Legal
Privacy policy
Last updated 24 September 2026 · in force 1 September 2026
Sojourn Logbook™ is in beta testing. This document mirrors the policy shown inside the app (version 11, in force 1 September 2026). Changed on 24 September 2026: the app keeps a diagnostics log you can read and choose to share yourself (section 4); and when you write to us for help, section 4 now names Google Workspace and n8n as the providers behind our support mailbox and ticket record, and discloses that a first answer to a help request may be written by an AI — always labelled as such, never for money, data, legal or duty-limit questions. Said plainly here, as section 12 promises. Earlier, 18 September 2026: the relay creates verification codes and hashes them; WhatsApp codes may go through Meta’s platform as well as Bird; the subscription identifier is pseudonymous; crew-group messages can pass sealed through our relay; abuse counters; the roster reader.
This policy explains what Sojourn does with your information in connection with Sojourn Logbook and this website. It is written to be read, not to be survived. If anything here is unclear, email support@sojourn-logbook.com and we will explain it.
1. The short version
Your logbook lives on your device. We do not hold a copy, we cannot read it, and we cannot recover it for you. On this website the only personal data we hold is what you deliberately hand us: an email address for the launch waitlist, and any support correspondence you start.
In the app, thirteen things can leave your device, almost all of them because you asked for them: a one-time code to your email or WhatsApp; the sign-in token Google or Apple issues if you continue with them, used once to confirm your email and then discarded; your subscription status; a report you export; a flight-data file you send to Sojourn Tax through your own share sheet; an encrypted backup you make; your operator’s own duty and rest scheme, if you send us one; an existing logbook you ask us to convert; a crew-group flight passing to the crew you flew with, phone-to-phone or as a sealed message through our relay that only the group’s own phones can open; a roster the app cannot read, if you tap “Send it to us to read”; the four-letter airport code you type into the METAR tool, sent to the US National Weather Service; a help request or suggestion you send us from the app — your message, any screenshot you attach, and the e-mail address or WhatsApp number on your account so we can answer; and — the one exception to “because you asked” — an anonymous crash report if you have left those switched on. That is the complete list; the app’s own policy carries each in full.
2. Who we are
Sojourn Technologies L.L.C-FZ ("we", "us"), a company incorporated in the United Arab Emirates, publishes Sojourn Logbook, operates sojourn-logbook.com, and is the data controller for the little data described below. For any privacy question, contact privacy@sojourn-logbook.com.
3. Your flight records
Flight records you enter or import — dates, aircraft, routes, times, crew roles, currency and licence details — are stored in a database on your device. They are not transmitted to us and are not stored on our servers, with two exceptions that only happen if you ask for them: if you send us an existing logbook to convert, that file does come to us — see below; and if the app cannot read a roster on your phone and you tap “Send it to us to read”, those roster pages come to us for that one reading — see below.
Your logbook contains other people’s names. A flight record names the commander you flew with, and may name the purser and other crew — in most jurisdictions the commander’s name is a required column. Those names are stored on your device like the rest of your record. If you use a crew group to receive a flight’s details from a colleague, the only personal information that travels is a first name and a last initial. When the two phones are not side by side, the details travel as a message sealed on the sending phone with a key that exists only inside the group’s own phones; our relay holds that sealed message for up to 48 hours and cannot open it. So that your phone can be told a message is waiting, the app may register a push token with the relay against the group’s opaque identifier — it expires after 30 days and says nothing about who you are.
This has a consequence you should understand before relying on the app: we cannot restore your logbook. If you lose your device and have no export, the record is gone. The app will let you export your complete record at any time, and we strongly recommend you do so regularly.
4. What we do collect
Waitlist email addresses
If you submit your email address on this website, we store that address so we can tell you when the app is released. We do not use it for anything else, we do not sell it, and we do not add it to a newsletter. You can have it deleted at any time — see Delete your data.
To limit abuse of that form we briefly record a derived, non-reversible value based on your IP address as a rate-limiting counter. It expires within minutes and is not used to identify you.
Website analytics
This site keeps aggregate, cookieless page metrics via Cloudflare Web Analytics — run by Cloudflare, the provider already serving every page of this site (see Processors). It sets no cookies, stores no visitor identifiers and does no fingerprinting. There are no advertising trackers and no cross-site profiling.
Your account, and the codes we send (app)
Your account holds an email address, and a mobile number only if you choose WhatsApp for your codes. When a code is needed, the app asks a small relay we operate on Cloudflare. The relay creates the six-digit code, keeps a one-way hash of it — never the code itself — together with a one-way hash of where it was sent, for ten minutes and at most five attempts, and passes the message to Postmark (email) or to Bird or Meta’s WhatsApp Business platform (WhatsApp), purely to deliver it. It refuses to send anything but that code.
When you enter the code correctly, the relay hands your device a signed proof that this account was verified — valid for 180 days, re-issued at every re-verification. The app presents that proof when a feature needs to know the account is yours. The relay keeps no record of the proofs it has issued; it recognises its own signature. To keep the relay from being abused, it counts requests in short-lived counters keyed by your network address (for up to an hour) or by a one-way hash of your account (for up to a month, for the features that cost us money per use). The counters hold numbers, not messages, and expire on their own.
Your account cannot open your logbook. The account identifies you; only the recovery key you were shown at setup can decrypt an encrypted backup. We never receive that key.
Subscriptions and referrals (app)
Payments are handled entirely by Apple or Google. We use RevenueCat to know whether your subscription is active. It receives a pseudonymous identifier and your subscription status — not your name, your email, or anything from your logbook. The identifier is derived from your account contact under a secret key that only our relay holds, so RevenueCat, or anyone else, cannot turn it back into your email address; it exists so the same person is recognised across Sojourn apps and across a change of phone. If you join the referral programme, our relay stores your referral code, the display name you give it, and the pseudonymous identifiers of the people who redeem it, for as long as the programme runs.
Your existing logbook, if you send it to us to convert
If you ask us to bring your existing record across — an app export, a spreadsheet, or photographs of a paper logbook — the file you choose is sent to us and stored privately while we build your import. A notification with the file’s details (name, size, the source you named) goes to our operations inbox so a person can act on it, and the app may hand the relay a push token so your phone can be told when the import is ready. We use the file for one purpose: preparing the import that comes back to your app for your review. Nothing enters your logbook until you confirm it.
To read and check your file we may use Anthropic Claude, an AI system, as part of building that import: it checks what our converter produced, and for a PDF or photographs of a paper logbook it reads the pages and drafts the import for us. Anthropic receives the file’s contents for that processing only. It does not train its models on your data, and inputs are deleted after a short abuse-monitoring window rather than kept. What the AI produces is always a draft — a person reviews it before it is sent back to you, and you review it again before anything is applied.
We keep the file while your import is being built, and afterwards as the reference in case a correction is needed. Ask us at any time and we delete it. We never publish it and never share it with anyone else; the AI processing above is part of building your import, not a further use.
Your roster, if you send it to us to read
The app reads your roster on your phone. If it cannot — an operator’s layout it has not seen — it offers “Send it to us to read”. Only if you tap that: the pages of that roster file are sent to our relay, read by Anthropic Claude, turned into the duties you then review on your phone, and returned. The file is not stored: the relay keeps nothing of the roster’s contents once the reading is back on your device.
Three things do stay, none of them your roster: a per-airline vocabulary — which printed words on that airline’s rosters mean off, standby, flight and so on — built from the readings crew confirm, holding words and nothing that identifies a person; a one-way hash of your account, used to count your readings (five a month) and to keep one vote per person in that vocabulary; and an operations log with the airline, the page count, the cost and whether the reading succeeded. Anthropic does not train its models on your data, and inputs are deleted after a short abuse-monitoring window rather than kept.
Support correspondence
If you email us, we hold that email and our reply so we can help you and keep a record of the issue.
App diagnostics
If the app fails and you have left crash reports switched on, an anonymous crash report is sent to Sentry, in the European Union, and kept for 90 days. Your personal details are stripped before it leaves the device, and it carries nothing from your logbook contents. You can turn it off at Settings → About → “Send crash reports”. We do not collect telemetry from your logbook.
Send diagnostics is the other diagnostic, and it never sends itself. The app keeps a short log on your phone of what it did — screen names, actions, error codes and times; never your name, your entries or anything you typed. You can read the whole log at Settings → “Send diagnostics”, clear it, or share it with support only if you share it yourself, through your own mail or share sheet. It travels from your phone to our support inbox and nowhere else; no new provider is involved.
When you write to us for help (app)
Help and Suggestions in the app send us your message, any screenshots you attach, and the e-mail address or WhatsApp number on your account, so we can answer. It reaches our relay, which records a ticket — the message, how to reach you and a ticket number — and passes it to our support mailbox.
Google Workspace hosts that mailbox and the sheet holding the ticket record. n8n runs the automation that logs and prioritises a support request: it reads your message in order to do that, and keeps only a ticket record — a reference, which product, whether it is help or a suggestion, its priority, when it arrived, whether it has been answered, and a link back to the original message in our mailbox. It does not keep your address or the text of what you wrote, and it never replies to you.
An answer written by an AI assistant. For a help request, the first answer may be written by Anthropic Claude, an AI system, from this app’s user manual — and only when the e-mail address on your account has been verified, so an answer is never sent to anyone but you. Anthropic receives the text of your message and nothing else: not your address, not your screenshots, not your logbook. It does not train its models on it, and its inputs are deleted after a short abuse-monitoring window. The answer says that an AI wrote it and that no person checked it before it was sent, and it asks whether it solved your problem: press No, or reply, and a person takes over.
Some things never go to the AI: questions about money, about your data, about deleting your account, anything legal, any request to exercise your data-protection rights — a copy of your data, a correction, erasure, or an objection — and any question about your duty limits, your rest or whether you are fit to fly. Those always go to a person. Suggestions are always read by a person.
5. Legal basis (UK and EU visitors)
- Consent — joining the waitlist. Withdraw it at any time by asking us to delete your address.
- Legitimate interests — keeping the site up, preventing abuse of our forms, and keeping aggregate visitor counts. We have balanced these against your rights and use the least intrusive method we can.
- Contract — providing support and the app itself once you subscribe.
6. Who else is involved
We use few providers by design; these are the ones that touch anything of yours, across the site and the app.
- Cloudflare — hosts this website and the small service behind the waitlist form.
- Postmark — sends the waitlist confirmation and launch email, and the app’s verification codes by email.
- Apple and Google — distribute the app and handle all subscription billing. We never see your payment details.
- Bird, or Meta’s WhatsApp Business platform — delivers WhatsApp verification codes. Either receives your mobile number for that delivery, nothing else.
- RevenueCat — manages subscription state for the app. It receives a pseudonymous identifier (derived under a secret only our relay holds, so it cannot be turned back into your email) and your subscription status, never your name or your records.
- Anthropic — reads and checks a logbook file you have asked us to convert, and drafts the import from it; reads a roster you have asked us to read; and may write the first answer to a help request, from the user manual. It receives that file’s contents for that processing only, does not train on your data, and its inputs are deleted after a short abuse-monitoring window. It is involved only if you send us a file.
- Google Workspace — hosts our support mailbox and the sheet holding the ticket record. Separate from Google’s role in distributing the app and handling billing.
- n8n — runs the automation that logs and prioritises a support request. It reads your message to do that and keeps only the ticket record described in section 4; it never replies to you.
- Sentry — receives anonymous crash reports from the app, in the European Union, if you leave them switched on.
We do not sell personal data, and we do not share it for advertising.
7. How long we keep things
- Waitlist addresses — until the launch email has been sent, or until you ask us to delete yours, whichever comes first. We will not keep the list running as a mailing list afterwards.
- Your account record (email, and mobile number if given) — until you delete your account.
- Verification codes — held by our relay as one-way hashes for ten minutes, then gone; the signed proof of identity on your device is valid for 180 days.
- Abuse counters — network address up to an hour; hashed account up to a month; then gone.
- Crew-group messages through the relay — sealed, 48 hours; the push token, 30 days.
- Support correspondence — up to 24 months, then deleted.
- Support tickets on our relay — up to 12 months, and deleted with your account.
- Support ticket record (n8n / Google Sheets) — held while a request is open and kept afterwards as a record of what was asked and when. It carries no address and no message text, but it does link to the message in our mailbox, which follows the support-correspondence retention above.
- AI processing of a support message (Anthropic) — transient: inputs are deleted after the provider’s short abuse-monitoring window and are never used for training.
- A logbook file you sent us to convert — while we build your import, and afterwards as the reference in case a correction is needed. Deleted whenever you ask. The relay’s record of the import itself (its status and timeline, never the file’s contents) is kept for 90 days after the import is finished.
- Roster readings — the roster’s contents are not kept; the per-airline vocabulary, your hashed reading count and the operations log are kept for as long as the reader runs.
- Referral programme records — for as long as the programme runs.
- AI processing of that file (Anthropic) — transient: inputs are deleted after the provider’s short abuse-monitoring window and are never used for training.
- Crash reports (Sentry) — 90 days, then deleted. They carry no personal details to begin with.
- Website rate-limit counters — minutes.
- Aggregate page counts — retained in aggregate; they contain no personal data.
8. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our use of your personal data, and to receive it in a portable form. Because the only data we hold about you is an email address and any correspondence, these requests are usually straightforward. Email privacy@sojourn-logbook.com and we will respond within 30 days.
If you are in the UK or EU and believe we have handled your data improperly, you may complain to your national supervisory authority. We would appreciate the chance to fix it first.
9. International transfers
Our service providers operate globally, so the limited data described above may be processed outside your country. Where required, transfers are covered by appropriate safeguards such as standard contractual clauses.
Our support automation runs on n8n Cloud; n8n’s published sub-processor list shows its infrastructure providers processing in the EU — Microsoft Azure (Germany, Sweden) and Hetzner (Germany) — and our agreement with n8n includes the European Commission’s Standard Contractual Clauses, so any transfer outside the EEA within their service is covered by them. Google Workspace hosts our support mailbox and the ticket register.
10. Children
Sojourn Logbook is a professional tool and is not directed at children. You must be at least 16 to use it, or older where your jurisdiction requires it.
11. Security
Traffic to this site and to our waitlist service is encrypted in transit. The strongest security property here is structural rather than procedural: the sensitive data — your logbook — is never in our custody in the first place. To report a vulnerability, email security@sojourn-logbook.com.
12. Changes
If we change this policy we will update the date at the top, and for material changes we will say so plainly rather than quietly re-dating the page.