← Debouillet

Privacy Policy

Effective August 4, 2026 · Last updated August 4, 2026 · Debouillet Inc.

Short version: we collect the details you send us to scope and build software, we use a handful of vetted vendors and enterprise AI providers to do it, we never sell your data or let it train third-party models, and you can have it deleted at any time by emailing privacy@debouillet.com.

1. Who we are

This Privacy Policy explains how Debouillet Inc. (“Debouillet”, “we”, “us”) handles personal information when you visit debouillet.com, submit a build request, apply for a role, use the client or team portal, or otherwise engage us to design, build and operate software.

Debouillet is the controller of the personal information described here. When we build and run software for a client, that client is the controller of the end-user data inside their product and we act as their processor under a separate data processing agreement. Consumer apps published by Debouillet or Social Sips Inc. have their own product-specific privacy policies, linked at the bottom of this page.

Privacy contact: privacy@debouillet.com — postal mail can be requested at the same address and we will provide our registered address in reply.

2. Scope of this policy

This policy covers:

  • The public marketing site at debouillet.com, including the build-request form, careers applications and venture pages.
  • The authenticated client portal and internal team studio, including projects, briefs, files and messages.
  • Our AI-assisted delivery workflow, including brief drafting, concept sketches and agent activity logs.
  • Business communications by email with prospects, clients, candidates and partners.

It does not cover third-party websites we link to, client-owned production systems we operate on their behalf, or individual App Store products, which each publish their own policy.

3. Information we collect

We collect only what we need to quote, build, deliver and support work.

CategoryExamplesSource
Identifiers and contact dataName, work email, company, job title, phone number if you provide itYou, via forms or email
Project and commercial dataProject description, goals, budget range, timeline, scope decisions, invoices and payment statusYou and our delivery records
Account dataPortal user ID, authentication provider identifier (GitHub or email), role, session timestampsCreated when you sign in
Content you uploadDocuments, screenshots, sketches, repository references and messages inside the portalYou
Recruitment dataApplication answers, links, résumé content and correspondenceYou, via the careers form
Technical and security dataIP address, user agent, request timestamps, error traces and security event logsAutomatically, from our hosting and error-reporting layers

We do not intentionally collect special-category data (health, biometric, precise geolocation, government identifiers, racial or ethnic origin, religious or political views, sexual orientation, or union membership) through this site, and we ask that you do not include such data in free-text fields. We do not knowingly collect information from children under 16; if you believe a child has provided data, contact us and we will delete it.

4. Why we use it, and our legal bases

PurposeLegal basis (GDPR / UK GDPR)
Responding to a build request, scoping and quoting the workSteps taken at your request prior to a contract (Art. 6(1)(b))
Delivering, hosting and supporting the software you engaged us to buildPerformance of a contract (Art. 6(1)(b))
Operating portal accounts, authentication and role-based accessContract and our legitimate interest in a secure service (Art. 6(1)(b), (f))
Evaluating job applicationsSteps prior to an employment contract and our legitimate interest in hiring (Art. 6(1)(b), (f))
Security monitoring, abuse prevention, debugging and service reliabilityLegitimate interests in protecting the service (Art. 6(1)(f))
Invoicing, tax, accounting and dispute recordsLegal obligation and legitimate interests (Art. 6(1)(c), (f))
Occasional direct business email about work you asked us aboutLegitimate interests, or consent where required by local law (Art. 6(1)(f) / 6(1)(a))

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train third-party foundation models. We do not carry out automated decision-making that produces legal or similarly significant effects about you.

5. AI processing

Parts of our workflow are AI-assisted. When you submit a build request or work inside the portal, the text you provide may be sent to enterprise AI providers so we can draft a scope brief, produce concept sketches and summarise project activity. Model output is always reviewed by a person before it becomes a quote, a commitment or delivered code.

  • Inputs are limited to project context — please do not paste credentials, production data, or personal data about third parties into free-text fields.
  • We use providers under commercial API terms that prohibit training on our inputs and outputs; prompts are retained by the provider only for a short abuse-monitoring window, if at all.
  • You may ask us to run your engagement without AI assistance by emailing privacy@debouillet.com; this may extend turnaround times.
  • AI output can be wrong. Briefs, estimates and generated artefacts are drafts, not professional, legal or financial advice.

6. Service providers and disclosure

We keep our vendor list deliberately small. Each provider is bound by contract to process data only on our instructions, with confidentiality and security obligations.

Provider roleWhat it handles
Cloud database, authentication and file storagePortal accounts, project records, submissions, uploads
Application hosting and CDNServing the site and portal, request logs
Transactional email providerSign-in links, request confirmations, project notifications
Enterprise AI providersBrief drafting, concept sketches, summarisation
Source control (GitHub)Repository access, portal sign-in for staff, delivery activity
Accounting and paymentsInvoices and payment records

We may also disclose information where we are legally required to, to enforce our agreements or protect rights and safety, or to a successor entity as part of a merger, acquisition or asset sale — in which case we will notify affected clients.

7. International transfers

Debouillet operates from the United States and our providers may process data in the US and other countries. Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with technical measures such as encryption in transit and at rest. A copy of the relevant transfer mechanism is available on request.

8. Retention

DataRetention
Build requests that do not become projectsUp to 24 months, then deleted
Client project records, briefs and deliverable metadataDuration of the engagement plus 7 years for contract, warranty and tax records
Portal accounts and uploaded contentUntil you close the account or ask us to delete it, then removed within 30 days
Job applications12 months from the decision, unless you ask us to keep you on file
Security, error and access logsUp to 12 months
Email correspondenceUp to 7 years, in line with our business-records obligations

Backups roll off on their own schedule and deleted records may persist in encrypted backups for up to 90 days after deletion from live systems.

9. How we protect information

  • TLS in transit and encryption at rest for databases and stored files.
  • Row-level security policies so portal users can reach only their own records; staff access is role-based and least-privilege.
  • Single sign-on with GitHub for staff, with credentials never stored by us.
  • Secrets held in managed secret storage, never in source control.
  • Logged and reviewed administrative access, with prompt revocation when someone leaves an engagement.

No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you and any competent supervisory authority without undue delay and, where required, within 72 hours. Report a suspected vulnerability to security@debouillet.com; we will not pursue good-faith researchers who follow coordinated disclosure.

10. Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict your personal information, to object to processing based on legitimate interests, to withdraw consent, and to lodge a complaint with your supervisory authority (in the EEA or UK) without contacting us first.

If you are a California resident, you may request disclosure of the categories and specific pieces of personal information we collected, request deletion or correction, and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising any right. Residents of Colorado, Connecticut, Virginia, Texas, Oregon and other states with comparable laws have equivalent rights, including appeal of a denied request.

To exercise a right, email privacy@debouillet.com from the address on file or from your portal account. We verify requests before acting, respond within 30 days (45 days in the US where permitted, extendable once with notice) and never charge for a first request. Authorised agents may submit requests with written proof of authority.

11. Cookies and tracking

The marketing site sets no advertising or cross-site tracking cookies and runs no third-party ad pixels. The portal stores a strictly necessary session token in your browser so you stay signed in, plus a local preference for reduced motion. These are essential to the service and cannot be switched off without breaking sign-in.

We honour Global Privacy Control and browser Do Not Track signals where they apply. If we later add analytics, we will publish it here and request consent where the law requires it.

12. Changes and contact

We will post any material change here with a new effective date and, for active clients, notify you by email at least 14 days before it takes effect. Continuing to use the site or portal after that date means the updated policy applies.

Questions, data requests or complaints: privacy@debouillet.com. General enquiries: build@debouillet.com.

Apps & legal

Each app we publish on the App Store has its own privacy policy, terms of service and EULA. Pick an app to read its documents.

CafeQ: AI Mobile Order

AI-powered coffee ordering for cafes

StewardAI: Leadership Coach

AI leadership development for managers

Fitplicity: The Gym Software

Radically simple gym and athlete management

AI Artifact Vault

Storage and organization for AI-generated content

CanaryAI

AI early-warning signals and insights for teams

EstiMate: AI Renovation Calc

AI renovation materials and cost calculator

Plant AI: Plant Doctor

AI plant disease diagnosis from photos

Social Sips

Policies live on its own product site.

Open the full app legal center →