Privacy Policy
Your data at ExpatPilot
1. Controller
Sovit Kumar Agarwal, trading as ExpatPilot, Elbgaustr. 31, 22523 Hamburg, Germany. Email: admin@expatpilot.de. The controller operates as an individual/natural person. ExpatPilot is a trading name.
ExpatPilot is for adults aged 18 or older who live in Germany or plan to move to Germany.
2. Data we process
- Account: email, name, authentication identifiers, settings, account status, and the server-recorded date, method, Terms version, and Privacy Policy version accepted during account creation or later re-consent.
- Profile and onboarding: city, arrival stage, nationality, date of birth if entered, residence situation, work, study, family, housing, language level, goals, and relevant dates.
- Journeys and tasks: answers, checklists, documents required, deadlines, appointments, notes, and progress.
- Documents: selected files/images, metadata, temporary OCR text, structured summaries, sender, reference, amounts, deadlines, obligations, risk indicators, and suggested actions.
- AI requests: your prompt, recent submitted conversation, visible context choice, and the minimum selected profile, journey, task, document-summary, community, and official-source context needed for the request, plus generated output and feedback.
- Private product feedback: Yes, Partly, or No; up to four predefined improvement reasons; the affected journey, task, document, receipt, appointment, onboarding result, or task-result reference; and app version/platform. This feedback has no free-text field and does not copy document contents, profile answers, names, addresses, or reference numbers.
- Contextual task results: contract reviews, receipt and tax organisation, call or appointment preparation, form preparation, document recovery, and other results that you explicitly create inside a journey, task, or Vault document.
- Notifications: email, push token, preferences, reminder content, delivery status, provider receipt, and error details.
- Community: ratings, tips, city/entity context, display choice, helpful votes, versioned Guidelines acceptance, private reports, user blocks, automated safety labels, moderation status, response deadline, and moderator decision/audit data.
- Technical and security: IP/request metadata, app/platform details, rate-limit, authentication, error, audit, and security logs. Privacy-safe product events may record the screen, event type, and counts such as how many document actions were selected or remained; they do not include task titles, questions, answers, document contents, names, addresses, or reference numbers.
The current Service has no advertising SDK, conventional behavioural advertising analytics, bank connection, direct payment-card processing, or web checkout. Mobile subscription payments are handled by Apple or Google as described below.
3. Why and on what basis
| Purpose | Legal basis |
|---|---|
| Create and secure your account; provide journeys, tasks, document processing, contextual AI assistance, reminders, and requested support | Article 6(1)(b) GDPR; Article 6(1)(f) GDPR for security and abuse prevention |
| Optional notification permissions or other genuinely optional processing | Article 6(1)(a) GDPR where consent is required |
| Security, moderation, service reliability, and legal claims | Article 6(1)(f) GDPR and Article 6(1)(c) where legally required |
| Review structured feedback to correct guidance, failed workflows, and product usability | Article 6(1)(f) GDPR (legitimate interest in improving and maintaining the requested Service) |
| Respond to legal requests and preserve required records | Article 6(1)(c) GDPR |
We use email and push notifications for requested account messages, reminders, and deadlines—not promotional marketing. Future marketing requires a separate lawful basis and preference.
4. Documents, sensitive data, and AI
For a scan, the API temporarily receives the selected file. Clear pages are normally read on the Railway application server. Extracted text and relevant context may be sent to Mistral AI for structured explanation. When a difficult Premium scan needs stronger extraction, the original file may also be sent automatically to Mistral for that purpose. The application retains structured results but clears full extracted text from the document database; temporary uploads are deleted after processing, with stale temporary files targeted for cleanup within about 60 minutes.
A user-selected original may remain in the app's private device-local vault until you delete it. User-exported backups remain under your control.
Do not upload medical records, diagnoses, prescriptions, treatment details, genetic information, biometric templates, or unnecessary information about another person. The app repeats this warning before Vault-document, letter, contract, and receipt uploads. Health-insurance administration documents are supported only when they do not contain diagnoses, prescriptions, treatment details, or other health data. German administrative documents may incidentally contain health, religion, ethnicity, trade-union, political, sexuality, genetic, or biometric information. Redact data that is not needed. ExpatPilot does not perform facial recognition or biometric matching.
When you deliberately use an AI feature, ExpatPilot builds the smallest relevant context on the authenticated server. Depending on the visible context choice, this can include your question and recent messages in that conversation; a compact overview of current journeys, blockers, missing evidence, open tasks, and recent completions; relevant profile facts such as city, residence route, permit dates, language, work/study/household setup; and one selected journey, task, or processed-document summary with extracted fields, official guidance, or community context. Choosing “No personal context” excludes the account-work overview and focused account record. A general question does not attach your whole document library. Client-supplied “profile context” is not trusted or merged into the server context.
Before dynamic text or OCR content is sent to an AI provider, ExpatPilot applies length limits and automated redaction for common identifiers such as email addresses, telephone numbers, street addresses, IBANs, tax IDs, social-insurance numbers, labelled names, and labelled dates of birth. Dates, amounts, authorities, legal terms, and document semantics may remain because they are necessary for a useful response. Automated redaction can miss unusual formats, so avoid entering unnecessary personal or third-party data.
General Ask ExpatPilot conversations are stored only in the app's private device storage, up to five chats, until you delete them, clear app data, or uninstall. Starting a sixth requires you to choose an existing chat to delete. The backend processes each submitted request but does not maintain a general chat-history table. When you invoke an AI action inside a journey, task, or document, the generated result and limited action metadata may be saved to that authenticated item so you can return to it. AI usage counters and privacy-safe operational events may also be stored.
Receipt, document, and contract uploads are placed temporarily in private Supabase Storage for background processing. The worker deletes the temporary object after success or final failure, and a separate cleanup job targets abandoned objects after 24 hours. Curated form templates use a separate private bucket. ExpatPilot does not use AWS for these workflows.
5. Providers
| Provider | Purpose and location |
|---|---|
| Supabase | Authentication and hosted PostgreSQL application data; production project region: Ireland. |
| Google and Apple | Optional social sign-in. The selected provider supplies an authentication identifier and available account profile fields to Supabase/ExpatPilot under that provider's terms. ExpatPilot records the social sign-in method with the policy acceptance. |
| Railway and Railway Redis | API/application deployment, jobs, queue/cache, and operational logs; deployment region: Amsterdam, Netherlands. |
| Hostinger | Domain registration and static website hosting; website request/log details require final provider verification. |
| Configured AI provider (currently Mistral AI; OpenAI- or Anthropic-compatible services may be configured) | AI inference; receives the redacted prompt, recent submitted conversation messages, and only the selected server-built context. Mistral may additionally receive an original difficult scan when automatic enhancement is required. |
| Apple App Store or Google Play | Processes subscription purchase, renewal, cancellation, and refund. ExpatPilot receives entitlement and product metadata, not your full payment-card details. |
| RevenueCat | Validates store purchases and sends ExpatPilot the subscription entitlement, product, store, renewal, expiry, and pseudonymous app-account identifier needed to provide Premium access. |
| Resend | Transactional email and reminders; recipient, message, and delivery data. Its primary processing may occur in the United States under transfer safeguards. |
| Expo, Apple APNs, Google FCM | Push registration and delivery; push token, generic payload, receipt, and error data. Processing may occur outside Germany/EEA under provider terms. |
| Sentry | Privacy-minimized application error and crash monitoring for the mobile app and API. ExpatPilot disables request bodies, user identity, screenshots, view hierarchy, session replay, profiling, and routine application logs in its Sentry configuration. Error events may include app/platform version, build, environment, technical stack information, and redacted failure details. The configured ingestion endpoint is in the EU (Germany); Sentry subprocessors and support access remain subject to its data-processing terms and transfer safeguards. |
When in-app subscriptions are enabled, Apple or Google processes the purchase and RevenueCat validates the resulting entitlement as described above. ExpatPilot does not receive full payment-card details and does not currently offer web checkout or Stripe billing. We may also disclose data when lawfully required or to establish, exercise, or defend legal claims.
6. International transfers
Some providers or subprocessors may process data outside the EEA. Where required, transfers rely on an adequacy decision, EU Standard Contractual Clauses, or another lawful safeguard with supplementary measures where appropriate. Contact us for information about applicable safeguards.
7. Retention
- Account, profile, journeys, tasks, derived document results, and user content: until you delete the item/account, unless a legal exception applies.
- Device-local originals: until you delete them, remove app data, or uninstall; external backups remain under your control.
- Ordinary server upload: processing time; stale temporary files targeted for deletion within 60 minutes.
- Full OCR text: transient; not retained in the document database after the processing boundary.
- Push token: until notifications are disabled, the token is invalidated, or the account is deleted.
- Notification delivery records, application/security/audit logs, support, feedback, and backups: retained only for the operational, security, support, or legal period for which they are needed, subject to applicable provider backup cycles.
- Community contributions: until you delete them or your account, or until moderation removes them; privacy-safe aggregates may be recalculated and retained. Reports, block relationships, Guidelines acceptance, and moderation audit data are retained while needed to enforce the rules, protect users, respond to disputes, or meet legal obligations, and are included in account export/deletion where applicable.
- Provider-side AI inputs/outputs: according to the active provider's commercial configuration and data-processing terms; provider systems may retain content temporarily for safety or service operation.
8. Security and automated processing
Design measures include encrypted transport, server-side secrets, authenticated access, ownership checks, restricted database roles, rate limits, security headers, upload validation, local-vault controls, generic push previews, data minimization, audit records, and account export/deletion workflows. No online service can guarantee absolute security. ExpatPilot does not claim “bank-grade” security or that every processor is located in the EU.
AI can classify documents, extract fields, suggest tasks or a journey, identify potential deadlines, and generate text. Suggested tasks and journey links remain previews until you explicitly confirm them. AI does not make decisions binding on authorities or other third parties and cannot change your journeys, tasks, deadlines, or documents through chat. Review, correct, disregard, or delete generated information and verify consequential outputs.
9. Permissions and choices
The app may request camera/photo/file access for a document, notification permission for reminders, and calendar access when you choose to add a deadline. You can refuse or withdraw device permissions, though the related feature may not work. Notification preferences are managed in the app.
10. Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, portability, or object to legitimate-interest processing, and withdraw consent for the future. The app includes data-export and account-deletion tools. Contact admin@expatpilot.de; identity verification may be required.
You may complain to the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany, or another competent supervisory authority. Website: datenschutz-hamburg.de.
11. Changes
We may update this policy when features, providers, legal requirements, or processing activities change. Material changes will be communicated appropriately. The current version remains available at this URL.