Skip to main content
SORAIEnter

Privacy

Last updated July 2026

SORAI (operated by MoClarus, the “Operator”, “we”) helps you discover, plan and book experiences in a city. This policy explains what we collect, why, and the choices you have. The short version: the model that learns your taste runs on your device, and we send the bare minimum to our servers to make features work.

Who we are (data controller)

The controller responsible for your personal data is MoClarus — a Swedish sole trader (enskild firma), org.nr 19790613-6473, approved for F-tax (godkänd för F-skatt), at Gnejsvägen 6, 746 41 Bålsta, Sweden. Our governing jurisdiction is Sweden, and our lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). For any privacy question or to exercise your rights, contact info@moclarus.com or call +46 76 412 75 71.

Personalisation lives on your device

Your taste and behaviour signals — what you search, where you look on the map, what you tap, save, plan, and how long you dwell — are stored locally in your browser (vialocalStorage), not on our servers and not tied to your name. Clearing your browser storage makes SORAI forget, completely. Data kept on your device includes things like your saved places, your plan/itinerary, your theme and view preferences, recent searches, and a local profile handle for venue chat. If you turn on the optional cross-device sync, your profile is end-to-end encrypted on your device before it leaves — our server stores only opaque ciphertext it cannot read.

What reaches our servers

  • Account. Sign-in is passwordless: we store your email address, your plan/subscription state, and session records. We never store a password.
  • Search & concierge requests. When you search or ask the AI concierge, your query and minimal context are processed to return ranked results. Your typed text is sent to an external AI model provider to generate the answer (see “AI processing” below). It is not used to build an advertising profile.
  • Reviews, chat & check-ins. If you post a review, send a message in a venue room, react, or check in, that content is stored so others can see it. Reviews are shown under a one-way pseudonym, never your email. Don't post anything you wouldn't want public.
  • Anonymous product analytics. Aggregate, non-identifying usage events (e.g. “a detail page opened”, “a ticket link was followed”) help us improve the product. They are anonymous and first-party — no ad profile, no cross-site tracking, and never your on-device taste model. Because they're privacy-light they run under our legitimate interest and are on by default; you can opt out any time on the Cookies page.
  • Purchases. If you buy a ticket or subscribe, payment is handled by our processor (Stripe) — we never see or store full card details. We keep an order record to deliver what you bought and to meet accounting obligations.
  • Technical data. Like any web service, our infrastructure briefly processes your IP address to route requests and to rate-limit abuse. We do not keep it in a durable log tied to you.

Why we're allowed to (lawful bases)

Under the GDPR we rely on these bases:

  • Contract (Art. 6(1)(b)) — to provide your account, run search/concierge, and deliver tickets and subscriptions you buy.
  • Legitimate interests (Art. 6(1)(f)) — to keep the service secure, prevent fraud/abuse, moderate user content, maintain reliability, and run anonymous, privacy-light product analytics. We balance these against your rights, and you can object to (opt out of) the analytics at any time on the Cookies page.
  • Legal obligation (Art. 6(1)(c)) — to retain billing/transaction records for the period tax and accounting law requires.

AI processing

The concierge, venue “reads”, and content moderation send the relevant text (your query or the content being checked) to a third-party AI model provider to generate a response. Please avoid typing sensitive personal information into free-text fields. We route only what the feature needs, and outputs are guarded against fabricating verifiable specifics. Which provider is used depends on the deployment's configuration (see sub-processors below).

Location

If you grant location access, your approximate position is used in the moment to show what's near you and is not stored on our servers. You can revoke it anytime in your browser or OS settings.

Sub-processors we rely on

We share personal data with the following processors only to perform their function. The specific provider set can vary by deployment; where a provider processes data outside the EEA/UK, the transfer relies on the safeguards described under “International transfers” below.

  • Stripe — payments, checkout and subscription billing.
  • Resend — sending your passwordless sign-in emails.
  • Upstash — the primary data store (accounts, sessions, orders, reviews, chat, the encrypted taste mirror).
  • Cloudflare — hosting, edge compute, object/asset storage and caching.
  • AI model providers — Google (Gemini), OpenAI-compatible providers, Anthropic and/or xAI, for the concierge, venue reads and moderation.
  • Map & weather providers — CARTO / OpenFreeMap (map tiles) and Open-Meteo (weather); your browser contacts these directly, so they receive your IP address.
  • Event & ticket partners — Ticketmaster, Billetto, Tickster and other listing/ticketing sources; buying a ticket hands you off to the seller's own site.

See Licenses & attributions for data-source credits and Cookies for on-device storage details.

International transfers

Some of these providers are based outside the EEA/UK (for example, in the United States). Where your data is transferred internationally, we rely on the safeguards in each provider's data-processing terms — the EU–US Data Privacy Framework where the provider is certified, and otherwise the European Commission's Standard Contractual Clauses (with the UK Addendum for UK transfers). You can request details of the safeguard applied to a specific provider at info@moclarus.com.

How long we keep it

  • Account (email, plan state) — kept while your account is active; sign-in tokens expire in 15 minutes and sessions within ~30 days.
  • Encrypted taste mirror (if you enable sync) — kept while active; it is opaque ciphertext we cannot read.
  • Reviews and order records — retained up to ~12 months (orders longer where accounting law requires).
  • Venue chat — ~24 hours; presence is ephemeral (minutes).
  • When you delete your account we also record a short-lived, hashed deletion marker (~90 days) so a delayed payment webhook can't recreate the account.

Your rights

Depending on where you live (including the EU/EEA under the GDPR), you may have the right to access, correct, export or delete your data, to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with your supervisory authority. Most on-device data you can clear yourself in your browser. For server-side data, signed-in users can download a copy of the data we hold or permanently delete their account and its associated data from the account page; you can also contact us at info@moclarus.com for help. When you delete your account we remove your account record, organiser submissions and the encrypted taste mirror, and revoke your sessions; billing records held by our payment processor are retained where required to meet legal (tax/accounting) obligations.

Children

SORAI is not directed to children under 16, and we don't knowingly collect their data.

Changes

We'll update this page when our practices change and revise the date above. Questions? Reach us at info@moclarus.com.

This document is provided in good faith and describes how SORAI actually works. It is not legal advice; the operator should confirm entity, registration and governing-law details with qualified counsel before launch.

Privacy — SORAI — SORAI