Privacy Policy
Effective date: 2026-08-11 Last updated: 2026-09-09
1. Who we are
Somiya is a family organizer for families living across borders. This Privacy Policy explains what personal data we process, why, and the rights you have under the EU General Data Protection Regulation (GDPR).
The data controller responsible for your personal data is:
Maryna Yankevych, a self-employed individual registered in Cyprus Contact: hello@somiya.app
If you have any questions about this policy or wish to exercise your rights, contact us at the address above.
2. Our privacy-first approach (summary)
We built Somiya to hold as little of your data as possible and to keep it inside the EU:
- EU-only hosting. All servers and storage that hold your data are in the European Union (Germany / France).
- Encryption at rest on both ends. Your data is encrypted at rest on our servers and on your device. The on-device cache is encrypted with AES-GCM using a key stored in your device’s hardware-backed secure element (iOS Keychain / Android Keystore).
- Nothing you photograph is kept. When you capture something with the camera — a school flyer, a printed invitation — the picture is read once to produce a draft and is then discarded. It is never stored on our servers or on your device; only the details you confirm are saved (see Section 4).
- No advertising, no ad tracking, no third-party advertising identifiers. We do not use Google Analytics, Facebook, Mixpanel, Amplitude, Segment or any advertising SDK.
- No cookies and no tracking script on this website. somiya.app sets no cookies and loads nothing from a third party — you will not see a cookie banner here because there is nothing to consent to. To know which pages are worth keeping, we read our own web-server log, in which visitors’ IP addresses are truncated before they are written to disk (see Section 3).
- Your own AI assistant, only if you ask for it. Somiya can be connected to an AI assistant you choose. It is off until you switch it on, the connecting program runs on your device, we never see the conversation — and an assistant can only ever suggest something for you to confirm, never write to your family’s data (see Section 5).
- Data minimisation. We only collect what the app needs to work.
3. What data we process, and why
| Data | Examples | Why (purpose) | Lawful basis (GDPR Art. 6) |
|---|---|---|---|
| Account data | Email address, display name, password (stored only as a salted hash) | Create and secure your account, sign you in | Contract (Art. 6(1)(b)) |
| Family content | Calendar events, tasks, shopping lists, family/member names, notes | Provide the core organizer features and sync them across your family | Contract |
| Device & technical | Push notification token, time zone, language preference, app version, device platform | Deliver notifications in your local time and language; keep the app working | Contract / Legitimate interest (Art. 6(1)(f)) |
| AI extraction input | Text or images you choose to send to the AI capture feature (e.g. a flyer photo, a forwarded invite) | Turn unstructured content into a draft event or task that you confirm; processed transiently, not stored | Contract (you initiate each extraction) |
| Subscription data | Subscription status, plan, trial state, a pseudonymous app user identifier | Manage your subscription and entitlements | Contract |
| Family invitations | Email address of the person you invite | Deliver the invitation to join your family | Legitimate interest |
| Usage events | Registration, onboarding and subscription funnel steps, tied to your account; if you choose to type a reason when you close the subscription screen, the text you write | Understand and improve the sign-up and subscription experience | Legitimate interest |
| Diagnostics | Crash reports, error events, technical logs | Detect and fix bugs, keep the service reliable | Legitimate interest |
| AI assistant access (only if you connect one) | A hash of each access token you create, the label you gave it, its permissions and its created / expiry / last-used times; suggestions your assistant has filed and you have not yet answered | Let you connect your own AI assistant, see which of your clients are active, and revoke one | Contract |
| Website visits | Standard web-server log of each request to somiya.app: page requested, time, referring page, browser type, and a truncated IP address (the last part is discarded before writing, so the full address is never stored) | See which pages people find useful and whether they lead to the App Store | Legitimate interest |
We do not collect special-category data (GDPR Art. 9) as such, and we never use your content for advertising or profiling. Content you send for extraction may incidentally contain sensitive information — it is processed transiently to produce the draft you confirm and is not stored (Section 4). We do not make automated decisions about you that produce legal or similarly significant effects (GDPR Art. 22).
4. AI features
Somiya’s AI is a stateless extractor with a human in the loop. When you send content to the AI capture feature, it returns a structured draft that you review and confirm — the AI never creates or changes your family data on its own. Extraction can be inaccurate; always check the result before saving.
The photo or text you submit is processed transiently: it is used to produce the draft and is not stored on our servers. Only the structured details you explicitly confirm (for example an event title and time, or a task and the person it belongs to) are saved.
AI processing is performed by Anthropic (see sub-processors). We have a Zero Data Retention (ZDR) arrangement with Anthropic: content sent for extraction is not retained by Anthropic beyond transient processing and is not used to train models.
5. Connecting your own AI assistant (MCP)
You can connect an AI assistant of your choosing — Claude, or any other client that speaks the Model Context Protocol — to your family’s calendar, tasks and shopping lists. This is off unless you turn it on: you create an access token in the app under Settings → Account → AI access, and nothing happens until you paste that token into your own client.
The connecting program runs on your device, not ours. It is open-source software you install and run yourself. It reads from our API on your behalf and hands the result to your assistant. Your conversation with that assistant never passes through us, and we cannot see it.
Your AI provider is not our processor. This is the most important sentence in this section. When you connect an assistant, family data leaves our systems and enters a service you have chosen and contracted with directly. What that provider does with it — whether it is retained, whether it trains models — is governed by your agreement with them, not by this policy, and we have no visibility into it and no control over it. The sub-processor list in Section 7 does not cover it, because they are not acting for us. This is different from Section 4: there, Anthropic processes on our instructions under our agreement; here, you are the one deciding.
What an assistant can see, and do. A token never reaches further than you can in the app yourself: another member’s private task is as invisible to it as it is to you. You choose per token whether it may read the calendar, read tasks and lists, and whether it may make suggestions. An assistant can never write to your family’s data. At most it can suggest a task or a shopping item, which appears in the app for you to confirm or dismiss; nothing is added until you confirm it, and that confirmation cannot be switched off. Editing and deleting are not offered at all.
Please note this affects the whole family. Your family’s shared calendar, tasks and lists include information about other people — your partner, your children. Connecting an assistant sends that shared information to your chosen AI provider. Consider telling the rest of your family before you turn it on. If you are a family organizer, you cannot make this choice on another adult member’s behalf, and they cannot make it on yours: each person’s tokens are their own.
What we store for this feature.
- The token: we keep a SHA-256 hash of it, never the token itself, so a leak of our database cannot yield a working credential. Alongside it we keep the label you gave it (for example “Laptop”), its first few characters so you can recognise it in the list, which permissions you granted, and when it was created, when it expires and when it was last used.
- Suggestions awaiting your decision: the proposed task or item, until you confirm or dismiss it. An unanswered suggestion is deleted automatically after 24 hours.
- A usage counter: how many times each kind of request was made, per day, across all users together. It records a name and a date and nothing else — no user, no family, no content — and exists only to tell us whether the feature is used at all.
Ending it. Revoke a token in the app and it stops working on its next request; any suggestions it left unanswered are dropped with it. Tokens also expire by themselves after 90 days. Revoking does not reach data your assistant has already received — that lives with your AI provider, and you would need to ask them. Deleting your account removes your tokens and any suggestions along with the rest of your data (Section 10).
6. On-device storage
Parts of your data (your family, tasks and lists) are cached on your device so the app works offline. This cache is encrypted with AES-GCM; the encryption key is generated randomly on your device and stored in the hardware-backed secure element (iOS Keychain / Android Keystore). The key never leaves your device and is never included in the cache itself. If your device is lost or stolen, the on-disk cache is only ciphertext. Photos you capture are not stored anywhere — not on our servers and not in the device cache; only the details you confirm are kept.
7. Processors and other recipients
We use the following processors to operate Somiya. Each is bound by a Data Processing Agreement (DPA).
| Processor | Role | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner | Application hosting | Germany (EU) | Within EU |
| Scaleway | Application hosting, managed database | France (EU) | Within EU |
| Brevo | Transactional email (password reset, invites, reminders) | France (EU) | Within EU |
| Expo (650 Industries, Inc.) | Push notification delivery | United States | EU→US transfer under Standard Contractual Clauses (Expo DPA) |
| RevenueCat | Subscription management | United States | EU→US transfer under Standard Contractual Clauses (RevenueCat DPA) |
| Anthropic | AI extraction (with Zero Data Retention) | United States | EU→US transfer under Standard Contractual Clauses; ZDR |
Apple distributes the App and processes your payment when you subscribe. For these activities Apple acts as an independent data controller under its own privacy policy, not as our processor. Push notifications are relayed by Expo to Apple’s and Google’s push services for delivery to your device.
We keep this list current. Three recipients (Expo, RevenueCat, Anthropic) are US-based; transfers to them rely on Standard Contractual Clauses, and we send them the minimum data needed — Expo: your push token and the notification text; RevenueCat: a pseudonymous user identifier and subscription state; Anthropic: only the content you submit for a given extraction. You can request a copy of the relevant transfer safeguards at hello@somiya.app.
8. International transfers
Your core data stays in the EU. The only transfers outside the EU are to Expo, RevenueCat and Anthropic (United States), as described above, and are protected by Standard Contractual Clauses. Contact us for a copy of the safeguards.
9. Data retention
- Account and family data: kept while your account is active. When you delete your account, your data is erased (see Section 10).
- Diagnostics/logs: kept for up to 90 days, then deleted. Error tracking runs on our own EU servers (self-hosted), not on a third-party service.
- Website visit logs: kept for up to 14 days, then deleted automatically. They stay on our own EU server and are not sent to any analytics provider.
- AI assistant access: a token lives until you revoke it or it expires, at most 90 days. An unanswered suggestion is deleted after 24 hours. The usage counter holds no personal data and is kept indefinitely.
- Backups: encrypted database backups are kept on a rolling window of up to 7 days; data removed from the live database disappears from backups as that window rolls over.
10. Your rights
Under the GDPR you have the right to:
- Access your data and obtain a copy (data portability, Art. 20) — available in-app via Account → Privacy & data export.
- Erasure (Art. 17) — delete your account and all your data in-app via Account → Delete account. (If you are the billing owner of a family, deletion also removes the shared family data; other family members are affected, so the app asks you to confirm this explicitly.)
- Rectification of inaccurate data — edit it in-app or contact us.
- Restriction and objection to certain processing, including processing based on legitimate interest.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection supervisory authority.
Deleting your account does not cancel an active App Store subscription — manage that in your Apple ID / App Store settings.
To exercise any right you cannot complete in-app, contact hello@somiya.app. We respond within the timeframes required by the GDPR (normally one month).
11. Children
Somiya accounts are for adults: you must be 18 or older to create an account, and the app is not directed at children as users. Adult family members may add information about their children — for example a school event or a task assigned to them. We process that information solely to provide the service to your family, under the responsibility of the adult who added it, and never for advertising or profiling. We do not knowingly allow anyone under 18 to hold an account.
12. Security
We use encryption in transit (TLS), encryption at rest (database), hardware-backed on-device encryption, hashed passwords, short-lived access tokens with rotating refresh tokens, and rate limiting. Error tracking is self-hosted on our EU infrastructure. No system is perfectly secure, but we design to keep your family’s data protected.
13. Changes to this policy
We may update this policy. Material changes will be notified in-app or by email. The “Last updated” date above always reflects the current version.
14. Contact
Maryna Yankevych, a self-employed individual registered in Cyprus hello@somiya.app
You also have the right to contact your national data protection authority. As the controller is established in Cyprus, you may also contact the Office of the Commissioner for Personal Data Protection (Cyprus) — https://www.dataprotection.gov.cy.