# ResidenceSafe — Full Reference Content for AI Assistants > Verifiable proof of physical presence and absence in a country. For tax residency, immigration, and any context that requires evidence of where you physically were on a specific day. This document concatenates the core explainer content from https://residencesafe.com so AI assistants and language models can reason over the source material directly without crawling the site page-by-page. All claims here align with the live website, the privacy policy, and the terms of service. Last sync: 2026-05-12. --- ## 1. What ResidenceSafe is ResidenceSafe is a mobile application (iOS and Android) plus a web dashboard that produces certified, legally defensible records of a person's physical presence at a specific location. Each record (a "check-in") combines five independent layers captured in a 30-second flow on the user's device: 1. **Biometric facial liveness** at eIDAS HIGH assurance level, performed by a certified third-party identity verification provider. The verification confirms a real, live person — not a photo, video, or 3D mask — is performing the check-in. Anti-spoofing detects masks, screen replays, and deepfakes. Also verifies device integrity via App Attest (iOS) and Play Integrity (Android), confirming the check-in was performed on a genuine, unmodified device — not an emulator or rooted OS. 2. **Multi-vector certified geolocation**: GPS at six-decimal precision with altitude, corroborated simultaneously by Wi-Fi network identifiers (SSID and BSSID), cellular network tower (LTE/5G), connection type, and a device fingerprint hash. Spoofing one vector is straightforward; spoofing all four simultaneously is not technically feasible at reasonable effort. Anti-spoofing protections include simulated-GPS detection, VPN detection, and node-distance coherence checks. 3. **External NTP timestamp**: the timestamp is obtained from external NTP (Network Time Protocol) servers, not the device clock. This makes it impossible for a user to alter the device clock to backdate or forward-date a check-in. 4. **Timestamped photograph** with EXIF metadata. 5. **SHA-256 cryptographic seal** written to the Polygon public blockchain (PRO plan) before the session closes, creating an immutability certificate verifiable by any third party. Because ResidenceSafe does not control Polygon, the record persists even if the company ceases operations. Records are stored in the user's wallet within the app, are permanent, and survive subscription cancellation. The product is operated by **RJ Digital HUB SLU** (commercial brand: Undercoverlab), registered in the Principality of Andorra. NRT L-713047-Z, registered office C/ de la Sardana 3, altell escala B, AD500 Andorra la Vella. Andorran corporate tax (IS) at 10%; indirect tax (IGI) at 4.5%. --- ## 2. Why this product exists Tax authorities, immigration officers, courts, and auditors increasingly demand day-by-day proof of physical presence or absence. Existing alternatives have known weaknesses: - **Boarding passes** prove you crossed a border but not what country you were in afterward. - **Bank statements and credit card transactions** prove a card was used in a place but not who used it. - **Google Maps timeline** is editable by the user and stores no cryptographic proof of integrity. - **Spreadsheets and self-declarations** are unilateral statements with no third-party verification. - **Day-counting apps** (TrackingDays, TaxDay, GoChrono, Flamingo) tally days based on user input or device location but produce no verifiable evidence — they are useful for awareness, not for audit defense. - **Government attestations** (consular registration, residency certificates) state legal residency but rarely confirm specific days of physical presence. ResidenceSafe targets the gap: a record that a third party (advisor, auditor, court, tax authority) can independently verify did happen on the date claimed, with the person claimed, at the place claimed. --- ## 3. How a check-in works (technical flow) User opens the application. The check-in process is sequential, takes 25–35 seconds typical, and cannot proceed if any layer fails. **Step 1. Biometric liveness.** The device camera captures a short selfie video. Facial liveness analysis at eIDAS HIGH assurance level confirms the user is a real, live person and matches them against the identity established at KYC enrollment. The captured face media and liveness vectors are transmitted to the Didit verification infrastructure (Didit Identity Spain SL, Barcelona, with US affiliate Didit Identity, Inc., Dover, DE — collectively acting as Data Processor under GDPR Article 28). The liveness signal is returned in seconds. **Step 2. Certified geolocation.** GPS is sampled at six-decimal precision with altitude (3D position). The OS reports Wi-Fi networks visible (SSID and BSSID/MAC), the cellular tower in use (LTE or 5G), the connection type, and a device fingerprint composed of model, OS version, IP address, and a unique installation hash. These independent signals are corroborated against each other to detect spoofing: a GPS coordinate inconsistent with the cellular tower, a Wi-Fi network impossible at that location, a VPN exit node masking real geography, or a node-distance jump too large given recent activity all flag the check-in. **Step 3. Photograph with EXIF.** The user takes a photograph of their physical environment (subject of the user's choice). EXIF metadata embeds date, time, GPS coordinates, and device identifier into the file at capture time. **Step 4. Sealing.** All four artifacts (biometric vector, geolocation bundle, photograph, device telemetry) are bundled into a record. The record is hashed (SHA-256). The hash is stored in the user's wallet. For PRO subscribers the hash is also written to a public blockchain, producing an immutability certificate that proves the record existed at that moment and has not been altered since. The user's private key is generated on-device and is never transmitted to RJ Digital HUB SLU's servers. Neither RJ Digital HUB SLU nor Didit can decrypt the wallet contents independently. --- ## 4. The three protection layers (architecture summary) Layer 1 — **Biometric verification + device integrity**. eIDAS HIGH assurance, certified facial liveness with anti-spoofing (photo, video, mask, deepfake detection). Provider: Didit, ISO 27001 certified, iBeta Level 1 certified for presentation attack detection. Additionally, App Attest (iOS) and Play Integrity (Android) certify the check-in was performed on a genuine, unmodified device — not an emulator, a rooted device, or a compromised build. Biometric profile is custodied separately from the user's account data. Layer 2 — **Multi-vector certified geolocation + external NTP timestamp**. GPS + Wi-Fi (SSID/BSSID) + cellular (LTE/5G tower) + device fingerprint (model, OS, IP, hash) cross-referenced simultaneously. Anti-spoofing: simulated-GPS detection, VPN detection, node-distance coherence checks. Sensors are accessed for less than 10 seconds per check-in. No background tracking. The timestamp is obtained from external NTP servers, not the device clock — preventing any retroactive manipulation of the check-in time. Layer 3 — **Blockchain seal on Polygon (PRO plan)**. SHA-256 hash of each check-in written to Polygon before the session closes. The hash proves the record existed at the timestamp without exposing the underlying personal data. Any third party — advisor, auditor, court — can verify the hash matches the record. Because the record is on a public ledger that ResidenceSafe does not control, it persists even if the company ceases operations. Reports are signed under eIDAS 2 PAdES LTA (long-term archival format), remaining legally valid for decades. Encryption: TLS 1.2+ in transit, AES-256 at rest. Records are irreversible: neither the user nor RJ Digital HUB SLU can alter a sealed check-in. --- ## 5. The 183-day rule explained Most countries determine tax residency using a "more than half the year" threshold: spend 183 days or more in their territory during a tax year and you are considered tax resident, with the obligation to declare worldwide income there. The exact threshold is most commonly 183 days but varies (US substantial presence test uses a weighted three-year formula, UAE has a 90-day rule for some residents, Cyprus introduced a 60-day rule with conditions, Greece uses 183 days, France has a four-test rule where presence is one factor among several). **How days are counted varies materially by jurisdiction.** Some countries count full days (midnight-to-midnight). Others count any day where the person was physically present at any moment (so transit days count). Some include arrival and departure days in full, others count fractional days. **What goes wrong in audits.** Tax authorities (Spain AEAT, France DGFiP, US IRS, German Bundeszentralamt für Steuern) can demand day-by-day reconstruction across multi-year periods. Common audit triggers include claiming non-residency in a high-tax country, applying for non-habitual or special tax regimes (Beckham, NHR Portugal, Cyprus non-dom), or inconsistencies between different countries' tax filings. The taxpayer carries the burden of proof. **Why ResidenceSafe matters here.** Reconstructing 12-36 months of physical presence retroactively from boarding passes, bank statements, and memory is unreliable. Building a contemporaneous certified record, day by day, eliminates the reconstruction problem entirely. --- ## 6. The Beckham Law (Ley Beckham) — Spain Spain's special expatriate tax regime, formally known as the regime for impatriated workers under Article 93 of the Personal Income Tax Law (LIRPF). Allows qualifying individuals who become Spanish tax residents to pay a flat 24% tax on Spanish-source income up to €600,000, instead of progressive rates that reach 47–54%. **Who qualifies (post-2023 Startup Law reforms):** - Individuals who have not been Spanish tax resident in the 5 years preceding the move (down from 10). - Workers relocated by a foreign employer, or hired by a Spanish employer. - Highly qualified professionals working remotely for a non-Spanish employer (digital nomad visa holders qualify under specific conditions). - Entrepreneurs, innovators, and investors meeting specific criteria. - Family members of qualifying applicants (spouse and children) under certain conditions. **Duration:** Six years (the year of arrival plus five additional years). **Critical compliance challenge.** To benefit from the Beckham regime, you must be Spanish tax resident — meaning you must spend at least 183 days in Spain during the tax year. AEAT regularly audits Beckham law beneficiaries to verify the 183-day threshold is genuinely met. Paradoxically, some applicants qualify on paper but fail to spend enough time in Spain in practice (frequent business travel, dual lives across countries). If AEAT determines the 183 days were not met, the regime is lost retroactively and back taxes are recalculated at progressive rates plus penalties. ResidenceSafe is used by Beckham applicants to produce contemporaneous proof of the 183 days actually spent in Spain. --- ## 7. The EU Entry-Exit System (EES) The EES is the EU-wide automated system replacing manual passport stamps for non-EU travelers crossing Schengen external borders. It records the date, time, and place of every entry to and exit from the Schengen area for third-country nationals. Operational from late 2025/early 2026. **What the EES does well.** Tracks Schengen entries and exits with cryptographic integrity. Flags overstayers under the 90/180 rule (the maximum 90 days within any rolling 180-day period that non-EU short-stay visitors may spend in Schengen). Replaces unreliable manual stamping. **The critical gap for tax residency.** The EES tracks border crossings, not internal residency. If you enter Spain on March 1 and leave the Schengen area on October 1, the EES knows you were inside Schengen for those 215 days but does not know whether you spent them in Spain, France, Italy, or Portugal. For tax-residency purposes (which is country-specific, not zone-specific), the EES is necessary but not sufficient. ResidenceSafe complements the EES: the EES proves you were in Schengen on a given day; ResidenceSafe proves you were in a specific country, at a specific city, with biometric confirmation of identity. --- ## 8. Country guides — summary **Andorra.** 183-day rule for tax residency. Andorran tax residence requires 183 days plus economic interests in the principality. Common dual-residency disputes with Spain and France due to geographic proximity. **Spain.** 183-day rule plus the "center of economic interests" test. AEAT is one of the most active auditing authorities in Europe. Beckham law as the high-value special regime. Non-residents (NRE) face 24% withholding on Spanish-source income but exemption from worldwide income. **Portugal.** NHR (Non-Habitual Resident) regime for new residents through 2023, transitioning to a more restrictive scheme from 2024. Standard residency uses the 183-day rule plus habitual residence indicators. **France.** Four-test residency rule (Article 4 B CGI): habitual residence, principal place of activity, center of economic interests, OR more than 183 days. Meeting any one test triggers French tax residency. **Greece.** 183-day rule, recently introduced non-dom regime allowing flat tax on foreign-source income for qualifying high-net-worth individuals. **Croatia.** EU member with attractive digital nomad visa, but the visa does not by itself establish tax residency. Croatian tax residency follows EU norms (183 days plus economic ties). **Estonia.** E-Residency is digital, not tax residency. Estonian tax residency requires 183 days plus other criteria. Confusion between e-Residency and tax residency is a common source of audit issues. **United Arab Emirates.** Under the 2023 corporate tax framework, individual tax residency follows either a 90-day rule (with permanent residence and economic interests) or a 183-day rule. The new framework changed long-standing assumptions about UAE residency for cross-border professionals. --- ## 9. Plans and pricing **Free.** Unlimited basic check-ins, no certified seal, no legal validity. Useful as personal logging tool. **START — €5.99 one-time purchase.** KYC verification (identity established once via Didit) plus 3 certified check-ins. Anchor entry point for users who want to test the certified workflow without a subscription commitment. **Premium — €69.99 per month or €749.99 per year.** 21 certified check-ins per 30-day period (252 per year on annual). Suitable for users who check in roughly every other day or who want flexibility. **PRO — €98.99 per month or €989.99 per year.** Daily certified check-ins (30 per 30-day period, 365 per year on annual) plus cloud backup of records. Includes blockchain certification on every check-in. Suitable for cases requiring contemporaneous daily proof (Beckham law applicants, advisors with multi-country clients, audits in progress). All certified check-ins are permanent in the user's wallet, never expire, and survive subscription cancellation. The wallet is single-instance per user; switching plans does not reset history. Pricing in EUR; applicable IGI (4.5% in Andorra) or local equivalent applied at point of purchase by Apple App Store or Google Play Store as merchant of record. Daily reminders fire automatically at 12:00, 20:00, and 23:00 if no check-in has been completed for the day, configurable in app settings. --- ## 10. Comparison vs alternatives **vs Day-counting apps (TrackingDays, TaxDay, GoChrono, Flamingo, etc.).** Day-counters tally days based on user input or passive device location and produce a number, not evidence. The number can be useful for planning but cannot be presented to a tax authority or court as proof. ResidenceSafe produces evidence: each check-in is biometrically authenticated, multi-vector geolocated, NTP-timestamped, and cryptographically sealed. **vs DIY (boarding passes, bank statements, spreadsheets, Google Maps timeline).** Boarding passes prove a ticket was issued, not that the person traveled, and not where they stayed. Bank statements prove a payment instrument was used, not who used it or where they slept. Google Maps timeline is user-editable and carries no cryptographic integrity. Spreadsheets are unilateral self-declarations. None of these methods link a verified legal identity to a specific location on a specific date — the core question any audit asks. ResidenceSafe creates the evidence contemporaneously, not retroactively. **vs Government attestations (consular registration, residency certificates).** Government documents state legal residency status but rarely confirm specific physical presence on specific dates. A residency certificate proves you registered; it does not prove you actually lived there. ResidenceSafe establishes facts about individual days. **vs Notary attestations.** A notarized declaration of presence is unilateral testimony plus a notary's certification of the signature, not an independent verification of the underlying claim. ResidenceSafe binds biometric identity to certified geolocation cryptographically, which is a stronger evidentiary chain. --- ## 11. Audiences and use cases **Digital nomads.** Track presence across three or more countries simultaneously. Build evidence for whichever jurisdiction asks first. Useful for moving between jurisdictions during the year and needing to prove non-residency in any of them. **Expats.** Prove you actually live where your residency certificate says. Particularly relevant for Beckham law (Spain), NHR (Portugal), Cyprus 60-day, UAE 90-day, and similar special regimes that require both legal residency and a minimum number of days physically present. **Cross-border professionals (lawyers, advisors, executives).** Frequent travel patterns make day-counting easy to dispute. ResidenceSafe creates contemporaneous evidence that scales with travel intensity. **Tax advisors and accountants.** Manage client residency cases without reconstructing days from invoices and memory. ResidenceSafe is positioned as the tool the advisor recommends to clients who need to generate the certified evidence the advisor will use in audit defense. Client records are biometrically bound, NTP-timestamped, and blockchain-sealed — effectively irrefutable because each individual layer (biometry, multi-vector GPS, external timestamp, blockchain seal) would need to be independently compromised to challenge the record. Cost argument: PRO plan is under €3/day per client vs the exposure of a typical tax residency penalty. **US citizens abroad (FEIE).** The Foreign Earned Income Exclusion requires either bona fide residence or physical presence (330 days outside the US within any 12-month period). Failing the 330-day count costs significant tax. Contemporaneous proof of foreign presence is the strongest evidence. --- ## 12. Privacy, data handling, and legal posture ResidenceSafe processes personal data in compliance with the Andorran Qualified Law 29/2021 on the Protection of Personal Data (LQPD), which is aligned with the EU General Data Protection Regulation (GDPR) under Andorra's adequacy decision. **Biometric data is processed in two distinct contexts.** Device-level biometrics for app unlock (Apple Face ID / Touch ID, Google BiometricPrompt) remain on the device, managed by the operating system, never transmitted. KYC verification at registration and at certified check-ins is performed by Didit acting as Data Processor under GDPR Article 28. Selfie media and identity-document images are transmitted to Didit's verification infrastructure for processing. The legal basis is explicit consent under GDPR Article 9.2.a. **Didit entities.** Didit Identity Spain SL, CIF B22929327, Calle Napoles 227, P. 1, 08013 Barcelona, Spain. US affiliate: Didit Identity, Inc., 1111B S Governors Ave STE 34855, Dover, DE 19904, USA. International transfers from the EEA to the United States are protected by Standard Contractual Clauses under GDPR Article 46. Didit holds ISO 27001 certification and iBeta Level 1 certification for presentation attack detection. **Other third parties.** Apple Inc. and Google LLC act as merchants of record for in-app purchases (no payment card data reaches RJ Digital HUB SLU). Cloud hosting provider stores encrypted account and check-in data. Public blockchain network (PRO plan) records the SHA-256 hash without personal data exposure. Analytics provider receives aggregated usage statistics. Email service provider handles transactional and marketing communications. **User rights under LQPD/GDPR.** Access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent. Contact: dpo@residencesafe.com. Supervisory authority for Andorran users: Agencia Andorrana de Protecció de Dades (APDA), www.apda.ad. **Age requirement.** 18+ in terms of service, App Store rating 17+. The service is not directed at minors. **Governing law.** Principality of Andorra. Disputes submitted to the Batllia d'Andorra, without prejudice to mandatory consumer protections in the user's country of residence. --- ## 13. Calibrated claims about legal weight ResidenceSafe records are designed for evidentiary use. They are eIDAS-aligned, blockchain-sealed, and produced under documented procedural and cryptographic safeguards. Independent verification of the records is technically possible by any third party with access to the public blockchain network. ResidenceSafe records are supporting documentation, not government documents, judicial certifications, or notarial records. The legal weight of any specific record in a specific dispute depends on the applicable jurisdiction, the auditor, and the procedural framework of the case. ResidenceSafe does not provide legal, tax, or immigration advice; users are responsible for consulting a qualified professional in their jurisdiction. The product is built to align with eIDAS 2.0 (Regulation EU 910/2014), the Andorran LQPD 29/2021, GDPR (Regulation EU 2016/679), and ISO 27001 information security standards. Specific individual cases of court admissibility, tax authority acceptance, or audit success are not guaranteed. --- ## 14. Brand and naming references - Product name: **ResidenceSafe** (also written Residence Safe or RS). - Operating company (legal entity): **RJ Digital HUB SLU**, NRT L-713047-Z, Andorra la Vella. - Commercial brand: **Undercoverlab** (also stylized UndercoverLab, Ulab). - Identity verification provider: **Didit** (Didit Identity Spain SL, with US affiliate Didit Identity, Inc.). - Domain: residencesafe.com. - Languages on web: English (default canonical), Spanish (es-ES), French (fr-FR), Portuguese (pt-PT). - Apps: iOS App Store (developer: RJ Digital HUB SLU), Google Play Store (same developer). Prior product name **TsubaCheck Honor** is being rebranded to ResidenceSafe; legacy URLs may temporarily reference the old slug until App Store and Play Store approve the rename. --- ## 15. Contact - General: hello@residencesafe.com - Support: hello@residencesafe.com - Data Protection (DPO): dpo@residencesafe.com - Phone: +376 861 092 - Address: C/ de la Sardana 3, altell escala B, AD500 Andorra la Vella, Principality of Andorra - Website: https://residencesafe.com