Plain-language summary: Granted keeps your immigration records on your device and in your own iCloud, where only you can access them. The only things on our servers are your sign-in details and any anonymous community timeline you choose to share. We never sell your data, never show ads, and you can delete everything at any time. Your documents are yours.
1. Overview
Granted processes personal data belonging to non-EU nationals living in Ireland. This data includes immigration status, document metadata, and identity information used for authentication. This policy defines how that data is collected, stored, processed, and protected in compliance with the General Data Protection Regulation (GDPR) and the Irish Data Protection Acts 2018.
As the developer and operator of Granted, the individual developer acts as the Data Controller for all personal data processed through the app. Third-party services (Firebase / Google — including Cloud Messaging, Apple iCloud and push delivery, RevenueCat) act as Data Processors under their respective data processing agreements. Anthropic is named in this policy for transparency only — the AI-assisted features that would use it are not currently active (see §2.4).
1.1 Data Controller
Name: Naveen George Thoppan, trading as Granted Apps
Contact: privacy@getgranted.ie
Address: Workhub, 6 Fern Road, Sandyford Business Park, Dublin 18, D18 FP98, Ireland
As an individual developer (sole trader) based in Ireland, Naveen George Thoppan is personally responsible for GDPR compliance under the Irish Data Protection Acts 2018.
1.2 Legal Bases for Processing
| Data Type | Legal Basis | GDPR Article |
|---|---|---|
| Anonymous session (no personal data) | Legitimate interest | Art. 6(1)(f) |
| Firebase UID + email (registered users) | Contract — to create and operate your account | Art. 6(1)(b) |
| Stamp records (IRP type, dates) | Contract — to provide the app's core tracking functionality | Art. 6(1)(b) |
| Absence records (travel dates, destination) | Contract — to provide the app's core tracking functionality | Art. 6(1)(b) |
| Document metadata (filename, type, year) | Contract — to provide the Pro Document Vault you purchase | Art. 6(1)(b) |
| Application Timeline submission (anonymous milestone dates) | Consent — optional community sharing | Art. 6(1)(a) |
| OCR text from IRP card scan (planned — not currently active) | Consent — optional Pro feature, if introduced | Art. 6(1)(a) |
2. Data Inventory
2.1 Data We Store
| Data | Where stored | Retention | Who can access |
|---|---|---|---|
| Firebase UID (anonymous) | Firebase Auth (Google) | Indefinitely, unless the user deletes their account (Settings → Delete My Account) — no automatic expiry is currently configured | Developer via Firebase Console |
| Email address (if registered) | Firebase Auth (Google) | Until account deleted | Developer via Firebase Console |
| Display name (if provided) | SwiftData, synced via Apple CloudKit to your own iCloud so it follows you across your own devices. A copy is also held in your Firebase Authentication account record (see §2.3). | Until user deletes; the account-record copy until account deleted | User (on your own signed-in devices); developer via Firebase Console for the account-record copy |
| Stamp records (type, dates, notes) | SwiftData, synced via Apple CloudKit to your own iCloud so it follows you across your own devices. Developer never has access. | Until deleted by user | User only (on your own signed-in devices) |
| Absence records (travel dates, destination) | SwiftData, synced via Apple CloudKit to your own iCloud so it follows you across your own devices. Developer never has access. | Until deleted by user | User only (on your own signed-in devices) |
| Document metadata (filename, type, year) | SwiftData, synced via Apple CloudKit to your own iCloud so it follows you across your own devices. Developer never has access. | Until deleted by user | User only (on your own signed-in devices) |
| Document files (PDF, images) | User's iCloud container — all subscription tiers. Developer never has access. | Until deleted by user | User only (encrypted in transit and at rest under Apple's iCloud security policies) |
| Application Timeline submission (anonymous, opt-in) | Firebase Firestore (Google) | Deleted after 3 years | Anonymous — not linked to device or account (see §2.5) |
2.2 Data We Do NOT Store
- IRP card photographs — card scanning (OCR) is not enabled in the current release; if activated in a future release, images would be held in memory only during extraction, then immediately discarded
- Passport photographs or biometric data of any kind
- Payment information — all payment processing is handled exclusively by Apple and RevenueCat
- Location data — the app never requests location permission
- Device identifiers for advertising — no advertising SDKs are used
- Health or biometric data
- Children's data — the app is intended for adults (18+) and is not directed at children; we do not knowingly collect or process children's data
2.3 Third-Party Data Processors
| Processor | Location | Data Shared |
|---|---|---|
| Firebase / Firestore (Google) | Firestore is hosted in the europe-west1 region (Belgium, EU) — your anonymous Application Timeline data does not leave the EU. Firebase Authentication does not offer a selectable region; any transfer outside the EEA is covered by Google's Standard Contractual Clauses and EU–US Data Privacy Framework certification (GDPR Art. 46) | Firebase Auth: UID, email address, display name (if provided), authentication tokens. Firestore: anonymous Application Timeline submissions only (see §2.5). Google's Firebase Data Processing and Security Terms apply automatically upon accepting Firebase's Terms of Service. |
| Firebase Cloud Messaging (Google) | Cloud Messaging does not offer a selectable region; any transfer outside the EEA is covered by Google's Standard Contractual Clauses and EU–US Data Privacy Framework certification (GDPR Art. 46) | Only if you turn on immigration news notifications. A push registration token generated by your device, and the fact that your device is subscribed to our single Ireland-wide news topic. No account link, no stamp or permit information, and nothing about your immigration status is shared — every subscriber receives the same broadcast. Turning the toggle off unsubscribes your device. |
| Apple (Push Notification service) | Apple infrastructure | Delivers the push notification to your device, under Apple's own DPA. Applies only if you turn on news notifications. |
| Anthropic (AI — not currently active) | USA (planned) | No data is sent to Anthropic in the current release. AI-assisted features (card scanning, eligibility chat) are disabled; if enabled in a future release this policy will be updated before any data is transferred. SCCs would cover any future EU–US transfer. |
| Apple iCloud | User's iCloud region | Document files (PDFs, images), plus your stamp, absence, profile, and document-metadata records (synced via Apple CloudKit so they follow you across your own devices). Processed under Apple's own DPA. Developer never has access to any of it. |
| RevenueCat | USA | Apple ID receipt data (subscription status and purchase history). For anonymous users, RevenueCat also uses a device identifier (Apple's IDFV) to identify your subscription before a registered account exists — this identifier is used only for this app-functionality purpose and never for advertising or tracking (see §2.2). No payment card data. SCCs apply. |
2.4 AI Features (Not Currently Active)
Earlier versions of this policy described AI-assisted features — IRP card scanning via optical character recognition (OCR) and an AI eligibility chat — that would send text to Anthropic in the United States. These features are disabled in the current release and no data is sent to Anthropic. No names, OCR text, or other personal data are transmitted to the United States by the app. If these features are introduced in a future release, this policy will be updated and the relevant consent and transfer disclosures provided before any data is processed.
2.5 Application Timeline (Opt-In Community Sharing)
The app includes an optional, community-powered Application Timeline feature. It is off by default and only operates when you actively choose to share.
- What is shared: when you choose to contribute, the app sends a single anonymous submission to Firebase Firestore (Google) consisting of a randomly generated identifier (not linked to your device or account), your country code, and your application milestone dates only. No name, no document content, and no device or account identifiers are included.
- Legal basis: consent (GDPR Art. 6(1)(a)). Sharing requires a registered (non-anonymous) account and is entirely voluntary.
- Retention: shared submissions are deleted after 3 years.
- Your control: you can remove your shared data at any time from within the app.
- Reading benchmarks and news: the app also reads anonymous, aggregate community benchmarks and immigration news. Reading this content involves no personal data and does not require an account.
3. Your Rights
Under GDPR, you have the following rights:
3.1 Right of Access (Article 15)
You can request a copy of all personal data we hold about you. We will respond within 30 days. Contact: privacy@getgranted.ie. What we can provide is your Firebase account record (account ID, email address, and display name). Your stamp, absence, and document records are stored only on your device and in your own iCloud — we have no access to them, so we cannot send them to you; you can export them yourself at any time (see §3.3). To protect your account, if the email address on your account has not been verified we will not send your account details by email; instead we will ask you to sign in to the app, where your email address and display name are shown on the Profile screen.
3.2 Right to Erasure (Article 17)
Settings → Delete My Account removes your Firebase account, all on-device records, and your documents from your iCloud Drive (including any family-member document folders) in a single action. The deletion runs in two passes: per-document removal for any files tracked in metadata, followed by a sweep of your entire iCloud subtree to catch any orphan files. Anonymous sessions that are never converted into a registered account are not automatically deleted by Firebase — deleting your account through the app is the only way to remove one.
3.3 Right to Data Portability (Article 20)
You can export your data at any time from within the app: Profile → Export My Data provides your stamp and absence records in structured, machine-readable JSON and CSV formats, delivered immediately via the iOS share sheet — no request needed. This is the only way to export them: because these records never reach our servers, we cannot produce the export for you by email. If you lose your device, records synced to your iCloud return when you reinstall Granted and sign back into the same iCloud account and the same Granted account. Records created as a guest, without an account, may not be recoverable.
3.4 Right to Withdraw Consent
Where we rely on your consent — the optional Application Timeline sharing — you can withdraw it at any time from within the app ("Remove my shared data"), without affecting the lawfulness of processing before withdrawal. Core account and tracking features rely on contract, not consent; you can stop that processing at any time by deleting your account or the app. Anonymous sessions hold no personal data.
3.5 Right to Rectification (Article 16)
You can correct inaccurate personal data. Your display name and email can be edited from the Profile screen; stamp and absence records can be edited or deleted at any time within the app. For the account record we hold, contact privacy@getgranted.ie.
3.6 Right to Restriction (Article 18)
You can ask us to restrict processing of your account data in the circumstances set out in Article 18 (for example, while a dispute about accuracy is resolved). Contact privacy@getgranted.ie.
3.7 Right to Object (Article 21)
Where processing is based on our legitimate interests, you can object at any time. Contact privacy@getgranted.ie. We do not use your data for direct marketing or profiling.
3.8 Automated Decision-Making (Article 22)
Granted's eligibility calculations are tools to help you understand your own records. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing within the meaning of Article 22 — you always decide what to do with the information, and you should verify it with the Irish Immigration Service (ISD) or a solicitor.
3.9 Right to Lodge a Complaint
If you believe your data has been handled incorrectly, you have the right to lodge a complaint with the Data Protection Commission Ireland (DPC):
www.dataprotection.ie · info@dataprotection.ie · +353 (0)761 104 800
4. Privacy by Design
4.1 Data Minimisation
- Anonymous sessions collect zero personal data — the app is fully functional without an account
- Stamp records contain only type and dates — no free-text fields except optional notes
- When IRP card scanning launches, the OCR pipeline will discard the card image immediately after text extraction — the image will never be stored or transmitted
- Only document metadata is stored in SwiftData — not document content
4.2 Storage Limitation
- Documents are stored in your own iCloud — we never have access to document content. This applies to all subscription tiers including Family.
- Firebase stores only authentication credentials (UID, email) — no immigration data, no documents
4.3 Security Measures
- All iCloud data is encrypted in transit and at rest under Apple's standard iCloud security policies
- Firebase Security Rules prevent any cross-user data access
- All network connections use TLS (App Transport Security enforced)
- No hardcoded credentials in source code
- No advertising SDKs — ATT prompt is never shown
5. App Store Privacy Nutrition Label
The following is declared in Granted's App Store Connect privacy label:
- Contact Info: Email address — used for account creation, linked to identity
- Identifiers: Firebase User ID — used for app functionality, linked to identity
- Name: Display name (if provided) — used for app functionality, linked to identity
- Stamp, absence, and document data stays on your device and in your own iCloud — it is not collected by us and does not leave your control
- No data is used for tracking
- No location, browsing, or health data is collected
6. Incident Response
In the event of a personal data breach:
- We will assess the scope within 24 hours of discovery
- If the breach poses risk to individuals, we will notify the DPC within 72 hours
- If the breach poses high risk, we will notify affected users directly without undue delay
- All breaches are documented in an internal breach register
7. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via an in-app notice. The "last updated" date at the top of this page reflects the most recent revision.
8. Contact
For any privacy-related queries:
📧 privacy@getgranted.ie
🌐 getgranted.ie