←COUNTLY
COUNTLY

Privacy Policy

Effective 18 September 2026 · Countly, by Endless River Labs Ltd.

With Countly, privacy isn't a setting — it's the architecture. The short version: the location your phone reads, and the day-by-day country history Countly builds from it, stay on your device. There's no account, and by default none of what you track is sent to us or anyone else. This page explains exactly what that means.

In short

  • Countly works out which country you're in from your phone's location, and counts the days you spend in each one.
  • All of that — reading location, resolving the country, counting days — happens on your device.
  • Your location and your history are never uploaded to Endless River Labs Ltd. There's no account system, and we can't see your data.
  • Anonymous product analytics are enabled by default through PostHog in the EU and can be fully disabled in Settings. They record only fixed app interactions and never your location or anything you track. A separate attribution tool measures our advertising; neither tool uses travel data for ads (see Product analytics and Measuring our ads).
  • Limited data can leave your device for a store purchase, anonymous product analytics while enabled, an OS backup you switched on, a report you export, advertising measurement, or an optional crash diagnostic.

Who we are

Countly is developed and operated by Endless River Labs Ltd. ("we", "us", "our"). If you have any question about this policy or your privacy, email us at privacy@endlessriver.xyz.

Your location

To count your days, Countly needs to know which country you're in — including while the app is in the background. With your permission, it reads your device's location and, on the device itself, converts it to a country using an offline map. There's no network request for this, even when you're abroad or roaming. From that, Countly keeps a record like "12 March 2026 · Portugal".

  • Your raw location is processed on your device and is not transmitted to us or any third party.
  • Countly stores the result — a country and a date — on your device, not a trail of the precise coordinates of where you were.
  • You can change or withdraw location permission at any time in your device settings. Without background location, automatic counting pauses and you can add days by hand.

What's stored, and where

Everything Countly knows lives in a database on your device: your country-by-day ledger, trips and stays you add or edit, notes you write, the documents and receipts you generate, the rules you set up (residency thresholds, the Schengen 90/180, visa limits), your notification preferences and app settings. Countly does not upload this database — your location and travel history, stays, notes, generated documents and receipts are never sent to analytics of any kind. There is no Countly account, no sign-up, and no cloud sync operated by us, and nothing the app sends can be tied directly to your identity or a personal profile. You can also lock the app behind Face ID, Touch ID or your device biometrics.

Photo History (optional, iOS and Android)

Only after you choose to allow it, Countly can scan the photo library that iOS or Android makes available to suggest past stays. It reads only each asset's creation date and embedded location metadata. The scan, reverse geocoding and trip inference happen entirely on your device. Countly never reads or uploads the image or video itself, thumbnails, filenames, albums or asset identifiers, and it never changes your library. Suggested stays are not saved until you review and import them. Only the resulting country and date ranges are then stored on your device; photo metadata and coordinates are not retained or sent anywhere. Full, limited or selected-photo access is supported where your operating system offers it, and you can change or withdraw permission at any time in device Settings.

What we don't collect

Because "we value your privacy" means nothing on its own, here's the specific list. Countly contains:

  • No location or travel content in analytics — PostHog never receives country history, dates, stays, trips, notes, rules, documents, receipts or free text.
  • No third-party trackers inside the app apart from those described on this page — anonymous product analytics, purchase infrastructure, advertising measurement and optional crash diagnostics. None receives your location or travel history.
  • No social logins, and no access to your contacts, calendar or microphone. Optional Photos access on iOS and Android is limited to the on-device Photo History process described above.
  • No profiling, and no selling or renting of your data. Your location and travel history are never shared with anyone.

Product analytics

To understand where people complete or leave Countly's onboarding and which features need improvement, the app sends anonymous product analytics through PostHog, hosted in the EU. It is enabled by default and can be fully disabled with the existing Anonymous analytics switch in Settings. It never touches anything you track.

  • You are represented only by a resettable anonymous installation ID. There is no account, and no name, email or personal profile is attached.
  • Events are limited to fixed screen, onboarding, product and paywall categories. There is no session replay and no automatic capture of your input.
  • It never receives your location or travel content — no country history, dates, stays, trips, rules, notes, documents, receipts, free text or transaction IDs — and no location is derived from your IP address (no GeoIP).
  • Turning Anonymous analytics off in Settings stops product analytics immediately and clears queued events. You can also reset the analytics identity so future events cannot be linked to earlier ones.

PostHog processes this limited event data as our service provider. While the switch is off, no PostHog product-analytics data leaves your device.

Measuring our ads

Countly is only useful if people can find it, so we run ads on platforms such as TikTok, Yandex and others. To avoid wasting that budget, we need to know which ad actually led to an install. For that single purpose — and nothing else — the app includes a standard attribution tool, Singular. Here is exactly what it does, and what it deliberately does not:

  • It records that an install happened and which ad campaign it came from, and that the app was opened. Store-verified Countly Pro trial, purchase, renewal, cancellation and refund events reach it server-side from RevenueCat, our purchase provider, so ad spend can be compared with real revenue. Matching an ad to an install and its outcome is its whole job.
  • It is used only to measure advertising. It is never matched to your name, email or any personal profile — we don't hold those to begin with.
  • It never receives your precise location or travel content. For ad attribution, Singular may receive network information such as an IP address and derive an approximate location from it; Countly does not send your device location, country history or anything else you track.
  • It receives only a small fixed set of milestone events — onboarding completed, Photo Rewind used, first rule created, paywall viewed and checkout started — so ad platforms can optimise for people who actually use Countly. These events carry no screens beyond those steps, no taps and nothing you've tracked, and they stop when you turn off analytics in Settings.
  • On iOS, Countly shows Apple's App Tracking Transparency prompt. If you allow tracking, Singular may use the IDFA solely to match an ad to an install and measure the campaign. If you decline, no IDFA is available and attribution remains aggregated through Apple's privacy-preserving systems. On Android, Google's Advertising ID may be used where available — you can reset or limit it at any time in your device's privacy settings.

Singular processes this limited install, milestone and purchase data as our service provider, and shares the attribution result with the ad platform that delivered the install so it can measure the same campaign. That is the full extent of it: an install, a campaign, a few milestones and purchase outcomes — never your travels, and never your location.

This website

The Countly landing page keeps privacy-safe daily totals so we can distinguish a real page load from an advertising-platform click and see whether visitors use the App Store or Google Play buttons. This counter works without cookies or local storage and does not create a visitor, device or session profile.

  • We store only the UTC date, a broad source bucket (Yandex or other), the event type, and the aggregate count.
  • We do not write an IP address, user agent, referrer, device ID, session ID or raw campaign parameters to the metrics database.
  • Our hosting and database providers necessarily process network requests to deliver the website, but the aggregate counter does not pass request identifiers into its stored records.
  • Our /download link sends you to the App Store or Google Play. Each tap records one anonymous PostHog event with only the social network the link was shared on (for example TikTok), an optional campaign label, and whether you were on iOS, Android or another device. No cookie, IP address, user agent or device identifier is sent, and the event cannot be linked to any other visit. The store link carries the same source label so Apple and Google can report which network an install came from.
  • Separate Google Analytics measurement loads only after you make a choice in the website's consent banner. Advertising storage remains disabled.

Crash reports (optional, no personal data)

So we can find and fix the bugs that crash the app, a published build of Countly may send anonymous crash reports through Sentry, a crash-reporting service. When this is active:

  • It sends only technical crash information — the error and stack trace, app version, OS version and device model.
  • It is configured to attach no personal data, and it never includes your location, your country history, or anything you've tracked.
  • It captures crashes only — there is no behavioural, performance or session tracking.
  • Reports are scrubbed before sending and used solely to make the app more stable.

Sentry processes this limited data as our service provider. If a build ships without a crash-reporting key configured, this is switched off entirely and nothing is sent.

Purchases (Countly Pro)

Some features are part of Countly Pro, a paid subscription or one-time purchase. Payments are handled entirely by Apple's App Store or Google Play — we never see or store your card or payment details. To unlock and validate a purchase, the store gives Countly limited transaction information (for example, whether a subscription is active). Apple's and Google's handling of your purchase is governed by their own privacy policies.

Purchases are restored and managed with RevenueCat, a purchase-infrastructure service. RevenueCat processes anonymous purchase and subscription state together with the store transaction and receipt identifiers issued by Apple or Google — to restore your entitlements, run paywall experiments, and understand subscriptions. It never receives your location, your travel content, or anything else you track.

Backups and exports

  • OS backups. If you turn on iCloud Backup (iOS) or Google / device backup (Android), your Countly data may be included in that backup, stored by Apple or Google under their terms. We have no access to it.
  • Exports you create. Countly can export your history as a PDF or CSV, or a data file you can re-import. Once you share or save an exported file, it goes wherever you send it and is no longer governed by this policy.

Notifications

Countly's reminders — approaching a threshold, entering a country, optional weekly or monthly digests — are local notifications generated on your device. We don't operate a push server, and no data leaves your device to deliver them.

Permissions we ask for

Countly requests only what it needs to do its job:

  • Location (including "Always" / background) — to detect the country you're in and count days automatically.
  • Notifications — to alert you before you reach a limit or threshold.
  • Run after restart (Android) — to resume counting after your phone reboots.

You can review or withdraw any of these at any time in your device settings.

Children

Countly is not directed to children, and we don't knowingly collect personal information from children under 13 (or under 16 in the EEA / UK). Because Countly keeps your data on your own device, this generally won't arise — but if you have a concern, please contact us.

Your rights and control

Because your data lives on your device, you hold the controls directly:

  • View, edit or delete any trip or day in the app.
  • Erase all Countly data from within the app, or uninstall the app to remove everything.
  • Export your data whenever you like.

Privacy laws such as the GDPR and the CCPA give you rights to access, correct, delete and port your personal data, and not to be treated unfairly for exercising them. We honour these — and in practice there is very little for us to act on, because we don't hold your personal data on any server. If you've emailed us, or an anonymous crash report has been sent, you can ask us about that information.

To request access to or deletion of the little we may hold — an email you sent us, an anonymous crash report, or a resettable anonymous analytics identifier — write to privacy@endlessriver.xyz.

International users

Countly processes your data on your device, wherever you are in the world. The limited third parties involved — Apple, Google, Vercel, Supabase, PostHog (anonymous product analytics, hosted in the EU), RevenueCat (purchase infrastructure), Singular (advertising measurement), and (if enabled) Sentry — process data in their own jurisdictions under their respective policies and safeguards.

Changes to this policy

If we change this policy, we'll update the "Effective" date above and flag any material change in the app or here. Continuing to use Countly after a change means you accept the updated policy.

Contact

Questions about privacy? Email us at privacy@endlessriver.xyz.