Donut Industries
About
  • Presometer
  • Sous
Contact
← Sous

Sous

Privacy Policy

Effective Date: June 21, 2026

Donut Industries, LLC ("Donut Industries," "we," "us," or "our") operates Sous, an iOS cooking assistant application (the "App"), and the donutindustries.com website (the "Site"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding it.

By using Sous or the Site, you agree to the collection and use of information as described in this policy.

1. Information We Collect

Account information. When you sign in with your Apple ID, we receive a unique account identifier, your name (if you choose to share it), and an email address (which may be a private Apple relay address). This creates and maintains your Sous account.

Recipe and conversation content. Sous is built around a conversational recipe canvas. We process the recipes you create, import, or edit, and your chat messages with the AI assistant.

Photos. Sous uses photos in two distinct ways:

  • Recipe import: photos of a recipe card, cookbook page, or screenshot are processed entirely on-device using Apple's Vision framework (OCR). These photos are never uploaded to our servers or to OpenAI.
  • Visual cooking questions: photos you submit to ask a visual question (e.g., "does this look done?") are sent to OpenAI to generate a response.

Preferences and memories. You may optionally tell Sous about dietary restrictions, kitchen equipment, default serving size, and other cooking preferences. Sous may also propose to remember things you mention in conversation ("memories"), which you can view, edit, or delete at any time in Settings.

Usage and diagnostic data. We collect basic usage data — such as the number of recipes created, crash reports, and performance signals — to keep the app reliable and to enforce subscription usage limits.

Subscription and payment information. Subscriptions are billed and processed by Apple through the App Store. We do not receive or store your payment card details. We receive subscription status (active, trial, lapsed) from Apple to manage your account access.

Voice data. If you use voice mode, your spoken audio is processed to convert it to text and to generate spoken responses, as described under Third Parties below.

2. How We Use Information

We use this information to:

  • Provide and operate the App's core functionality (recipe generation, editing, conversation)
  • Personalize recipes based on your stated preferences and memories
  • Authenticate your account and sync your data across devices
  • Process subscription billing and enforce usage limits
  • Diagnose and fix technical issues, and keep the service secure
  • Respond to support requests

We do not sell your personal information.

3. Model Training

We do not use your recipes, chat messages, or photos to train AI models, and we do not sell or license this content to third parties for that purpose.

Sous sends requests to OpenAI through OpenAI's API platform (not the consumer ChatGPT product). Under OpenAI's API data usage policy, content submitted through the API is not used to train or improve OpenAI's models by default, and is retained for a limited period — generally up to 30 days — for abuse and safety monitoring before deletion, unless OpenAI is legally required to retain it longer. Donut Industries has not opted in to any OpenAI program that would allow your content to be used for model improvement.

4. Third Parties We Share Data With

We work with a small number of service providers to operate Sous:

  • OpenAI — processes your chat messages and recipe requests, and (for visual cooking questions) photos, to generate AI responses. Voice mode audio is processed by OpenAI's Realtime API for speech-to-text and text-to-speech.
  • Apple — provides Sign in with Apple authentication, processes subscription payments via the App Store, and delivers local notifications (e.g., for cooking timers).
  • Supabase — hosts our account, preferences, and memory database.
  • Railway — hosts our backend API server.

These providers process information on our behalf to provide the service. You can find more detail on their own data practices in their respective privacy policies.

"Bring your own key" (BYOK) users. If you use Sous with your own OpenAI API key, requests are sent directly from your device to OpenAI using that key. Donut Industries does not see, store, or proxy this traffic. Your key is stored in your device's Keychain and never transmitted to our servers.

5. Data Storage and Security

Account data, preferences, and memories are stored on Supabase-managed infrastructure. We use industry-standard measures (encrypted transport, access-controlled databases) to protect your information, but no system is completely secure and we can't guarantee absolute security.

On your device, in-progress recipe sessions, chat history, and (for BYOK users) your OpenAI API key are stored using Apple's secure on-device storage (Keychain and local file storage).

6. Data Retention

  • Account data: retained for as long as your account is active. If you delete your account, your record is removed from our active systems promptly after we process the request; residual copies in backups are removed as part of our normal backup rotation.
  • AI request logs: OpenAI retains API request content for a limited period — generally up to 30 days — for abuse and safety monitoring, then deletes it, unless legally required to retain it longer.
  • Crash and performance diagnostics: retained for a limited period sufficient to diagnose issues, then deleted.
  • Support correspondence: retained for as long as reasonably necessary to resolve your inquiry and for our records, consistent with applicable law.
  • Abuse-prevention identifier: to prevent free-trial abuse through repeated account deletion and re-registration, we retain a one-way cryptographic hash derived from your Apple account identifier after account deletion. This hash cannot be reversed to identify you or used to access your deleted account data — it is used solely to recognize a returning device/account for trial eligibility purposes.
  • Subscription and billing records: Apple transaction identifiers and receipt data associated with your subscription are retained after account deletion for accounting, tax, and payment-dispute purposes, even though other account data is deleted or anonymized.

7. Legal Basis for Processing (EU/UK Users)

Where the GDPR or UK GDPR applies, we process your personal information on the following legal bases:

  • Performance of a contract — to provide the core functionality of Sous, including your account, recipes, subscription, and optional features like memories and preferences that you choose to use.
  • Legitimate interests — to maintain, secure, and improve the App, where these interests are not overridden by your data protection rights.
  • Legal obligation — where we are required to retain or disclose information to comply with applicable law.

8. Your Rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing.

  • EU / UK residents: rights under the GDPR / UK GDPR, including the right to lodge a complaint with your local data protection authority.
  • California residents: rights under the CCPA/CPRA, including the right to know what personal information we collect and to request deletion.

To exercise these rights, contact us at hello@donutindustries.com. Most of this can also be done directly in the App: Settings → Account → Delete Account; Settings → Memories / Preferences. If we need to verify your identity before fulfilling a request, we may ask for additional information.

9. Children's Privacy

Sous is not directed at children under 13 (or the relevant minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

10. International Data Transfers

Our service providers (OpenAI, Apple, Supabase, Railway) may process and store information in the United States or other countries outside your own. Where required, these transfers are made under appropriate safeguards, such as standard contractual clauses or other legal mechanisms recognized under applicable data protection law.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date. Continued use of Sous after a change constitutes acceptance of the update.

12. Contact Us

Donut Industries, LLC
hello@donutindustries.com

Terms of Service Back to Sous
© 2026 Donut Industries LLC Contact