Sodal is built so that we cannot read your data. Not "we promise not to" — we hold no key that opens it. This page explains what that means precisely, and is honest about the things we can see.

The short version

  • Your messages, locations, photos, voice notes, circle names and member names are encrypted on your phone before they are uploaded. Our servers store unreadable bytes.
  • There is no account to create. No email, no phone number, no password — nothing that identifies you.
  • There are no ads, no trackers, no analytics SDKs, and nothing is sold or shared for marketing.
  • Content is deleted from our servers after 30 days.
  • This website sets no cookies.

What we cannot see

Everything you and your circle actually create is end-to-end encrypted with keys generated on your device and never sent to us:

  • The text of every message, and any reaction, edit or reply.
  • Your location — every coordinate, every place you have saved, and every arrival or departure.
  • Photos, videos, voice notes and files, including everything in the Vault.
  • Your display name, avatar and profile within a circle.
  • The name, emoji and colour of a circle, and the places saved inside it.
  • SOS alerts and their contents.

The encryption is standard and public — XChaCha20-Poly1305, Ed25519, X25519, HKDF-SHA256 and Argon2id, all via libsodium. We invented none of it, which is the point.

What we can see

A server that routes messages has to know where to route them. We would rather state this plainly than let "end-to-end encrypted" imply more than it does. Our servers hold:

  • Device records — a device identifier, whether it is iOS or Android, the OS version and the app version. Used to deliver notifications and to tell you when an update is required.
  • Push notification tokens issued by Apple, so a notification can reach your phone. The notification's contents are encrypted; your phone decrypts it locally before showing it.
  • Membership structure — that a circle exists, how many members it has, and which member sent a given encrypted item at what time. Within one circle, this means we could work out who talks to whom. We chose this deliberately so that muting a person or a category of update can be handled before a notification is ever sent to your phone.
  • A category label per item — whether an encrypted item is a message, a location update, a call or an SOS. Never its contents.
  • Whether you are currently connected, so we know whether to deliver directly or fall back to a push notification.
  • Your notification preferences for each circle — which people or categories you have muted.

Each circle you join gets its own separate identity and its own keys. There is no shared identifier linking your membership in one circle to your membership in another, so we cannot assemble a single profile of you across circles.

There is no account

Sodal never asks for an email address, a phone number or a password, because it has no use for one. When you first open the app it generates a set of encryption keys on your phone. Those keys are your identity. Every request the app makes is signed with them, which is how our servers know it is really you — the same way a signature proves authorship without revealing who you are.

So there is no sign-up form, no confirmation email, no password to be stolen, and no address for us to lose, sell or be compelled to hand over. We hold nothing that identifies you as a person.

The trade is real and worth stating plainly: if you lose your phone and your keys, we cannot let you back in. We have nothing to check you against. That is why Sodal shows you a 24-word recovery phrase when you set up a circle, and why your keys are stored in your iCloud Keychain by default so a new iPhone picks them up automatically.

Location

Sodal requests location access so you can share where you are with the circles you choose. Location is encrypted on your phone before upload; we store coordinates we cannot read.

If you allow background location, Sodal keeps sharing while the app is closed — that is what makes a family locator useful, and iOS shows you a periodic reminder that it is happening. You control which circles receive your location, how precisely, and you can stop sharing at any time from inside the app. Turning it off in iOS Settings works too, and Sodal will simply have nothing to send.

Maps

The map itself comes from us. Sodal serves its own map data from its own storage, so no map company receives a request every time you pan, zoom or open the Map tab. That matters because those requests would otherwise describe, quite precisely, where you and your family look — which is close to describing where you are.

The underlying map is OpenStreetMap data, prepared by Protomaps. We host a copy; we do not call their servers from your phone.

Calls

Voice and video calls are encrypted in transit between participants. Where a direct connection between two phones is not possible — common on mobile networks — the encrypted stream is relayed through a server we run. That relay passes bytes through; it does not record them.

Setting up a call also needs each phone to discover its own public address. That step runs on our server too, so no outside party is told that a call is beginning.

Diagnostics

Sodal contains no analytics SDK, no advertising SDK, and no crash reporter that uploads your data. The app's privacy manifest declares no collected data types and no tracking.

The one exception is deliberately narrow. When the app can update itself without a full App Store release, it reports whether the update launched successfully. That report contains a random identifier for the installation, which update it was, and one of four reasons it failed. No message, no stack trace, nothing tied to you or your device. It exists so a bad update can be pulled back automatically.

How long we keep things

  • Encrypted content — messages, locations and media are deleted from our servers 30 days after they are sent. Your phone keeps its own copy for as long as you want it; deleting the app deletes that copy.
  • Account records — device and membership records last while the account exists.
  • Deleting a circle or leaving one removes the corresponding records. Because content is encrypted under that circle's keys, anything left in transit becomes permanently unreadable once those keys are gone.

Where your data is held

Our servers and our encrypted storage are both in Frankfurt, Germany, run on OVHcloud. Your encrypted content does not leave the EU on our side. What your own phone does — an iCloud Keychain backup of your keys, for instance — follows Apple's regions, not ours.

Who else touches your data

We use as few outside services as we can, and none of them can read your content:

  • OVHcloud — hosts our servers and stores the encrypted media, in Frankfurt. Sees encrypted bytes and network metadata such as IP addresses.
  • Apple — delivers push notifications and runs TestFlight and the App Store. Notification payloads are encrypted.
  • Cloudflare — runs the DNS for sodal.app and serves this website. It is not in the path of the app's traffic and holds none of your media. Looking up our address passes through Cloudflare's DNS, as it does for most of the internet.

That is the whole list.

We do not sell your data, and we do not share it for advertising. There is no version of Sodal where that changes.

Children

Sodal is designed for families, and a child using it does so within a circle that a parent or guardian set up. Sodal is not intended for children to sign up independently. The same encryption applies to everyone: a child's location and messages are readable only by their circle.

Your choices

  • Delete everything — "Erase all data" inside the app destroys the keys held on your device. Without them, any copy of your content that still exists on our servers is permanently unreadable by anyone, including us.
  • Leave a circle at any time; you stop receiving and sending immediately.
  • Revoke a device you no longer use from inside the app.
  • Ask us what records we hold for you, or ask us to delete them, by writing to the address below. Be aware that we have no way to connect an email you write from to anything stored on our servers — that is the point of the design — so you will need to tell us which circle you mean and prove you are in it. You are entitled to ask, and we will answer.

This website

sodal.app sets no cookies and runs no analytics. If you join the waiting list, we store the email address you give us for that purpose only, and stop when you ask us to.

Changes

If this policy changes in a way that affects what we collect or how we use it, we will say so in the app rather than quietly editing this page. The date at the top always reflects the current version.

Contact

Questions about privacy, or a request about your data: [email protected].