Privacy policy

Version of 4 October 2026, updated the same day: sync between devices enabled, flight status added. This is a translation; if it differs from the Russian version, the Russian version prevails.

In short. Your trips and document details are stored on your device and in your account on our server, so they are available on all your devices. Document scans are stored on your device only. The server also keeps your email address, your name from Google and information about your sign-ins. We do not sell data, show ads or track you: site visits are counted without cookies or anything that identifies a person, and the app counts nothing. You can delete your account in the app with one button.

1. Who is responsible for your data

Apus (apus.page) is run by a private individual, German Galimov, Argentina, who is the data controller.

For any question about your data, write to [email protected].

2. What data we keep and where

Only on your device, never sent to us. Scans and photos of documents, settings. Text recognition on scans runs on your device; the scans themselves are not sent anywhere.

On your device and in your account on the server, so they are available on all your devices: trips (country, dates, passport, means of transport, notes), passports, visas, residence permits and other permits (country, type, number, dates, notes), records of overstays and entry bans, and rules you created yourself. The app sends them automatically when you change something.

On the server, only if you sign in:

Sync between devices is on for everyone who is signed in. Data on the server is not encrypted with a key of your own: it is protected by HTTPS and Cloudflare disk encryption, but it is technically accessible to the operator of the service. The operator does not browse it and accesses the database only for maintenance and fixing faults.

Checking entry rules. When you refresh a country's rules, only a pair of country codes (destination and passport) goes to our server and from there to an AI provider, with nothing about you, your dates or your documents. The answer is saved in the shared reference data.

Flight status. If a plane trip has a flight number, the app shows its status and, if reminders are on, tells you about delays, cancellations and boarding. For this our server sends the flight data provider AeroDataBox (via the RapidAPI or API.market marketplace) only the flight number and date, without your name, email, trip country or documents, and only when the status is requested or the flight is watched for notifications, that is on the day of departure and the day before. We keep the answer for up to a week. A "Share flight" link shows only the flight itself: number, airports, times, terminal and gate; it stops working three days after the flight or when you revoke it. "Send ticket" sends the ticket file straight from your device through the system share menu; it does not pass through our server.

Technical data. Our hosting provider, Cloudflare, processes IP addresses and request times to deliver the site and protect it from attacks. We keep no visitor logs of our own.

Counting site visits. apus.page (but not the app at app.apus.page) uses Cloudflare Web Analytics: page views, referrers, country, device type and load speed. It sets no cookies, does not recognise a visitor between visits and collects nothing that identifies a person.

Error reports. If the app crashes, it sends our server the error text, the place in the code, the page path without parameters, the build number and the browser type — none of your trips, documents or email. We use this to find and fix faults and keep reports until the fault is fixed.

Messages from the app. If you write to us via Contact us, we keep the message and your account email so we can reply.

3. What we do not do

4. Why we process data

5. Who receives data

Data may therefore be processed outside your country, including in the USA. We work with providers that commit to protecting data. Data may be disclosed to public authorities only when legally required.

6. How long we keep data

7. How data is protected

Connections use HTTPS only. Your sign-in key is kept in a cookie that page scripts cannot read; the server stores only a fingerprint of the key, which cannot be used to sign in. Administrators see users' email, name, role and last visit; they do not see your trips or documents in the app.

8. Cookies and browser storage

We use only essential cookies:

Browser storage holds your data and app settings. There are no advertising or analytics cookies, so no consent is needed for them.

9. Your rights

Wherever you live, you can:

Send requests to [email protected]. We reply within 30 days. We may ask you to confirm that the request comes from the account holder.

Residents of Argentina: the supervisory authority under Personal Data Protection Law No. 25.326 is the Agencia de Acceso a la Información Pública (AAIP), which handles complaints about data protection breaches. Residents of the EU and the UK have rights under the GDPR, residents of Brazil under the LGPD (authority: ANPD), and residents of California under the CCPA: we do not sell or share personal information within the meaning of that law.

10. Children

You must be 16 or older to create an account. If we learn that an account belongs to someone younger, we will delete it.

11. Changes to this policy

We will announce significant changes in the app in advance. The date of the current version is shown at the top of this page.