Skip to content
NomadCheck
  • Features
  • Pro
  • FAQ
Launching soon

Legal

Privacy Policy

Version 1.0 · Effective 8 August 2026

This policy explains how NomadCheck collects, uses, shares, keeps and protects your personal data when you use the app, and what rights you have over it. We do not sell your personal data, we do not share it with advertising networks or data brokers, and we never see your password or your card details.

On this page

  1. 1. Who we are
  2. 2. Scope and principles
  3. 3. What we collect
  4. 4. Where it comes from
  5. 5. Why we process it, and on what basis
  6. 6. Automated decision-making
  7. 7. Who we share it with
  8. 8. How we protect it
  9. 9. International transfers
  10. 10. How long we keep it
  11. 11. Your rights
  12. 12. Storage on your device
  13. 13. Children
  14. 14. Platforms and links
  15. 15. Changes to this policy
  16. 16. Contact

1. Who we are

1.1 Controller. The controller of personal data processed in connection with the app is NomadCheck, established in the Republic of Bulgaria.

1.2 Contact. For anything to do with your personal data or your rights, write to support@nomadcheck.app.

1.3 Supervisory authority. Our competent supervisory authority is the Commission for Personal Data Protection of the Republic of Bulgaria (Комисия за защита на личните данни). Where our processing is cross-border within the meaning of Article 4(23) GDPR, that authority acts as our lead supervisory authority under Article 56 GDPR.

This policy is issued to satisfy the information duties in Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act. It is an information notice, not a contractual term: the Terms of Service refer to it for information, and accepting those terms is not consent to any processing described here.

2. Scope and principles

2.1 Scope. This policy covers personal data we process as controller when you download, install, register for, access and use the app, and when you contact us.

2.2 Principles. We process personal data in line with Article 5 GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

2.3 Minimisation by design. The app is built to work on the least personal data possible. We do not need your name, home address, date of birth, phone number, identity documents, financial account details or precise location to provide it.

3. What we collect

3.1 Account and identity data

Email address; a unique internal user identifier; display name and profile image if you choose to add them; the authentication method on your account; account creation, verification and last-activity timestamps; and, if you use a federated sign-in method, the identifier and basic profile attributes it releases to us.

We do not store your password. Credentials are handled entirely within dedicated, professionally operated identity infrastructure and never reach our systems in any form. See section 8.

3.2 Preference and configuration data

Your display currency; your theme; language and locale; notification preferences; and other in-app configuration choices. Some of these are stored on your device so the app opens the way you left it.

3.3 What you create in the app

Saved and favourited cities; recent searches; comparison selections; budget entries and category allocations you enter; and household composition — counts of adults and children, used only to scale cost calculations.

3.4 Subscription and entitlement data

Your tier; the identifier, status, activation, renewal and expiry dates of any entitlement on your account; the platform and territory of purchase; and the transactional events — purchase, renewal, cancellation, refund, billing issue — reported to us for it.

We never receive, process or store your card number, bank details, cardholder name or any other payment instrument data. Payment happens entirely outside our systems, inside the payment infrastructure of the digital distribution platform you got the app from.

3.5 Technical and device data

IP address, kept for a short period for security, abuse-prevention and diagnostic purposes and then truncated or deleted as section 10.2 sets out; device type, model and manufacturer; operating system and version; app version and build; device language and time zone; a pseudonymous installation or session identifier; network type; and crash reports, exception traces, error logs and diagnostic performance measurements.

3.6 Usage and interaction data

Aggregated, pseudonymised records of the features and screens you open, how often and how long you use them, request timing, and error and latency events. We do not build advertising profiles and we do not track you across other apps or websites.

3.7 Communications

The content and metadata of any support request, bug report, feedback, feature request, complaint or rights request you send us, your contact details, and our replies.

3.8 Compliance and security records

Records of consent, acceptance of terms, rights requests and our responses; security event logs; records of suspected abuse, fraud, unauthorised access or breach of the Terms; and records needed to demonstrate that we comply with our legal obligations.

3.9 Special category data

We do not seek, request or knowingly collect any special category data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation — nor any data about criminal convictions or offences under Article 10 GDPR. Please do not enter any of it into free-text fields. If it is submitted anyway it is processed only incidentally and deleted when we notice it.

3.10 Data about other people

If you enter anything about members of your household, you must be entitled to do so. The app is designed to need only non-identifying counts, so please do not enter anyone else's name, contact details or other identifying particulars.

4. Where it comes from

We get personal data:

  • directly from you, when you register, configure the app, enter content, subscribe or contact us;
  • automatically from your device and our systems as you use the app, in the form of technical, security and usage data; and
  • from the infrastructure providers that support the app on our behalf, as authentication confirmations and entitlement status, and — if you choose a federated sign-in method — from that method's provider, limited to the attributes you authorise it to release.

5. Why we process it, and on what basis

We process personal data only where a lawful basis under Article 6(1) GDPR applies. Each purpose below names the data categories from section 3 and the basis relied on.

  1. Creating, authenticating, securing and administering your account — 3.1, 3.5, 3.8 — Art. 6(1)(b), performance of a contract.
  2. Providing the app: city search, cost breakdowns, indices, comparisons, currency presentation, saved cities, budget and household calculations — 3.1, 3.2, 3.3, 3.5 — Art. 6(1)(b), performance of a contract.
  3. Keeping your preferences so the app opens configured — 3.2 — Art. 6(1)(b), performance of a contract.
  4. Verifying, activating, maintaining and revoking paid entitlements and providing the matching features — 3.1, 3.4 — Art. 6(1)(b), performance of a contract.
  5. Support and replying to you — 3.1, 3.3, 3.5, 3.7 — Art. 6(1)(b), performance of a contract; Art. 6(1)(f), legitimate interest in answering enquiries effectively.
  6. Security, integrity and availability: detecting, investigating and preventing fraud, abuse, unauthorised access, credential misuse, automated extraction and breaches of the Terms — 3.1, 3.5, 3.6, 3.8 — Art. 6(1)(f), legitimate interest in protecting the service, our users and our rights; Art. 6(1)(c), legal obligation to implement appropriate security.
  7. Diagnosing faults, monitoring stability and performance, debugging — 3.5, 3.6 — Art. 6(1)(f), legitimate interest in a reliable service.
  8. Analysing usage in aggregated, pseudonymised form to understand, improve and develop the app, and producing aggregated statistics — 3.5, 3.6 — Art. 6(1)(a), your consent, where the analysis relies on information stored on or read from your device that is not strictly necessary (see section 12); otherwise Art. 6(1)(f), legitimate interest in improving the product.
  9. Service, transactional, security and administrative messages — 3.1, 3.4, 3.8 — Art. 6(1)(b), performance of a contract; Art. 6(1)(c), legal obligation.
  10. Optional product news and marketing, where offered — 3.1 — Art. 6(1)(a), your consent, withdrawable at any time.
  11. Complying with legal, regulatory, accounting, tax and record-keeping obligations — 3.1, 3.4, 3.8 — Art. 6(1)(c), legal obligation.
  12. Establishing, exercising or defending legal claims, enforcing the Terms, and responding to lawful requests from competent authorities — all relevant categories — Art. 6(1)(f), legitimate interest in protecting our legal position; Art. 6(1)(c), legal obligation.
  13. A merger, acquisition, financing, reorganisation, insolvency or sale of business or assets — 3.1, 3.4, 3.8 — Art. 6(1)(f), legitimate interest in conducting corporate transactions.

5.1 Legitimate interests. Where we rely on Article 6(1)(f) we have carried out a balancing assessment weighing our interests against your interests, rights and freedoms, and concluded that the processing is necessary, proportionate, consistent with what you would reasonably expect, and does not override them. Ask us at support@nomadcheck.app for more about any of those assessments.

5.2 Withdrawing consent. Where processing is based on consent you may withdraw it at any time. That does not affect the lawfulness of processing before withdrawal.

5.3 What happens if you do not provide data. Your email address, the account identifiers in 3.1 and the technical data in 3.5 are necessary to perform our contract with you; without them we cannot create an account, authenticate you or provide the app. The rest of 3.1 — display name, profile image — and everything in 3.2, 3.3 and 3.7 is entirely voluntary; the app still works without it, though some features will be unavailable or reduced.

6. Automated decision-making

6.1 We carry out no automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

6.2 The calculations, indices, comparisons and estimates the app shows are informational outputs generated from the parameters you choose. They are estimates, not advice, assessment, scoring, evaluation or a decision about you. Section 2 of the Terms of Service describes what they are and are not.

7. Who we share it with

7.1 No sale, no advertising. We do not sell personal data, we do not share it with advertising networks, data brokers, ad-technology platforms or analytics providers for advertising purposes, and we do not let any recipient use data received from us for its own commercial purposes.

7.2 Categories of recipient. We disclose personal data only where necessary, and only to the categories below. Each is bound by a written data processing agreement meeting Article 28 GDPR where it acts as processor, by confidentiality obligations, and by contractual restrictions limiting processing to our documented instructions and to the purpose of the disclosure.

  • Identity and authentication infrastructure — specialist providers that run the authentication layer, verify credentials and issue session tokens for us.
  • Cloud hosting, database and storage infrastructure — providers hosting our application servers and database within the European Union.
  • Subscription and entitlement management infrastructure — providers that receive purchase and renewal events from the digital distribution platform and tell us the resulting entitlement status.
  • Diagnostics, crash-reporting and error monitoring — providers that receive technical error and stability telemetry.
  • Communications infrastructure — providers that send transactional and service email and, where applicable, push notifications.
  • Professional advisers — lawyers, auditors, accountants and insurers, bound by professional confidentiality, where needed to establish, exercise or defend legal claims or to comply with the law.
  • Competent authorities — courts, regulators, supervisory authorities and law enforcement, where disclosure is required by law, court order or binding request, or necessary to protect our rights, property or safety or those of our users or the public. Where we are legally allowed to, we will tell you about such a request before responding, and we will resist requests we consider overbroad, invalid or unlawful.
  • Corporate transaction counterparties — a prospective or actual acquirer, investor, successor or assignee and their advisers, on a merger, acquisition, financing, reorganisation, insolvency or sale of business or assets, subject to confidentiality undertakings and to this policy continuing to govern the data.

7.3 How we choose and oversee them. We select processors that provide sufficient guarantees to implement appropriate technical and organisational measures so that processing meets the GDPR and protects your rights. We carry out due diligence before engaging them, impose contractual security and audit obligations, and require prior authorisation for any sub-processor.

7.4 No independent controllers. Apart from the professional advisers, competent authorities and corporate counterparties above, and the digital distribution platform in respect of payment transactions it conducts under its own terms, we do not disclose personal data to anyone acting as an independent controller for their own purposes.

8. How we protect it

8.1 Our commitment. Protecting personal data is central to how the app is built and run. We implement appropriate technical and organisational measures under Article 32 GDPR to ensure a level of security appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing.

8.2 Delegated authentication — we hold no passwords. Authentication is delegated to dedicated, professionally operated and independently assured identity infrastructure built specifically for handling credentials. Passwords are never transmitted to, processed by, or stored on our servers in any form — hashed, encrypted or otherwise. That materially reduces the credential-exposure surface of the app: our systems do not contain your password, so a compromise of them would not disclose it. That infrastructure applies contemporary credential-protection controls, including password-strength enforcement, rate limiting, automated protection against automated guessing and account-enumeration attacks, managed session and token lifecycles, and support for multi-factor authentication where you enable it.

8.3 We hold no payment data. We never handle payment instrument data. Purchase, billing and renewal happen entirely inside the payment environment of the digital distribution platform. Our systems receive only the resulting entitlement status; they do not contain your card or bank details, so a compromise of them would not disclose those details.

8.4 Technical measures. These include:

  • Encryption in transit — all traffic between the app and our servers, and between our servers and infrastructure providers, is protected by TLS 1.2 or above with modern cipher suites and certificate validation.
  • Encryption at rest — database volumes, backups and stored files are encrypted at rest with industry-standard algorithms.
  • Token-based access control — API access is authorised by short-lived, cryptographically verified tokens checked on every request at the server boundary; requests without a valid token are rejected before any data is read.
  • Least privilege and segregation — administrative access is restricted to named individuals on a need-to-know basis, protected by multi-factor authentication, separated between production and non-production environments, and logged.
  • Network and infrastructure hardening — firewalling, private networking for database access, restricted ingress, and regular patching of operating systems and dependencies.
  • Secrets management — credentials, keys and configuration secrets are held in dedicated secret stores, injected at runtime and kept out of source control.
  • Input validation and injection resistance — server-side validation and parameterised, type-checked database access throughout.
  • Rate limiting and abuse controls — throttling, anomaly detection and automated blocking of enumeration, scraping and credential-stuffing patterns.
  • Pseudonymisation and minimisation — internal identifiers are used instead of direct identifiers wherever possible, and diagnostic telemetry is scrubbed of identifying content.
  • Logging and monitoring — security-relevant events are logged, retained and monitored for indicators of compromise.
  • Backup and recovery — encrypted backups with defined restoration procedures, so availability and access can be restored in a timely way after an incident.

8.5 Organisational measures. Confidentiality undertakings binding everyone who works on the app; role-based access provisioning and prompt removal; secure development practices including code review and dependency vulnerability scanning; change control; vendor security due diligence; a documented incident response procedure; and periodic review and testing of how well the measures work.

8.6 If there is a breach. We will assess any personal data breach without undue delay and, where it is likely to result in a risk to people's rights and freedoms, notify the competent supervisory authority within seventy-two hours of becoming aware of it under Article 33 GDPR. Where it is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay under Article 34 GDPR, unless an exception in Article 34(3) applies.

8.7 Your part, and the residual risk. Security is shared. Use a strong, unique password, turn on multi-factor authentication where it is available, secure the device the app is installed on, and keep your credentials to yourself. No method of transmission over the internet and no method of electronic storage is completely secure. We apply measures appropriate to the risk, but we cannot and do not guarantee absolute security, and so far as the law allows we do not warrant that unauthorised access, disclosure, alteration or destruction will never happen.

9. International transfers

9.1 Where processing happens. Our application servers and primary database are hosted within the European Union. Our default position is that personal data is stored and processed inside the European Economic Area.

9.2 Transfers outside the EEA. Some infrastructure providers may process limited personal data — mainly authentication metadata, entitlement status and technical diagnostics — in, or provide technical support from, countries outside the EEA. We maintain the current list of destination countries, the safeguard relied on for each and whether a European Commission adequacy decision covers it; ask us under section 9.4.

9.3 Safeguards. Where a transfer to a third country or international organisation happens, it is subject to appropriate safeguards under Chapter V GDPR — one or more of:

  • an adequacy decision of the European Commission under Article 45 GDPR covering the destination country or framework;
  • the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, written into our agreement with the recipient and supplemented where necessary by additional technical, contractual and organisational measures identified through a transfer impact assessment;
  • binding corporate rules approved under Article 47 GDPR; or
  • a derogation under Article 49 GDPR, used only where nothing else is available and strictly within that Article's conditions.

9.4 Ask for the detail. Write to support@nomadcheck.app for a copy of the relevant safeguards, redacted where needed to protect commercial confidentiality and security.

10. How long we keep it

10.1 Principle. We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires, and then delete or irreversibly anonymise it.

10.2 Retention periods.

  • Account and identity data (3.1) — for the life of the account, plus thirty days after deletion so an accidental deletion can be undone, then deleted or irreversibly anonymised. An account inactive for twenty-four continuous months may be closed and its data deleted, after notice to your registered email address.
  • Preference and configuration data (3.2) — for the life of the account; local copies on your device stay until you uninstall the app or clear its data.
  • What you create in the app (3.3) — for the life of the account, or until you delete the item, whichever comes first.
  • Subscription and entitlement data (3.4) — for the life of the account and then for as long as tax, accounting and consumer law require: generally five years, and up to ten years for accounting records under Bulgarian law.
  • Technical and device data (3.5) — IP addresses up to 30 days, then truncated or deleted; other technical data and crash reports up to 12 months.
  • Usage and interaction data (3.6) — up to 14 months pseudonymised; indefinitely once irreversibly aggregated and anonymised.
  • Communications (3.7) — up to 24 months after the matter is closed.
  • Compliance and security records (3.8) — up to 5 years, or longer where needed to establish, exercise or defend legal claims or to comply with a legal obligation.
  • Anything under legal hold — until the claim, investigation, proceeding or obligation is finally resolved.

10.3 Anonymised information. Information irreversibly anonymised so that it no longer relates to an identifiable person is not personal data, and may be kept and used indefinitely — including in the aggregated statistics we use to improve the app.

10.4 Backups. Data deleted from live systems may persist in encrypted backups for a limited period until those backups expire on their normal cycle. It is not used for any operational purpose in the meantime.

11. Your rights

11.1 Subject to the conditions and exceptions in applicable law, you have the right:

  • of access (Art. 15) — to confirmation of whether we process personal data about you, access to it, and the supplementary information in Article 15(1);
  • to rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed;
  • to erasure (Art. 17) — to have data erased where a ground in Article 17(1) applies, subject to the exceptions in Article 17(3);
  • to restriction of processing (Art. 18) — in the circumstances in Article 18(1);
  • to data portability (Art. 20) — to receive data you provided to us in a structured, commonly used, machine-readable format and transmit it to another controller, where processing is based on consent or contract and carried out by automated means;
  • to object (Art. 21) — at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, in which case we stop unless we can show compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is for legal claims; and at any time, without giving reasons, to direct marketing, which we then stop immediately;
  • to withdraw consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal;
  • not to be subject to automated decision-making (Art. 22) — noting that we carry out none, as section 6 says;
  • to lodge a complaint (Art. 77) — see section 11.6.

11.2 How to exercise them. Some rights you can exercise directly in the app: reviewing and correcting your profile, editing or deleting your saved content, managing notification and marketing preferences, and deleting your account. Otherwise write to support@nomadcheck.app.

11.2A Consent, marketing and notifications. Where we offer optional product news or marketing, we send it only with your prior, specific, informed and freely given consent, collected through an unticked opt-in shown separately from anything else. Push notifications are sent only where you have enabled them at operating-system level and in the app. You may withdraw consent and unsubscribe at any time, free of charge — through the unsubscribe link in any such message, in the app's preferences, in your device settings, or by writing to support@nomadcheck.app. It takes effect without undue delay and does not affect the lawfulness of processing before it. It does not stop service, transactional, security or administrative messages, which are necessary to perform our contract with you while you hold an account.

11.3 Verifying who you are. To protect your data from being disclosed to the wrong person, we take reasonable steps to verify the identity of anyone making a request — normally by requiring it to come from, or be confirmed by, the email address on the account. Where we have reasonable doubts we cannot resolve, we may ask for more information or decline to act, under Article 12(6) GDPR.

11.4 Timing and cost. We respond without undue delay and within one month of receiving a request. That can be extended by up to two further months where the complexity or number of requests makes it necessary, in which case we tell you within the first month and explain why. Requests are free. Where a request is manifestly unfounded or excessive, particularly if repetitive, we may charge a reasonable fee reflecting our administrative costs or refuse to act, under Article 12(5) GDPR.

11.5 Limits. These rights are not absolute. We may decline a request in whole or in part where an exception or restriction applies — including where complying would adversely affect the rights and freedoms of others, where the law requires us to keep the data, or where it is needed to establish, exercise or defend legal claims. If we decline we will explain why and tell you about your right to complain and to a judicial remedy.

11.6 Complaining to a supervisory authority. You may lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement — and you have the right to an effective judicial remedy under Articles 78 and 79 GDPR. Our competent supervisory authority is the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Republic of Bulgaria — cpdp.bg.

We would like the chance to put things right first, at support@nomadcheck.app, but you are under no obligation to come to us before going to them.

12. Storage on your device

12.1 The app stores a small amount of information on your device, of two kinds.

(a) Strictly necessary, stored without consent because it is strictly necessary to provide what you asked for: your authenticated session token; your currency, theme and language preferences, read at start-up so the app opens configured; cached reference data that reduces network requests and improves responsiveness; and security items used to detect and prevent abuse of the authentication and request layers.

(b) Non-essential, stored only with your prior consent: a pseudonymous installation identifier used for optional stability diagnostics, crash attribution and aggregate usage measurement.

12.2 Consent for (b) is asked for on first launch, through a clear, granular, unticked opt-in. Declining changes nothing about your ability to use the app or which features you get. You can grant or withdraw consent at any time in the app's privacy settings; withdrawing is as easy as giving, takes effect immediately, and the identifier is then deleted.

12.2A None of this is used for advertising, ad measurement, cross-app or cross-site tracking, audience building or behavioural profiling, and none of it goes to an advertising network or data broker.

12.3 You can clear locally stored information at any time in your device's app settings, or by uninstalling. Doing so signs you out and resets your local preferences.

12.4 Cookies and similar technologies on this website are covered by the cookie notice published here.

13. Children

13.1 NomadCheck is a general-audience informational tool. It is not designed for, directed to or marketed to children, and we do not knowingly solicit personal data from them.

13.2 Where the law makes processing a child's personal data below a given age conditional on the consent or authorisation of a holder of parental responsibility, an account must not be created without it. That age is fourteen under Bulgarian law and ranges from thirteen to sixteen across EU Member States.

13.3 If you believe a child has given us personal data without the required consent, write to support@nomadcheck.app and we will look into it and, where appropriate, delete the data and the account without undue delay.

14. Platforms and links

14.1 Your device, its operating system, your network provider and the digital distribution platform you got the app from each process data under their own privacy notices, independently of us. Those notices govern what they do, and we are not responsible for it. Do read them.

14.2 Where the app or this site links out, we do not control and are not responsible for the content, security or privacy practices at the other end.

15. Changes to this policy

15.1 We may update this policy to reflect changes in the app, in how we process data, in technology or in the law.

15.2 The current version is always in the app and at nomadcheck.app/privacy, and the date at the top says when it last changed. The Terms of Service are at nomadcheck.app/terms.

15.3 Where a change is material — in particular a new purpose of processing, a new category of recipient, or a materially different retention period — we will tell you in advance by email or a prominent in-app notice, and where the change needs your consent we will ask for it before it takes effect.

15.4 Continuing to use the app after a non-material change indicates you are aware of the revised policy.

16. Contact

Questions, requests and complaints about this policy or about how we process personal data:

NomadCheck, established in the Republic of Bulgaria — support@nomadcheck.app

NomadCheck

Cost-of-living companion for people who move.

Product

  • Features
  • Pro
  • FAQ

Legal

  • Privacy Policy
  • Terms of Service
  • Delete your account

Contact

© 2026 NomadCheck. All rights reserved.

Visa information is provided for guidance only and is not legal advice.