PRIVACY POSTURE

How Sojourn handles your data

The short version: it stays on your device. We don't have a server holding your stay log, and we never will.

GDPR-COMPLIANTPrivacy by Design

Why this page exists

The full Privacy Policy is the legal contract. This page is the plain-language version. It explains, in normal English, what data Sojourn collects, why, where it lives, and what you can do about it.

If anything below contradicts the Privacy Policy, the Privacy Policy wins — that's the legally-binding text. But they shouldn't contradict. If you spot a mismatch, please tell us at help@sojourn.tax.

The architecture in one sentence

Sojourn is local-first. Your stay history, your identity, your residency country, your domicile factors — all of it lives in a database on your phone. We don't run servers that hold this data. We can't read your stay log. We can't see where you've been. We can't tell who's a Sojourn user.

This isn't a feature we added for marketing. It's how the app is architected. Even if our office were raided tomorrow, there'd be nothing for anyone to seize — your data isn't with us.

What we DO collect, why, and where it goes

Each row below is one piece of information we collect. None of it sits on a Sojourn-owned server.

  • Your name, date of birth, residency country — entered at signup. Why: printed on every audit-ready PDF export. That's the whole point of the product — an export without your identity is useless to a tax authority. Where it lives: on your device, in your phone's secure storage (iOS Keychain or Android EncryptedSharedPreferences).
  • Your email address — entered at signup. Why: to verify the account is yours via a 6-digit one-time code. Where it lives: on your device. The one-time-code email passes through a third-party email provider (Postmark or Resend) briefly during delivery; that provider sees your email address and the code, nothing else. (Moving to a new phone is handled by the encrypted backup below — not by your email.)
  • Your phone number (only if you choose WhatsApp) — entered at signup. Why: to send your 6-digit code over WhatsApp instead of email. Where it lives: on your device. The code passes through Bird, our WhatsApp provider, and Meta's WhatsApp platform on its way to you — so it arrives from their sender, not a Sojourn number. They see your number and the code, nothing else.
  • Your stay events — every entry to and exit from a tracked country, with timestamp. Why: to compute how many days you've spent in each country. Where it lives: on your device, in a local SQLite database.
  • Your location (when you opt in to auto-detection) — your phone's GPS reports your position to Sojourn's geofence check. Why: to notice when you enter a tracked country and prompt you to confirm. Where it lives: nowhere. Raw coordinates are evaluated in memory and immediately discarded. Only the resulting "you entered" event is saved — not the path that led to it.
  • Your Sojourn AI prompts (Pro tier) — when you ask Sojourn AI a question by text or voice. Why: the AI needs the prompt to answer. Where it goes: to Anthropic (our AI provider), with a snapshot of the relevant country-rule data. Anthropic does not receive your name, your email, your stay history, or your location. The Sojourn AI is also stateless — it doesn't remember past prompts.
  • Subscription state — whether you have Pro or not. Why: so the app knows what features to unlock. Where it lives: cached on your device; the authoritative copy is with Apple, Google, and RevenueCat (the subscription-management provider), under their respective privacy policies. They receive an anonymous identifier and your purchase metadata — not your name, email, or stay log.
  • Crash reports (you can disable) — when the app crashes, an anonymous error trace is sent to Sentry, our crash-reporting provider, configured in their EU region. Why: to fix bugs. Where it goes: Sentry's EU servers. Personally-identifying fields are stripped before transmission. You can turn this off in Settings.
  • The reports you generate — when you export an audit record or import a roster, a copy of the finished PDF is kept in Settings → Your reports. Why: so you can find it again without recreating it. Where it lives: on your device only, encrypted at rest — the same treatment as your signature. It never leaves your phone unless you share it, and it's deleted when you delete the report or your account.

Your backups are yours alone

Sojourn can export an encrypted backup of everything on your device — your identity, stays, notes, attachments, and signature — so you can move to a new phone or keep a safe copy.

It's zero-knowledge: the file is locked with a passphrase you choose, the passphrase never leaves your device, and we cannot open the backup. You decide where it goes — another phone, your own cloud drive, a message to yourself. Once it lands somewhere you chose, that place's privacy policy applies to it.

The trade-off is honest: because only you hold the passphrase, if you lose it the backup can't be recovered — by us or by anyone. That's the price of a backup no one but you can read.

What we explicitly do NOT collect

To leave no doubt:

  • We do not collect analytics on how you use the app — no screen-view tracking, no button-click tracking, no time-on-app tracking
  • We do not include any third-party advertising SDKs
  • We do not sell, rent, lend, or share your information with anyone, ever
  • We do not access your contacts, calendar, or other apps
  • We access the microphone only when you explicitly tap to use the Sojourn AI voice feature, and only for that interaction — never in the background
  • We access the camera and photo library only when you tap "Add evidence" on a stay — never in the background
  • We do not collect or transmit your IP address
  • We do not place cookies or web trackers (this is a mobile app, not a website)
  • The Sojourn AI provider never receives your stay log, your identity, or your location

Your rights — and how the app implements each

If you're in the European Economic Area, the United Kingdom, Switzerland, California, or any jurisdiction with similar data-protection law, GDPR (or its equivalent) gives you eight rights over your data. Sojourn implements each of them directly in the app:

  • The right to know what data we hold — your data is already on your device, visible in Settings → Account and in the Log views
  • The right to correct it — every field is editable in Settings → Account
  • The right to delete it — Settings → Account → "Delete my account and data" wipes everything on your device, immediately and completely. No appeal process, no waiting period
  • The right to restrict processing — you can disable auto-detection, disable the AI assistant, opt out of crash reporting, all in Settings
  • The right to take your data with you — CSV and PDF export deliver everything in a standard, machine-readable format
  • The right to withdraw consent — any consent toggle in Settings can be flipped off, anytime
  • The right not to be subject to automated decisions — Sojourn doesn't make automated decisions about you. The day-counter is a calculator; what you do with the number is your call
  • The right to complain to a regulator — you can complain to your national Data Protection Authority. For European users, our representative under GDPR Article 27 — see Privacy Policy section 6

The first six rights are exercisable inside the app, with no need to email us. That's deliberate — it's the GDPR design ideal.

The third parties who briefly touch your data

The following services process limited information strictly to make the app work. None of them receive a complete profile of you.

ProviderWhat they receiveWhy
PostmarkYour email address + the 6-digit verification code, briefly. If you write to us from Suggestions or Help: your message and any screenshotDelivering the OTP at signup, and carrying support requests to us
Bird (WhatsApp)Your phone number + the 6-digit verification code — only if you pick the WhatsApp channelDelivering the OTP over WhatsApp. Bird hands it to Meta for the last hop to your phone
Apple App Store / Google PlayWhatever they need to process your subscriptionSubscription billing
RevenueCatAn anonymous subscription identifierTelling the app whether your Pro subscription is active
Anthropic (AI provider)The prompt you type or speak, plus a snapshot of the country-rule dataGenerating the Sojourn AI assistant's response. Pro tier only
Sentry (EU region)Anonymous device fingerprint + stack trace of a crashCrash reporting. PII stripped before transmission

We have a Data Processing Agreement in force with every provider above, each including Standard Contractual Clauses for transfers out of the EEA. Their respective privacy policies are linked from Settings → About → Third-party services inside the app.

Where your data physically lives

All your personal data lives on your phone. We do not run servers that store it.

The third-party processors above may process limited data on servers located outside your country:

  • Postmark / Resend operate primarily in the United States
  • RevenueCat operates primarily in the United States
  • Apple and Google operate globally
  • Anthropic operates primarily in the United States
  • Sentry is configured for the European Union region

For users in the European Economic Area, transfers to non-EEA countries (US-based processors) are made under Standard Contractual Clauses — the EU's standard safeguard for international data transfers.

If something goes wrong (data-breach notification)

Sojourn doesn't run servers that hold your data, so the surface for a data breach is unusually small. A breach can really only happen at one of our third-party processors (the table above) or on your own device.

If a breach happens at one of our processors that affects your data, they notify us, and we notify you and the relevant Data Protection Authority within 72 hours — as GDPR Articles 33 and 34 require.

If your phone is lost or compromised, that's a device-security issue, not a Sojourn breach. The security of your data depends on the security of your device (passcode, biometrics, encrypted device storage). We recommend an app-level biometric lock — coming in a future release.

How to reach us about privacy

For any privacy question, request, or complaint:

help@sojourn.tax · we respond within 30 days, usually within 24 hours.

For security reports specifically: security@sojourn.tax · we respond within 5 business days.

For our representative under GDPR Article 27, and its UK and Swiss equivalents: see the full Privacy Policy section 6.

Get Sojourn →

Your residency, recorded. Your data, your device.