Privacy posture In development
We cannot read
your logbook.
Not as a promise about what we choose to do. As a description of how the app is built.
The shape of it
Local-first, not cloud-with-encryption
Your flight records live in a database on your phone. They are not uploaded to us, because there is no account on our servers holding them.
This is a different claim from “we encrypt your data”. Encrypted cloud storage still means your logbook is on someone else's computer, and someone else holds an operational path to it. Here there is no copy to reach.
Being precise
What we can see
Honesty cuts both ways, so here is the other side.
If you join the waitlist on this website, we hold the email address you typed, so we can email you once at launch. That is a marketing list and it is entirely separate from the app.
This site keeps first-party, cookieless visitor counts. No advertising trackers, no third-party analytics, no cross-site profile.
If you contact support and choose to send a diagnostic file, we see what is in that file — because you sent it.
The Tax hand-off
Even the sync stays on the device
When Sojourn Tax reads your flight legs, the transfer happens locally between two apps on the same phone. It is not a server-to-server integration and there is no upload step. We could not observe it if we wanted to.
It also only carries sectors — dates, aerodromes and times. Licence data does not cross: no command times, no endorsements, no instructor names.
The consequence
Which means backups are yours to keep
There is a real trade here and you should know it before you rely on the app. Because we hold no copy of your logbook, we cannot restore it for you. If you lose the device and have no backup, we have nothing to send you.
Sojourn Logbook will export your complete record in an open format at any time, and we will push you to keep one. A logbook you cannot reproduce is a career problem, and no privacy posture is worth that.