LEGAL

Privacy Policy

Sojourn is operated by Sojourn Technologies L.L.C-FZ, located in United Arab Emirates. For any privacy-related questions, contact support@sojourn.tax. In this policy, "we", "us" and "our" refer to Sojourn Technologies L.L.C-FZ, and "you" refers to the user of the Sojourn mobile application — and, for section 3(j) only, to anyone who joins our launch waitlist on the website. For the purposes of the EU and UK General Data Protection Regulation ("GDPR") and comparable data-protection laws, Sojourn Technologies L.L.C-FZ is the data controller responsible for the limited personal data described in this policy.

Sojourn is a tax-residency day-tracking app. We have built it to keep your personal data on your phone — not on our servers. We run no backend that stores your stay log, your identity, or your location, and we have no analytics, advertising, or tracking. The requests the app does make travel through a small relay we run on Cloudflare, which passes them to the providers in section 5 and keeps nothing. The one exception — the only personal data we hold on our own infrastructure — is an email address you give us on our website to be told when Sojourn launches (section 3(j)). The only times your information leaves your device are: (a) to send a one-time code to your email — or to your phone over WhatsApp, if you pick that channel — so we can verify the account is yours; (b) when Apple or Google process your subscription payment; (c) when we exchange subscription state with our subscription-management provider, RevenueCat, so we know whether to grant you Pro features; (d) when you write to us from Suggestions or Help, which sends that message to our support inbox; (e) when you ask the Sojourn AI assistant a question, which sends your prompt (Pro only); (f) if the app crashes and you have left crash reports switched on — an anonymous diagnostic trace with your personal details stripped out first; and (g) if you create an encrypted backup and choose where to save it — a file locked with a passphrase only you hold, that not even we can open. That is the entire list. You can read the long version below, but those points are the policy.

We collect only what we need to make the app work. Each item below explains what it is, why we need it, and where it lives.

We need your name, date of birth, and residency country because these appear on every CSV or PDF export of your stay log — that is what makes the export usable as supporting evidence with a tax authority. We need your email so we can verify the account is yours (anti-abuse). Your username is what we display inside the app and on exports. To move your data to a new phone, or to keep a safe copy, you use the encrypted-backup feature described in section 3(h) — recovery is that file, not your email. If you choose to receive verification codes via WhatsApp, your mobile number is also used to deliver those codes — see section 3(b) below.

Where it lives: on your device only. We never transmit your name, date of birth, residency country, or username to any server.

When you register or log in, we send a 6-digit verification code to the channel you picked at registration — email by default, or WhatsApp if you opted in to that channel:

Switching channels later (Account settings → Verification channel) does not retroactively delete logs at the previous provider; their retention periods continue to apply.

If you grant background location permission and turn on auto-detection, the app uses your device's GPS to detect when you cross the geofenced border of your tracked country, so it can prompt you to confirm an entry or exit. Your raw location is never recorded, transmitted, or analysed — the app simply reacts to "inside" or "outside" the geofence and writes the resulting entry / exit event to the local database.

If you are a Pro subscriber and have "Track US state residency" enabled, Sojourn also uses background location to detect which US state you are in, so it can propose days toward your state residency count. The GPS reading is reverse-geocoded on your device to a state name; only the date and state are stored, never your raw coordinates. Proposed days are presented for your confirmation before they count toward any total. You can disable this at any time by turning off state tracking in Settings → Tracking.

Where it lives: nowhere. Coordinates are evaluated in memory and discarded. Only the resulting event (country entry/exit, or date + state for US state tracking) is persisted on your device.

Every entry-into-country or exit-from-country event, with timestamp, source (auto-detected, manually entered, or edited), and any note you add.

Where it lives: on your device, in a local SQLite database.

If you purchase a Pro subscription, the transaction is processed by Apple (on iOS) or Google (on Android). We do not see your payment card. We use a third-party service, RevenueCat, to track whether you have an active subscription so the app knows whether to unlock Pro features. RevenueCat receives an anonymised identifier for you and your transaction details from Apple/Google, but not your name, email, or any other personal data we collect.

Where it lives: the active state of your subscription is cached locally so the app works offline. The authoritative copy lives with Apple, Google, and RevenueCat under their respective privacy policies.

When you choose to attach a photo as evidence, take one in the app, or import stays from your photos, Sojourn reads the location and time embedded in that photo to suggest where and when you travelled. This happens entirely on your device — the coordinates are turned into a country name locally, using a borders dataset bundled inside the app, and are then discarded. Your photo coordinates are never uploaded or sent to anyone. We only ever read photos you explicitly select or capture; we never scan your photo library.

Where it lives: only the resulting country and date are kept, on the draft stay you confirm; the raw coordinates are evaluated in memory and discarded. The photo itself is stored on your device only if you attach it as evidence.

When you send us a message from Suggestions or Help, that message leaves your device so it can reach our support inbox. It carries your name and title, the text you wrote, and any screenshot you chose to attach. The text of your message — and never your name, title, or email — is also sent to Anthropic to draft a suggested first reply for us; a person reads and sends the actual response.

Where it lives: in our support inbox, and in the sending logs of the providers in section 5. A copy of what you sent is also kept on your device so you can read it back in the app.

Sojourn lets you export an encrypted backup of your on-device data so you can move it to a new phone or keep a safe copy. The backup contains a copy of what is already on your device — your identity fields, stay events, notes, attached evidence, and signature — packaged into a single file and encrypted with a key derived from a passphrase you choose.

This is a zero-knowledge design: your passphrase never leaves your device, we never see it, and we cannot open your backup. When you create a backup, your device hands the finished encrypted file to your operating system's share sheet, and you decide where it goes — another device, your own cloud storage (such as iCloud Drive or Google Drive), or a message to yourself. Once the file reaches a destination you chose, that destination's own privacy policy applies to it.

To recover, you open the backup file on any device running Sojourn and enter the same passphrase. Because only you hold the passphrase, if you lose it the backup cannot be recovered — by us or by anyone else. That is the trade-off for a backup no one but you can read.

Where it lives: nowhere on our side. We never receive, store, or have the ability to decrypt your backup. It lives only where you choose to save it.

If the app crashes, an anonymous diagnostic trace is sent to Sentry, our crash-reporting provider, so we can find and fix the fault. Before anything leaves your device it is stripped: your name, email, date of birth, phone number, address, PIN, verification codes and any GPS coordinates are removed, and network request logs are dropped entirely. What remains is the technical trace of the failure and an anonymous device identifier. Sentry is configured in its European Union region.

You can turn this off at any time in Settings → About → "Send crash reports". It is on by default; switching it off stops the reports at your device.

Where it lives: with Sentry, in the EU, under their privacy policy.

If you enter your email address on our website to be told when Sojourn launches, we store that address — and nothing else — so that we can send you that one announcement. It sits in Cloudflare's key-value store, which the relay runs on. This is the only personal data we keep on our own infrastructure, and it exists because there is no other way to email you later.

We use it for exactly one message: that Sojourn is live. No marketing, no newsletter, no sharing with anyone. Write to support@sojourn.tax and we will remove you immediately; otherwise we delete the list once the launch announcement has been sent.

Where it lives: with Cloudflare until we send the announcement, and with Postmark at the moment of sending. Never on your phone — this one runs the other way round.

When you export an audit record, or import an airline roster, Sojourn keeps a copy of the finished PDF in Settings → Your reports, so you can find it again without recreating it. A report contains the same information as the export itself — your identity fields and the stays it covers — and nothing more.

These reports are stored on your device only, encrypted at rest with a key held in your device's secure keystore, exactly as your signature and your attached evidence are. They never leave your phone unless you choose to share one. When you delete a report — or delete your account — the encrypted file is removed from your device.

Where it lives: on your device only, encrypted. Never on our servers.

Where the GDPR applies to you, we rely on the following legal bases for the limited processing above:

To remove any doubt:

The following service providers process limited information strictly to make the app work. Except for Apple and Google — who act as independent controllers for the payment relationship under their own policies — these providers act as our data processors, handling the data only on our instructions and only for the purpose shown. None of them receive a complete profile of you.

We have a Data Processing Agreement in force with every provider above, each including Standard Contractual Clauses for transfers out of the European Economic Area. Their respective privacy policies are linked from inside the app at Settings → About → Third-party services.

If you are in the European Economic Area, the United Kingdom, Switzerland, California, or any other jurisdiction with similar data-protection laws, you have the following rights:

To exercise any of these rights that aren't already available inside the app, email us at support@sojourn.tax. We will respond within 30 days.

EU / UK / Swiss representative. Because Sojourn Technologies L.L.C-FZ is established outside the European Economic Area, the United Kingdom and Switzerland, we have appointed a representative in each of those places for data-protection matters — under Article 27 of the GDPR, Article 27 of the UK GDPR, and Article 14 of the Swiss FADP respectively.

Our representative is DataRep (the trading name of Data Protection Representative Limited, a company registered in Ireland under number 616588; appointment reference SOJO01). On any data-protection matter concerning Sojourn you may contact DataRep — as an alternative to writing to us at support@sojourn.tax, and alongside your right to complain to your own national data-protection authority.

Write to DataRep at the address for your country below. Address your letter to "DataRep" and mention Sojourn Technologies L.L.C-FZ, so it reaches the right place — post addressed to us directly at these locations may not be received. For anything about the app itself, rather than your data-protection rights, please use support@sojourn.tax instead.

We are represented by DataRep in the EU We are represented by DataRep in the UK We are represented by DataRep in Switzerland

When you delete your account, we wipe everything on your device. However, six categories of information persist outside our control:

The "Delete my account" confirmation screen restates these caveats in the app so you see them before you delete.

All identity, location, and stay data lives on your phone. We do not run servers that store your data. The third-party services in section 5 may process limited data on servers located outside your country of residence; specifically:

If you are in the European Economic Area, transfers to non-EEA countries are made under appropriate safeguards (typically Standard Contractual Clauses).

How long we keep it. Your on-device data stays on your device until you remove it — either by deleting individual entries or by using "Delete my account and data", which wipes it immediately. Because we hold none of it on a server, there is nothing for us to retain on a schedule or to delete on your behalf. The third-party providers in section 5 keep the limited data they process only for the periods stated in their own privacy policies.

We do not promise that no security incident can ever occur, because no one honestly can. We do promise to design the app so that the consequences of an incident are minimised.

If a breach occurs. Because your data lives on your device and not on our servers, the realistic breach surface is one of the third-party processors in section 5, or your own device. If a personal-data breach at one of our processors affects you and is likely to result in a risk to your rights, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, as required by Article 33 GDPR — and we will inform affected users without undue delay where Article 34 requires it. A lost or stolen device is a device-security matter rather than a breach of our systems; its protection depends on your device passcode and biometrics.

Sojourn is not directed at children. The registration form rejects any date of birth that would make the user under 16 years of age at the time of sign-up. If you become aware that a child under 16 has provided personal data through the app, please contact us at support@sojourn.tax and we will help you delete the account.

We may update this policy from time to time — for example, to reflect new third-party providers we add, or new features that change what we collect. When we make a material change, we will:

If you do not accept the updated policy, you may delete your account at that point.

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights, which we honour:

For any privacy-related question, request, or complaint:

support@sojourn.tax

Sojourn Technologies L.L.C-FZ

United Arab Emirates