Privacy Policy for Sojourn
Last updated: 26 July 2026
1. Who we are
Sojourn is operated by Sojourn Technologies L.L.C-FZ, located in United Arab Emirates. For any privacy-related questions, contact support@sojourn.tax. In this policy, "we", "us" and "our" refer to Sojourn Technologies L.L.C-FZ, and "you" refers to the user of the Sojourn mobile application — and, for section 3(j) only, to anyone who joins our launch waitlist on the website. For the purposes of the EU and UK General Data Protection Regulation ("GDPR") and comparable data-protection laws, Sojourn Technologies L.L.C-FZ is the data controller responsible for the limited personal data described in this policy.
2. The short version
Sojourn is a tax-residency day-tracking app. We have built it to keep your personal data on your phone — not on our servers. We run no backend that stores your stay log, your identity, or your location, and we have no analytics, advertising, or tracking. The requests the app does make travel through a small relay we run on Cloudflare, which passes them to the providers in section 5 and keeps nothing. The one exception — the only personal data we hold on our own infrastructure — is an email address you give us on our website to be told when Sojourn launches (section 3(j)). The only times your information leaves your device are: (a) to send a one-time code to your email — or to your phone over WhatsApp, if you pick that channel — so we can verify the account is yours; (b) when Apple or Google process your subscription payment; (c) when we exchange subscription state with our subscription-management provider, RevenueCat, so we know whether to grant you Pro features; (d) when you write to us from Suggestions or Help, which sends that message to our support inbox; (e) when you ask the Sojourn AI assistant a question, which sends your prompt (Pro only); (f) if the app crashes and you have left crash reports switched on — an anonymous diagnostic trace with your personal details stripped out first; and (g) if you create an encrypted backup and choose where to save it — a file locked with a passphrase only you hold, that not even we can open. That is the entire list. You can read the long version below, but those points are the policy.
3. Information we collect, and why
We collect only what we need to make the app work. Each item below explains what it is, why we need it, and where it lives.
a) Identity information you enter at registration:
- Username (3–30 characters)
- First name and last name
- Date of birth
- Email address
- Mobile number with country code (optional — required only if you choose to receive your verification code via WhatsApp)
- Country in which you are claiming residency, and the residency rule you have selected
We need your name, date of birth, and residency country because these appear on every CSV or PDF export of your stay log — that is what makes the export usable as supporting evidence with a tax authority. We need your email so we can verify the account is yours (anti-abuse). Your username is what we display inside the app and on exports. To move your data to a new phone, or to keep a safe copy, you use the encrypted-backup feature described in section 3(h) — recovery is that file, not your email. If you choose to receive verification codes via WhatsApp, your mobile number is also used to deliver those codes — see section 3(b) below.
Where it lives: on your device only. We never transmit your name, date of birth, residency country, or username to any server.
b) Verification code delivery, transiently:
When you register or log in, we send a 6-digit verification code to the channel you picked at registration — email by default, or WhatsApp if you opted in to that channel:
- Email: we hand your email address and the code to Postmark (the email provider), which delivers the message on our behalf. The email and the code may be retained in Postmark's delivery logs for the period stated in their own privacy policy (typically up to 30 days). We do not store the email-side trail ourselves.
- WhatsApp: we hand your phone number in international E.164 format (e.g. +971501234567) and the code to Bird (our WhatsApp Business provider), which passes the message through Meta's WhatsApp Business platform to your phone. The message reaches you from Bird's sender rather than from a Sojourn number, so the sender name and its country code will not look like ours. Bird and Meta may retain delivery metadata under their own privacy policies; the message content is the same 6-digit code you see on screen. WhatsApp is used ONLY for delivering verification codes — there is no chat surface, no inbound webhook, and the app never asks for or receives messages from you over WhatsApp.
Switching channels later (Account settings → Verification channel) does not retroactively delete logs at the previous provider; their retention periods continue to apply.
c) Location data:
If you grant background location permission and turn on auto-detection, the app uses your device's GPS to detect when you cross the geofenced border of your tracked country, so it can prompt you to confirm an entry or exit. Your raw location is never recorded, transmitted, or analysed — the app simply reacts to "inside" or "outside" the geofence and writes the resulting entry / exit event to the local database.
If you are a Pro subscriber and have "Track US state residency" enabled, Sojourn also uses background location to detect which US state you are in, so it can propose days toward your state residency count. The GPS reading is reverse-geocoded on your device to a state name; only the date and state are stored, never your raw coordinates. Proposed days are presented for your confirmation before they count toward any total. You can disable this at any time by turning off state tracking in Settings → Tracking.
Where it lives: nowhere. Coordinates are evaluated in memory and discarded. Only the resulting event (country entry/exit, or date + state for US state tracking) is persisted on your device.
d) Stay events:
Every entry-into-country or exit-from-country event, with timestamp, source (auto-detected, manually entered, or edited), and any note you add.
Where it lives: on your device, in a local SQLite database.
e) Subscription information:
If you purchase a Pro subscription, the transaction is processed by Apple (on iOS) or Google (on Android). We do not see your payment card. We use a third-party service, RevenueCat, to track whether you have an active subscription so the app knows whether to unlock Pro features. RevenueCat receives an anonymised identifier for you and your transaction details from Apple/Google, but not your name, email, or any other personal data we collect.
Where it lives: the active state of your subscription is cached locally so the app works offline. The authoritative copy lives with Apple, Google, and RevenueCat under their respective privacy policies.
f) Photo location data:
When you choose to attach a photo as evidence, take one in the app, or import stays from your photos, Sojourn reads the location and time embedded in that photo to suggest where and when you travelled. This happens entirely on your device — the coordinates are turned into a country name locally, using a borders dataset bundled inside the app, and are then discarded. Your photo coordinates are never uploaded or sent to anyone. We only ever read photos you explicitly select or capture; we never scan your photo library.
Where it lives: only the resulting country and date are kept, on the draft stay you confirm; the raw coordinates are evaluated in memory and discarded. The photo itself is stored on your device only if you attach it as evidence.
g) Support messages (only when you write to us):
When you send us a message from Suggestions or Help, that message leaves your device so it can reach our support inbox. It carries your name and title, the text you wrote, and any screenshot you chose to attach. The text of your message — and never your name, title, or email — is also sent to Anthropic to draft a suggested first reply for us; a person reads and sends the actual response.
Where it lives: in our support inbox, and in the sending logs of the providers in section 5. A copy of what you sent is also kept on your device so you can read it back in the app.
h) Encrypted backups (only when you create one):
Sojourn lets you export an encrypted backup of your on-device data so you can move it to a new phone or keep a safe copy. The backup contains a copy of what is already on your device — your identity fields, stay events, notes, attached evidence, and signature — packaged into a single file and encrypted with a key derived from a passphrase you choose.
This is a zero-knowledge design: your passphrase never leaves your device, we never see it, and we cannot open your backup. When you create a backup, your device hands the finished encrypted file to your operating system's share sheet, and you decide where it goes — another device, your own cloud storage (such as iCloud Drive or Google Drive), or a message to yourself. Once the file reaches a destination you chose, that destination's own privacy policy applies to it.
To recover, you open the backup file on any device running Sojourn and enter the same passphrase. Because only you hold the passphrase, if you lose it the backup cannot be recovered — by us or by anyone else. That is the trade-off for a backup no one but you can read.
Where it lives: nowhere on our side. We never receive, store, or have the ability to decrypt your backup. It lives only where you choose to save it.
i) Crash reports (only if you leave them switched on):
If the app crashes, an anonymous diagnostic trace is sent to Sentry, our crash-reporting provider, so we can find and fix the fault. Before anything leaves your device it is stripped: your name, email, date of birth, phone number, address, PIN, verification codes and any GPS coordinates are removed, and network request logs are dropped entirely. What remains is the technical trace of the failure and an anonymous device identifier. Sentry is configured in its European Union region.
You can turn this off at any time in Settings → About → "Send crash reports". It is on by default; switching it off stops the reports at your device.
Where it lives: with Sentry, in the EU, under their privacy policy.
j) The launch waitlist (only if you ask for it on our website):
If you enter your email address on our website to be told when Sojourn launches, we store that address — and nothing else — so that we can send you that one announcement. It sits in Cloudflare's key-value store, which the relay runs on. This is the only personal data we keep on our own infrastructure, and it exists because there is no other way to email you later.
We use it for exactly one message: that Sojourn is live. No marketing, no newsletter, no sharing with anyone. Write to support@sojourn.tax and we will remove you immediately; otherwise we delete the list once the launch announcement has been sent.
Where it lives: with Cloudflare until we send the announcement, and with Postmark at the moment of sending. Never on your phone — this one runs the other way round.
k) The reports you generate (kept on your device):
When you export an audit record, or import an airline roster, Sojourn keeps a copy of the finished PDF in Settings → Your reports, so you can find it again without recreating it. A report contains the same information as the export itself — your identity fields and the stays it covers — and nothing more.
These reports are stored on your device only, encrypted at rest with a key held in your device's secure keystore, exactly as your signature and your attached evidence are. They never leave your phone unless you choose to share one. When you delete a report — or delete your account — the encrypted file is removed from your device.
Where it lives: on your device only, encrypted. Never on our servers.
l) Legal bases for processing (EEA / UK users):
Where the GDPR applies to you, we rely on the following legal bases for the limited processing above:
- Identity fields, stay events, and exports — performance of our contract with you (Article 6(1)(b)); these are the service you asked us to provide.
- The reports you generate (kept in Your reports) — performance of that same contract (Article 6(1)(b)); a saved report is the output you asked us to produce, and it stays on your device.
- Email verification codes (and WhatsApp codes, if you opt in) — performance of that contract, together with our legitimate interest in preventing abuse of the service (Article 6(1)(b) and (f)).
- Background location for country auto-detection and US state detection — your consent (Article 6(1)(a)), given when you grant the permission and withdrawable at any time in Settings.
- Sojourn AI prompts — performance of contract, initiated by you each time you invoke the assistant (Article 6(1)(b)).
- Subscription state via RevenueCat — performance of contract (Article 6(1)(b)).
- Photo location data — your consent (Article 6(1)(a)), given when you pick or capture a photo; the reading happens on your device and the coordinates are discarded.
- Support messages — performance of contract and our legitimate interest in answering you (Article 6(1)(b) and (f)); you choose whether to write to us at all.
- Crash reports — our legitimate interest in keeping the app working (Article 6(1)(f)), balanced by stripping personal data before sending and by giving you an off switch in Settings.
- Encrypted backups — your consent, given each time you choose to create one (Article 6(1)(a)).
- The launch waitlist — your consent (Article 6(1)(a)), given when you type your address in and press the button, and withdrawable by emailing support@sojourn.tax.
4. What we do NOT collect
To remove any doubt:
- We do not collect analytics on how you use the app.
- We do not track which screens you view, which buttons you tap, or how long you spend in the app. The crash reports in section 3(i) are the one exception to our silence, and they describe a fault rather than your behaviour — no screen views, no taps, no session lengths — and you can switch them off.
- We do not include any third-party advertising SDKs.
- We do not sell, rent, lend, or share any of your information with anyone, ever, except as listed in section 5 below.
- We do not access your contacts or calendar.
- We access your camera and photo library only when you choose to take or attach a photo, or import stays from your photos — and only the specific photos you select. We never scan your library and never read photos in the background (see section 3(f)).
- We access the microphone only when you explicitly invoke the Sojourn AI assistant by voice, and only for the duration of that interaction; we never record audio in the background. Speech-to-text is performed by your device's operating system; raw audio is not transmitted off-device.
- The Sojourn AI provider does not receive your stay log, your identity, your location, or your subscription details. It receives only the prompt you type or speak and a snapshot of the country-rule data needed to answer that prompt. See section 5 for the full disclosure.
- We do not collect or transmit your IP address.
- We do not place cookies or any other tracking identifiers (this is a mobile app; there is no web component that sees your traffic).
5. Third parties who briefly touch your data
The following service providers process limited information strictly to make the app work. Except for Apple and Google — who act as independent controllers for the payment relationship under their own policies — these providers act as our data processors, handling the data only on our instructions and only for the purpose shown. None of them receive a complete profile of you.
| Provider | What they receive | Why |
|---|---|---|
| Postmark | Your email address and the 6-digit verification code (only when you ask us to send a code by email). If you write to us from Suggestions or Help: your name and title, your message, and any screenshot you attach | To deliver the verification code by email, to carry a support request to us and our reply back to you, and — if you joined the waitlist — to send the confirmation and the one launch announcement |
| Bird (WhatsApp Business provider) | Your phone number in E.164 format and the 6-digit verification code (only when you ask us to send a code by WhatsApp) | To deliver the verification code via WhatsApp. Bird passes the message through to Meta's WhatsApp Business platform for the final hop to your phone. No other personal data is shared. |
| Apple App Store / Google Play | Whatever Apple or Google require to process a subscription purchase | To process your subscription payment |
| RevenueCat | An anonymised subscription identifier and transaction metadata from Apple/Google. If you entered a referral code, that code is attached as a subscriber attribute | To tell the app whether you have an active subscription, and — if you were referred — to attribute the referral to the person who referred you |
| Referral attribution (our Cloudflare relay) | If you enter a referral code: the code and an anonymous subscription identifier, shared server-to-server | To credit the person who referred you and count it toward their reward. No name, email, location, or stay data is included |
| Sojourn AI provider (currently Anthropic Claude) | The prompt you type or speak to the Sojourn AI assistant, plus a snapshot of the country-rule data needed to answer it. Separately, if you write to us from Suggestions or Help: the text of your message only | To generate the assistant's response (Pro subscribers only), and to draft a suggested first reply to your support request. In neither case does it receive your name, date of birth, email, location, or stay history beyond what you type yourself. |
| Cloudflare | Requests the app makes to our relay pass through Cloudflare, which forwards them to the providers in this table and stores nothing from them. Separately, it stores your email address if you join the launch waitlist (section 3(j)) | To run the relay the app talks to, and to hold the waitlist until the launch announcement is sent |
| Sentry (European Union region) | An anonymous device identifier and the technical trace of a crash, with your personal details stripped out on your device beforehand | To let us find and fix crashes. Only if you leave "Send crash reports" switched on in Settings. |
We have a Data Processing Agreement in force with every provider above, each including Standard Contractual Clauses for transfers out of the European Economic Area. Their respective privacy policies are linked from inside the app at Settings → About → Third-party services.
6. Your rights
If you are in the European Economic Area, the United Kingdom, Switzerland, California, or any other jurisdiction with similar data-protection laws, you have the following rights:
- Right of access: You already have it — your data is on your device, visible inside the app.
- Right to correction: You can edit any field at any time inside the app (Settings → Account).
- Right to deletion ("right to be forgotten"): Settings → Account → "Delete my account and data" wipes everything on your device immediately — or start the process from the web on our Delete your account and data page. See section 7 below for what we cannot delete on your behalf.
- Right to data portability: Use the CSV or PDF export inside the app. The CSV is in a standard format you can give to anyone.
- Right to restrict processing: You can turn off auto-detection and US state tracking (Settings → Tracking) and crash reports (Settings → About) at any time, without leaving the app.
- Right to withdraw consent: Use the switches above, or delete the app, or use the deletion option above.
- Right to lodge a complaint: You may complain to your national data-protection authority if you believe we are mishandling your data.
To exercise any of these rights that aren't already available inside the app, email us at support@sojourn.tax. We will respond within 30 days.
EU / UK / Swiss representative. Because Sojourn Technologies L.L.C-FZ is established outside the European Economic Area, the United Kingdom and Switzerland, we have appointed a representative in each of those places for data-protection matters — under Article 27 of the GDPR, Article 27 of the UK GDPR, and Article 14 of the Swiss FADP respectively.
Our representative is DataRep (the trading name of Data Protection Representative Limited, a company registered in Ireland under number 616588; appointment reference SOJO01). On any data-protection matter concerning Sojourn you may contact DataRep — as an alternative to writing to us at support@sojourn.tax, and alongside your right to complain to your own national data-protection authority.
Write to DataRep at the address for your country below. Address your letter to "DataRep" and mention Sojourn Technologies L.L.C-FZ, so it reaches the right place — post addressed to us directly at these locations may not be received. For anything about the app itself, rather than your data-protection rights, please use support@sojourn.tax instead.
| Country | Postal address (write to "DataRep" at) |
|---|---|
| Austria | City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria |
| Belgium | Rue des Colonies 11, Brussels, 1000 |
| Bulgaria | 132 Mimi Balkanska Str., Sofia, 1540, Bulgaria |
| Croatia | Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia |
| Cyprus | Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus |
| Czech Republic | Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic |
| Denmark | Lautruphøj 1-3, Ballerup, 2750, Denmark |
| Estonia | 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia |
| Finland | Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland |
| France | 72 rue de Lessard, Rouen, 76100, France |
| Germany | 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany |
| Greece | Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece |
| Hungary | President Centre, Kálmán Imre utca 1, Budapest, 1054, Hungary |
| Iceland | Laugavegur 13, 101 Reykjavik, Iceland |
| Ireland | The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland |
| Italy | Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy |
| Latvia | 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia |
| Liechtenstein | City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria |
| Lithuania | 44A Gedimino Avenue, 01110 Vilnius, Lithuania |
| Luxembourg | BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg |
| Malta | Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta |
| Netherlands | Cuserstraat 93, Floor 2 and 3, Amsterdam, 1081 CN, Netherlands |
| Norway | C.J. Hambros Plass 2c, Oslo, 0164, Norway |
| Poland | Budynek Fronton ul Kamienna 21, Krakow, 31-403, Poland |
| Portugal | Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal |
| Romania | 15 Piaţa Charles de Gaulle, nr. 1-T, Bucureşti, Sectorul 1, 011857, Romania |
| Slovakia | Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia |
| Slovenia | Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia |
| Spain | Calle de Manzanares 4, Madrid, 28005, Spain |
| Sweden | S:t Johannesgatan 2, 4th floor, Malmo, SE - 211 46, Sweden |
| Switzerland | Leutschenbachstrasse 95, ZURICH, 8050, Switzerland |
| United Kingdom | 107-111 Fleet Street, London, EC4A 2AB, United Kingdom |
7. What we cannot delete on your behalf
When you delete your account, we wipe everything on your device. However, six categories of information persist outside our control:
- Subscription receipts at Apple or Google. Apple and Google retain purchase records for tax, accounting, and legal reasons. To manage or cancel your subscription, follow the standard process in your App Store or Play Store account.
- Anonymised metadata at RevenueCat. RevenueCat retains anonymised subscription analytics per their privacy policy.
- Email transmission logs. Postmark may retain delivery logs for the period stated in their privacy policy. These contain your email address and the verification code that was sent, not the contents of your account.
- WhatsApp delivery logs. If you used the WhatsApp channel, Bird and Meta may retain delivery metadata under their own privacy policies. This typically includes your phone number and the message-delivery status, not the contents of your account.
- Support correspondence. If you wrote to us from Suggestions or Help, your message stays in our support inbox and in the sending providers' logs. Ask us at support@sojourn.tax and we will delete it.
- Crash reports. Any diagnostic traces already sent to Sentry remain there for the retention period in their privacy policy. They contain no personal details — those are stripped on your device before sending — so there is nothing in them that identifies you to delete.
The "Delete my account" confirmation screen restates these caveats in the app so you see them before you delete.
8. Where your data lives
All identity, location, and stay data lives on your phone. We do not run servers that store your data. The third-party services in section 5 may process limited data on servers located outside your country of residence; specifically:
- Postmark's servers are located in the United States.
- Bird operates servers in the European Union.
- Meta (WhatsApp Business platform) operates globally.
- RevenueCat operates servers in the United States.
- Anthropic operates servers in the United States.
- Cloudflare runs the relay on its global edge network; the waitlist store is replicated across it.
- Sentry is configured in its European Union region, so crash diagnostics stay in the EU.
- Apple and Google operate globally.
If you are in the European Economic Area, transfers to non-EEA countries are made under appropriate safeguards (typically Standard Contractual Clauses).
How long we keep it. Your on-device data stays on your device until you remove it — either by deleting individual entries or by using "Delete my account and data", which wipes it immediately. Because we hold none of it on a server, there is nothing for us to retain on a schedule or to delete on your behalf. The third-party providers in section 5 keep the limited data they process only for the periods stated in their own privacy policies.
9. Security
- Your sensitive identity fields (email, date of birth) are stored using your operating system's secure storage (iOS Keychain or Android EncryptedSharedPreferences), protected by your device's screen lock.
- All communication with third-party services is over HTTPS / TLS.
- Verification codes are stored hashed (not in plaintext) and expire after 10 minutes.
- We do not, and cannot, see what is in your local database. If your device is lost or stolen, the security of your data depends on the strength of your device passcode and biometrics.
We do not promise that no security incident can ever occur, because no one honestly can. We do promise to design the app so that the consequences of an incident are minimised.
If a breach occurs. Because your data lives on your device and not on our servers, the realistic breach surface is one of the third-party processors in section 5, or your own device. If a personal-data breach at one of our processors affects you and is likely to result in a risk to your rights, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, as required by Article 33 GDPR — and we will inform affected users without undue delay where Article 34 requires it. A lost or stolen device is a device-security matter rather than a breach of our systems; its protection depends on your device passcode and biometrics.
10. Children
Sojourn is not directed at children. The registration form rejects any date of birth that would make the user under 16 years of age at the time of sign-up. If you become aware that a child under 16 has provided personal data through the app, please contact us at support@sojourn.tax and we will help you delete the account.
11. Changes to this policy
We may update this policy from time to time — for example, to reflect new third-party providers we add, or new features that change what we collect. When we make a material change, we will:
- Update the "Last updated" date at the top of this policy.
- Show you the new policy in-app on your next launch and ask you to accept it before continuing to use the app.
If you do not accept the updated policy, you may delete your account at that point.
12. California privacy notice
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights, which we honour:
- Categories of personal information we collect: identifiers (username, email, and — only if you opt in — mobile number); your name and date of birth; your residency country and stay history; and, only while an interaction is in progress and never stored, approximate location. We collect these for the purposes described in section 3.
- We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information beyond the purposes the CCPA permits.
- Your rights: to know what we collect, to access it, to correct it, to delete it, to opt out of sale or sharing (not applicable, as we do neither), and not to be discriminated against for exercising any of these rights.
- How to exercise them: because your data lives on your device, you can access, correct, and delete it directly in the app (Settings → Account); or email support@sojourn.tax. We will not charge you or degrade your service for making a request.
13. Contact
For any privacy-related question, request, or complaint:
support@sojourn.tax
Sojourn Technologies L.L.C-FZ
United Arab Emirates