Privacy notice

Starter and Complete storage

Local Starter stores moving plans and four supporting lists in IndexedDB in your browser. We do not receive those entries unless you preview and confirm an import into Complete.

Complete stores authenticated workspace rows, relationships, actor history, reminder preferences, annual snapshots, access metadata, and tombstones in Neon. Signed-in devices keep an offline IndexedDB cache. Original documents are not uploaded.

Collaboration and access links

An owner can invite one adult collaborator with a manually shared single-use link. Neon stores a token hash, not the bearer token. Revocable summary and calendar links also keep token hashes server-side. A private calendar feed excludes notes, contact details, and record labels.

Connected household planning

The local connected-planning candidate stores household country labels and explicit time zones, plan answers and anchors, task connections, user-entered record expiration dates, renewal rules and saved calculation inputs and assumptions. Country labels are planning context, not verified residence. These structures are included in cloud exports and account deletion.

Source preferences and checking

Complete stores the sources you choose to follow, your acknowledgement or dismissal of factual page-change notices, and follow-up tasks you request. Central source checks retain bounded operational fingerprints and failure classifications, not complete fetched pages or household information. A page change is not a finding that a law or your obligations changed.

Worldwide calendar-provider retrieval

Only a valid read-only calendar bearer endpoint can be fetched worldwide, including by UK and EEA calendar infrastructure. Feed creation and management remain authenticated and region-restricted. Other private features keep their UK and EEA restrictions. Feed verification records customer-reported observations, not remote access to the customer’s calendar.

Copies, collaboration and revocation

A household shares its workspace with one adult collaborator without private compartments. Removing that collaborator revokes existing household feeds and summary links. Revocation stops future requests but cannot erase downloads, exports or offline copies. The removed browser clears its Complete cache when it next receives the revoked state.

Notifications and sessions

Web Push and application reminder email are not included in this release. Session controls use Neon Auth metadata and do not place raw IP addresses, user agents, or tokens in the workspace or account export.

Providers and deletion

Vercel hosts the service. Neon provides the database and authentication. Google provides optional sign-in. Paddle acts as Merchant of Record if paid orders open. Account deletion cancels an active subscription, deletes Neon workspace data and Neon Auth, then clears Complete device caches.

Contact

Email hello@usexpatdesk.com for a privacy request.