Privacy policy sections
Privacy Policy
SCHNGN is designed to calculate travel plans without requiring an account. This policy explains what stays in your browser, what is processed when you choose optional online features, and the controls available to you.
Last updated
The short version
- Guest trip details stay in your browser unless you explicitly choose account sync.
- Google sign-in is used to create, secure, authenticate and identify an optional SCHNGN account and to associate trips you choose to save.
- Plausible may receive coarse usage and result categories, but never your trip dates, labels, countries, email or account ID.
- You can export the current browser trip copy and delete the active trip snapshot saved to your account.
1. What this policy covers
This policy covers schngn.com, the SCHNGN web app and its account, synchronization, analytics and support features. SCHNGN is a planning calculator and does not request GPS access, scan passports, or collect visa and residence-document numbers as part of its normal features.
2. Who is responsible and why data is processed
SCHNGN operates schngn.com and is responsible for the application-specific processing described here. Contact support@schngn.com with privacy questions. We process account, synchronization and support data to provide features you request; limited analytics and security data to understand and protect the service; consent-based data where consent is required; and data needed to meet applicable legal obligations.
3. Guest use and browser storage
When you use SCHNGN as a guest, trip dates, labels, optional border-country context, stay ranges, status and calculation results remain in your browser. Calculations and unsaved simulations run on your device. The optional passport question uses only the issuing country in temporary browser memory to show a possible bilateral-agreement notice; it is not saved with trips or sent to analytics. Browser storage also keeps functional preferences such as language and the previous-travel answer; public app files may be cached for offline use. A JSON backup is created and read locally under your control and is not uploaded merely because you export or import it.
- Browser trip storage remains until you clear it, replace it, or clear site data.
- The language preference cookie lasts up to one year.
- Local JSON backups are plain files; you are responsible for storing them securely.
4. Optional accounts and Google sign-in
Clerk loads on public SCHNGN pages to check whether you are signed in and may process essential session, device and network data under its privacy policy. If you choose Google sign-in, Google sends your basic identity data and OAuth response to Clerk. Clerk handles the provider credentials or tokens and the account session under its policy. SCHNGN receives the resulting Clerk session and user ID to identify the active account, show your signed-in state and email, and associate trips you explicitly choose to save. Only the Clerk user ID—not your Google email, name, profile image, password or provider tokens—is stored in Cloudflare D1 with those trips. SCHNGN does not request Gmail, Google Drive, Calendar, contacts or other Google content, and does not sell Google user data or use it for advertising.
5. Optional trip sync, export and deletion
Completing a clearly labelled sign-up-and-save action, or separately enabling sync while signed in, sends the current validated trip snapshot to Cloudflare D1. That snapshot includes the verified Clerk user ID, full saved trip details, revision and consent metadata, and timestamps. Once enabled, later saved edits or imports can synchronize. The browser also stores the Clerk user ID, server revision, sync state and a trip fingerprint for reconciliation, while a sign-up-and-save choice is held temporarily in session storage. This sync metadata is not part of the trip JSON export; it is removed by the “sign out and clear this browser” action or when you clear site data. The JSON export contains the current browser trip copy, not all identity, support, log or provider-held data. “Delete saved account trips” removes the active D1 snapshot but does not delete browser trips or the Clerk account. Deleting the Clerk account triggers cleanup of the snapshot and creates a one-way hashed account-deletion guard that is active for 30 days to block stale-session re-creation; after that it is ignored and purged opportunistically.
6. Aggregate analytics
On the production site, Plausible may receive allowlisted events such as page view, calculator start, trip added and simulation run, together with coarse categories such as trip-count range, verdict, safe-buffer range or source. SCHNGN strips query strings and hashes and prohibits trip dates, labels, countries, timelines, passport choice, email and account identifiers. Plausible analytics is configured without analytics cookies or automatic form, download and outbound-link tracking. Ordinary network information may still be processed by Plausible to produce aggregate statistics.
7. Support, security and technical data
If you contact us, SCHNGN sends your request type, optional name, email address, message and selected language through Cloudflare email services to our Proton support mailbox. Trip history is never attached automatically, although anything you type into the message will be received. Separately, the browser sends a Turnstile token for verification; that token is not included in the support email. Cloudflare uses the connecting IP address for rate limiting and Turnstile verification and processes ordinary request, device, browser, security and error metadata when delivering and protecting the site. SCHNGN does not use Sentry and its application logs must not contain trip bodies, account emails or Clerk user IDs.
8. Service providers and international processing
SCHNGN uses Cloudflare for hosting, storage, security and email delivery; Clerk for identity and sessions; Google only when you choose Google sign-in; Plausible for restricted aggregate analytics; and Proton for the support mailbox. These providers may process data in countries outside your own. Their published notices describe their locations, retention and transfer safeguards. We share data only as needed to provide these functions, protect the service, follow your instructions, or comply with law; we do not sell personal data.
9. Retention, deletion and security
Browser data remains until you or your browser removes it. Active synchronized trips remain until replaced or deleted. Support messages remain in the Proton mailbox until SCHNGN deletes them; no fixed deletion period is currently promised, and they should be removed when no longer reasonably needed for follow-up, service protection, disputes or applicable obligations. Provider backups, operational records, account data and aggregate analytics follow the providers’ configured retention schedules and may take time to expire after active data is deleted. SCHNGN uses access controls, validated inputs, authenticated ownership and encrypted HTTPS connections, but no online or local storage method is completely secure.
10. Your choices, rights and policy changes
You can use the calculator without an account, clear browser data, export browser trips, delete the active account trip snapshot, or manage and delete your Clerk account. Depending on the law that applies, you may ask for access, correction, deletion, restriction or portability, object to certain processing, withdraw consent where consent is the basis, and complain to your local data-protection authority. Providing account or support data is optional, but those features cannot work without it. SCHNGN does not make legally significant automated decisions: calculator results are planning estimates. We will update this page before materially changing how data is used.
Provider privacy information
Privacy questions or requests
Email support@schngn.com. Please describe the request without sending passport, visa or other sensitive document numbers. We may need to verify an account request before acting on it.
Contact SCHNGN support