1. Introduction

Welcome to Sorom (“we,” “us,” “our,” or “Sorom”). This Privacy Policy explains how Sorom Inc. collects, uses, shares, and protects personal information when you use our mobile applications, website, web application, and related services (collectively, the “Services”).

By using Sorom, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, please do not use our Services.

2. Information We Collect

2.1 Information You Provide

Account Information. When you create an account, we collect your email address and authentication information. Web registration begins with email and password and requires an age and terms acknowledgment; users must be at least 18. Passwords are processed through our authentication provider’s password-protection mechanisms. We collect additional profile information, such as your name, date of birth, username, photo, bio, and home city/country, when you provide it or complete a feature’s required profile steps.

Profile & Matching Information. To provide our matching services, we collect your travel preferences and interests, personality assessment responses based on the Big Five traits, communication style preferences, travel style preferences including budget, pace, and spontaneity, languages spoken, travel availability dates and destinations, and match profile photos and descriptions.

Content You Create. This includes journals containing text, photos, and videos; Moments (48-hour stories); travel diaries; comments and reactions; chat messages; itinerary details; per-day travel mood selections chosen from a fixed list (chill, adventurous, culture, foodie, recovery, or surprise) together with an optional free-text note of up to 280 characters; and Interesting Places submissions including descriptions, categories, photos, and location coordinates, as well as comments on Interesting Places, bookmarks, and visit markers.

Safety Information. To support our safety features, we collect emergency contact details including name, phone, email, and relationship; safety check-in schedules; and meetup verification PINs. If you enable emergency recording and give explicit consent when you set it up, we also collect the recordings it captures: audio, and video as well where you have chosen video. Those are captured only when you raise a panic alert (including hands-free voice-activated panic) or enter your duress PIN, never at any other time, and duress-triggered recordings are audio only.

Booking Information. When you use our booking features, we collect Price Check request details, guest information for reservations, booking history, and payment information which is processed securely by third parties.

Trip Expenses and Receipts. Monthly and Annual subscribers can record trip expenses and split them with the other participants of an itinerary. We collect the expense details you enter, such as amount, currency, date, category, and who the expense is shared with. If you scan a receipt, we also collect the receipt image you photograph or upload, which is sent to our AI service providers to extract the expense details for you (see Section 8).

Email Import. Monthly and Annual subscribers may use the Email Import feature to forward booking confirmation emails to a unique Sorom email address. When you use this feature, we collect the content of forwarded emails (including sender, subject, body, and attachments), which is processed by our inbound email handling and AI parsing providers to extract booking details such as hotel names, dates, guest names, and confirmation numbers into itinerary items. Parsed data is stored in your itinerary; the raw email content is retained for 30 days for troubleshooting, then deleted. You opt in by generating your unique forwarding address in Settings.

Maya AI Conversations. When you use the Maya AI Travel Advisor (Monthly and Annual subscribers), we collect your chat messages and queries, photos and images you share (analyzed via AI vision capabilities), itinerary and trip details referenced during conversations, your GPS location (used for local knowledge features such as transit routes, nearby services, weather, and emergency information), preference data derived from your confirmed and rejected suggestions, and trip memories that carry over between conversations. All Maya AI data is sent to third-party AI service providers for processing. Web search queries are sent to a third-party search service. See Section 8 ("AI Data Consent & Third-Party AI Disclosure") for full details on what data is shared, how consent works, and your rights.

2.2 Information Collected Automatically

Device Information. We automatically collect information about your device type and model, operating system version, unique device identifiers, and push notification tokens.

Usage Information. We process service interactions, feature usage, search queries, content viewed, crash logs and diagnostics. Optional website and web-app analytics is controlled through the site’s privacy settings; mobile optional product analytics is controlled through the Product Analytics setting. Essential security and operational processing may still occur.

Location Information. We collect location data when you tag content, which is optional and user-initiated, city-level location for matching purposes (approximate), real-time location when using the Live Connexions feature (opt-in, time-limited sessions), and viewport-based queries when browsing Interesting Places on the map (user-initiated). We do NOT continuously track your location.

Coordinates Used for Trip Planning. When you use our itinerary and trip planning features, the coordinates saved on your itinerary items and lodging are transmitted from our servers to our route-planning and weather providers. These requests are used to check whether the days we show you are realistic to travel between and to add local weather context to day plans. The requests carry coordinates and timing only, and the travel times we compute are cached on our servers in a form that contains no user identifiers (see Section 7).

2.3 Information from Third Parties

Authentication Providers. Sorom offers three ways to create an account: email and password, Google Sign-In, or Apple Sign-In. All three methods are optional.

Google Sign-In. When you sign in with Google, Sorom receives your name, email address, and profile photo to create your account. We do not access your Google contacts, calendar, Google Drive, or any other Google services. Your Google credentials are never stored by Sorom. You can revoke Sorom's access at any time via your Google Account security settings at myaccount.google.com.

Apple Sign-In. When you sign in with Apple, Sorom receives your name and email address (or Apple's private relay address if you choose "Hide My Email") to create your account. We do not access your iCloud data, contacts, calendar, or any other Apple services. Apple's private relay email forwarding is fully supported. You can manage or revoke Sorom's access via Settings > Apple ID > Password & Security > Apps Using Apple ID on your Apple device.

Sign-in providers share the information needed to authenticate you and create or access your Sorom account. Sorom and its authentication provider maintain session credentials so you can remain signed in. This is separate from permission to access other Google or Apple services.

Identity Verification. For Annual subscribers who opt into verification, we receive verification status from our identity verification provider indicating whether you are verified or not verified. We do not receive copies of identity documents.

Payment Processors. Subscriptions are processed by our payment infrastructure provider, and we receive subscription status only. We do not store credit card numbers.

3. How We Use Your Information

Providing Core Services. We use your information to create and manage your account, enable travel matching based on compatibility, facilitate communication between matched users, display and share your content, and manage itineraries and bookings.

Improving and Personalizing. We calculate compatibility scores, recommend potential travel matches, personalize your feed and content, analyze usage patterns to improve our features, and provide personalized AI-powered travel planning and recommendations through Sorom's AI features, based on your conversation history, your trips, and your preferences.

Safety and Security. We process emergency contact alerts, enable safety check-ins and panic button features, generate meetup verification PINs, detect and prevent fraud, spam, and abuse, and enforce our Terms of Use.

Communications. We send account-related notifications, deliver push notifications with your permission, send email updates about matches, messages, and activity, and provide customer support.

Legal and Compliance. We use your information to comply with legal obligations, respond to legal requests, and protect rights and safety.

Marketing Emails. If you opt in, we use your email address to send Sorom app news, updates and travel tips. We record your choice and the information needed to honor it, including when and how you opted in or unsubscribed. We do not treat account creation or acceptance of the Terms as marketing consent.

4. How We Share Your Information

4.1 With Other Users

Public Information. Your profile name, photo, and bio are visible based on your privacy settings. Journals marked as "public" are visible to all users, and Moments are visible to your followers. Approved Interesting Places submissions, community-contributed photos, and your attribution name are visible to all users.

Matched Users and Shared Itineraries. Profile information is shared through the discovery and matching features you use. Chat messages are visible to conversation participants, and shared itinerary information, trip moods and their notes are visible to the itinerary’s participants. If you enable a public read-only share link, anyone with the link can access the information included in that preview. Review the preview before sharing it and revoke the link when you no longer want it available.

Private Accounts. If your account is set to private, your content is only visible to approved followers.

4.2 With Service Providers

We share data with trusted third-party service providers who process personal data on our behalf. We enter into data processing agreements with each provider to ensure your data is handled securely and in accordance with applicable law.

Cloud infrastructure and hosting providers that store and process your account data, content, and application data on secure servers.

Media storage providers that securely host photos, videos, and other media you upload.

Location and mapping services support search, routing and map display in the mobile and web applications. When you use web place search, the browser sends your search text, selected language and request metadata to Google Places for suggestions and details. Selected place details are stored with an itinerary when you save them. This web search does not request or cache Google Places photos.

Travel data providers that supply flight schedules, tracking information, weather forecasts, currency exchange rates, and other travel-related data to power itinerary and trip planning features.

Payment and subscription processors that handle subscription billing, payment transactions, and related financial operations. We do not store your payment card details.

AI service providers that power our AI features, including our AI travel advisor (Maya AI), the AI Trip Builder with its in-trip daily planning, automated email parsing, and receipt scanning. These features require your explicit consent before your own free-text content and media are processed, and Section 8 explains how that consent works, including on group trips. Your data is not used to train third-party AI models.

Communication services that deliver email notifications, push notifications, SMS alerts, and other messages on our behalf.

Inbound email processing providers that receive and route forwarded booking confirmation emails for our Email Import feature.

Identity verification providers that confirm your identity for our premium verification feature, without sharing copies of identity documents with us.

Analytics providers help us understand use of the Services, in aggregate where possible. Website and web-app optional analytics choices are available through the site’s privacy settings; mobile optional product analytics is controlled in Settings → Privacy → Product Analytics. Essential security and operational processing may still occur.

4.3 For Legal Reasons

We may disclose information to comply with legal obligations, respond to valid legal requests, protect the safety of users or the public, prevent fraud or security issues, or in connection with a merger or acquisition.

4.4 With Your Consent

We may share information for other purposes with your explicit consent.

4.5 With Your Emergency Contacts

When you use our safety features, we send information to the emergency contacts you have chosen. A panic alert sends your current location, and a missed check-in alert sends your last known location. If you have enabled emergency recording, a completed recording is delivered to your emergency contacts by email as a secure download link, sent either to the contacts you selected for that alert or to all of your emergency contacts if you selected none. Download access expires 60 days after the recording session is created. Expired recordings are scheduled for automatic cleanup; temporary service failures may delay deletion, which is retried.

5. Your Rights & Choices

5.1 Access & Portability

You can view your profile and account information in the app at any time. You may also request a copy of your data through Settings → Account Management → Export Data, and download your data in a portable format.

5.2 Correction

You can update your profile information at any time through the app.

5.3 Deletion

You can delete individual content such as journals, moments, and comments. You can also delete your entire account through Settings → Account Management → Delete Account. Account deletion removes your data within 30 days, with anonymized backup retention for 12 months. Account deletion is subject to the exception for separately retained administrative points-adjustment audit records described in Section 7 of the Privacy Policy.

5.4 Privacy Controls

Use the available account and content-visibility controls to choose an audience, and review location sharing separately. Blocking restricts access and contact through the blocked account; it cannot remove external copies or prevent another account. Optional web analytics is controlled through site privacy settings, and mobile optional product analytics through Settings → Privacy → Product Analytics. Live ConneXions sessions are opt-in and time-limited. AI data consent can be managed in the app’s privacy settings; see Section 8.

5.5 Communication Preferences

You can manage notifications in Settings → Notifications, where you can toggle push notifications and email notifications by type, and mute specific conversations.

Marketing emails have a separate optional setting. You can unsubscribe at any time using the link in a marketing email or turn off marketing emails in account settings. This does not change necessary account, security, safety or transaction messages.

5.6 GDPR Rights (EEA/UK Users)

If you are in the European Economic Area or UK, you have the right to access and request a copy of your data, the right to rectification to correct inaccurate data, the right to erasure to request deletion of your data, the right to restrict processing to limit how we use your data, the right to data portability to receive your data in a portable format, the right to object to certain processing, and the right to withdraw consent at any time. To exercise these rights, contact privacy@sorom.co.

5.7 CCPA Rights (California Users)

California residents have the right to know what personal information we collect, request deletion of personal information, opt-out of the sale of personal information (we do not sell your data), and non-discrimination for exercising privacy rights. To exercise these rights, contact privacy@sorom.co.

6. Data Security

We use access controls to restrict private data and permit sharing through the features you choose, along with security measures such as encrypted transport and authentication controls. No system is completely secure. Use a strong password and protect your account credentials.

Chat Messages & Maya AI Conversations. All chat messages — both user-to-user and Maya AI conversations — are encrypted in transit. Database-level access controls ensure that only conversation participants can access their own messages. Maya AI conversations are transmitted to our AI service providers over encrypted connections only after you have granted explicit AI data consent (see Section 8). We recommend not sharing sensitive personal information (such as passport numbers, financial details, or health information) in any chat or Maya AI conversation.

7. Data Retention

Separate administrative points-adjustment audit records are retained as a record of adjustment requests and decisions. They can include identity snapshots, request reasons and supporting information. Account deletion and points-balance expiry do not erase these records, and currently no automatic purge is active for them. This exception does not limit your existing access, correction or deletion-request rights; contact privacy@sorom.co to exercise those rights.

8. AI Data Consent & Third-Party AI Disclosure

Sorom's AI features, including the Maya AI Travel Advisor, the AI Trip Builder with its in-trip daily planning, AI email parsing, and AI receipt scanning, are powered by third-party artificial intelligence and web search services. In compliance with Apple App Store Guidelines 5.1.1(i) and 5.1.2(i), we provide the following disclosure about how your data is handled when you use these features.

8.1 Your Consent Controls AI Processing

Sorom's AI features require your explicit opt-in consent before your personal free-text content and media are sent to our AI service providers. When you first access one of these features, a consent dialog explains what data will be shared, who receives it, and how it is protected. You can grant or withdraw this consent at any time in Settings. Without your consent, these features are disabled for you, and your own free-text content and media (your messages, notes, photos, preferences, and other free text you write) are never transmitted to AI service providers.

On group trips, a trip organizer (the trip's owner or a trip admin) who has granted their own consent can use AI planning features for the whole trip. When that happens, limited non-content signals about the group are included in the organizer's request under the organizer's consent: the number of mood submissions included in the request, and any mood selections participants have chosen from Sorom's fixed list. Separately, when a trip is first generated, the request carries the group size under the consent of whoever asked for it. Your free-text contributions (such as a note attached to your mood selection) are included only if you have granted AI data processing consent yourself. If you have not, your notes are withheld automatically.

8.2 Data Shared with AI Providers

When Sorom's AI features are used with consent granted, the following data may be sent to our AI service providers for processing:

We anonymize personal identifiers before transmitting data to our AI service providers where technically feasible. However, conversation content (such as travel destinations, preferences, photos, and planning details) is shared in order to provide the service. Your data is not used to train third-party AI models.

8.3 How AI Providers Process Your Data

Our AI service providers process your data to generate responses in accordance with their respective usage policies. All data is transmitted over encrypted connections (HTTPS/TLS). We recommend not sharing sensitive personal information (such as passport numbers, financial details, or health information) in Maya AI conversations, or in any other free text our AI features process, including travel mood notes.

8.4 Managing Your Consent

You can revoke your AI data consent at any time through Settings → Privacy in the app. Revoking consent immediately disables Sorom's AI features for you and stops your own free-text content and media from being transmitted to AI service providers. If you stay on a group trip whose organizer has granted their own consent, the limited non-content signals described in Section 8.1 (the count of mood submissions in the request, and any mood selection you have chosen from Sorom's fixed list) may still be included in that organizer's requests, while your free-text notes are withheld automatically. Previously sent data is subject to our providers' respective data retention policies. You can re-enable consent at any time to resume using these features.

8.5 AI-Generated Content Disclaimer

Sorom's AI features provide recommendations and travel planning assistance powered by artificial intelligence. AI-generated content may contain errors, inaccuracies, or outdated information. AI suggestions regarding places, prices, opening hours, travel requirements, and other details should be independently verified before making travel decisions or bookings. Sorom does not guarantee the accuracy, completeness, or reliability of any AI-generated content. Users are responsible for verifying information and exercising their own judgment when acting on AI recommendations.

9. Children's Privacy

Sorom is not intended for users under 18 years of age. We do not knowingly collect information from children. If we learn we have collected data from a child under 18, we will delete it promptly.

10. International Data Transfers

Your data may be processed in countries outside your residence, including the United States. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses where required.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy with a new "Last Updated" date, sending an email notification for significant changes, and providing an in-app notification. Your continued use of Sorom after changes constitutes acceptance.

12. Contact Us

For privacy questions, concerns, or to exercise your rights, please contact us:

Email: privacy@sorom.co
Data Protection Officer (EEA/UK): dpo@sorom.co