Privacy Policy

Last updated: October 1, 2026

SoKal is a service operated by JAMES B FLORENCE. References in this Privacy Policy to "SoKal," "we," "our," or "us" refer to JAMES B FLORENCE, the legal operator of the SoKal service. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application and related services.

Information We Collect

We collect information you provide directly to us, including:

Device Permissions

SoKal may request the following device permissions:

Third-Party Calendar Access

SoKal offers optional integration with third-party calendar services. You can connect Google Calendar, Apple Calendar and Microsoft Outlook Calendar. These integrations are entirely opt-in — we never access an external calendar unless you explicitly connect it, and you can disconnect one at any time.

What We Access

When you connect a third-party calendar, we access:

Why We Access It

We use your third-party calendar data to:

How We Handle It

Event Classification & Visibility

When you sync a calendar from any provider (Google, Apple, or Microsoft), SoKal processes your events in the same way regardless of the source. We analyze event titles and details to classify each event into a category such as travel, outing, exercise, errand, online, or work. When we are unsure, the event remains unclassified. You can review or change the classification of any event at any time.

Unclassified events are completely private. Events without a confirmed type are never visible to anyone other than you. They are used only internally to determine whether you are free or busy.

For classified events, SoKal gives you two independent privacy controls:

Per-event control. When you create or edit an event, you can override these defaults for that specific event — for example, hiding a single outing from everyone, hiding it from one specific friend, or sharing an otherwise-private errand with one specific connection.

Conservative by design. Our classification system errs on the side of privacy: we would rather leave an event unclassified (and therefore completely hidden) than risk classifying a private event. You can always adjust the classification of any event, change your privacy settings at any time, or disconnect your calendar entirely to remove all synced data.

Google Calendar — Limited Use Disclosure

SoKal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Microsoft Outlook Calendar — Data Use Disclosure

SoKal's use of information received from Microsoft APIs complies with the Microsoft APIs Terms of Use. Specifically:

Apple Calendar — Data Use Disclosure

SoKal's use of information from Apple Calendar complies with the Apple App Store Review Guidelines and Apple's privacy requirements. Specifically:

Text and WhatsApp Messaging

Text messages for the SoKal service are sent by JAMES B FLORENCE (the registered brand and legal operator of SoKal), through our messaging provider Twilio. We send messages to phone numbers provided by our users for friend invitations, event invitations, and updates to events you have been invited to — plus a verification code when you sign in with a phone number. These are transactional messages triggered by a specific action; we never send marketing or promotional messages.

Two channels: SMS and WhatsApp. Which one we use is determined by the recipient’s country, not by any choice on our side. Numbers in the United States and Canada (+1) receive SMS. Numbers in all other countries receive WhatsApp, because international SMS is both costly and a frequent target for fraud. The message content is the same either way, and the opt-out below applies identically to both.

Opt-In

Invitation messages — friend invitations, event invitations, and the update or cancellation messages that follow an event invitation — are sent only when an existing SoKal user takes an explicit action to invite a specific person, by selecting that person's phone number from their own device contacts inside the app. We do not send unsolicited messages, and we never message a number that has not been deliberately selected by a user for that purpose.

Verification codes work differently and are not invitations: a code is sent only when the owner of the number asks to sign in with it. Nobody else can trigger one for your number.

Message Frequency

No marketing or promotional messages, ever. Every message is transactional — triggered by a specific action someone took. There are five kinds, and these are all of them:

Update and cancellation messages mean you may receive more than one message about the same event. We send them because being told that an event moved is rather the point of having been invited — but they are why we do not describe this as a one-time-only program. Frequency depends on how much the events you are invited to change; in practice most recipients receive fewer than five messages per month. Once you have an account, ongoing notifications move to in-app push and email rather than text.

Opt-Out & Help

Reply STOP to any message to opt out. One opt-out covers everything: it is recorded against your phone number rather than against a single message or channel, so it stops SMS and WhatsApp alike and applies to all five message types above, including verification codes. Reply HELP for assistance, or contact us at team@sokal.app. Replying START or YES to a later invitation opts you back in. Message and data rates may apply.

Data We Collect for Messaging

How We Use Messaging Data

Questions

Opt-out is covered under “Opt-Out & Help” above — reply STOP to any message. For anything else, reply HELP or contact us at team@sokal.app. See our Terms of Service for the full messaging terms.

Contact Discovery

SoKal offers a contact-based friend discovery feature. When you grant contacts permission, the app periodically uploads your contacts' phone numbers to our servers in a privacy-preserving way.

How We Protect Contact Data

What We Use Contact Data For

Your Control

Photos You Share

SoKal has two ways to share photos. A photo dump is a shared collection tied to a travel event; membership is limited to people who were on the same trip, either as a co-participant on the event or by having an overlapping travel event to the same destination within the same dates. A postcard is a single photo you post from an event, visible to your connections. Both are described below, and both are handled the same way technically.

How We Handle Shared Photos

Creating Events by Voice or Text

SoKal can turn a phrase like "dinner with Maya Saturday at 7" into a draft event. To do that we send the words themselves to Anthropic, our AI provider, along with today's date and your time zone so that "Saturday" means the right day.

What We Do Not Send

We do not send your contacts or your friends list, your name, your email, your phone number, or anything that identifies your account. Names you mention are matched against your own friends on our servers, after the AI has answered — the AI never sees who your friends are. It receives a phrase and a date, and nothing that says whose phrase it is.

What We Keep, and For How Long

We store what you typed or said, and the draft we produced from it, so that we can see how often the feature gets things wrong and improve it. Both are encrypted. We delete them 90 days after you use the feature.

We keep a longer record of which fields you corrected — that the date was wrong, say — with the words themselves removed. That tells us what to fix without keeping what you wrote.

The feature does nothing unless you use it, and creating a draft does not create anything on your calendar. Nothing is saved until you confirm it.

How We Use Your Information

We use the information we collect to:

Information Sharing

We do not sell your personal information, and we do not share it with advertising networks. SoKal contains no advertising SDK, no behavioural-advertising or ad-network analytics, and no tracking pixels, and we do not collect advertising identifiers. Our product analytics are our own and stay on our own servers. We do use a third-party crash reporter (Sentry, listed below) to find out when the app breaks; it receives error reports, not a record of your browsing. We share your information only:

Service Providers

These are every third party that receives personal information from SoKal, and what each one gets:

Each of these acts as a processor on our instructions rather than as an independent controller of your data, and none is permitted to use it for their own marketing.

Data Security

All traffic between your device and SoKal is encrypted in transit (TLS). Passwords are hashed with Argon2id and are never stored or recoverable in readable form. Your calendar access tokens and the names you saved your contacts under are additionally encrypted at the application level, so they are unreadable even to someone holding a copy of the database. Uploaded photos are stored with server-side encryption. Access to production systems is restricted, and we take automated database backups daily. No system is perfectly secure, and we will not claim otherwise — but we would rather tell you exactly what is protected and how than say "industry-standard" and leave you guessing.

Data Retention

We keep your information for as long as your account exists. There are two different ways to close it, and the difference matters:

Two kinds of record have a fixed life of their own, because they concern people who may have no account here at all — someone we texted an invitation to, for instance:

Two things outlast a permanent deletion, and we would rather say so. Our encrypted database backups are kept on a rolling schedule and a recent backup may still contain your data until it rotates out. And where the law requires us to keep something — for example a record that a phone number asked not to be messaged, which is the only way we can honour that request, or evidence relating to a report of illegal content — we keep that specific record and nothing more.

Your Rights

These rights are yours wherever you live. Two of them you can exercise yourself, right now, without asking us:

Making a Request

Email team@sokal.app. Say what you want and which account it concerns.

We also record that you accepted this policy. When you create an account we store the date and which revision of this page and the Terms you were shown, so that if either changes we can tell what you actually agreed to rather than assuming it was the current version. It is two fields next to your account and it is included in any copy of your data you ask us for.

How we check it is you. We reply to the email address or phone number already on the account, and we may ask you to confirm a detail we already hold. We deliberately do not ask you to send us a photo of your ID: collecting a new, more sensitive piece of information in order to answer a request about your existing information is a bad trade, and it would make us a more attractive target. If we cannot satisfy ourselves that a request is genuinely yours we will say so rather than guess, because handing your data to the wrong person is the worse mistake.

How long. We aim to answer within 30 days. If it is going to take longer we will tell you before the 30 days are up and explain why. We do not charge for this.

Someone acting for you. An authorised agent may make a request on your behalf with your written permission; we will still confirm with you directly before acting.

If we say no. We will tell you why, and what you can do next. You can complain to your data protection regulator (see the GDPR section below) at any point, including instead of asking us first.

Notice for California Residents (CCPA/CPRA)

We have never sold your personal information, and we do not share it for cross-context behavioural advertising. That is not a policy position we are choosing; it is a fact about how the app is built. SoKal contains no advertising SDK, no behavioural-advertising or ad-network analytics, and no tracking pixels, and we do not collect advertising identifiers like the IDFA. The one third party that receives anything analytics-shaped is our crash reporter, Sentry, which gets error reports when the app fails — not a profile of what you do. There is consequently no "Do Not Sell or Share My Personal Information" link on this site, because there is nothing for it to switch off. We also do not use or disclose sensitive personal information beyond what is needed to provide the service, so the right to limit its use has nothing to restrain either.

In the twelve months before the date at the top of this policy, we collected the following categories, all of it from you or from your device unless stated:

CategoryExamples of what we holdWhyHow long
IdentifiersName, username, email address, phone number, device and push notification tokens, IP addressTo create and secure your account, deliver invitations and notifications, and rate-limit abuseWhile your account exists. A destination phone number in our message log: 24 months
Identifiers of people who are not usersThe phone number, and the name the inviter had saved you under, of someone invited to an event or a photo collection by text messageTo deliver the invitation, to let you accept it, and to honour a STOP reply180 days after the event ends, then cleared
Customer recordsThe same contact details, plus your profile photoTo run the serviceWhile your account exists
Protected classification characteristicsYour date of birth, which implies your ageTo show birthdays to your connections and to enforce our under-13 ruleWhile your account exists
Commercial informationSubscription and payment records — businesses only, never personal accountsTo bill a SoKal for Business subscriptionWhile the subscription exists, then as tax law requires
Internet or network activityWhich screens and features you use, when you open the app, the platform and app versionOur own product analytics, and diagnosing faultsWhile your account exists
Geolocation, including precise geolocationCoordinates of places you add — your hometown, your current city, travel destinations, event locations. This is "sensitive personal information" under the CPRA.To show you what is nearby, tell you who is in town, and fetch the weather for an eventWhile your account exists
Audio, visual or similar informationPhotos you upload to a shared collection or a postcard, and your profile photoTo show them to the people you shared them withUntil you delete them, or your account
InferencesInterests we derive from your events, who you spend time with, your travel patterns and your typical free daysTo suggest plans and show you when friends are freeWhile your account exists; recomputed as your calendar changes

We disclose these categories to the service providers listed under "Information Sharing" above, each for the purpose named there and under a contract that forbids them using it for anything else. We do not disclose personal information to anyone for money or for advertising.

Retention. The table gives the period for each category. Three general points: a deactivated account is kept indefinitely so that you can return; a permanent deletion is immediate; and two categories have a fixed period regardless of any account — unaccepted invitations are cleared 180 days after the event, and message logs lose the destination number after 24 months. See "Data Retention" above for the difference between deactivating and deleting, and for the small number of records that outlast a deletion because the law requires it.

Your California rights are the ones listed under "Your Rights" above: to know, to delete, to correct, to opt out of sale or sharing (inapplicable, as explained), and to limit the use of sensitive personal information (likewise). We will not discriminate against you for exercising any of them — no loss of features, no worse price, no degraded service. Use the same address, team@sokal.app.

Notice for Users in the UK, EU and Switzerland (UK GDPR / GDPR)

For people in these regions, JAMES B FLORENCE is the data controller. You can reach us at team@sokal.app.

What we rely on to process your data, purpose by purpose:

Your rights are the ones under "Your Rights" above — access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent — plus the right to complain to a supervisory authority. You can complain to the authority where you live or work; in Ireland that is the Data Protection Commission, in Germany your state authority, in the UK the Information Commissioner's Office. You do not have to come to us first, though we would rather you did so we can fix it.

Where your data goes. SoKal is operated from the United States and your data is stored and processed there, along with the service providers listed above. That means a transfer out of your region. Where a provider offers Standard Contractual Clauses or operates under an approved adequacy framework we rely on those; we are a small operation and we would rather tell you plainly that this is an area we are still formalising than imply a paperwork position we have not completed. If that matters to you, ask us before you sign up.

Automated decisions. When you connect an external calendar we classify each event automatically — travel, outing, work, errand and so on — because that classification decides what your connections can see. It is deliberately cautious: an event we are unsure about is left unclassified, and an unclassified event is private. Nothing here has a legal effect on you, and you can review or change any classification yourself, per event, at any time. No decision about you is made solely by a machine in a way that materially affects you.

No EU representative yet. Article 27 asks controllers outside the EU to appoint a representative inside it. We have not appointed one. We would rather say so here than leave you to discover it; in the meantime every request and complaint reaches a person directly at team@sokal.app.

Children's Privacy & Child Safety

SoKal is not intended for children under 13 years of age, and the minimum age is 16 if you are in the European Economic Area — some countries there set it lower, and where yours does, that lower age applies to you. In the UK the minimum is 13.

We do not knowingly collect personal information from anyone below the minimum age that applies to them. If we learn that an account does, we disable it and delete the associated data. We ask for your date of birth but do not require it, so we rely in part on being told — if you believe an underage account exists, tell us at team@sokal.app and we will act on it.

SoKal has zero tolerance for child sexual abuse and exploitation (CSAE), including child sexual abuse material (CSAM). Our full Child Safety Standards set out what is prohibited, how to report it from inside the app, how we respond to and report confirmed CSAM to NCMEC, and how to reach our child safety point of contact at team@sokal.app.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

Contact Us

If you have any questions about this Privacy Policy, please contact us at team@sokal.app