Privacy Policy

Effective date: 2026-07-28 Last updated: 2026-07-28

1. Who we are

Somiya is a family organizer for families living across borders. This Privacy Policy explains what personal data we process, why, and the rights you have under the EU General Data Protection Regulation (GDPR).

The data controller responsible for your personal data is:

Maryna Yankevych, a self-employed individual registered in Cyprus Contact: hello@somiya.app

If you have any questions about this policy or wish to exercise your rights, contact us at the address above.

2. Our privacy-first approach (summary)

We built Somiya to hold as little of your data as possible and to keep it inside the EU:

3. What data we process, and why

Data Examples Why (purpose) Lawful basis (GDPR Art. 6)
Account data Email address, display name, password (stored only as a salted hash) Create and secure your account, sign you in Contract (Art. 6(1)(b))
Family content Calendar events, tasks, shopping lists, family/member names, notes Provide the core organizer features and sync them across your family Contract
Document details Document type, holder name and expiry date that you confirm after scanning (e.g. “passport, expires March 2027”). The scanned file itself is not stored Track expiry dates and remind you 90/30/7 days ahead Contract
Device & technical Push notification token, time zone, language preference, app version, device platform Deliver notifications in your local time and language; keep the app working Contract / Legitimate interest (Art. 6(1)(f))
AI extraction input Text or images you choose to send to the AI capture feature (e.g. a flyer photo, a forwarded invite, a document scan) Turn unstructured content into a draft event/task/document detail that you confirm; processed transiently, not stored Contract (you initiate each extraction)
Subscription data Subscription status, plan, trial state, a pseudonymous app user identifier Manage your subscription and entitlements Contract
Family invitations Email address of the person you invite Deliver the invitation to join your family Legitimate interest
Usage events Registration, onboarding and subscription funnel steps, tied to your account Understand and improve the sign-up and subscription experience Legitimate interest
Diagnostics Crash reports, error events, technical logs Detect and fix bugs, keep the service reliable Legitimate interest
Website visits Standard web-server log of each request to somiya.app: page requested, time, referring page, browser type, and a truncated IP address (the last part is discarded before writing, so the full address is never stored) See which pages people find useful and whether they lead to the App Store Legitimate interest

We do not collect special-category data (GDPR Art. 9) as such, and we never use your content for advertising or profiling. Content you scan for extraction may incidentally contain sensitive information — it is processed transiently to produce the draft you confirm and is not stored (Section 4). We do not make automated decisions about you that produce legal or similarly significant effects (GDPR Art. 22).

4. AI features

Somiya’s AI is a stateless extractor with a human in the loop. When you send content to the AI capture / document-extract feature, it returns a structured draft that you review and confirm — the AI never creates or changes your family data on its own. Extraction can be inaccurate; always check the result before saving.

The photo or text you submit is processed transiently: it is used to produce the draft and is not stored on our servers. Only the structured details you explicitly confirm (for example an event title and time, or a document’s expiry date) are saved.

AI processing is performed by Anthropic (see sub-processors). We have a Zero Data Retention (ZDR) arrangement with Anthropic: content sent for extraction is not retained by Anthropic beyond transient processing and is not used to train models.

5. On-device storage

Parts of your data (your family, tasks and lists) are cached on your device so the app works offline. This cache is encrypted with AES-GCM; the encryption key is generated randomly on your device and stored in the hardware-backed secure element (iOS Keychain / Android Keystore). The key never leaves your device and is never included in the cache itself. If your device is lost or stolen, the on-disk cache is only ciphertext. Document scans are not stored anywhere — not on our servers and not in the device cache; only the details you confirm (such as expiry dates) are kept.

6. Processors and other recipients

We use the following processors to operate Somiya. Each is bound by a Data Processing Agreement (DPA).

Processor Role Location Transfer safeguard
Hetzner Application hosting Germany (EU) Within EU
Scaleway Application hosting, managed database France (EU) Within EU
Brevo Transactional email (password reset, invites, reminders) France (EU) Within EU
Expo (650 Industries, Inc.) Push notification delivery United States EU→US transfer under Standard Contractual Clauses (Expo DPA)
RevenueCat Subscription management United States EU→US transfer under Standard Contractual Clauses (RevenueCat DPA)
Anthropic AI extraction (with Zero Data Retention) United States EU→US transfer under Standard Contractual Clauses; ZDR

Apple distributes the App and processes your payment when you subscribe. For these activities Apple acts as an independent data controller under its own privacy policy, not as our processor. Push notifications are relayed by Expo to Apple’s and Google’s push services for delivery to your device.

We keep this list current. Three recipients (Expo, RevenueCat, Anthropic) are US-based; transfers to them rely on Standard Contractual Clauses, and we send them the minimum data needed — Expo: your push token and the notification text; RevenueCat: a pseudonymous user identifier and subscription state; Anthropic: only the content you submit for a given extraction. You can request a copy of the relevant transfer safeguards at hello@somiya.app.

7. International transfers

Your core data stays in the EU. The only transfers outside the EU are to Expo, RevenueCat and Anthropic (United States), as described above, and are protected by Standard Contractual Clauses. Contact us for a copy of the safeguards.

8. Data retention

9. Your rights

Under the GDPR you have the right to:

Deleting your account does not cancel an active App Store subscription — manage that in your Apple ID / App Store settings.

To exercise any right you cannot complete in-app, contact hello@somiya.app. We respond within the timeframes required by the GDPR (normally one month).

10. Children

Somiya accounts are for adults: you must be 18 or older to create an account, and the app is not directed at children as users. Adult family members may add information about their children — for example school events or a passport expiry date. We process that information solely to provide the service to your family, under the responsibility of the adult who added it, and never for advertising or profiling. We do not knowingly allow anyone under 18 to hold an account.

11. Security

We use encryption in transit (TLS), encryption at rest (database), hardware-backed on-device encryption, hashed passwords, short-lived access tokens with rotating refresh tokens, and rate limiting. Error tracking is self-hosted on our EU infrastructure. No system is perfectly secure, but we design to keep your family’s data protected.

12. Changes to this policy

We may update this policy. Material changes will be notified in-app or by email. The “Last updated” date above always reflects the current version.

13. Contact

Maryna Yankevych, a self-employed individual registered in Cyprus hello@somiya.app

You also have the right to contact your national data protection authority. As the controller is established in Cyprus, you may also contact the Office of the Commissioner for Personal Data Protection (Cyprus) — https://www.dataprotection.gov.cy.