Sojourn, last updated 23 August 2026
Plain-language summary: Sojourn helps you track where you spend your nights so your tax residence stays clear. We collect the data you enter, plus two things you have to switch on yourself: your device's location, and a read-only scan of your mailbox that looks for your travel bookings. Your data is yours, you can export it or delete your account at any time, and we never sell it.
Sojourn ("we", "us") is operated by an individual established in Zurich, Switzerland, trading as Sojourn, who is the data controller for the personal data described below. Postal address: Sojourn, Hammerstrasse 103, 8032 Zurich, Switzerland. The controller's identity is given on request at [email protected]. There is no company behind Sojourn today. If one is set up, this page will name it as the controller before it takes over. For any privacy question, or to exercise the rights in section 7, write to [email protected]. Because the controller is established in Switzerland, the Swiss Federal Act on Data Protection (FADP, revised, in force since 1 September 2023) applies. The EU and UK GDPR apply as well to users in those territories, and this policy is written to meet both.
| Account | Email address and name you provide when creating an account. |
| Residence & travel data | The countries, regions, nights, trips, worked days and targets you enter to use the tracker, and the free-text notes you may write on a day or on a trip. Those notes are stored on your device and backed up to your account with the rest of your travel data, so that you can read them back after a reinstall. They are yours to write: nothing in the app analyses them, they change no count and no verdict, and as with proofs we do not ask for special categories of data in them. The only way they leave your device beyond that backup is if you tick “Your notes” in an export, a box that starts unticked, and share the file yourself. |
| Location (optional) | If you enable location tracking, the app receives your device's position whenever you move a significant distance (roughly 800 metres), including while it is in the background or closed, plus one check each night so that a day spent at home is still recorded. Each position is immediately turned into a country, region and city, and only those place names are written down, never the coordinates themselves. This log stays on your device: it is not uploaded to our servers, and it is kept there, for as long as you use the app on that device, so that you can see how a night was attributed and correct it. It is erased when you sign a different account into the app or uninstall it. What does leave your device is the resulting nightly attribution, one country and region per night, which is backed up to your account so that reinstalling the app does not lose your calendar. Two anonymous counts also leave your device each time a batch of positions is processed: how many readings were turned into a place, and how many had to be discarded because that lookup failed. They are numbers only, with no place and no coordinates, recorded with a timestamp under the random device identifier described in section 8, and they exist so that we know how often the lookup fails. The only way the log itself can leave your device is if you include the GPS journal in an export and share that file yourself. The purpose is to attribute each night to a place without asking you to type it. You can turn tracking off at any time in Settings, and iOS or Android will also let you revoke the permission directly. |
| Inbox scan (optional) | If you connect a mailbox, you grant Sojourn read-only access to it through Google's standard sign-in screen (scope gmail.readonly). Your access tokens are kept in your device's secure keychain and never reach our servers. The app then searches your mailbox from your device, with two targeted queries: one restricted to known travel and lodging senders, the other to subject lines typical of a booking confirmation, whoever sent them. It downloads only the messages those queries return. The search runs when you ask for it, and once a day in the background so that a new booking is picked up without you opening the app. The content of those messages is sent to our parse-email function and analysed automatically (see section 4) to extract trip details (dates, cities, countries, booking reference). When the text alone is not enough, a rendered image or PDF of the message, or a PDF attachment, is analysed the same way. Two things are then stored: the extracted trip fields plus the message's subject, sender and Gmail message id, as a suggestion you accept or reject; and the original message, with its attachments, copied into your own proof storage, because the raw email carries the headers that prove it is genuine. That copy is made as soon as a trip is detected, before you decide. Rejecting the suggestion does not remove it: you delete it yourself in Proofs, like any other document. You can disconnect a mailbox at any time in Settings, which revokes our access. |
| Forwarded travel emails | Not currently offered. An earlier design gave each user a personal forwarding address; that channel is inactive and no forwarded mail is processed. Should it return, this policy will be updated before it is enabled. |
| Website waitlist | If you join the waitlist on hellosojourn.com, we store your email address to send you your invitation. It is deleted on request and not used for anything else. For cookies on the website, see section 8. |
| Proofs | Documents and files you upload or import as evidence (e.g. transport tickets, lodging invoices). We do not ask for special categories of data, and Sojourn does not look for any. If a document or a scanned message you keep happens to reveal something of that kind, it is stored only as your own proof and you can delete it at any time. |
| Feedback | The category and the message you send from Settings, Send feedback, together with up to three screenshots you choose yourself from your photo library, and a short technical context: the app version, the build number, the over-the-air update id, your device model and your operating system version. The screen shows you that context, in full and read-only, before you send. It carries nothing about your countries, nights or trips, and no screenshot is ever taken by the app: only the images you pick are sent. All of it is stored with your account so that we can answer you at your account email address, it is emailed to us with the screenshots attached (see section 4), and it is read by us. |
| Subscription | Whether you have an active subscription, and which plan, so the app can unlock. We never see your payment details: the purchase is made on your device through the App Store, Apple takes the money and holds the card, and nothing about it reaches us. The status is held by RevenueCat (see section 4) under a random identifier its software creates on your phone, not under your name, your email or your Sojourn account id. If you unlock Sojourn with an offer code, the code is redeemed at Apple and we are told only that a subscription became active. |
| Technical | The app version, and crash reports, recorded under the random device identifier described in section 8. |
| Usage & analytics (see section 8) | How you use the app and website: screens viewed, features used, crashes, and product milestones such as finishing setup, running a scan, saving a trip or exporting a report. These records carry no country, night, trip, document or free text, and no account identifier. See section 8 for which of them depend on your consent. |
Sojourn's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In plain terms, and without exception:
The access you grant is read-only (gmail.readonly) and limited to the messages our travel-related searches return. You can revoke it at any time, either by disconnecting the mailbox in Settings or from your Google Account permissions page.
We use your data for the purposes below. Where the law that applies to you requires a legal basis to process personal data, the basis we rely on is indicated:
We do not sell your personal data. We share it only with the service providers below, who act on our instructions, except where the row says otherwise:
| Supabase (USA / EU) | Database, authentication, file storage, and the functions that read your travel emails and your proofs. Your data is stored in the European Union (Frankfurt, Germany), on AWS. Supabase Inc. is a US company, so access from the United States by its staff cannot be excluded. Safeguard: EU standard contractual clauses with Swiss addendum. |
| Anthropic (USA) | Automated reading of two things, and only these two. One, the travel confirmation emails found by your inbox scan, to extract the trip details, including, where the text alone is insufficient, a rendered image or PDF of the message or of a PDF attachment. Two, the proof documents you upload or import (tickets, invoices, receipts), when Sojourn checks that a proof matches the trip it is filed against. The content is processed by Anthropic's Claude API in the United States. Under Anthropic's commercial terms it is not used to train models, and inputs and outputs are deleted within 30 days at the latest, except where Anthropic must keep them longer to comply with the law or to investigate a breach of its usage policy. Safeguard: EU standard contractual clauses with Swiss addendum. |
| Resend (USA / EU) | Sending the waitlist acknowledgement, the account emails (sign-up code, password reset, invitation) where they are routed through our own domain, and the feedback you send from Settings, with the screenshots you attached to it, delivered to our own team address. Resend Inc. is a US company; email data is processed in Ireland (EU, via Amazon SES). Account emails that are not routed through Resend are sent by Supabase's own email service instead. Safeguard: EU standard contractual clauses. |
| Expo / EAS (USA) | Building the app and delivering its over-the-air updates. Notifications are scheduled by the app on your own device: no push token is created, sent or stored, and we cannot send you a notification remotely. Safeguard: EU standard contractual clauses. |
| Apple / Google (USA) | App distribution, sign-in with Apple or Google, and, for the inbox scan, the Gmail API. These companies act as controllers in their own right for the account you hold with them, under their own privacy policies. |
| Cloudflare (USA) | Hosting and delivery of the hellosojourn.com website, including the waitlist form, and the address that serves your proof files to the app. Safeguard: EU standard contractual clauses. |
| RevenueCat (USA) | Managing your subscription: it records that a subscription exists and whether it is active, so the app can unlock. It receives no account identifier of yours — no name, no email, no Sojourn account id — only a random identifier its software creates on your phone. The link between a subscription and a person exists at Apple, not here. Safeguard: EU standard contractual clauses. |
| PostHog (EU) | Product analytics, on EU-hosted infrastructure, and only if you enable the "Anonymous usage" setting (see section 8). It receives which screens you open and which features you use, never your countries, nights, trips or documents. |
| Advertising partners | Only if we run advertising campaigns, and only with your consent (see section 8): advertising platforms such as Meta or Google may process identifiers to measure campaigns. None are active unless the cookie banner or in-app prompt says so. |
We may also disclose data where required by law.
Your data is stored in the European Union: your account, nights, trips, suggestions, proofs and feedback with Supabase in Frankfurt, Germany; the analytics described in section 8 with PostHog on its EU infrastructure; outgoing emails with Resend in Ireland. Switzerland and the EU/EEA recognise each other's level of data protection, so data flows freely between them.
One destination sits outside that: the United States, where the content of the travel emails found by your inbox scan, and of the proof documents Sojourn checks against a trip, is processed by Anthropic; and where Supabase, Resend, Cloudflare, Expo and RevenueCat are incorporated, so their staff may access data from there in the course of operating their services. There is no other country of destination. All of these transfers rest on the EU standard contractual clauses (2021) together with the Swiss addendum, under art. 16 al. 2 let. d FADP and art. 46 GDPR. You can ask for a copy at [email protected], free of charge.
We keep your data while your account is active. In addition:
Wherever you live, we offer you the following controls over your data:
We answer free of charge, within 30 days. Depending on where you live, your local law may give you further rights. Our supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC), and you may complain to it at no cost. If you are in the EU or the UK, you may instead complain to your own national authority, for example the CNIL in France; Sojourn has no establishment in the EU, so there is no lead authority and each national authority is competent for the people it protects. We do not make automated decisions producing legal effects about you: the trips found in your mailbox are proposals you accept or reject, any night the app fills in from your position can be corrected by you and never overrides what you entered yourself, and the figures Sojourn shows are indicative, not a tax assessment.
We keep tracking to the minimum the product needs, and we tell you here exactly what is active. Five categories:
When a category becomes active, we update this section (with the named providers) and, where required, ask for your consent before anything runs. Refusing non-essential cookies never blocks the website or the app.
Data is encrypted in transit and at rest. Your session credentials, and your mailbox access tokens, are stored in the device's secure keychain and never sent to our servers. Every table in our database enforces row-level security, so an account can only ever read its own rows; the proof storage is private and is opened only through links that expire within the hour. Access to the production database is limited to the controller named in section 1. No method of transmission or storage is perfectly secure, but we work to protect your data, and if a breach were likely to put you at high risk we would notify the FDPIC and you.
Sojourn is not intended for anyone under 18, or the minimum age required in your country. We do not knowingly collect data from children.
We may update this policy. We will post the new version here and update the date above; significant changes will be notified in-app or by email.
Questions or requests: [email protected], or by post to Sojourn, Hammerstrasse 103, 8032 Zurich, Switzerland.