Privacy Policy
Last updated: October 1, 2026
SoKal is a service operated by JAMES B FLORENCE. References in this Privacy Policy to "SoKal," "we," "our," or "us" refer to JAMES B FLORENCE, the legal operator of the SoKal service. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application and related services.
Information We Collect
We collect information you provide directly to us, including:
- Account information — your name, username, email address and/or phone number, profile photo, date of birth, and a short bio if you write one. Which of these exist depends on how you signed up: email and password, Google, Apple, or a phone number alone.
- Calendar events and availability — including titles, descriptions, times, and locations, both for events you create in SoKal and for events imported from a calendar you connect.
- Connections and friend relationships, and the per-connection privacy choices you make about them.
- Location. We store your hometown, your current city, and a temporary location while you are travelling. Where a place comes from a map or address lookup we keep its coordinates, not just its name — so an event at a specific address is stored with that address's coordinates. Coordinates for the places you save, the trips you take and the events you create are held at the precision the lookup returned. We do not track your device's position in the background, and we do not build a continuous location history; what we hold is the places you tell us about.
- Device information and push notification tokens, plus the app version and platform you last used.
- Contacts — phone number hashes for friend discovery, and the name you saved each contact under. See "Contact Discovery" below.
- Photos you upload to a shared photo collection or a postcard. See "Photos You Share" below.
- How you use the app — we keep a first-party record of actions like opening the app, creating an event or sending an invitation, with the platform you used. This is our own analytics; it is not sent to an advertising network. Before you have an account, an action taken with a phone number is recorded against that number.
Device Permissions
SoKal may request the following device permissions:
- Camera: Used to scan QR codes to connect with friends and to take profile pictures. We do not record or store any camera footage beyond the photos you choose to upload as your profile picture.
- Contacts: Used to help you find friends already on SoKal and to invite others to events. When you grant contacts permission, your contacts' phone numbers and names are sent to our servers over an encrypted (TLS) connection. Phone numbers are then converted into one-way cryptographic hashes (SHA-256) on the server before being stored — we do not retain the raw phone numbers from your contacts. These hashes are used to match against other SoKal users for friend discovery and to notify you when a contact joins. See the "Contact Discovery" section below for full details.
- Push Notifications: Used to notify you about event invitations, friend requests, and activity from your connections. You can disable notifications at any time in your device settings.
- Calendar: Used to sync your device calendar with SoKal so you can see all your events in one place. See the "Third-Party Calendar Access" section below for full details.
- Photo Library (read): Used to let you choose a profile picture and to upload photos to a shared photo dump from your existing photos. We only access the specific photos you select.
- Photo Library (save): Used to save photos from a shared photo dump to your device's Photos library when you tap the download button in the photo viewer. We only write the specific photo you choose to download — we do not read your existing library with this permission.
Third-Party Calendar Access
SoKal offers optional integration with third-party calendar services. You can connect Google Calendar, Apple Calendar and Microsoft Outlook Calendar. These integrations are entirely opt-in — we never access an external calendar unless you explicitly connect it, and you can disconnect one at any time.
What We Access
When you connect a third-party calendar, we access:
- Event data: Event titles, start/end times, locations, descriptions, all-day status, and recurrence rules from your connected calendars.
- Calendar list: The names and identifiers of your calendars so you can choose which ones to sync.
Why We Access It
We use your third-party calendar data to:
- Display your schedule: Show your existing events alongside SoKal events in a unified calendar view, so you can see your full availability in one place.
- Two-way sync: Keep events synchronized between SoKal and your external calendar. Events you create in SoKal can appear in your Google/Apple/Microsoft calendar, and vice versa, so you never have to manage events in two places.
- Availability detection: Understand when you are free or busy so we can suggest social activities at times that work for you and your friends.
How We Handle It
- Imported calendar events are stored on our servers to enable syncing and the social features described below. Visibility of these events to your connections is controlled by the rules in the "Event Classification & Visibility" section.
- We do not use your calendar data for advertising, marketing, or any purpose unrelated to providing the SoKal service.
- We do not sell, share, or transfer your calendar data to third parties, except as necessary to provide the sync functionality (i.e., writing events back to your connected calendar service via their API).
- You can disconnect a third-party calendar at any time from the app settings. When you disconnect, we stop syncing and delete the imported event data from our servers.
Event Classification & Visibility
When you sync a calendar from any provider (Google, Apple, or Microsoft), SoKal processes your events in the same way regardless of the source. We analyze event titles and details to classify each event into a category such as travel, outing, exercise, errand, online, or work. When we are unsure, the event remains unclassified. You can review or change the classification of any event at any time.
Unclassified events are completely private. Events without a confirmed type are never visible to anyone other than you. They are used only internally to determine whether you are free or busy.
For classified events, SoKal gives you two independent privacy controls:
- Activity feed visibility (which event types appear in your friends' feeds). By default, your travel and outing events appear in your connections' activity feeds. All other classified types — work, errands, exercise, online, blocked time, and life moments such as birthdays — are hidden from feeds by default. You can change which types are visible in your privacy settings, override the list on a per-connection basis (for example, sharing exercise events only with a workout partner), or remove all types to disappear from every feed entirely.
- Calendar detail level (what friends see when they look at your calendar directly). Three levels are available:
- Just busy — Friends see only that you are busy at a given time. No titles, types, or locations.
- Title only (the default) — Friends see the title, time, and event type. Exact locations are hidden, with one exception: for travel events, the destination city is shown, since the city is the entire point of a travel event.
- Full details — Friends see all event details, including descriptions and exact addresses.
Per-event control. When you create or edit an event, you can override these defaults for that specific event — for example, hiding a single outing from everyone, hiding it from one specific friend, or sharing an otherwise-private errand with one specific connection.
Conservative by design. Our classification system errs on the side of privacy: we would rather leave an event unclassified (and therefore completely hidden) than risk classifying a private event. You can always adjust the classification of any event, change your privacy settings at any time, or disconnect your calendar entirely to remove all synced data.
Google Calendar — Limited Use Disclosure
SoKal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google Calendar data to provide and improve the calendar features described above.
- We do not use Google Calendar data for serving advertisements.
- We do not allow humans to read your Google Calendar data unless (a) we have your explicit consent, (b) it is necessary for security purposes (e.g., investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.
- We do not transfer Google Calendar data to other apps or services except as necessary to provide the SoKal service or as required by law.
Microsoft Outlook Calendar — Data Use Disclosure
SoKal's use of information received from Microsoft APIs complies with the Microsoft APIs Terms of Use. Specifically:
- We only use Microsoft Calendar data to provide and improve the calendar features described above.
- We do not use Microsoft Calendar data for serving advertisements.
- We do not allow humans to read your Microsoft Calendar data unless (a) we have your explicit consent, (b) it is necessary for security purposes (e.g., investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.
- We do not transfer Microsoft Calendar data to other apps or services except as necessary to provide the SoKal service or as required by law.
Apple Calendar — Data Use Disclosure
SoKal's use of information from Apple Calendar complies with the Apple App Store Review Guidelines and Apple's privacy requirements. Specifically:
- We only use Apple Calendar data to provide and improve the calendar features described above.
- We do not use Apple Calendar data for serving advertisements.
- We do not allow humans to read your Apple Calendar data unless (a) we have your explicit consent, (b) it is necessary for security purposes (e.g., investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.
- We do not transfer Apple Calendar data to other apps or services except as necessary to provide the SoKal service or as required by law.
Text and WhatsApp Messaging
Text messages for the SoKal service are sent by JAMES B FLORENCE (the registered brand and legal operator of SoKal), through our messaging provider Twilio. We send messages to phone numbers provided by our users for friend invitations, event invitations, and updates to events you have been invited to — plus a verification code when you sign in with a phone number. These are transactional messages triggered by a specific action; we never send marketing or promotional messages.
Two channels: SMS and WhatsApp. Which one we use is determined by the recipient’s country, not by any choice on our side. Numbers in the United States and Canada (+1) receive SMS. Numbers in all other countries receive WhatsApp, because international SMS is both costly and a frequent target for fraud. The message content is the same either way, and the opt-out below applies identically to both.
Opt-In
Invitation messages — friend invitations, event invitations, and the update or cancellation messages that follow an event invitation — are sent only when an existing SoKal user takes an explicit action to invite a specific person, by selecting that person's phone number from their own device contacts inside the app. We do not send unsolicited messages, and we never message a number that has not been deliberately selected by a user for that purpose.
Verification codes work differently and are not invitations: a code is sent only when the owner of the number asks to sign in with it. Nobody else can trigger one for your number.
Message Frequency
No marketing or promotional messages, ever. Every message is transactional — triggered by a specific action someone took. There are five kinds, and these are all of them:
- Friend invitation — one message, when a SoKal user invites you to connect.
- Event invitation — one message per event, when a SoKal user invites you to it.
- Event update — if the time, date or location of an event you were invited to changes.
- Event cancellation — if that event is called off.
- Verification code — a one-time code, only when you ask to sign in with your phone number.
Update and cancellation messages mean you may receive more than one message about the same event. We send them because being told that an event moved is rather the point of having been invited — but they are why we do not describe this as a one-time-only program. Frequency depends on how much the events you are invited to change; in practice most recipients receive fewer than five messages per month. Once you have an account, ongoing notifications move to in-app push and email rather than text.
Opt-Out & Help
Reply STOP to any message to opt out. One opt-out covers everything: it is recorded against your phone number rather than against a single message or channel, so it stops SMS and WhatsApp alike and applies to all five message types above, including verification codes. Reply HELP for assistance, or contact us at team@sokal.app. Replying START or YES to a later invitation opts you back in. Message and data rates may apply.
Data We Collect for Messaging
- Phone numbers: For invitations, taken from the inviting user's device contacts at the moment they invite you. For verification codes, entered by you when you choose to sign in by phone. Either way we keep the number only as long as needed to deliver the message and track RSVP status.
- Opt-out preferences: If a recipient replies STOP, we record their opt-out status to ensure no further messages are sent.
How We Use Messaging Data
- Phone numbers are used only to deliver the five message types listed above, over SMS or WhatsApp. We do not use phone numbers for marketing, advertising, promotional messages, or any other purpose.
- We do not sell, rent, loan, trade, lease, or otherwise share phone numbers or SMS data with any third parties for their marketing or promotional purposes.
- We do not share phone numbers or messaging data with third parties except as necessary to deliver the message — our messaging provider Twilio, and for the WhatsApp channel, WhatsApp/Meta as the network carrying it — or as required by law.
Questions
Opt-out is covered under “Opt-Out & Help” above — reply STOP to any message. For anything else, reply HELP or contact us at team@sokal.app. See our Terms of Service for the full messaging terms.
Contact Discovery
SoKal offers a contact-based friend discovery feature. When you grant contacts permission, the app periodically uploads your contacts' phone numbers to our servers in a privacy-preserving way.
How We Protect Contact Data
- Hashing: Phone numbers from your contacts are converted into one-way cryptographic hashes (SHA-256) on our servers before storage. We do not store raw phone numbers from your contacts.
- No reverse lookup: SHA-256 hashes are one-way — they cannot be directly converted back into phone numbers. However, because phone numbers have limited combinations, we acknowledge a theoretical reverse-lookup risk. We mitigate this by restricting database access and never exposing hashes externally.
- Contact names: We store the display name associated with each contact (e.g., "Mom", "John") solely to personalize notifications (e.g., "John just joined SoKal"). Contact names are never shared with other users.
What We Use Contact Data For
- Friend discovery: We match your contact hashes against the hashed phone numbers of verified SoKal users to show you "People you know on SoKal" — helping you find friends who are already on the platform.
- Join notifications: When a new user verifies their phone number, we check if any existing users have that number in their contacts and send a push notification ("John just joined SoKal") so they can connect.
Your Control
- Contact discovery requires the Contacts permission. If you deny or revoke this permission, no contact data is uploaded or stored.
- You can dismiss the discovery card, and it will not reappear for 30 days.
- You can disable "Contact joined" push notifications in your notification settings.
- Permanently deleting your account removes every contact hash and contact name stored for you. Deactivating your account does not — see "Data Retention" below for the difference.
Photos You Share
SoKal has two ways to share photos. A photo dump is a shared collection tied to a travel event; membership is limited to people who were on the same trip, either as a co-participant on the event or by having an overlapping travel event to the same destination within the same dates. A postcard is a single photo you post from an event, visible to your connections. Both are described below, and both are handled the same way technically.
How We Handle Shared Photos
- Storage: Photos you upload are stored on our cloud storage provider (Amazon Web Services S3) with server-side encryption. Photos are served to other dump members through short-lived signed URLs.
- EXIF metadata stripped: When we process an uploaded photo, we re-encode it and discard EXIF metadata (camera model, GPS coordinates, capture timestamp, etc.) before storing it. The location and dates of the trip itself live on the parent travel event; per-photo metadata is removed.
- Automated content moderation: Before a photo is added to a dump, we send it to an automated moderation service (Amazon Web Services Rekognition) to detect prohibited content such as explicit nudity, sexual activity, graphic violence, or visually disturbing imagery. Photos that fail moderation are rejected at upload time and not stored. The moderation result for the rejected upload is logged for safety review and is never shown to other users.
- Visibility: Photos in a photo dump are visible only to the other members of that dump. A postcard is visible to the connections of the person who posted it. Neither is used for recommendations, and neither is shown to anyone outside those groups.
- Limits: Each user can upload up to 10 photos to a given dump.
- Deletion: You can delete any photo you uploaded, and permanently deleting your account deletes your photos — both the records in our database and the underlying image files in our storage. That includes your profile pictures (every version, not just the current one), your postcards, photos you were part-way through posting, and any file you uploaded to import a schedule. Two things survive on purpose: a recent backup still contains you until it rotates, and if a photo was flagged by our child-safety scanning we are required by law to preserve it. If you deactivate your account instead of deleting it, nothing is deleted — that is the point of it, and you can come back at any time.
Creating Events by Voice or Text
SoKal can turn a phrase like "dinner with Maya Saturday at 7" into a draft event. To do that we send the words themselves to Anthropic, our AI provider, along with today's date and your time zone so that "Saturday" means the right day.
What We Do Not Send
We do not send your contacts or your friends list, your name, your email, your phone number, or anything that identifies your account. Names you mention are matched against your own friends on our servers, after the AI has answered — the AI never sees who your friends are. It receives a phrase and a date, and nothing that says whose phrase it is.
What We Keep, and For How Long
We store what you typed or said, and the draft we produced from it, so that we can see how often the feature gets things wrong and improve it. Both are encrypted. We delete them 90 days after you use the feature.
We keep a longer record of which fields you corrected — that the date was wrong, say — with the words themselves removed. That tells us what to fix without keeping what you wrote.
The feature does nothing unless you use it, and creating a draft does not create anything on your calendar. Nothing is saved until you confirm it.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Connect you with friends and facilitate social planning
- Send push notifications about events and friend activity
- Suggest activities based on your calendar and interests
- Respond to your comments, questions, and support requests
Information Sharing
We do not sell your personal information, and we do not share it with advertising networks. SoKal contains no advertising SDK, no behavioural-advertising or ad-network analytics, and no tracking pixels, and we do not collect advertising identifiers. Our product analytics are our own and stay on our own servers. We do use a third-party crash reporter (Sentry, listed below) to find out when the app breaks; it receives error reports, not a record of your browsing. We share your information only:
- With your friends and connections, as you choose to share
- With the service providers listed below, who process data on our behalf in order to run the service
- When required by law, or to protect rights and safety
Service Providers
These are every third party that receives personal information from SoKal, and what each one gets:
- Amazon Web Services (S3, CloudFront, Rekognition) — photos and uploaded files, served through a content delivery network that sees viewers' IP addresses, plus our database backups. Rekognition receives uploaded photos for automated content moderation.
- Twilio — recipient phone numbers and message content, for SMS and WhatsApp. On the WhatsApp channel the message also passes through WhatsApp/Meta as the network carrying it.
- Google — sign-in details if you use Google to sign in; your calendar data if you connect Google Calendar; and addresses or place names you enter, sent to Google's geocoding and places services to resolve them.
- Apple — sign-in details if you use Sign in with Apple, and push notification delivery.
- Microsoft — your calendar data, if you connect an Outlook calendar.
- Expo — push notification delivery to your device, including the notification text, which can contain an event title or a friend's name. Expo passes it on to Apple or Google for final delivery.
- Sentry — crash and error reports from the mobile app, tagged with your user ID, email address and username so we can tell whether a crash affected one person or everyone.
- Zoho — our email provider, which receives your email address and the content of any email we send you.
- Stripe — payment details, only for businesses that subscribe to SoKal for Business. Stripe receives nothing about personal accounts.
- Open-Meteo — the coordinates of an upcoming event, to fetch its weather forecast. No name, account or identifier is sent with it.
- Anthropic — the words you type or say when you create an event by voice or text, plus the date and time zone needed to read them. No name, account or identifier is sent with it, and your contacts are never sent. See "Creating Events by Voice or Text" above.
Each of these acts as a processor on our instructions rather than as an independent controller of your data, and none is permitted to use it for their own marketing.
Data Security
All traffic between your device and SoKal is encrypted in transit (TLS). Passwords are hashed with Argon2id and are never stored or recoverable in readable form. Your calendar access tokens and the names you saved your contacts under are additionally encrypted at the application level, so they are unreadable even to someone holding a copy of the database. Uploaded photos are stored with server-side encryption. Access to production systems is restricted, and we take automated database backups daily. No system is perfectly secure, and we will not claim otherwise — but we would rather tell you exactly what is protected and how than say "industry-standard" and leave you guessing.
Data Retention
We keep your information for as long as your account exists. There are two different ways to close it, and the difference matters:
- Deactivate. You stop being able to sign in and you disappear from other people's feeds and calendars, but your data is kept so that you can come back later and pick up where you left off. We do not put a time limit on this and we do not delete deactivated accounts on a schedule — the choice of whether and when to erase your data stays yours rather than becoming a deadline.
- Delete permanently. Available in the app at any time, and it is exactly what it says: your account and the data attached to it are erased from our systems and cannot be restored. You do not have to email anyone or wait for us to action it. That includes your phone number in places you would not think to look: invitations other people sent you, our log of texts we sent you, and any saved location tied to your number. Where a record belongs to somebody else — an invitation they sent, for instance — we keep their record of having sent it and remove your number and name from it.
Two kinds of record have a fixed life of their own, because they concern people who may have no account here at all — someone we texted an invitation to, for instance:
- An invitation nobody accepted: 180 days after the event. If you were texted an invitation, never took it up, and the event has been over for six months, we clear your phone number and name from it. We keep the record that an invitation was sent, because that is the inviter's, not yours.
- Our log of messages we sent: 24 months. We keep the destination number for two years so we can answer a carrier or a network operator asking whether a message was really sent and really consented to. After that the number is removed and only the delivery record remains.
- What you typed or said to create an event: 90 days. A phrase can name someone who has no account here, so we do not keep it indefinitely. After three months the words and the draft made from them are erased, and only the record of which fields needed correcting remains.
Two things outlast a permanent deletion, and we would rather say so. Our encrypted database backups are kept on a rolling schedule and a recent backup may still contain your data until it rotates out. And where the law requires us to keep something — for example a record that a phone number asked not to be messaged, which is the only way we can honour that request, or evidence relating to a report of illegal content — we keep that specific record and nothing more.
Your Rights
These rights are yours wherever you live. Two of them you can exercise yourself, right now, without asking us:
- See what we hold — ask us for a copy of everything (see "Making a Request" below).
- Correct it — most of it you can edit in the app; ask us for anything you cannot reach.
- Delete it — in the app, yourself. Settings has both "deactivate" and "delete permanently"; the second is immediate and final, and you do not need our permission or our involvement.
- Take it elsewhere — the copy we give you is machine-readable JSON, so it can be moved.
- Object, or ask us to stop — to a particular use of your information, including our own product analytics.
- Withdraw a permission — contacts, notifications, photos, calendar access: all revocable in your device settings or in the app, at any time, without losing your account.
- Stop messages — reply STOP to any text or WhatsApp message.
Making a Request
Email team@sokal.app. Say what you want and which account it concerns.
We also record that you accepted this policy. When you create an account we store the date and which revision of this page and the Terms you were shown, so that if either changes we can tell what you actually agreed to rather than assuming it was the current version. It is two fields next to your account and it is included in any copy of your data you ask us for.
How we check it is you. We reply to the email address or phone number already on the account, and we may ask you to confirm a detail we already hold. We deliberately do not ask you to send us a photo of your ID: collecting a new, more sensitive piece of information in order to answer a request about your existing information is a bad trade, and it would make us a more attractive target. If we cannot satisfy ourselves that a request is genuinely yours we will say so rather than guess, because handing your data to the wrong person is the worse mistake.
How long. We aim to answer within 30 days. If it is going to take longer we will tell you before the 30 days are up and explain why. We do not charge for this.
Someone acting for you. An authorised agent may make a request on your behalf with your written permission; we will still confirm with you directly before acting.
If we say no. We will tell you why, and what you can do next. You can complain to your data protection regulator (see the GDPR section below) at any point, including instead of asking us first.
Notice for California Residents (CCPA/CPRA)
We have never sold your personal information, and we do not share it for cross-context behavioural advertising. That is not a policy position we are choosing; it is a fact about how the app is built. SoKal contains no advertising SDK, no behavioural-advertising or ad-network analytics, and no tracking pixels, and we do not collect advertising identifiers like the IDFA. The one third party that receives anything analytics-shaped is our crash reporter, Sentry, which gets error reports when the app fails — not a profile of what you do. There is consequently no "Do Not Sell or Share My Personal Information" link on this site, because there is nothing for it to switch off. We also do not use or disclose sensitive personal information beyond what is needed to provide the service, so the right to limit its use has nothing to restrain either.
In the twelve months before the date at the top of this policy, we collected the following categories, all of it from you or from your device unless stated:
| Category | Examples of what we hold | Why | How long |
|---|---|---|---|
| Identifiers | Name, username, email address, phone number, device and push notification tokens, IP address | To create and secure your account, deliver invitations and notifications, and rate-limit abuse | While your account exists. A destination phone number in our message log: 24 months |
| Identifiers of people who are not users | The phone number, and the name the inviter had saved you under, of someone invited to an event or a photo collection by text message | To deliver the invitation, to let you accept it, and to honour a STOP reply | 180 days after the event ends, then cleared |
| Customer records | The same contact details, plus your profile photo | To run the service | While your account exists |
| Protected classification characteristics | Your date of birth, which implies your age | To show birthdays to your connections and to enforce our under-13 rule | While your account exists |
| Commercial information | Subscription and payment records — businesses only, never personal accounts | To bill a SoKal for Business subscription | While the subscription exists, then as tax law requires |
| Internet or network activity | Which screens and features you use, when you open the app, the platform and app version | Our own product analytics, and diagnosing faults | While your account exists |
| Geolocation, including precise geolocation | Coordinates of places you add — your hometown, your current city, travel destinations, event locations. This is "sensitive personal information" under the CPRA. | To show you what is nearby, tell you who is in town, and fetch the weather for an event | While your account exists |
| Audio, visual or similar information | Photos you upload to a shared collection or a postcard, and your profile photo | To show them to the people you shared them with | Until you delete them, or your account |
| Inferences | Interests we derive from your events, who you spend time with, your travel patterns and your typical free days | To suggest plans and show you when friends are free | While your account exists; recomputed as your calendar changes |
We disclose these categories to the service providers listed under "Information Sharing" above, each for the purpose named there and under a contract that forbids them using it for anything else. We do not disclose personal information to anyone for money or for advertising.
Retention. The table gives the period for each category. Three general points: a deactivated account is kept indefinitely so that you can return; a permanent deletion is immediate; and two categories have a fixed period regardless of any account — unaccepted invitations are cleared 180 days after the event, and message logs lose the destination number after 24 months. See "Data Retention" above for the difference between deactivating and deleting, and for the small number of records that outlast a deletion because the law requires it.
Your California rights are the ones listed under "Your Rights" above: to know, to delete, to correct, to opt out of sale or sharing (inapplicable, as explained), and to limit the use of sensitive personal information (likewise). We will not discriminate against you for exercising any of them — no loss of features, no worse price, no degraded service. Use the same address, team@sokal.app.
Notice for Users in the UK, EU and Switzerland (UK GDPR / GDPR)
For people in these regions, JAMES B FLORENCE is the data controller. You can reach us at team@sokal.app.
What we rely on to process your data, purpose by purpose:
- Performance of a contract — running your account, storing and syncing your calendar, delivering invitations and RSVPs, and showing your availability to the people you chose. Without this there is no service.
- Consent — access to your contacts, your camera and photo library, your location, and push notifications. Each is asked for separately, each is refusable, and each is withdrawable in your device settings at any time without losing your account. We treat your precise location as requiring consent in this way too.
- Legitimate interests — keeping the service secure and working: rate-limiting, abuse and fraud prevention, our own product analytics, and diagnosing crashes. We have weighed these against your interests, and we use the least data that answers the question; our analytics stay on our own servers and are not sold or shared.
- Legal obligation — keeping a record that a phone number asked not to be messaged (the only way we can honour that request), and preserving and reporting material relating to child sexual abuse.
Your rights are the ones under "Your Rights" above — access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent — plus the right to complain to a supervisory authority. You can complain to the authority where you live or work; in Ireland that is the Data Protection Commission, in Germany your state authority, in the UK the Information Commissioner's Office. You do not have to come to us first, though we would rather you did so we can fix it.
Where your data goes. SoKal is operated from the United States and your data is stored and processed there, along with the service providers listed above. That means a transfer out of your region. Where a provider offers Standard Contractual Clauses or operates under an approved adequacy framework we rely on those; we are a small operation and we would rather tell you plainly that this is an area we are still formalising than imply a paperwork position we have not completed. If that matters to you, ask us before you sign up.
Automated decisions. When you connect an external calendar we classify each event automatically — travel, outing, work, errand and so on — because that classification decides what your connections can see. It is deliberately cautious: an event we are unsure about is left unclassified, and an unclassified event is private. Nothing here has a legal effect on you, and you can review or change any classification yourself, per event, at any time. No decision about you is made solely by a machine in a way that materially affects you.
No EU representative yet. Article 27 asks controllers outside the EU to appoint a representative inside it. We have not appointed one. We would rather say so here than leave you to discover it; in the meantime every request and complaint reaches a person directly at team@sokal.app.
Children's Privacy & Child Safety
SoKal is not intended for children under 13 years of age, and the minimum age is 16 if you are in the European Economic Area — some countries there set it lower, and where yours does, that lower age applies to you. In the UK the minimum is 13.
We do not knowingly collect personal information from anyone below the minimum age that applies to them. If we learn that an account does, we disable it and delete the associated data. We ask for your date of birth but do not require it, so we rely in part on being told — if you believe an underage account exists, tell us at team@sokal.app and we will act on it.
SoKal has zero tolerance for child sexual abuse and exploitation (CSAE), including child sexual abuse material (CSAM). Our full Child Safety Standards set out what is prohibited, how to report it from inside the app, how we respond to and report confirmed CSAM to NCMEC, and how to reach our child safety point of contact at team@sokal.app.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy, please contact us at team@sokal.app