Still being completed. The marked gaps below are waiting on details that have to be right rather than quick — who the contracting party is, and where. Until they are filled this document is a draft and should not be relied on. Anything urgent: support@torrere.com.

Torrere — Privacy Policy

Effective date: 11 September 2026

This policy explains what Submarius LLC (“Torrere”, “we”, “us”) collects when you use the Torrere apps and the Torrere website, why, who else sees it, how long we keep it, and what you can make us do about it.

It is written to be read. Where something is a genuine limitation rather than a reassurance, it says so.

1. The short version

2. What we collect

Your account. Your email address, a hash of your password (never the password), and — if you use one — the public half of a passkey. Passkeys are created and held by your device; the private key never reaches us.

What you write. Your messages to the assistant, and the recipes they produce. A recipe is stored as a versioned document, so we hold its history as well as its current state — that is what makes “undo” work.

Your cook profile. If you record dietary preferences, equipment, or allergies and intolerances, we store them and send them to the assistant so it can take them into account. Allergy and intolerance data is health data, and we treat it as the more sensitive category the law makes it: we ask for your explicit consent on the screen where you enter it, we record that consent, and withdrawing it removes the data and switches the feature off.

Photos and pasted text. If you send a photo of a recipe — a cookbook page, a handwritten card — or paste text for the assistant to read, that content is processed to extract the recipe and is stored with the resulting recipe. Photos are sent to the AI provider inline with the request and are never uploaded to a separate file store there, so there is no second copy to forget about.

Billing. Which plan you are on, when it renews, and whether a payment succeeded. We never see your card number. Payments on the web are handled by Stripe; on iPhone and iPad by Apple; on Android by Google. Each of them tells us that a subscription exists, not how it was paid for.

Usage and cost. Every request to the AI model writes a metered row: which model, how many tokens, what it cost, how long it took, and a one-way hash of the prompt. The row holds no message content — that is enforced in code, not by policy. We use these rows to bill correctly, to hold the free allowance to its limit, and to notice abuse.

Technical data. Your IP address and the time of a request, in web-server logs and in the security records behind sign-in throttling and session-reuse detection. Native apps send a device attestation from Apple or Google, which tells us the device is genuine and how much free use it has had. That check is deliberately kept in a separate database from everything above, because combining a device identifier with health data is something Google’s own terms forbid and we would rather not be able to do it at all.

What we do not collect. No advertising identifiers. No location. No contacts. No analytics SDK, no session recording, no third-party tracker, no cookie banner, because there is nothing to consent to: the only cookie we set is the one that keeps you signed in.

3. Why we are allowed to hold it

Where the GDPR or UK GDPR applies:

What Basis
Account, recipes, messages, cook profile (other than allergies) Performing our contract with you
Allergies and intolerances Your explicit consent (Art. 9(2)(a)) — withdrawable at any time
Sending your content to the AI provider Performing our contract, plus the separate in-app consent we ask for before your first message
Billing records Contract, and our legal obligation to keep tax records
Security, abuse prevention, spend limits Our legitimate interest in not being defrauded, balanced against your rights
Service emails (verification, password reset, receipts) Contract

We do not send marketing email. If that ever changes we will ask first.

4. Cookies

One cookie, set when you sign in on the web, holding your session. It is HttpOnly and Secure, and it exists so you do not have to sign in on every page. Clearing it signs you out. There are no advertising, analytics or cross-site cookies to refuse.

5. AI processing by Anthropic, PBC

This is the part most worth reading.

To answer you, we send your content to Anthropic, PBC, in the United States, which processes it on our behalf under a contract and returns the response. What we send:

We ask you to agree to this on a screen in the app, before your first message. If you do not agree, the assistant cannot run — there is no version of this product that works without it.

Anthropic, PBC acts as our processor: it uses what we send to produce the response and does not use it to train its models.

One limit we cannot design away, stated plainly. If Anthropic, PBC’s safety classifiers flag a session, Anthropic, PBC may retain that session for up to 2 years, and the classification scores for up to 7 years, even under the zero-retention arrangement we otherwise operate under. That retention is outside our control, it survives your deleting your account with us, and it caps what any promise of deletion can honestly mean. It is disclosed here, and again on the receipt we give you when you delete.

Web search. When it helps, the assistant searches the web through Anthropic, PBC’s search service. The search query — which may contain what you asked — goes to that service and to its search provider. The pages it then reads are retrieved by our own servers, not by your browser and not from your address.

6. Who else sees it

Everyone we use, and what they get. They are processors: they act on our instructions and may not use your data for their own purposes.

Who What they get Where
Anthropic, PBC Messages, recipe, photos, cook profile — see section 5 United States
Amazon Web Services Hosting. Everything lives on servers we run in AWS United States (Ohio)
Amazon SES Your email address and the text of service emails United States
Stripe Web payments. Your card details go to Stripe, not to us United States / Ireland
RevenueCat Mobile purchase receipts and your Torrere account identifier United States
Apple, Google Purchases made through their stores, and device attestation Per their own policies

We disclose data to anyone else only where the law requires it, or where it is necessary to establish or defend a legal claim. If we are ever compelled to hand over your data, we will tell you unless we are legally prevented from doing so.

International transfers. We operate from the United States. If you are in the UK, the EEA or Switzerland, your data is transferred there under the European Commission’s Standard Contractual Clauses (and the UK Addendum where it applies), which each processor above has signed.

7. How long we keep it

Retention is set when a record is written, not decided later.

What Kept for
Your account, recipes and cook profile Until you delete them, or the account
Chat messages, paid accounts 400 days from when they were written
Chat messages, free and provisional accounts 90 days
Superseded recipe versions Pruned to the most recent 30 per recipe after 180 days
Usage and cost rows (no content) 400 days
Safety and abuse records 400 days — they are the evidence behind a suspension
Proof that you consented, reduced to the fact and its date 6 years after deletion
Backups 35 days

Backups are the honest caveat. Restoring a backup can bring back data from up to 35 days earlier, including data you deleted. We keep a permanent record of every deletion, and replaying it is the first step after any restore, so a restore cannot quietly resurrect a deleted account.

8. Security

Everything is encrypted in transit. The database is not reachable from the internet at all — it listens only on the server’s own loopback interface. Passwords are hashed with a memory-hard function; we could not tell you your password if we wanted to. The AI provider’s key is not stored on the server’s disk; it is fetched at start-up from a secrets store. Message content is kept out of every log by a build-time check that fails the build rather than trusting anyone to remember.

None of that makes us unbreakable, and we are not going to claim it does. If your data is ever exposed in a way that puts you at risk, we will tell you and the relevant regulator within the time the law allows.

9. Children

Torrere is not for children under 13, and we do not knowingly collect anything from one. If you believe a child has given us their data, write to support@torrere.com and we will delete it.

10. Deleting your account

You can delete your account and everything in it:

Deletion removes your profile, your allergy and dietary data, your recipes, your chat history, and revokes every link you have shared. There is a 24-hour window in which you can change your mind; after that it is permanent and we cannot recover it. When it completes we give you a receipt saying what was removed and what was kept.

What we keep afterwards, and why. The fact that you consented, reduced to the date and the purpose, for six years, because it is the proof we were allowed to hold your data at all. Billing records the tax authorities require. Aggregate cost totals with your identity stripped out and replaced by a one-way hash, and — for free-tier devices — a hashed device identifier and a count of sessions used, so that deleting an account is not a way to reset a free allowance. That last one is fraud prevention under Art. 17(3), and it is named on your receipt.

And the limit in section 5: a session flagged by the AI provider’s classifiers is outside the reach of this deletion.

11. Your rights

Wherever you are, you can ask us to:

Write to support@torrere.com from the address on your account. We answer within 30 days and we do not charge for it. If you are in the UK or the EEA you can complain to your national data protection authority; we would rather you came to us first.

If you are in California, we do not sell or share personal information as CCPA defines those words, we have not in the past 12 months, and we will not discriminate against you for exercising any right above.

12. Changes

We may change this policy. If a change is material we will tell you before it takes effect — by email, or in the app — and the effective date at the top will change. Continuing to use Torrere after that means the new version applies.

13. Contact

Submarius LLC NOTICE_ADDRESS PHONE_NUMBER support@torrere.com


Also here: terms of use · privacy · copyright · deleting your account