Privacy
Effective 7 September 2026SÒMI is a private travel journal. It is a product of M B Squared Inc., Phoenix, Arizona, USA, who can be reached at help@somi.life.
This policy is short because the app is small and does not sell anything about you. There is no advertising in SÒMI, no analytics, no tracking cookies, and no third-party trackers of any kind.
What we hold
Your account. Your email address, and a display name if you enter one. Signing in uses a one-time link sent to your email — there is no password to lose.
Your journal. The trips you create: titles, dates, places, stops, tags and any notes you write. If you record when you met someone, or where home is, we store that too, because the app uses it to draw your map and pace your film.
Your photos. Photos are processed in your browser before they are uploaded. We read the date, the GPS coordinates and the camera model out of the file, and we store those alongside the photo. The image we upload is re-encoded first, which removes the embedded metadata — so the stored image file carries no location data, even though we hold the coordinates in our database so the photo can appear in the right place on your map. The original file never leaves your device.
Things the app works out. Photo dimensions, a blurred placeholder that stands in while a picture loads, and the handful of colours a trip’s page is drawn in. If a photo has coordinates, we also work out the nearest city and store its name — that lookup runs against a list of cities held on our own server, so your coordinates are not sent to a mapping service to be named.
Invitations. If you invite someone, we store the email address you invited and a token that lets them accept.
The iOS app. If you connect the SÒMI app on your phone, we store a hashed device token. We cannot read the token back; revoking it in your account ends that device’s access.
What we do not do
We do not sell or rent your data. We do not show advertising. We do not use analytics or tracking cookies, and we do not build a profile of you. SÒMI sets three cookies and every one of them is functional: the one that keeps you signed in, one remembering which atlas you are looking at, and one remembering whether you let your browser share your location while setting up. None of them follow you anywhere.
Who else touches it
To run the service, your data passes through a small number of providers, each acting on our instructions:
- Vercel — hosting.
- Neon — the database.
- Amazon Web Services — photo storage (S3) and delivery (CloudFront).
- Resend — sign-in links and notification email.
- Anthropic — only if you ask SÒMI to draft trip details for you. When you use that button, the photos you selected and their details are sent to Anthropic’s API to generate the suggestion. If you never press it, nothing is sent. This feature can be switched off entirely.
- Apple — the map inside the iOS app is Apple’s. Drawing the globe asks Apple for imagery of the places you look at, and when the app draws the road between two stops on a trip it sends those two coordinates to Apple to work the route out. That happens under Apple’s own privacy policy, not ours. Apple also takes the payment if you subscribe inside the app (below). The website uses no map service at all.
- Stripe — payment processing on the web, once subscriptions are available (below).
Your data is stored in the United States. If you are outside the United States, using SÒMI means your data is transferred there.
Payments
Subscriptions are not yet available. When they are: if you subscribe on the web, Stripe processes the payment and holds your card details — we never see your card number, only the fact that a subscription is active and when it renews. If you subscribe inside the iOS app, Apple processes the payment through In-App Purchase under Apple’s own privacy policy, and tells us only that an entitlement exists. We store your subscription status, plan and renewal date.
How long we keep it
Your journal stays until you delete it. A sign-in link works once and expires 24 hours after we send it. Deleted trips and photos are removed from the database and from storage immediately, though a deleted photo may still be served from a cached copy on our content delivery network for up to 24 hours before it falls out of the cache.
Your choices
You can edit or delete any trip, photo or note in the app. You can revoke an invitation you sent, remove someone’s access to your atlas, and disconnect a phone at any time. You can delete your account, which removes your journal, your photos and your account record. To ask what we hold about you, to correct it, or to have it deleted for you, write to help@somi.life and we will answer within 30 days. Depending on where you live you may have a legal right to access, correct, export or erase your data, and to object to how it is handled; we apply those rights to everyone regardless.
Children
SÒMI is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has an account, write to help@somi.life and we will remove it.
Security
Data is encrypted in transit. Device tokens and sign-in tokens are stored hashed, never in the clear. Photos sit in private storage that nothing but our content delivery network can read, and every photo’s address contains a random identifier that cannot be guessed — but the address itself is not password-protected, so treat a direct link to one of your photos as something you would only hand to a person you meant to show it to. No system is perfect, and we do not claim otherwise; if a breach affects you, we will tell you.
Changes
If this policy changes materially, we will update the date at the top and, where the change affects how your data is used, tell you by email before it takes effect.
Questions: help@somi.life.