Privacy Policy
Effective August 4, 2026 · Last updated August 4, 2026 · Debouillet Inc.
Short version: we collect the details you send us to scope and build software, we use a handful of vetted vendors and enterprise AI providers to do it, we never sell your data or let it train third-party models, and you can have it deleted at any time by emailing privacy@debouillet.com.
1. Who we are
This Privacy Policy explains how Debouillet Inc. (“Debouillet”, “we”, “us”) handles personal information when you visit debouillet.com, submit a build request, apply for a role, use the client or team portal, or otherwise engage us to design, build and operate software.
Debouillet is the controller of the personal information described here. When we build and run software for a client, that client is the controller of the end-user data inside their product and we act as their processor under a separate data processing agreement. Consumer apps published by Debouillet or Social Sips Inc. have their own product-specific privacy policies, linked at the bottom of this page.
Privacy contact: privacy@debouillet.com — postal mail can be requested at the same address and we will provide our registered address in reply.
2. Scope of this policy
This policy covers:
- The public marketing site at debouillet.com, including the build-request form, careers applications and venture pages.
- The authenticated client portal and internal team studio, including projects, briefs, files and messages.
- Our AI-assisted delivery workflow, including brief drafting, concept sketches and agent activity logs.
- Business communications by email with prospects, clients, candidates and partners.
It does not cover third-party websites we link to, client-owned production systems we operate on their behalf, or individual App Store products, which each publish their own policy.
3. Information we collect
We collect only what we need to quote, build, deliver and support work.
| Category | Examples | Source |
|---|---|---|
| Identifiers and contact data | Name, work email, company, job title, phone number if you provide it | You, via forms or email |
| Project and commercial data | Project description, goals, budget range, timeline, scope decisions, invoices and payment status | You and our delivery records |
| Account data | Portal user ID, authentication provider identifier (GitHub or email), role, session timestamps | Created when you sign in |
| Content you upload | Documents, screenshots, sketches, repository references and messages inside the portal | You |
| Recruitment data | Application answers, links, résumé content and correspondence | You, via the careers form |
| Technical and security data | IP address, user agent, request timestamps, error traces and security event logs | Automatically, from our hosting and error-reporting layers |
We do not intentionally collect special-category data (health, biometric, precise geolocation, government identifiers, racial or ethnic origin, religious or political views, sexual orientation, or union membership) through this site, and we ask that you do not include such data in free-text fields. We do not knowingly collect information from children under 16; if you believe a child has provided data, contact us and we will delete it.
4. Why we use it, and our legal bases
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Responding to a build request, scoping and quoting the work | Steps taken at your request prior to a contract (Art. 6(1)(b)) |
| Delivering, hosting and supporting the software you engaged us to build | Performance of a contract (Art. 6(1)(b)) |
| Operating portal accounts, authentication and role-based access | Contract and our legitimate interest in a secure service (Art. 6(1)(b), (f)) |
| Evaluating job applications | Steps prior to an employment contract and our legitimate interest in hiring (Art. 6(1)(b), (f)) |
| Security monitoring, abuse prevention, debugging and service reliability | Legitimate interests in protecting the service (Art. 6(1)(f)) |
| Invoicing, tax, accounting and dispute records | Legal obligation and legitimate interests (Art. 6(1)(c), (f)) |
| Occasional direct business email about work you asked us about | Legitimate interests, or consent where required by local law (Art. 6(1)(f) / 6(1)(a)) |
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train third-party foundation models. We do not carry out automated decision-making that produces legal or similarly significant effects about you.
5. AI processing
Parts of our workflow are AI-assisted. When you submit a build request or work inside the portal, the text you provide may be sent to enterprise AI providers so we can draft a scope brief, produce concept sketches and summarise project activity. Model output is always reviewed by a person before it becomes a quote, a commitment or delivered code.
- Inputs are limited to project context — please do not paste credentials, production data, or personal data about third parties into free-text fields.
- We use providers under commercial API terms that prohibit training on our inputs and outputs; prompts are retained by the provider only for a short abuse-monitoring window, if at all.
- You may ask us to run your engagement without AI assistance by emailing privacy@debouillet.com; this may extend turnaround times.
- AI output can be wrong. Briefs, estimates and generated artefacts are drafts, not professional, legal or financial advice.
7. International transfers
Debouillet operates from the United States and our providers may process data in the US and other countries. Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with technical measures such as encryption in transit and at rest. A copy of the relevant transfer mechanism is available on request.
8. Retention
| Data | Retention |
|---|---|
| Build requests that do not become projects | Up to 24 months, then deleted |
| Client project records, briefs and deliverable metadata | Duration of the engagement plus 7 years for contract, warranty and tax records |
| Portal accounts and uploaded content | Until you close the account or ask us to delete it, then removed within 30 days |
| Job applications | 12 months from the decision, unless you ask us to keep you on file |
| Security, error and access logs | Up to 12 months |
| Email correspondence | Up to 7 years, in line with our business-records obligations |
Backups roll off on their own schedule and deleted records may persist in encrypted backups for up to 90 days after deletion from live systems.
9. How we protect information
- TLS in transit and encryption at rest for databases and stored files.
- Row-level security policies so portal users can reach only their own records; staff access is role-based and least-privilege.
- Single sign-on with GitHub for staff, with credentials never stored by us.
- Secrets held in managed secret storage, never in source control.
- Logged and reviewed administrative access, with prompt revocation when someone leaves an engagement.
No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you and any competent supervisory authority without undue delay and, where required, within 72 hours. Report a suspected vulnerability to security@debouillet.com; we will not pursue good-faith researchers who follow coordinated disclosure.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict your personal information, to object to processing based on legitimate interests, to withdraw consent, and to lodge a complaint with your supervisory authority (in the EEA or UK) without contacting us first.
If you are a California resident, you may request disclosure of the categories and specific pieces of personal information we collected, request deletion or correction, and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising any right. Residents of Colorado, Connecticut, Virginia, Texas, Oregon and other states with comparable laws have equivalent rights, including appeal of a denied request.
To exercise a right, email privacy@debouillet.com from the address on file or from your portal account. We verify requests before acting, respond within 30 days (45 days in the US where permitted, extendable once with notice) and never charge for a first request. Authorised agents may submit requests with written proof of authority.
12. Changes and contact
We will post any material change here with a new effective date and, for active clients, notify you by email at least 14 days before it takes effect. Continuing to use the site or portal after that date means the updated policy applies.
Questions, data requests or complaints: privacy@debouillet.com. General enquiries: build@debouillet.com.
Apps & legal
Each app we publish on the App Store has its own privacy policy, terms of service and EULA. Pick an app to read its documents.
CafeQ: AI Mobile Order
AI-powered coffee ordering for cafes
StewardAI: Leadership Coach
AI leadership development for managers
Fitplicity: The Gym Software
Radically simple gym and athlete management
AI Artifact Vault
Storage and organization for AI-generated content
CanaryAI
AI early-warning signals and insights for teams
EstiMate: AI Renovation Calc
AI renovation materials and cost calculator
Plant AI: Plant Doctor
AI plant disease diagnosis from photos
Social Sips
Policies live on its own product site.