Sojourn
Privacy Policy
Last updated: 15 September 2026
Sojourn is a private-by-default diary. You can record a place, time, optional note, optional photo, and optional location for yourself. If you choose to share a post with your invite-only family, that post is visible to those family members. This policy explains the data Sojourn handles, where it lives, who else can see it, and how to delete it.
In plain terms. Sojourn contains no analytics, advertising, or tracking SDKs. We do not sell your data or send marketing. Your posts are private to your account unless you deliberately mark a post Family. Family posts are visible only to the members of your current invite-only family; Sojourn has no public feed or public profiles.
1. Who this policy covers
This policy applies to the Sojourn mobile app and to this account-management website. Sojourn is operated by Chaze Digital, LLC (“Sojourn,” “we,” “us”). For any privacy question, or to exercise the rights described below, contact us at support@sojourn.chaze.net.
2. How Sojourn stores your data
Sojourn is local-first. Your diary is written to an on-device database that is encrypted with SQLCipher. When you are signed in, that data is also synced to our servers so it survives a lost or replaced phone and can be restored on a new device.
Your synced data lives in two places we operate:
- Your check-in records (text and coordinates) are stored in our Supabase Postgres database, isolated per user by row-level security so that each account can only ever read or write its own rows.
- Your photos are stored, resized, in a private Cloudflare R2 bucket and are served only through short-lived signed links generated for your account.
Important — Sojourn is not end-to-end encrypted. Your on-device database is encrypted, and all data is transmitted over encrypted connections (HTTPS/TLS). However, the copy synced to our servers is not encrypted in a way that hides it from us: as the service operator we are technically able to access it in order to run and support the service. We do not claim zero-knowledge or “we can't read your data” encryption. Please keep this in mind for anything you would consider highly sensitive.
3. What data we collect
We only collect what the app needs to store and sync your diary. Concretely:
| Data | What it is | When |
|---|---|---|
| Google account identifier & email | Provided by Sign in with Google to identify your account. We never receive your Google password. | When you sign in |
| Check-in content | Venue/place name, address, category, your written note, and the date & time of the check-in. | Whenever you create or import a check-in |
| Location coordinates | The latitude & longitude attached to a check-in, from your device's location (optional) or from a place you pick. | Only for check-ins where you add a location |
| Photos | Images you attach to a check-in. They are resized on your device before upload. | Only for check-ins where you add a photo |
| Imported history | If you choose to import from Foursquare/Swarm, your past check-ins (place, time, coordinates, photos) are pulled into Sojourn. | Only if you start an import |
We do not collect analytics, usage tracking, advertising identifiers, contacts, or device fingerprints. Sojourn ships no analytics, advertising, or tracking SDKs.
4. How we use your data
We use the data above for one purpose: to provide Sojourn — to store your diary, sync it across your devices, show your check-ins on a map, let you search your history, and let you import your past check-ins if you ask us to. We do not use your data to build advertising profiles, and we do not sell or rent it.
Family sharing. If you create or join an invite-only family, you may choose Family when posting. A Family post is shared with the current members of that family and shows your display name. The content shared can include the post's note, place, date and time, location details, photos, and links. Posts remain private unless you choose Family. You can leave a family, and an administrator can remove a member; after membership ends, the former member can no longer access Family posts through Sojourn after their device next syncs. People who already saw or saved information outside Sojourn may retain it.
Reports. A family member can report a Family post in the app. We review reports as appropriate for service safety and may remove content or restrict access where warranted. Reporting does not make a post public.
5. Third parties and service providers
Sojourn relies on a small number of third parties. Some process your data on our behalf to run the service; others are reached only when you take a specific action.
| Provider | Role | What they receive |
|---|---|---|
| Google — Sign in with Google | Authentication | Handles your sign-in and returns your account identifier and email to us. Governed by Google's Privacy Policy. |
| Google — Maps SDK | Map display | When you view a map in the app, Google receives the map requests, including the map area being shown. Governed by Google's Privacy Policy. |
| Supabase | Backend host | Hosts the database and authentication that store your account and check-in records on our behalf. |
| Cloudflare (R2) | Photo storage | Stores your uploaded, resized photos in a private bucket on our behalf. |
| Foursquare | Optional import | Only if you start an import: Sojourn connects to Foursquare's API, with your authorization, to retrieve your own check-in history. |
Venue search inside the app runs against map data (from the Overture Maps places dataset) that is stored on your device. Searching for a place does not send your query to us or to any third party.
A note on Google. Because Sojourn shows maps using Google Maps, Google does see the map views you look at. Sojourn is not a Google-free app, and we do not claim that your data never reaches Google.
6. Data retention
We keep your data for as long as your account exists, so your diary is there when you come back. When you delete your account (see below), your account and database records, including photo metadata, are deleted immediately. Stored photo bytes are queued for deletion from private storage and retried if cleanup needs another attempt. Residual copies may persist briefly in routine, encrypted infrastructure backups before they are rotated out on our provider's standard schedule; our own routine backups are retained for about 60 days.
7. Your rights and choices
You control your data:
- Access & portability. Your full history is on your device and in your account. You can export a copy yourself, at any time, from inside the app: Settings → Export my data (JSON or CSV). You can also contact us at support@sojourn.chaze.net.
- Correction. You can edit or remove individual check-ins and photos directly in the app.
- Deletion. You can delete your account and all associated data at any time — see the section below and our account-deletion page.
Depending on where you live (for example, under the EU/UK GDPR or the California CCPA/CPRA), you may have additional rights to access, correct, delete, or restrict the processing of your data, and to object to it. We honor these requests; contact us at support@sojourn.chaze.net. We do not sell or share your personal information as those terms are used under California law.
8. Deleting your account and data
You can delete everything yourself, at any time, from inside the app: Settings → Delete account. This immediately deletes your account and its check-ins, photo metadata, and import records from our database, and wipes the local copy on your device. Stored photo bytes are queued for deletion from private storage and retried if cleanup needs another attempt.
If you cannot access the app, you can request deletion through the web instead. See the Delete your Sojourn account page for the full steps.
9. Children
Sojourn is not directed to children and is not intended for use by anyone under 13 (or the minimum age required in your country). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Security
We protect your data with on-device encryption (SQLCipher), encrypted connections (HTTPS/TLS) for all sync, per-user access isolation on the server (row-level security), and private storage for photos accessible only through short-lived signed links. No system is perfectly secure, and — as noted in Section 2 — Sojourn is not end-to-end encrypted.
11. International data transfers
Our service providers may store and process your data in the United States and other countries. By using Sojourn you understand your data may be transferred to and processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
12. Changes to this policy
If we make material changes to this policy, we will update the “Last updated” date above and, where appropriate, notify you in the app. Continued use of Sojourn after a change means you accept the revised policy.
13. Contact
Questions, requests, or complaints: support@sojourn.chaze.net. Postal/legal contact: Chaze Digital, LLC, 24842 Golden Vista, Laguna Niguel, CA 92677-7461, United States.