Legal

Privacy Policy

Last updated: 17 August 2026

This statement explains what settlme does with your personal data, on what legal basis, and what you can require of us. It is written to the General Data Protection Regulation (GDPR) as it applies in the Netherlands through the Uitvoeringswet AVG.

Five things are never sent to us at all

Your burgerservicenummer (BSN), your IBAN, your health insurance policy number, your residence permit number and the address you registered at are stored on your own phone, in the keychain the operating system provides and encrypts: the iOS Keychain or the Android Keystore. They are not in our database, and our servers have no field that could receive them.

What we do store is the dates the checklist runs on, such as when you registered or enrolled. Section 3 sets out what follows from that, including the part that is a trade-off rather than a benefit.

1. Who is responsible for your data

settlme is run by one person rather than a company. The controller (verwerkingsverantwoordelijke) for the processing described here is D. Antonelli, an individual based in the Netherlands. Article 4(7) GDPR makes no distinction here: a natural person carries the same obligations a company would, and this statement is written on that basis.

You can reach us through the contact form, which is the fastest route and gives you a written reference, or by email at hello@settlme.app. If you need a postal address in order to exercise a right or to make a complaint, ask and we will give you one.

There is no data protection officer. The processing here does not meet any of the thresholds in Article 37 GDPR that would require one.

2. What we collect, why, and on what basis

We collect as little as the app can work with. Every purpose below has a legal basis under Article 6 GDPR.

  • A device identifier, created the first time you open the app, so we can recognise your device without asking you to create an account. Basis: performance of our agreement with you (Art. 6(1)(b)). Without it the app cannot keep your checklist between sessions.
  • Your profile: nationality group, permit type, arrival date and city, used to work out which rules and deadlines apply to you. Basis: performance of our agreement with you (Art. 6(1)(b)).
  • Documents and files you choose to save: the dates on them, your insurer's name, and any photos or PDFs you attach. Basis: your consent (Art. 6(1)(a)), given by choosing to save each one. Identifying numbers are not in this list, and section 3 explains why.
  • An email address, only if you add one, so you can sign in on a second device or receive the weekly summary. Basis: performance of our agreement (Art. 6(1)(b)) for sign-in, and your consent (Art. 6(1)(a)) for the summary, which you can withdraw at any time in the app.
  • Questions and answers you post in the Ask section, shown to other users signed with your initials. Basis: performance of our agreement (Art. 6(1)(b)).
  • A push notification token, only if you turn notifications on. Basis: your consent (Art. 6(1)(a)), withdrawn by turning them off.
  • Explanations of letters you scan, described in section 4. Basis: your consent (Art. 6(1)(a)), given per scan.
  • Messages you send us through the contact form, kept so we can answer and show that we did. Basis: our legitimate interest in handling correspondence (Art. 6(1)(f)), and our legal obligation to answer data requests (Art. 6(1)(c)) where that is what you sent.

We do not sell your data to anyone, we do not run advertising networks, and we do not share your data with third parties except the processors named in section 6.

3. What stays on your phone

Five things are never sent to us: your burgerservicenummer (BSN), your IBAN and the name on the account, your health insurance policy number, your residence permit number, and the address you registered at.

They are written to your phone's keychain, which is the iOS Keychain or the Android Keystore depending on your device. That is storage the operating system encrypts and keeps separate from ordinary app files, unlocked by your passcode or biometrics. They are not in our database, they are not in our backups, and our servers have no field that could receive them even if an older version of the app tried to send one.

What we store instead is the part the checklist actually runs on: the date you registered, the date you enrolled, the date a permit runs to. Those are what the deadlines are worked out from, and they are useless to anyone who is not you.

For the BSN this is not only good manners. Under Article 46 of the Uitvoeringswet AVG, which gives effect to Article 87 GDPR, a national identification number may only be processed where a law provides for it, and settlme is not an organisation any law designates. Not holding it is a better answer than holding it carefully.

The address is there for a plainer reason. Nothing on our side reads it: no rule, no route, nobody in your household. The two places it is used — the line at the top of your Passport, and the search for a huisarts near your postcode — both run on the phone that already has it. Keeping a copy we never read would also have contradicted section 4, where every postcode is stripped out of every letter we read before anything is stored. Deleting a string from a scan while accepting the same string from a form is not a rule.

Two things follow, and they are worth knowing before you rely on them. What is kept on one phone stays on that phone: it does not travel with the rest of your Passport to a new device, and nobody in your household can see it. And deleting your account clears the keychain too, because none of it should outlive the account it belonged to.

4. Scanned letters

This is the one feature that sends something of yours to a third-party AI service, so it is the one feature that asks first. Before your first scan the app shows you, in the app itself, what is sent and to whom, and nothing is sent until you agree. The agreement is recorded on our server and checked there on every scan, which means a scan without it is refused before the image is read, not merely hidden from view.

What is sent: the single photo or PDF you choose, and the current date. Nothing else accompanies it: not your name, your profile, your documents, nor any other letter. Who it is sent to: Anthropic (United States), whose Claude model reads the letter and returns the explanation. Anthropic acts as our processor under a data processing agreement, and their terms do not permit them to use what we send for their own purposes or to train their models on it. Anthropic deletes what we send within 30 days of receiving it. That deletion is theirs to perform, on their systems, and it is the one part of this we cannot carry out ourselves.

Withdrawing. Turn AI letter scanning off under Account and no further letter is sent, with immediate effect and no other part of settlme affected. Withdrawal is as easy as agreeing was, as Article 7(3) GDPR requires, and it does not delete the explanations of letters you already scanned. Delete those individually, or delete your account. If what we send, or who we send it to, ever changes, the disclosure is put back in front of you and your previous agreement no longer counts.

When you scan a Dutch letter, the image is sent to our AI processor for analysis and then discarded. settlme's own servers never write the photo to disk, to a log, or to our database at any point. Only the plain-English explanation is kept: what the letter is about, any deadline, any amount, and the sending organisation.

Before that explanation is saved, it is automatically scrubbed of personal identifiers. We remove burgerservicenummers (BSN), IBANs and bank details, postcodes, telephone numbers, and e-mail addresses. This runs on our servers on every scan, so it applies even if the analysis model returns something it should not.

One honest limit: automated redaction matches patterns, so it reliably catches structured identifiers like the ones above, and just as reliably misses the things that have no pattern. A postcode is removed because "1015 DX" has a shape; a street name and house number do not, and neither does a personal name. The analysis is instructed to write about you in the second person and to skip the letterhead, but we cannot promise either one never survives. Do not scan documents you would not want stored in summary form, and use the delete option if you change your mind.

5. Who inside settlme can see what

Our admin panel exposes aggregate statistics only: totals, averages and breakdowns across all users. There is no admin tool, screen or query that shows an individual user's profile, documents, email or activity. That is a structural limit in how the panel is built rather than a promise about behaviour.

Two deliberate exceptions, both limited to what you sent us on purpose: posts reported by other users are readable in the moderation queue, and messages you send through the contact form are readable by the person answering them.

6. Who processes data for us

Your data lives in the Netherlands. It is stored on servers in Amsterdam, and the two providers below that hold it do so inside the European Union.

  • Railway — the application and the database, hosted in Amsterdam. This is where everything you save actually sits.
  • Cloudflare — serves this website from within the EU. The app talks to the server directly, so nothing you save in settlme passes through it.

Two features reach outside the EU, and only those two. Each is a single API call, carrying only what that call needs:

  • Anthropic (United States) — reads a letter you scan and sends back the explanation. It receives the photograph and nothing else about you, and only after you have agreed to it in the app. Their terms delete it within 30 days and do not permit them to train models on it. Section 4 covers what is disclosed, and how to withdraw.
  • Resend (United States) — delivers sign-in links, the weekly summary and replies to your messages. It receives your email address and the text of the message being sent.

For those two transfers we rely on the European Commission's standard contractual clauses, and where the provider is certified, on the EU-US Data Privacy Framework. Each of the providers above acts as a processor under a processing agreement (verwerkersovereenkomst) as Article 28 GDPR requires. You can ask us for the details through the contact form.

If you turn notifications on, the reminder itself is scheduled on your own phone and never leaves it. The weekly summary and community notices are the exception: those are sent from the server through Expo (United States), which receives your device's notification token and the text of the notice. Turning notifications off removes the token.

7. How long we keep it

  • Your profile, document dates and saved files: until you delete them, or until you delete your account. The identifying numbers in section 3 have no retention period here, because we never receive them.
  • Letter explanations: until you delete the letter or your account. The photograph itself is never stored by us at all; the copy Anthropic receives in order to read it is deleted on their side within 30 days.
  • Contact form messages: up to two years after the message is answered, so we can show a request was handled, then deleted.
  • Sign-in link records: the link itself expires after 15 minutes, and the record of it being requested is deleted a month later. It is kept that month so we can investigate a link you tell us you never asked for.
  • Posts in Ask: kept after account deletion with every identifying detail removed, as described in section 8, because other people rely on the answers.

8. Deleting your account

You can delete your account and all associated data at any time from the Account screen in the app. Deletion is immediate and permanent: there is no grace period and no way to undo it.

The one exception: if you have posted questions or answers in the community, that content may be kept after deletion, with every piece of identifying information stripped out, because it may still be useful to other people going through the same process. Nobody can trace a kept post back to you afterwards.

9. Your rights

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you (Art. 15);
  • correct data that is wrong or incomplete (Art. 16);
  • erase your data (Art. 17), which the Account screen also does immediately;
  • restrict what we do with it while a question about it is open (Art. 18);
  • hand it over in a portable, machine-readable form, to you or to another provider (Art. 20);
  • stop processing based on our legitimate interest, on grounds relating to your situation (Art. 21).

Two of those do not need us at all. Account, then Download my data, builds a zip of everything we hold about you and hands it straight to your phone: your checklist and its dates, what was read out of the letters you scanned, your contracts, what you posted in Ask, and the files you uploaded, as JSON any program can read, with a plain-English README beside it. That is Article 15 and Article 20 both, answered in a second rather than in the month the law gives us. Deletion is in the same place and is just as immediate.

The five things above are not in that archive, and cannot be: they were never sent to us. They are still on the phone you typed them into.

If the phone is gone, write to us and we will build the same archive and email it — but only to an address the account itself has verified, never to one named in the request. Where there is no verified address, we will have to ask you something only you would know first. That question is what stops someone else obtaining your data by asking politely.

Where we rely on your consent you can withdraw it at any time, which does not affect what we did with it beforehand. Requests go through the contact form, which gives you a reference and a date. We answer within one month, the deadline Article 12 sets. Because the app recognises a device rather than a person, we may have to ask you something only you would know before acting on a request, so that nobody else can make it about you.

If you are not satisfied with how we handle it, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority where you live.

10. Automated decisions

settlme works out which deadlines apply to you by applying published rules to the profile you gave it. That is automated, but it produces a checklist rather than a decision about you: nothing here has legal effect or similarly significant effect in the sense of Article 22 GDPR, and no authority sees or acts on it. Every binding decision about your situation is made by the relevant authority, not by this app.

11. Children

settlme is meant for adults handling their own paperwork. We do not knowingly collect data from anyone under 16, the age the Uitvoeringswet AVG sets for consent in the Netherlands. If you believe a child has given us data, tell us and we will remove it.

12. Security

Data is encrypted in transit and at rest, and it is stored in Amsterdam. Documents and files you upload are only ever readable in the context of your own account. If a breach ever puts your rights at risk, we will report it to the Autoriteit Persoonsgegevens within 72 hours and tell you directly where the law requires it.

13. This website

This site sets no tracking or advertising cookies and runs no analytics. The app stores a small amount of data on your own device so it can remember you between sessions, which is what makes the app work rather than something we read.

14. Changes to this policy

If this policy changes in a material way, we will tell you inside the app before the change takes effect, and the date at the top of this page will change.