Privacy Policy

CafeQ: AI Mobile Order

Effective August 4, 2026

1.Who we are

CafeQ: AI Mobile Order is published on the App Store by Social Sips Inc. and operated by Debouillet Inc. This policy explains what the app collects, why, and the control you have over it. It applies to the iOS app and any companion web experience.

2.Information we collect

We collect only what the app needs to work:

  • Account information (name, email address, phone number)
  • Order history and drink preferences
  • Payment information (processed securely by Stripe — we never store card numbers)
  • Location data, used to coordinate pickup with nearby participating cafes
  • Natural-language order inputs processed by our AI ordering model
  • Device identifiers and basic analytics events

We do not sell your personal information, and we do not use it for third-party advertising or cross-app tracking.

3.How we use your information

CafeQ uses your data to process and personalize coffee orders using AI-powered natural language understanding, coordinate pickups with participating cafes, process payments through our secure payment provider, and improve the ordering experience.

Concretely, we process personal data to:

  • Create and authenticate your account and keep it secure
  • Deliver the features you ask for and save your work across devices
  • Provide customer support and respond to your requests
  • Process purchases, manage entitlements and prevent payment fraud
  • Diagnose crashes, monitor abuse and keep the service reliable
  • Send service messages such as receipts, security alerts and policy changes
  • Comply with legal, tax and accounting obligations

We never use your content for behavioural advertising, we do not build advertising profiles, and we do not track you across other companies' apps or websites.

4.What we deliberately do not collect

CafeQ is built to collect the minimum needed to function. We do not collect:

  • Card numbers, CVV or bank credentials
  • Background location while the app is closed
  • Contacts, photos, health data or browsing history
  • The advertising identifier (IDFA) — we do not run App Tracking Transparency prompts

5.Legal bases for processing (EEA and UK)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract — operating your account and delivering the features you request
  • Legitimate interests — securing the service, preventing abuse and improving reliability, balanced against your rights
  • Consent — optional permissions such as notifications, camera, location and Apple Health, which you can withdraw at any time in iOS Settings
  • Legal obligation — retaining tax, accounting and fraud records

Where Debouillet Inc. processes data on behalf of an organization that gave you access to the app, that organization is the controller and we act as its processor under a data processing agreement.

6.Sharing with participating cafes

When you place an order we share your first name, order contents, pickup time and order number with the cafe you selected so it can prepare and hand off your order. Cafes receive no other personal information and are contractually barred from marketing to you without your consent.

7.AI data processing

CafeQ uses large language models (including Anthropic's Claude) to generate its AI features. When you use those features, the content you submit — your prompts, text, and any files or images you attach — is transmitted to our AI provider for processing and returned as a result.

Your content is not used to train third-party foundation models. AI providers process it on our behalf under a data processing agreement and retain it only transiently for abuse monitoring. AI output can be inaccurate; see our Terms for the limits on relying on it.

We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement. You can stop AI processing at any time by not using the AI features, or by deleting your account.

8.Location

CafeQ requests location access while the app is in use, to find nearby participating locations and coordinate pickup. We do not collect background location and you can revoke the permission at any time in iOS Settings; the app remains usable with manual location entry.

9.Payments and purchases

In-app purchases and subscriptions are processed by Apple. We receive a purchase receipt and entitlement status; we never receive your payment card details. Card payments made outside the App Store are processed by Stripe, a PCI-DSS Level 1 provider. We store only the last four digits and card brand for your records.

10.Service providers

We rely on a small set of vendors, each bound by a data processing agreement:

  • Apple — App Store distribution, in-app purchases and push notifications
  • Managed cloud platform — authentication, database and file storage
  • Stripe — payment processing
  • Anthropic — AI model inference
  • Resend — transactional email

11.Push notifications and messages we send

If you enable notifications, Apple issues a push token we use only to deliver the alerts and reminders you configured; you can disable them in iOS Settings at any time. We also send transactional email — receipts, password resets, security notices and material policy changes. These are not marketing, and you cannot opt out of them while your account is active. Any product or marketing email is opt-in and has a one-click unsubscribe link.

12.Analytics and tracking

We collect privacy-preserving product analytics — screen views, feature usage and crash reports — tied to a random installation identifier rather than to advertising IDs. We do not use the IDFA, we do not present an App Tracking Transparency prompt because we do not track you across other companies' apps or sites, and we do not sell or share data for cross-context behavioural advertising. Our companion web pages use no advertising cookies; we honour Global Privacy Control and Do Not Track signals where they are sent.

13.Data retention

We keep your account data for as long as your account is active. When you delete your account, personal data is removed within 30 days. Specific schedules:

  • Account and profile records — deleted within 30 days of account deletion
  • Content you created — deleted within 30 days of account deletion, or immediately when you delete the item
  • AI prompts and outputs — retained with the item they belong to; provider-side abuse-monitoring copies expire within 30 days
  • Support correspondence — up to 24 months so we can follow up on recurring issues
  • Crash logs and security telemetry — up to 12 months
  • Invoice, receipt and tax records — up to 7 years, as required by law
  • Anonymised, aggregated statistics that can no longer identify you — retained indefinitely

14.Your rights

Wherever you live, you can request access to your data, correction of it, export of it in a portable format, or its deletion. Residents of the EEA and UK have these rights under the GDPR; California residents have equivalent rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined by California law.

Email privacy@debouillet.com or use the account deletion page to exercise any of them. We respond within 30 days.

15.US state privacy rights

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws may request to know, access, correct, delete or port their personal data, and may opt out of targeted advertising, sale, or profiling with legal effects. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not profile users in ways that produce legal effects — so there is nothing to opt out of, but you may still exercise every other right.

You may use an authorized agent, and we will never discriminate against you for exercising a right. If we deny a request, you can appeal by replying to our decision email within 30 days; we respond to appeals within 45 days and will tell you how to contact your state attorney general if you disagree.

16.Complaints and supervisory authorities

If you are in the EEA or UK and believe we have mishandled your data, please contact privacy@debouillet.com first — we take complaints seriously. You also have the right to lodge a complaint with your local data protection authority or, in the UK, with the Information Commissioner's Office.

17.Breach notification

If a personal data breach occurs that is likely to affect you, we will notify affected users without undue delay, and notify supervisory authorities within 72 hours where the GDPR requires it, and within the deadlines set by applicable US state breach laws. Our notice will describe what happened, what data was involved and what you should do.

18.Links and third-party destinations

CafeQ may link to sites and services we do not control, including the App Store, our providers' pages. This policy does not cover them; review their privacy notices before sharing data with them.

19.Children's privacy

CafeQ is not directed to children under 13, we do not knowingly collect personal information from them, and we do not serve ads or use child data for any secondary purpose. If you believe a child has provided us information, contact privacy@debouillet.com and we will delete it within 7 days and confirm in writing. Where a guardian has enrolled a minor, the guardian may access, correct or delete the minor's records at any time.

20.Security

Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production data is limited to the small number of staff who need it, and row-level security isolates each account's records. No system is perfectly secure, but we will notify affected users and regulators of any breach as required by law.

21.International transfers

We operate from the United States, and our providers may process data in the United States and other countries. Where required, transfers rely on the European Commission's Standard Contractual Clauses.

22.Changes to this policy

We will post any change here and update the effective date. Material changes will also be announced in the app before they take effect.

23.Contact

Privacy questions and data requests: privacy@debouillet.com. Postal mail can be addressed to Social Sips Inc., c/o Debouillet Inc.

Published by Social Sips Inc. · App Store developer of record.

Operated and engineered by Debouillet Inc.

© 2026 Debouillet Inc. Legal: legal@debouillet.com · Privacy: privacy@debouillet.com · Support: support@debouillet.com