Privacy Policy
Effective date: 2026-09-25 · Applies to the Raven: Travel History iOS app and ravenhistory.com
Raven exists to keep a record of where you have been. That record is yours. It is stored on your iPhone and, if you choose, in your private iCloud database. We operate no server that receives your location, trips, photos or evidence, and we have no account system. This policy explains exactly what the app and this website do with data.
1. Who we are
Raven: Travel History is published by Raven History ("we", "us"). Contact: [email protected]. We are the data controller for the limited data described in sections 3 and 4. If you are in the EU or UK and we appoint a representative, their details will appear here.
2. What the app processes, and where it stays
The items below match the App Store privacy label ("Data Not Collected" for location, photos and identifiers) and the app's privacy manifest. "Processed on your device" means the data never leaves your iPhone except into your own iCloud account.
| Data | When | Why | Where it lives |
|---|---|---|---|
| Location (precise or coarse, as you choose) | While the app is in use, or in the background if you grant "Always" | To work out which country you were in on each day, so the app can count days for visa, citizenship and tax-residency rules | Converted to a country and a date on your device using an offline map; the resulting daily record is stored on your device and, optionally, in your private iCloud. Raw coordinates are not kept as a trail. |
| Photos (read-only) | Only when you run a Photos import | To read the capture dates and geotags of photos you select and suggest past trips | Read on your device; only the resulting dates and countries are stored. No image or metadata is uploaded anywhere. |
| Imports (Google Maps Timeline JSON, calendar events, manual trips) | Only when you choose to import | To rebuild past history | Parsed on your device; stored as trips on your device and optionally in your iCloud. |
| Evidence attachments (boarding passes, stamps, receipts you attach to trips) | Only when you attach them | To support your trip record | Stored on your device and optionally in your private iCloud. |
| Exports (PDF, CSV) | Only when you tap Export | To give you a report to hand to an authority | Generated on your device and handed to the iOS share sheet; you decide where it goes. |
We consider location history and travel records sensitive. That is why the app is designed so that we cannot see them.
3. iCloud sync
If you turn on sync (Premium), the app stores your daily record, trips, rules and evidence in the private database of your own iCloud account using Apple's CloudKit. Only devices signed in to your Apple Account can read it. We cannot access your private iCloud database. Apple's handling of iCloud data is governed by Apple's privacy policy. You can turn sync off at any time; the data then stays only on the device.
4. Third parties and what they receive
We use a small number of processors. None of them receives your location, trips, photos or evidence. None sells or shares your data, and no third-party AI service receives personal data from Raven.
- Apple (App Store, in-app purchases, iCloud, crash reports). Apple processes purchases and, if you opted in to share analytics with developers in iOS Settings, sends us aggregated crash and usage data.
- TelemetryDeck (anonymous analytics). The app sends anonymous, aggregated usage signals such as "export tapped" or "Schengen rule added" together with a salted, hashed device identifier that cannot be reversed to you. No location, dates or trip data are included. TelemetryDeck is based in Germany and processes data under GDPR; see their privacy policy.
- AppsFlyer (install measurement). Used to attribute installs to our own advertising campaigns. On iOS 14.5 and later it can link an install to an ad only if you allow tracking when the App Tracking Transparency prompt appears; if you decline, measurement is aggregated and not linked to you. It receives device-level technical data (device model, OS version, IP address, IDFV) and event names such as "trial started", never your travel record. See AppsFlyer's privacy policy.
- RevenueCat (purchase management). Validates App Store receipts so your Premium status works across your devices. It receives an anonymous app user identifier generated on your device, your purchase and subscription status and the transaction identifiers Apple issues. It does not receive your name, email or travel data. See RevenueCat's privacy policy.
- Plausible Analytics (this website only). Cookieless, aggregated page-view statistics; no personal data is stored and no consent banner is needed.
- Hosting: this website is served from our own server in the EU. The server keeps standard access logs (IP address, requested page, user agent) for up to 30 days for security. Nothing you type into the free calculators is sent to the server; they run entirely in your browser.
5. How we use data and on what basis
- Providing the app (location, photos, imports, iCloud): processed on your device to perform the contract with you, under your explicit iOS permission grants.
- Purchases (RevenueCat, Apple): performance of the contract.
- Anonymous analytics and crash reports (TelemetryDeck, Apple): our legitimate interest in keeping the app working and understanding which features are used. You can opt out in the app's settings at any time.
- Install measurement (AppsFlyer): consent, given through the App Tracking Transparency prompt; aggregated measurement without consent is a legitimate interest.
- Support email: performance of the contract; we keep your message for as long as needed to resolve it and up to 24 months afterwards.
6. Retention
- Your travel record, evidence and settings: on your device and in your iCloud until you delete them. We hold no copy.
- TelemetryDeck anonymous signals: aggregated; raw signals are deleted by TelemetryDeck after 90 days.
- AppsFlyer measurement data: up to 24 months, then deleted.
- RevenueCat purchase records: for the life of your subscription plus the period required for accounting and Apple dispute handling.
- Website server logs: 30 days.
7. Your rights and how to delete everything
Because your data lives on your own device and iCloud account, you exercise most rights yourself:
- Access and export: everything is visible in the app; Premium exports it as PDF or CSV.
- Deletion: delete the app to remove all local data. To remove iCloud data, open iOS Settings › your name › iCloud › Manage Account Storage › Raven › Delete Data (or use "Delete all data" inside the app before uninstalling).
- Revoke permissions: iOS Settings › Privacy & Security › Location Services (or Photos) › Raven.
- Opt out of analytics: in the app's settings, or decline the tracking prompt.
For anything we hold (support emails, purchase identifiers, measurement data), email [email protected] and we will respond within 30 days. If you are in the EU or UK you may also complain to your data protection authority.
8. Children
Raven is not directed at children under 13 (or under 16 where that is the age of consent). We do not knowingly process their data; if you believe a child has provided data to us, contact us and we will delete it.
9. Purchases
All purchases are processed by Apple through the App Store. We receive transaction identifiers and subscription status only, never your payment details. Refunds are handled by Apple at reportaproblem.apple.com.
10. The record is yours; the decisions are too
Raven is informational software. Day counts and rule results are computed from the data you and your device provide and from published rules as we understand them. They are not legal, tax or immigration advice. Exports are user-initiated; you decide who receives them.
11. Changes
If this policy changes materially we will update the effective date above and show a notice in the app before the change takes effect. Earlier versions are available on request.