Ground Passport
Privacy Policy
Updated 8 October 2026 · Public release clarification
Who is responsible
Ground Passport is developed by Yurii Koshkin in Spain under the Gatoficio studio brand. Contact support@gatoficio.com for privacy questions.
Your passport stays on your device
Ground names, cities, countries, teams, visit dates, scores, notes, chosen coordinates and photo or ticket images are held in local app storage. We do not operate a server for your passport, receive your records or create an app account. Device and iCloud backups may contain app data according to your Apple settings; these are separate from app-operated cloud sync. Local storage is not an independent backup.
Maps and photos
Apple Maps search runs only when you explicitly search. The query is sent to Apple under its privacy policy. Displaying maps can also make requests to Apple's map service. The app does not request or read your device location. You choose and confirm a ground's position; it is not an independently verified stadium record. The system Photos picker supplies only the image you select, without broad photo-library access. A downsampled local image is re-encoded without original image metadata. Keep your original separately.
Import, export and sharing
CSV import and export are explicit actions using local processing and the system Files interface. CSV contains record text and any chosen coordinates, not photos or ticket images. View/copy CSV text writes the clipboard only when you press Copy; clipboard text can be read by apps where you paste it. The app does not automatically inspect the clipboard. Recap sharing creates an image locally and opens the system share sheet. The destination you choose handles a shared copy under its own rules. Check the content before sharing.
Product analytics and your choice
Limited product analytics is enabled by default, with a persistent opt-out in Settings → Product analytics. TelemetryDeck receives coarse events such as onboarding step numbers, first or later saved-visit milestones, feature use, typed error categories, offer-layout exposure and commerce outcomes when commerce is configured. It does not receive visit content, country or team names, dates of visits, map coordinates, images, filenames, record IDs, receipts or transaction IDs.
The SDK attaches an app-specific hashed client identifier, session identifier, event timestamp, app version/build and technical device/runtime metadata. This can include operating system, device model, architecture, display characteristics, language/region, time zone, appearance, layout direction and accessibility settings. We do not set an account identity or combine events with passport records, support correspondence or advertising profiles. No advertising identifier or cross-company advertising tracking is used.
Turning analytics off blocks future app transmissions and discards queued events locally. Data already received by the provider cannot be recalled by the switch. Re-enabling requires restarting the app. Debug and simulator runs send no events; TestFlight and sandbox analytics remain test data, not production revenue. TelemetryDeck describes its processing and retention in its privacy FAQ, including no storage of IP addresses and no guaranteed routine deletion interval for analytics. Analytics is not required to use the app.
Commerce
The public app offers one optional one-time Pro purchase for adding new past-dated visits, including new historical CSV rows, and exporting or sharing a designed year-card image. It is not a subscription or trial. Today’s entries, existing history, ordinary editing, photos, chosen map pins, local search, collections, CSV export, import preview and restoring previously saved records remain available without Pro. Changing an existing visit to a different past day requires Pro. Apple handles billing; StoreKit verifies access and supports Restore Purchases. The analytics exclusions above apply to purchase events too: we do not send visit history, photos or purchase receipts as analytics parameters.
Support, deletion and rights
Emailing support sends your address, message and any attachments to our email providers and us. We use this information to answer the request and maintain necessary support records, not advertising. Do not send your whole passport, unredacted tickets or Apple credentials. Local visits can be deleted in the app; uninstalling removes local data while offloading can preserve it. Shared copies and device backups are separate. We cannot recover records we do not hold.
Contact support to request access, correction, deletion or restriction of information we hold, or to object where applicable. Support correspondence is retained only as needed for the request, follow-up and applicable obligations. You may contact your local supervisory authority, including Spain's AEPD. For website hosting and connection information, see the Gatoficio website privacy notice.