the feature. Legal basis: Art. 6(1)(b) GDPR for requested content; Art. 6(1)(f) for cached, reliable delivery. Retention: Response cached locally as needed; Persie0 keeps no server log. Provider retention applies.
This policy page
GitHub Pages receives the IP address, browser information, request time and requested page path to deliver and protect this page. Persie0 does not add analytics or advertising cookies to these policy pages. Processing is based on Art. 6(1)(f) GDPR; GitHub's infrastructure retention applies.
AI features
Optional AI features send only the content described above after you start the feature. AI output may be inaccurate. Persie0 does not use AI output to make decisions about you that produce legal or similarly significant effects.
Processing outside the EEA
Some service providers may process information outside the European Economic Area. Where GDPR requires safeguards, processing relies on an adequacy decision, an applicable EU–US Data Privacy Framework certification, or Standard Contractual Clauses together with appropriate safeguards. You may request information about the applicable safeguard by email.
Deletion and retention
Local data can be removed through the app's delete or reset functions, by clearing app data, or by removing the app. Information held by a connected provider follows the period stated above and that provider's deletion process. Requests concerning data controlled by Persie0 can be sent to persie0@protonmail.com.
Your rights
Subject to the GDPR's conditions, you may request access, correction, deletion, restriction and portability; object to processing based on legitimate interests; and withdraw consent for future processing. You may also lodge a complaint with the Austrian Data Protection Authority.
Children
The app is not specifically directed at children. In Austria, consent for an information-society service can generally be given from age 14; below that age, parental authorization may be required. Provider-specific higher age limits described above continue to apply.
Changes and contact
This policy may change when the app or a connected service changes. The effective date appears at the top of the page. Questions and privacy requests can be sent to persie0@protonmail.com.