Privacy policy (Datenschutzerklärung)
Last updated: 2 October 2026
The short version. Your visa and immigration data is never shared with any third party, including employers and universities, without your explicit consent for each individual disclosure. Uploaded payslips are never stored. We read them in memory, keep only the dates and hours you confirm, and delete the document within seconds. Permit Radar is a free, non-commercial student project. We do not sell data, show ads, or use your data for marketing. You can download or delete everything at any time in Settings.
1. Who is responsible
Controller under Art. 4(7) GDPR:
Akram El Basri Huntemannstraße 2, Apt. 02/0209 26131 Oldenburg, Germany Email: seasonedwebdev@gmail.com Phone: +49 155 10951726
Permit Radar is run by one private person as a free, non-commercial student project. A data protection officer is not required (fewer than 20 people process personal data, § 38 BDSG). For every privacy question, contact the address above.
2. What we collect and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Name, email, password (stored only as an argon2id hash), language | Your account, sign-in, service emails | Art. 6(1)(b) contract |
| Visa type, your configured limits, permit and Fiktionsbescheinigung expiry dates | Calculating your usage and warning you | Art. 6(1)(b) contract |
| Work entries: date, hours, optional employer name and note | Calculating your usage | Art. 6(1)(b) contract |
| Document checklist and expiry dates, Ausländerbehörde appointment | Reminders | Art. 6(1)(b) contract |
| Change history of your limits, work entries and documents (audit log) | Integrity of your record, your own reference | Art. 6(1)(b) and (f) |
| Reminder history: which reminder was sent and when | Never sending the same reminder twice | Art. 6(1)(b) contract |
| Security and activity records (section 4) | Protecting the service against abuse | Art. 6(1)(f) legitimate interest |
| Anonymous counts of page views and clicks (date, page or button, number) | Knowing how the site is used | No personal data |
| Analytics events with a visitor cookie (section 6) | Recognizing returning visitors | Art. 6(1)(a) consent, § 25(1) TDDDG |
| Your consent choices with timestamp | Proving consent | Art. 6(1)(c) legal obligation |
Information about your residence status is sensitive. We restrict access to it in code: even the administrator of Permit Radar cannot view your work log, visa data or documents through any admin screen.
You must be at least 16 years old to create an account.
3. Payslip uploads: processed, never retained
If you upload a payslip to fill in your hours:
- The file is processed transiently, in server memory only. It is never written to disk, never stored in our database, and never kept in backups.
- Text is read from the file directly (digital PDFs) or with text recognition that runs on our own server (photos and scans). No third-party service sees the document.
- From that text we derive only: a date or pay period, the number of hours, and, if listed, the number of work days. Everything else on the payslip, including your salary, tax ID, social security number, bank details and address, is discarded together with the file.
- Nothing is saved until you confirm. You see the values first and can edit them. Only the dates and hours you confirm are stored, as ordinary work entries.
- The document, its text and its values are never written to logs, error reports or analytics. We record only that an upload was processed and whether it was readable, for abuse prevention.
- Legal basis: Art. 6(1)(b) GDPR. Retention of the document: none.
You can always enter your hours manually instead.
4. Security monitoring and activity tracking
We record security-relevant events for every account and network: sign-ins and failed attempts, new devices used to sign in (a random device ID and the browser type, such as "Chrome on macOS"), sign-outs, password changes, requests per day, rate-limit hits, blocked requests, failed security checks, suspected session theft, and your last activity time. We combine these into a risk level to detect abuse.
- Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in keeping the service secure and available, and Art. 32 GDPR.
- IP addresses are never stored by us in plain form. We store a keyed one-way hash (HMAC-SHA256) so repeated abuse from one network can be blocked.
- Retention: activity records 180 days, request counters 90 days.
- You can object under Art. 21 GDPR. Because these records are needed to run the service safely, an objection may require closing the account.
5. Hosting and server log files
When you open Permit Radar, your browser sends technical data to our hosting providers: IP address, date and time, the page requested, browser type and operating system. The providers process this in their server logs to deliver the website and defend against attacks.
- Legal basis: Art. 6(1)(f) GDPR (secure and reliable operation).
- Retention: according to the provider's log retention, usually a few days to 30 days.
- The providers act as our processors (section 8).
6. Cookies and browser storage
Essential (always on, § 25(2) TDDDG): session cookies to keep you signed in, a CSRF security cookie, a sign-in hint, a device ID that lets us warn you about sign-ins from new devices, and your cookie choice. Details are in the cookie policy.
Browser storage (essential): we store two small flags in your browser, not on our servers: that you dismissed the disclaimer banner for this session (sessionStorage), and that you finished the guided tour (localStorage). They contain no personal data and only change what the page shows you.
Analytics cookie (only with consent): if you click Accept, we set a random visitor ID (pr_vid) and record page views and clicks with it, plus a one-way hash of your shortened IP address. This lets us count returning visitors. If you reject or withdraw consent, we delete the events linked to that ID and remove the cookie. Without consent we still count page views and clicks as plain numbers per day, with no cookie and no identifier of any kind.
We use no third-party analytics, advertising or tracking pixels. Fonts are served from our own servers, not from Google.
7. Bot protection (Cloudflare Turnstile)
Sign-in, registration and password reset are protected by Cloudflare Turnstile to stop automated attacks. When the check loads, Cloudflare processes technical data from your browser, including your IP address, to tell humans from bots. Turnstile sets no tracking cookies and the data is not used for advertising.
- Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
- Legal basis: Art. 6(1)(f) GDPR (protecting accounts and the service from abuse).
- Transfer to the USA: Cloudflare is certified under the EU-US Data Privacy Framework.
8. Processors and recipients
We use these service providers under data processing agreements (Art. 28 GDPR):
| Provider | Purpose | Location of data |
|---|---|---|
| MongoDB, Inc. (MongoDB Atlas) | Database | Frankfurt, Germany (EU) |
| Railway Corporation | Running the API server | EU region |
| Vercel Inc. | Hosting the website | EU-US Data Privacy Framework; content delivered from servers near you |
| Resend, Inc. | Sending emails | EU-US Data Privacy Framework |
| Cloudflare, Inc. | Bot protection (section 7) | EU-US Data Privacy Framework |
Transfers outside the EU rely on the EU-US Data Privacy Framework (Art. 45 GDPR) or EU standard contractual clauses (Art. 46 GDPR).
We never share your visa or immigration data with employers, universities, authorities or any other third party without your explicit consent for that specific disclosure, unless a court or authority legally compels us. If you download a summary and give it to someone, that is your own decision.
9. Retention
| Data | Kept |
|---|---|
| Account, limits, work log, documents, audit history | Until you delete your account |
| Inactive accounts | Warning email after 5 months without sign-in; deleted 30 days later unless you sign in |
| Accounts never confirmed by email | 7 days |
| Suspended or banned accounts | Kept as long as needed to prevent abuse, at most 2 years |
| Security and activity records | 180 days |
| Request counters | 90 days |
| Reminder history | 13 months |
| Analytics events (with consent) | 13 months, or until you withdraw consent |
| Anonymous page view and click counts | Indefinitely (no personal data) |
| Sign-in sessions | 30 days |
| Email confirmation and reset links | 24 hours and 30 minutes |
| Uploaded payslips | Not retained. Deleted from memory within seconds |
| Database backups at MongoDB Atlas | Overwritten on the provider's backup schedule, at most 30 days |
10. Your rights
You have the right to:
- access your data (Art. 15) and portability (Art. 20): Settings, "Download my data" gives you everything as JSON;
- rectification (Art. 16): edit your data in the app at any time;
- erasure (Art. 17): Settings, "Delete my account" erases everything immediately and permanently;
- restriction (Art. 18) and objection (Art. 21): email us;
- withdraw consent at any time with effect for the future (Art. 7(3)): Settings, Privacy, or the cookie banner;
- lodge a complaint with a supervisory authority (Art. 77). Ours is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, lfd.niedersachsen.de.
We answer requests within one month.
11. Security
Passwords are hashed with argon2id. Sessions use short-lived tokens in secure, httpOnly cookies with rotation. Every request is checked against your account on the server. All connections are encrypted (HTTPS). Access to your data is limited by design.
12. Automated decisions
The risk level described in section 4 may lead to automatic rate limiting or a temporary network block. Account suspensions and bans are decided by a person. You can contest any measure by emailing us.
13. Changes
We will announce material changes to this policy by email or in the app.