✓StayLimit
DE EN ES

Legal

Privacy Policy

Last updated: 23 July 2026

No user tracking data on our servers. Your travel data stays encrypted on your device. Personal cloud sync is planned but is not currently active.

1. Controller

The controller for data processing on this website and in the app is:

chocosite LLC
3833 Powerline Rd, Suite 201
Fort Lauderdale, FL 33309
USA

Privacy enquiries: please send an e-mail to mail [at] stay-limit [dot] com.

2. EU Representative pursuant to Art. 27 GDPR

Dirk Murrnautzky
Phone: +49 173 585 91 00
E-mail: dirk [at] chocosite [dot] info

3. Core principle of the app

StayLimit is local-first. Travel, location, and visa data is processed on-device and stored encrypted in the native iOS and Android app by default. No personal or central cloud sync is currently active. Personal sync through iCloud or Google Drive is planned as a future Pro feature and will only be used after it is explicitly enabled. StayLimit does not store user tracking data, movement profiles, or complete travel histories on its own servers.

4. Data processed in the app

  • Travel data such as country, entry date, and exit date
  • When location detection is enabled: precise foreground and background location data. Coordinates are assigned to a country locally; only a country-level trip suggestion is stored, and the raw coordinates used for it are then discarded.
  • When photo import is used: access to the photo library and local analysis of GPS metadata in photos from the last 365 days. Photos and coordinates are not sent to StayLimit or a geocoding service.
  • Optional custom areas, place information, and personal labels
  • Nationality, passport, or profile details for selecting applicable rules
  • Visa, tax, and country alerts as well as entries in the local notification archive
  • App settings, Pro status, and purchase status
  • Optional: content from e-mail enquiries about visa rules, support, press, or partnerships

5. Purposes and legal bases

Processing is carried out to provide app functionality, manage travel history and settings, handle enquiries, fulfil Pro feature contracts, and comply with legal obligations. Legal bases include Art. 6(1)(b) GDPR for contractual and pre-contractual performance, Art. 6(1)(f) GDPR for legitimate interests in secure operation, support, and product improvement, and Art. 6(1)(c) GDPR for legal obligations. Location, photo, and notification features are used only after the relevant operating-system permission is granted. Permissions can be changed or withdrawn at any time in device settings.

6. Website and hosting

This website is hosted by ALL-INKL.COM, Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. When the website is accessed, technical access data may be processed, including IP address, date and time of access, file requested, data volume transferred, browser and operating system data, and referrer URL. Processing serves the secure and stable operation of the website.

7. E-mail contact

When you contact us by e-mail, we process your e-mail address, the content of your message, and associated communication data in order to respond to your enquiry. Depending on the content, retention may be necessary for traceability of support or contractual matters.

8. Purchases, subscriptions, and app stores

Digital purchases, subscriptions, and lifetime unlocks are processed via the Apple App Store or Google Play. Apple or Google process payment, device, account, and transaction data under their own terms. StayLimit generally receives only the information needed to verify and activate purchase status, not complete payment data.

9. Recipients and third countries

Personal data may be transferred to technical service providers, hosting providers, app store operators, or communication services where necessary for operation, support, security, or contract performance. Travel, location, photo GPS, and profile data is not currently sent to a cloud provider or central StayLimit service. Since the controller is based in the USA and individual services may be operated outside the EU, transfers to third countries may occur. In such cases, appropriate GDPR safeguards are applied where required.

10. Retention and deletion

Locally stored app data remains on the device until it is deleted in the app or the app is removed. Notification archive entries are stored for no more than 365 days. Photo GPS data is evaluated only during import; raw location coordinates are not retained as travel history after local country assignment. Plain-text backup export is currently disabled for privacy. E-mail enquiries are deleted once they are no longer needed for processing, unless statutory retention periods apply. Technical server logs are retained only as long as necessary for security, error analysis, and operation.

11. Security

We apply appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access. In the native iOS and Android app, sensitive local data is stored in a database encrypted with SQLCipher. The database key is device-bound and kept in the operating system's protected key storage. The app is additionally protected by Face ID, fingerprint, or the device passcode. Android backups and screenshots are disabled; on iOS, sensitive content is covered in the app switcher. These measures complement, but do not replace, secure device configuration.

12. Our own visitor analytics

This website uses no advertising networks, no marketing cookies and no behaviour-based tracking. To understand how the site is used, we operate our own privacy-friendly visitor analytics on our own infrastructure. No external analytics providers are involved, and no data is passed on to advertising or analytics services.

What we record: the pages viewed and their order, the content sections that became visible within a page and therefore the last section reached, the broad origin of the visit (direct, Google, Bing, Instagram, Facebook, Pinterest, AI services, other), the device class (desktop, tablet, mobile), and the opening and successful submission of a form. We do not record form contents, your name, email address or IP address. The analytics never receives an IP address and never stores one.

Two randomly generated identifiers for visit and session are stored in your browser's local storage; a session ends after 30 minutes without activity. Individual visitor paths are deleted after no more than 72 hours. Only anonymous daily counters are kept permanently.

Consent: from Germany, the EU/EEA, the United Kingdom and Switzerland, and where the country of origin cannot be determined, we only record after your consent; the notice offers “Reject” and “Accept” as equally weighted options. From other countries, recording takes place without a prior dialogue and can be switched off at any time via “Privacy settings” in the footer. The country is determined exclusively on the server; the IP address is not passed to the visitor analytics. The legal basis is Art. 6(1)(a) GDPR where consent is required, otherwise Art. 6(1)(f) GDPR (legitimate interest).

13. Rights of data subjects

Under the GDPR, you have rights of access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you may withdraw that consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority.

14. Contact for privacy enquiries

Privacy enquiries: mail [at] stay-limit [dot] com.

Back to home
Legal Notice Privacy settings Privacy Terms
© chocosite LLC · StayLimit · All rights reserved No legal or tax advice. @stay.limit.app