Legal
Privacy policy
Last updated 31 July 2026
Sojourn Logbook™ is not yet released. This document is published ahead of launch so it can be reviewed, and so the app stores have something to point at. It takes effect when the app ships.
This policy explains what Sojourn does with your information in connection with Sojourn Logbook and this website. It is written to be read, not to be survived. If anything here is unclear, email [email protected] and we will explain it.
1. The short version
Your logbook lives on your device. We do not hold a copy, we cannot read it, and we cannot recover it for you. The only personal data we hold is what you deliberately hand us: an email address for the launch waitlist, and any support correspondence you start.
2. Who we are
Sojourn Technologies L.L.C-FZ ("we", "us"), a company incorporated in the United Arab Emirates, publishes Sojourn Logbook, operates sojourn-logbook.com, and is the data controller for the little data described below. For any privacy question, contact [email protected].
3. Your flight records
Flight records you enter or import — dates, aircraft, routes, times, crew roles, currency and licence details — are stored in a database on your device. They are not transmitted to us and are not stored on our servers, with one exception that only happens if you ask for it: if you send us an existing logbook to convert, that file does come to us — see below.
This has a consequence you should understand before relying on the app: we cannot restore your logbook. If you lose your device and have no export, the record is gone. The app will let you export your complete record at any time, and we strongly recommend you do so regularly.
4. What we do collect
Waitlist email addresses
If you submit your email address on this website, we store that address so we can tell you when the app is released. We do not use it for anything else, we do not sell it, and we do not add it to a newsletter. You can have it deleted at any time — see Delete your data.
To limit abuse of that form we briefly record a derived, non-reversible value based on your IP address as a rate-limiting counter. It expires within minutes and is not used to identify you.
Website analytics
This site keeps aggregate, cookieless page metrics via Cloudflare Web Analytics — run by Cloudflare, the provider already serving every page of this site (see Processors). It sets no cookies, stores no visitor identifiers and does no fingerprinting. There are no advertising trackers and no cross-site profiling.
Your existing logbook, if you send it to us to convert
If you ask us to bring your existing record across — an app export, a spreadsheet, or photographs of a paper logbook — the file you choose is sent to us and stored privately while we build your import. We use it for one purpose: preparing the import that comes back to your app for your review. Nothing enters your logbook until you confirm it.
To read and check your file we may use Anthropic Claude, an AI system, as part of building that import: it checks what our converter produced, and for a PDF or photographs of a paper logbook it reads the pages and drafts the import for us. Anthropic receives the file’s contents for that processing only. It does not train its models on your data, and inputs are deleted after a short abuse-monitoring window rather than kept. What the AI produces is always a draft — a person reviews it before it is sent back to you, and you review it again before anything is applied.
We keep the file while your import is being built, and afterwards as the reference in case a correction is needed. Ask us at any time and we delete it. We never publish it and never share it with anyone else; the AI processing above is part of building your import, not a further use.
Support correspondence
If you email us, we hold that email and our reply so we can help you and keep a record of the issue.
App diagnostics
If the app fails and you have left crash reports switched on, an anonymous crash report is sent to Sentry, in the European Union, and kept for 90 days. Your personal details are stripped before it leaves the device, and it carries nothing from your logbook contents. You can turn it off at Settings → About → “Send crash reports”. We do not collect telemetry from your logbook.
5. Legal basis (UK and EU visitors)
- Consent — joining the waitlist. Withdraw it at any time by asking us to delete your address.
- Legitimate interests — keeping the site up, preventing abuse of our forms, and keeping aggregate visitor counts. We have balanced these against your rights and use the least intrusive method we can.
- Contract — providing support and the app itself once you subscribe.
6. Who else is involved
We use few providers by design; these are the ones that touch anything of yours, across the site and the app.
- Cloudflare — hosts this website and the small service behind the waitlist form.
- Postmark — sends the waitlist confirmation and launch email.
- Apple and Google — distribute the app and handle all subscription billing. We never see your payment details.
- Bird — delivers WhatsApp verification codes. It receives your mobile number for that delivery, nothing else.
- RevenueCat — manages subscription state for the app. It receives an anonymous identifier and your subscription status, never your name or your records.
- Anthropic — reads and checks a logbook file you have asked us to convert, and drafts the import from it. It receives that file’s contents for that processing only, does not train on your data, and its inputs are deleted after a short abuse-monitoring window. It is involved only if you send us a file.
- Sentry — receives anonymous crash reports from the app, in the European Union, if you leave them switched on.
We do not sell personal data, and we do not share it for advertising.
7. How long we keep things
- Waitlist addresses — until the launch email has been sent, or until you ask us to delete yours, whichever comes first. We will not keep the list running as a mailing list afterwards.
- Support correspondence — up to 24 months, then deleted.
- A logbook file you sent us to convert — while we build your import, and afterwards as the reference in case a correction is needed. Deleted whenever you ask.
- AI processing of that file (Anthropic) — transient: inputs are deleted after the provider’s short abuse-monitoring window and are never used for training.
- Crash reports (Sentry) — 90 days, then deleted. They carry no personal details to begin with.
- Rate-limit counters — minutes.
- Aggregate page counts — retained in aggregate; they contain no personal data.
8. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our use of your personal data, and to receive it in a portable form. Because the only data we hold about you is an email address and any correspondence, these requests are usually straightforward. Email [email protected] and we will respond within 30 days.
If you are in the UK or EU and believe we have handled your data improperly, you may complain to your national supervisory authority. We would appreciate the chance to fix it first.
9. International transfers
Our service providers operate globally, so the limited data described above may be processed outside your country. Where required, transfers are covered by appropriate safeguards such as standard contractual clauses.
10. Children
Sojourn Logbook is a professional tool and is not directed at children. You must be at least 16 to use it, or older where your jurisdiction requires it.
11. Security
Traffic to this site and to our waitlist service is encrypted in transit. The strongest security property here is structural rather than procedural: the sensitive data — your logbook — is never in our custody in the first place. To report a vulnerability, email [email protected].
12. Changes
If we change this policy we will update the date at the top, and for material changes we will say so plainly rather than quietly re-dating the page.