Still being completed. The marked gaps below are waiting on details that have to be right rather than quick — who the contracting party is, and where. Until they are filled this document is a draft and should not be relied on. Anything urgent: support@torrere.com.
Torrere — Privacy Policy
Effective date: 11 September 2026
This policy explains what Submarius LLC (“Torrere”, “we”, “us”) collects when you use the Torrere apps and the Torrere website, why, who else sees it, how long we keep it, and what you can make us do about it.
It is written to be read. Where something is a genuine limitation rather than a reassurance, it says so.
1. The short version
- We collect the account you create, the things you write to the assistant, the recipes that come out of it, and enough billing and usage data to charge you correctly and stop the service being abused.
- To answer you, we send your messages, your recipe and your cook profile to Anthropic, PBC, an AI provider in the United States. Section 5 is the important one.
- We do not sell your data, we do not share it for advertising, and there is no analytics or tracking SDK in the apps or on this site.
- You can get a copy of your data, correct it, or have it deleted. Section 11.
2. What we collect
Your account. Your email address, a hash of your password (never the password), and — if you use one — the public half of a passkey. Passkeys are created and held by your device; the private key never reaches us.
What you write. Your messages to the assistant, and the recipes they produce. A recipe is stored as a versioned document, so we hold its history as well as its current state — that is what makes “undo” work.
Your cook profile. If you record dietary preferences, equipment, or allergies and intolerances, we store them and send them to the assistant so it can take them into account. Allergy and intolerance data is health data, and we treat it as the more sensitive category the law makes it: we ask for your explicit consent on the screen where you enter it, we record that consent, and withdrawing it removes the data and switches the feature off.
Photos and pasted text. If you send a photo of a recipe — a cookbook page, a handwritten card — or paste text for the assistant to read, that content is processed to extract the recipe and is stored with the resulting recipe. Photos are sent to the AI provider inline with the request and are never uploaded to a separate file store there, so there is no second copy to forget about.
Billing. Which plan you are on, when it renews, and whether a payment succeeded. We never see your card number. Payments on the web are handled by Stripe; on iPhone and iPad by Apple; on Android by Google. Each of them tells us that a subscription exists, not how it was paid for.
Usage and cost. Every request to the AI model writes a metered row: which model, how many tokens, what it cost, how long it took, and a one-way hash of the prompt. The row holds no message content — that is enforced in code, not by policy. We use these rows to bill correctly, to hold the free allowance to its limit, and to notice abuse.
Technical data. Your IP address and the time of a request, in web-server logs and in the security records behind sign-in throttling and session-reuse detection. Native apps send a device attestation from Apple or Google, which tells us the device is genuine and how much free use it has had. That check is deliberately kept in a separate database from everything above, because combining a device identifier with health data is something Google’s own terms forbid and we would rather not be able to do it at all.
What we do not collect. No advertising identifiers. No location. No contacts. No analytics SDK, no session recording, no third-party tracker, no cookie banner, because there is nothing to consent to: the only cookie we set is the one that keeps you signed in.
3. Why we are allowed to hold it
Where the GDPR or UK GDPR applies:
| What | Basis |
|---|---|
| Account, recipes, messages, cook profile (other than allergies) | Performing our contract with you |
| Allergies and intolerances | Your explicit consent (Art. 9(2)(a)) — withdrawable at any time |
| Sending your content to the AI provider | Performing our contract, plus the separate in-app consent we ask for before your first message |
| Billing records | Contract, and our legal obligation to keep tax records |
| Security, abuse prevention, spend limits | Our legitimate interest in not being defrauded, balanced against your rights |
| Service emails (verification, password reset, receipts) | Contract |
We do not send marketing email. If that ever changes we will ask first.
4. Cookies
One cookie, set when you sign in on the web, holding your session. It is
HttpOnly and Secure, and it exists so you do not have to sign in on every
page. Clearing it signs you out. There are no advertising, analytics or
cross-site cookies to refuse.
5. AI processing by Anthropic, PBC
This is the part most worth reading.
To answer you, we send your content to Anthropic, PBC, in the United States, which processes it on our behalf under a contract and returns the response. What we send:
- your chat messages;
- the recipe document you are working on;
- photos you send for the assistant to read;
- your cook profile, including any allergies and dietary restrictions you have entered.
We ask you to agree to this on a screen in the app, before your first message. If you do not agree, the assistant cannot run — there is no version of this product that works without it.
Anthropic, PBC acts as our processor: it uses what we send to produce the response and does not use it to train its models.
One limit we cannot design away, stated plainly. If Anthropic, PBC’s safety classifiers flag a session, Anthropic, PBC may retain that session for up to 2 years, and the classification scores for up to 7 years, even under the zero-retention arrangement we otherwise operate under. That retention is outside our control, it survives your deleting your account with us, and it caps what any promise of deletion can honestly mean. It is disclosed here, and again on the receipt we give you when you delete.
Web search. When it helps, the assistant searches the web through Anthropic, PBC’s search service. The search query — which may contain what you asked — goes to that service and to its search provider. The pages it then reads are retrieved by our own servers, not by your browser and not from your address.
6. Who else sees it
Everyone we use, and what they get. They are processors: they act on our instructions and may not use your data for their own purposes.
| Who | What they get | Where |
|---|---|---|
| Anthropic, PBC | Messages, recipe, photos, cook profile — see section 5 | United States |
| Amazon Web Services | Hosting. Everything lives on servers we run in AWS | United States (Ohio) |
| Amazon SES | Your email address and the text of service emails | United States |
| Stripe | Web payments. Your card details go to Stripe, not to us | United States / Ireland |
| RevenueCat | Mobile purchase receipts and your Torrere account identifier | United States |
| Apple, Google | Purchases made through their stores, and device attestation | Per their own policies |
We disclose data to anyone else only where the law requires it, or where it is necessary to establish or defend a legal claim. If we are ever compelled to hand over your data, we will tell you unless we are legally prevented from doing so.
International transfers. We operate from the United States. If you are in the UK, the EEA or Switzerland, your data is transferred there under the European Commission’s Standard Contractual Clauses (and the UK Addendum where it applies), which each processor above has signed.
7. How long we keep it
Retention is set when a record is written, not decided later.
| What | Kept for |
|---|---|
| Your account, recipes and cook profile | Until you delete them, or the account |
| Chat messages, paid accounts | 400 days from when they were written |
| Chat messages, free and provisional accounts | 90 days |
| Superseded recipe versions | Pruned to the most recent 30 per recipe after 180 days |
| Usage and cost rows (no content) | 400 days |
| Safety and abuse records | 400 days — they are the evidence behind a suspension |
| Proof that you consented, reduced to the fact and its date | 6 years after deletion |
| Backups | 35 days |
Backups are the honest caveat. Restoring a backup can bring back data from up to 35 days earlier, including data you deleted. We keep a permanent record of every deletion, and replaying it is the first step after any restore, so a restore cannot quietly resurrect a deleted account.
8. Security
Everything is encrypted in transit. The database is not reachable from the internet at all — it listens only on the server’s own loopback interface. Passwords are hashed with a memory-hard function; we could not tell you your password if we wanted to. The AI provider’s key is not stored on the server’s disk; it is fetched at start-up from a secrets store. Message content is kept out of every log by a build-time check that fails the build rather than trusting anyone to remember.
None of that makes us unbreakable, and we are not going to claim it does. If your data is ever exposed in a way that puts you at risk, we will tell you and the relevant regulator within the time the law allows.
9. Children
Torrere is not for children under 13, and we do not knowingly collect anything from one. If you believe a child has given us their data, write to support@torrere.com and we will delete it.
10. Deleting your account
You can delete your account and everything in it:
- In the app — Settings → Account → Delete account.
- On the web — https://torrere.com/delete, without going back into the app.
Deletion removes your profile, your allergy and dietary data, your recipes, your chat history, and revokes every link you have shared. There is a 24-hour window in which you can change your mind; after that it is permanent and we cannot recover it. When it completes we give you a receipt saying what was removed and what was kept.
What we keep afterwards, and why. The fact that you consented, reduced to the date and the purpose, for six years, because it is the proof we were allowed to hold your data at all. Billing records the tax authorities require. Aggregate cost totals with your identity stripped out and replaced by a one-way hash, and — for free-tier devices — a hashed device identifier and a count of sessions used, so that deleting an account is not a way to reset a free allowance. That last one is fraud prevention under Art. 17(3), and it is named on your receipt.
And the limit in section 5: a session flagged by the AI provider’s classifiers is outside the reach of this deletion.
11. Your rights
Wherever you are, you can ask us to:
- give you a copy of your data, in a portable format;
- correct anything wrong;
- delete it (section 10);
- stop or limit a particular use;
- withdraw a consent — for the allergy feature, or for AI processing — without affecting what was lawful before you withdrew it.
Write to support@torrere.com from the address on your account. We answer within 30 days and we do not charge for it. If you are in the UK or the EEA you can complain to your national data protection authority; we would rather you came to us first.
If you are in California, we do not sell or share personal information as CCPA defines those words, we have not in the past 12 months, and we will not discriminate against you for exercising any right above.
12. Changes
We may change this policy. If a change is material we will tell you before it takes effect — by email, or in the app — and the effective date at the top will change. Continuing to use Torrere after that means the new version applies.
13. Contact
Submarius LLC NOTICE_ADDRESS PHONE_NUMBER support@torrere.com