Belong Nordic, Privacy Policy
Belong Nordic comes in three versions and they handle your data differently. The iPhone app and the Android app keep everything on your device and send us nothing. The web app needs an account, so the situation you enter is stored on our servers and synced to your browser, though your documents and your practice never leave the browser. This policy explains all three.
Who we are
Belong Nordic is made by Belong Europe ApS, a company registered in Copenhagen, Denmark, CVR number 46649044. For the web app we are the data controller for the personal data described below. You can reach us at hello@belongeurope.com.
The phone apps: everything stays on your device
This part is the same on iPhone and on Android. Your residence history, any penalties, your language and test progress, your practice history, any documents you attach, the name and the photo you add for yourself and which country you are tracking are stored only on your device. They are not sent to us, to any server we control or to any third party. If you delete the app, that data goes with it.
Your What if scenarios are not stored at all. The sandbox runs on a copy of your situation held in memory while the sheet is open, and it is discarded when you close it.
On the iPhone, signing in is optional. If you sign in on the You tab so one subscription unlocks both the iPhone app and the web app, two things reach us and nothing more: your email address and, if you have an App Store subscription, Apple’s signed confirmation of it. Your tracker data still stays on your device, signed in or not.
The Android app has no account at all. There is nothing to sign in to, nothing to link and no email address for us to hold. What unlocks the app is your Google Play subscription, and that question is asked and answered between the app and Google Play on your phone. The one other thing that can open it is an access code we give Google’s own review team, which works on a single phone, buys nothing and reaches no server. Either way no server of ours is involved in that decision, and the Android app sends us nothing about you. The one time it reaches a site of ours is when you tap a link to one, this page included: that opens in the in-app browser and is an ordinary web request, so our page is served the same standard technical information any site is.
The web app: saved to your account
The web app needs an account so you can open your tracker in any browser. When you sign up we store your email address and the situation you enter on our servers, including the name you choose to add, which appears on the You and Passport tabs, so it is there when you sign in again. We use it only to run your account and show you your tracker. We do not sell it, we do not use it for advertising, and we share it only with the service providers below. You can edit or clear your entries at any time, and you can ask us to delete your account and its data.
Two things are deliberately not part of your account: the documents you attach and your practice history, including the run of days Today’s five keeps. Both stay in the browser you used, are never uploaded, and do not follow you to another browser or computer. They are filed under the account you were signed in with, so you only ever see your own.
What we collect
On the iPhone, nothing personal unless you choose to sign in, in which case we hold your email address and your subscription status. On Android, nothing at all, because there is no account to hold anything in. Neither phone app carries analytics, advertising or tracking, and we add no software development kit that collects data about you. The stores are the exception, because they have to be: Apple’s in-app purchase and review components on the iPhone, and Google Play’s billing and review libraries on Android, which sell the subscription and offer you the store’s own review card, and which bring components of Apple’s and Google’s own along with them. Those are governed by Apple’s and Google’s privacy policies, and nothing they do reaches us in a form that identifies you. For the web app we hold only what the account needs: your email address, the tracker information you enter and the billing status of your subscription. We do not build an advertising profile of you.
The tracker information is what you type into the app: the name you choose to add, when your residence began, whether you hold permanent residence, your language and test progress, the trips you log, and any fines or penalties you record so the app can work out whether they delay you. You choose what to enter, and you can change or clear any of it at any time.
The Android app asks you for one permission: notifications. On Android 13 and later that is a question you are asked, and can refuse or withdraw at any time; on older versions notifications start on and you turn them off in Settings. Either way the app checks that setting again immediately before it posts anything. There is no permission for your location, your contacts, your camera or your files, because the app has no use for any of them. Adding a document or a photo goes through Android’s own picker, which hands the app the one file you chose and nothing else. The rest of what the Play page lists is plumbing granted at install, and none of it reads anything about you: internet access for the news feed and for Google Play, network state so the background news check can wait until you have a connection, Google Play billing for the subscription, the permissions Android’s work scheduler needs so a reminder survives a reboot and finishes once it starts, and one private permission the app defines so that only it can receive its own broadcasts.
Signing in on the web sets one cookie, belong_session. It carries a signed token with your email address so the site knows you are signed in, it lasts up to 60 days, and scripts cannot read it. It exists to run your account and nothing else: we set no analytics, advertising or tracking cookies. Signing out deletes it.
News
The News tab shows The Local’s stories for the country you are tracking, from their public tag feeds at feeds.thelocal.com: the immigration tag and that country’s own citizenship tag. The three versions fetch them differently, and the difference is worth stating.
On the iPhone and on Android, the app requests the feeds directly. The stories are already scoped to citizenship and immigration by The Local’s own tags, and your device trims them to recent ones; no server of ours sees any of it. The request itself is an ordinary web request, so The Local’s servers see standard technical information such as your IP address, exactly as they would if you opened their site yourself. Besides this, the only things either phone app puts on the network are the App Store or Google Play check on your subscription, the store’s own request to show you a review card and any page you choose to open, which loads in the in-app browser from whoever publishes it.
On the web, your browser asks our server and our server fetches the feeds, so The Local sees our server and not you. The only thing sent is which country you are tracking.
In all three versions we add no identifier to the request, we do not tell The Local who you are, and we receive nothing back about you.
Feeds exist for Denmark, Sweden and Norway. There is no Finland edition, so tracking Finland fetches nothing at all.
If you turn on news notifications, the check for new stories runs in the background and makes the same request: on the iPhone when iOS decides to run it, and on Android roughly every two hours through Android’s own scheduler, which waits for a connection and picks its own moment. The preference is stored on your device only. Tapping a story opens it on The Local’s own site, where their privacy policy applies and some articles may require a subscription.
Practice
The citizenship test questions in the Practice tab come with the app rather than from a server, and on both phone apps practising works fully offline. In all three versions your answers, your scores, your mistakes deck, the schedule that decides when a question comes back and your run of days are written to your own device and never sent anywhere; on the web they stay in your browser and are not part of your account. Opening an official preparation page loads it from the authority’s own site: in an in-app browser on the iPhone and on Android, and as a normal link in your browser on the web.
Passport
The facts on the Passport tab (validity, fee, where to apply, dual citizenship and the notes on each passport’s design) ship with the app and are shown without any network request. If you add your name on the You tab, the Passport tab displays it; it is the same name described above and nothing else is collected. On the iPhone and on Android you can also add a photo of yourself, shown on the You and Passport tabs: it is scaled down and stored only on your device, it is never uploaded or synced, and removing it, or deleting the app, deletes it. On Android it is also kept out of your phone’s cloud backup and out of a transfer to a new phone. The web app has no photo. Opening an issuing authority’s page loads it from the authority’s own site: in an in-app browser on the phone apps, and as a normal link in your browser on the web.
Documents you attach
On the Path tab you can attach a document to a requirement (a language certificate, a residence permit, a payslip, a test result) with a name and, if you want, an expiry date. Wherever you attach it, the file stays on the device you attached it on, and we never receive it.
On the iPhone, the files are written inside the app’s own storage with iOS file protection switched on, so the system keeps them encrypted and unreadable while your iPhone is locked.
On Android, they are written inside the app’s own private storage, which Android keeps encrypted under your device credential and unreadable until the phone has been unlocked once after a restart. No other app can read them.
On both phones, removing a document deletes the file, and deleting the app deletes all of them. A file you pick and then do not save waits in the app’s own temporary storage, private in the same way and out of any backup. It is deleted the next time you open a document sheet, once it is more than a day old, and Android is free to reclaim it sooner when the phone runs short of space.
On the web, the files are stored by your browser on your own computer, in the storage it keeps for this site, and each one is filed under the account that added it. You only ever see your own. Removing a document deletes it, clearing this site’s data in your browser deletes all of them, and the Path tab has a control that removes them all at once. Because they never leave that browser, they do not appear in another browser or on another device, and we keep no copy anywhere else.
A computer can be shared, so signing in with a different account on the same browser clears what the previous account left there, documents, tracker and practice alike, rather than leaving one person’s papers on a machine they have walked away from. If you share a computer with someone who also uses Belong Nordic, each of you signing in will clear the other’s, so keep your own copies.
In all three versions they are never uploaded, we never see them, and they are not part of anything a Belong Nordic account syncs.
One thing worth knowing about both phone apps: these files are deliberately kept off any backup. If you back your iPhone up to iCloud or to a computer, your documents are not part of that backup. On Android they are excluded from cloud backup and from device transfer, so they cannot be copied onto a new phone during its setup either. The name and the expiry date you give a document are kept alongside it, in the same place, and stay out of the backup with it. Files up to 15 MB are accepted; anything larger is refused with a plain error rather than trimmed. If you set an expiry date and turn milestone alerts on, the name you gave the document is used as the title of that alert, and like any notification it can appear on your lock screen. On Android that alert is handed to the system’s own scheduler until it fires, so the name waits outside the vault and can travel with a transfer to a new phone. That is worth knowing when you name something sensitive. Only that name ever leaves the vault; the file itself never does. The cost is worth stating plainly: restoring a new phone from a backup, or setting one up from your old one, will not bring your documents back, and you attach them again. That is the version of this we can stand behind. Papers this sensitive should not travel further than the phone you chose to put them on. Keep your own copies of anything you cannot easily get again, and attach only what you actually need.
Reminders and alerts
The daily practice reminder, the news alerts and the alerts for dates in What’s coming are local notifications. Your phone schedules them from information already on it, so they use no server of ours, no push service and no device token. Nothing about them reaches us: not that you switched them on, not when one fires, not whether you opened it. The settings are stored on your device.
On Android, the three kinds sit in three separate notification channels, so you can mute any one of them in Android Settings without losing the others, and nothing is posted at all unless Android’s notification permission is granted. Every scheduler checks that permission again immediately before posting, so turning notifications off in Settings takes effect whether or not the app hears about it.
News notifications are the exception to the no-network rule, because checking for new stories needs the request described above.
The web app has no reminders or alerts at all. What’s coming is a list you look at when you open it, and nothing is sent to you.
Subscriptions and payments
Belong Nordic Pro is an optional auto-renewable yearly subscription with a 7-day free trial, priced in your own currency and always shown to you in full before you buy.
On the iPhone, purchases are handled by Apple through your Apple Account and we never see your payment details. On Android, they are handled by Google through your Google Account on Google Play, and again we never see your payment details. The Android app asks Google Play what this Google Account holds and Play answers on the phone; that answer is what unlocks the app, and no server of ours is told about it. On the web, payments are handled by Stripe: you enter your card details directly with them, we never see or store your full card number, and Stripe tells us only what we need to manage the subscription, such as whether it is active and the last few digits of your card. Apple’s, Google’s and Stripe’s own privacy policies govern those transactions.
One subscription unlocks the iPhone app and the web app. To link them, the iPhone app sends us Apple’s signed confirmation of your subscription: it says the subscription is genuine, active, and when it expires. It contains no payment details. Android stands on its own, because it has no account: it is unlocked by an active Google Play purchase. That is a limitation worth knowing before you buy, and it is stated in the terms as well.
Service providers
To run the web app we use a small number of providers who process data on our behalf: a hosting and database provider that stores your account, an email provider that sends your sign-in codes and links, and Stripe for payments. They act under agreements requiring them to protect your data and use it only to provide their service to us. We use no third-party analytics or advertising services.
The phone apps use the stores they are sold in: Apple’s in-app purchase and review services on the iPhone, and Google Play’s billing and in-app review services on Android. Those ship as Apple’s and Google’s own libraries inside the app and talk to the App Store or Google Play on your phone rather than to anything we run. They act for Apple and Google under their own privacy policies, and neither passes us anything that identifies you. Play’s review card is a good example: Play decides on its own whether to show it and tells the app nothing about what happened, so we learn nothing from it either.
Where your data is stored, and for how long
Web app data is stored on servers in the European Union or in countries offering an equivalent level of protection. Payment data handled by Stripe may be processed outside the European Economic Area under the safeguards Stripe maintains. We keep your account data for as long as your account is open; if you delete your account we remove your tracker data and keep only the limited billing records the law requires. If you only use the iPhone app and never sign in, or you use the Android app, where there is nothing to sign in to, we hold nothing about you, so there is nothing to retain.
Deleting your account removes what we hold. It does not touch what is on your phone or in your browser, because we cannot reach it: remove your documents in the app, or clear this site’s data in your browser, if you want those gone too.
Appearance
Your choice of the Midnight or Mediterranean look is a setting stored on your device. It is not a profile and it is not sent anywhere.
Diagnostics
If you have turned on Apple’s optional analytics sharing in iOS Settings, Apple may send us crash and performance reports in a form that does not identify you. We use them only to find and fix problems. You can turn this off at any time in Settings → Privacy & Security → Analytics & Improvements.
Android works the same way. If you have turned on Google’s optional usage and diagnostics sharing, Google may show us crash and performance reports in the Play Console, again in a form that does not identify you, and again used only to find and fix problems. You can turn it off in your phone’s Settings, under Google, in Usage & diagnostics. We add no crash reporting of our own to either app.
Your data and your rights
For the phone apps your tracker information stays on your device and never reaches us, so we hold no copy to export or erase, and you stay in full control through the app. The same is true of the documents you attach and your practice history in any version: they never reach us, so there is nothing on our side to export or erase, and removing them is done in the app. For any account you hold, on the web or signed in on the iPhone, you have the rights the GDPR gives you: access, rectification, erasure, restriction, objection and a copy in a portable form. To exercise any of these, or to delete your account, contact us and we will respond. You also have the right to complain to your local data protection authority, or, since we are established in Denmark, to the Danish Datatilsynet at datatilsynet.dk.
Children
Belong Nordic is made for adults navigating their own immigration and nationality path. It is not directed at children and we do not knowingly collect anything from them.
Changes to this policy
If we change how the app handles data, we will update this page and its effective date, and we will say so in the app when the change is material.
Contact
Questions about this policy: hello@belongeurope.com.