This policy covers the Setent iOS app and the website setent.app. It explains what data we process, why, and how you can manage it. We do not sell personal data.
1. Account and Passport
Sign in with Apple is required. We receive an identifier, your email or private relay address, and your name if shared. Your Passport and profile are linked to your account and synced to the cloud.
We store visited countries and regions, visit dates and stays, your wish list, collection progress, profile information and preferences. We calculate aggregate collection counts from users’ progress. When exporting your Passport, you choose who receives it.
Apple handles purchases. We receive subscription status information, but not your card details. If you contact support, we receive your message, contact details and any other information you send.
2. Location and photos
Location is optional. With permission, Setent uses precise location for maps and visit detection, including in the background with “Always” access. Places and visit dates are saved to your Passport. Map and location services may also process location, device and usage information.
Photo scanning is optional. Photo locations and dates are processed on your device to identify visits. Original photos and raw metadata are not uploaded to Setent; records added to your Passport sync to the cloud.
Profile photo. An image you add is processed on a server and stored in the cloud for display in the app. It can be accessed without signing in to an account.
You can revoke location and photo permissions in iOS Settings and enter visits manually. Revoking access does not erase records already added.
3. Analytics and notifications
To improve the app and measure advertising, we process installation, device and account identifiers, device and app information, approximate location derived from IP, in-app actions, purchases, subscription status and installation source. Events can include countries and regions you viewed, marked or added to a wish list, and how a visit was detected. These records have technical identifiers and can be linked to your account; they are not anonymous. Our custom events do not include images, message text or precise GPS coordinates.
Analytics is collected automatically; there is no separate in-app switch. Contact us to exercise applicable objection or deletion rights. The app does not use the IDFA advertising identifier.
Push notifications use a device token that may be stored with your account independently of permission to display notifications. Manage their display in iOS Settings.
4. Providers and international processing
We use Google Firebase for accounts, storage, notifications and hosting; Google Analytics for analytics; Cloudflare for images and website security; Mapbox for maps; and Apple for sign-in, purchases, location services, notifications and advertising measurement. These providers, along with currency-rate and font providers, may receive IP addresses and other connection data and keep technical logs. They process data under applicable terms, in some cases as independent controllers.
Partner offers open external services with their own privacy and cookie rules. A partner may receive connection and referral data; we may earn a commission. We do not send partners your Passport or use it for advertising across other companies’ services. We may also disclose data as required by law or to protect rights and security.
Data may be processed outside your country, including in the United States. Depending on the provider, service and country, provider terms include safeguards such as standard contractual clauses (SCCs) or, for eligible transfers to certified recipients, the Data Privacy Framework. You can request information and copies of applicable safeguards from us.
5. Why we process data
Data is used to operate and sync your Passport, provide features you choose, conduct analytics, offer support and maintain security. Where a legal basis is required, service delivery relies on our contract with you; support and security on legitimate interests in reliably operating Setent; and legally required processing on legal obligations. Additional processing, including analytics and location and photo access, requires consent where the law says so. Withdrawal does not affect the lawfulness of earlier processing.
6. Storage and deletion
Account, Passport and profile photo data remain until you delete them or your account. Individual analytics events are retained for 2 months; user-level data for 14 months from the last activity, followed by deletion in a monthly cycle. Standard aggregated reports may be retained longer.
Support correspondence and technical logs are retained as needed to resolve requests, maintain security and troubleshoot problems. Necessary records may be kept to comply with law or resolve disputes. Provider backups and deletion cycles require additional time: Firebase documents up to 180 days for authentication data after deletion is initiated.
- “Erase all data” in Settings clears your Passport and collection progress, including the synced copy, but keeps your account.
- “Delete account” starts removal of your account, Passport, profile, tokens and profile photo. Contact us if you cannot sign in or deletion fails.
Account deletion does not automatically erase individual analytics records with technical identifiers: the periods above apply, or you can request their deletion separately. Anonymised aggregate statistics that cannot identify a user may be retained.
Deleting the app does not delete your cloud account; deleting your account does not cancel your Apple subscription. Passport copies you share remain under their recipients’ control.
7. Your rights and contact
Depending on applicable law, you may request access, a copy, correction, deletion or portability of your data, restrict or object to processing, withdraw consent, or appeal a refusal. You can also complain to a data-protection authority. Rights are subject to legal conditions and exceptions; exercising them will not result in unlawful discrimination.
Contact Setent: [email protected].
Liam Baev is responsible for the processing of personal data.
We may request information needed to verify your account. We respond within applicable legal deadlines: ordinarily one month for GDPR requests, with permitted extensions explained to you.
We use encrypted connections and access controls to protect data. No storage or transmission method is completely secure.
8. Children and changes
Setent is not intended for children under 13. Local law may require a higher age or parental authorization. If we learn that a child’s data has been collected without required authorization, we will take steps to remove it.
We will notify you of material policy changes in the app or by another appropriate means and request new consent where necessary. The version date appears at the top of this page.