Skip to content
S SUCRE
  • Support
  • Privacy

SUCRE Privacy Policy

This policy is also available in German: Datenschutzerklärung auf Deutsch

This document covers the SUCRE iOS app. What happens when you visit this website is covered by the Website Privacy Notice.

Last updated: 8 August 2026 Applies to: the SUCRE iOS app and its Share Extension


1. In short

SUCRE keeps your recipes on your device. There are no accounts, no advertising, no tracking, and nothing is sold or shared with data brokers.

One thing does leave your device: when you import a recipe, the link or the text you paste is sent to our server so it can be turned into a structured recipe. That is the only user content SUCRE transmits, and this policy explains exactly what happens to it.

You can delete everything SUCRE stores on your device at any time, in one step, from Settings → Erase All SUCRE Data.


2. Who is responsible

The controller for the purposes of the EU General Data Protection Regulation (GDPR) is:

Hakim Bahdo, trading as Vitality Sphere Auf der Au 6 54296 Trier Germany

SUCRE is the product and brand name. Vitality Sphere is the trading name of the individual operator and is named here only because data-protection law requires the controller to be identified. SUCRE is not a separate legal entity or company.

Privacy contact: privacy@sucreapp.com General support: support@sucreapp.com

We have not appointed a Data Protection Officer, and we are not required to. SUCRE is run by one person; our core activity is not the regular and systematic monitoring of people on a large scale; and we do not process special categories of data (Art. 37(1) GDPR, § 38 BDSG).


3. What stays on your device

Almost everything. The following are stored only in SUCRE's own storage area on your iPhone, and are never transmitted to us:

  • Your saved recipes, including their titles, ingredients, steps, notes, tags and the source link they came from
  • Photos of recipes that SUCRE has downloaded and cached so they work offline
  • Collections
  • Your shopping list
  • Your meal plan
  • Your bake history (which recipes you started and finished, and any rating you gave)
  • Your name, if you enter one, plus your unit and skill preferences
  • Onboarding and getting-started checklist progress
  • Your notification preference

We cannot see any of this. SUCRE has no user accounts, no login, and no cloud sync. We have no copy of your library.

Device backups

Because this data is stored in SUCRE's normal app storage, it is included in your device's regular iPhone and iCloud backups, in the same way as other app data. That backup is made and controlled by Apple under Apple's terms, not by us — we have no access to it.

The one exception is the cached recipe photo folder, which SUCRE explicitly marks as excluded from backup, because those images can be downloaded again.

This is deliberate. Your recipes, collections, shopping list and meal plan are the work you put into the app, and being in the backup is what lets them survive a lost, broken or replaced phone. If you would rather they were not in your iCloud backup, you can switch SUCRE off under Settings → [your name] → iCloud → Manage Account Storage → Backups on your device.

This is device backup only. SUCRE does not offer cloud sync and does not store your library on any server.


4. What leaves your device, and why

4.1 Recipe imports

When you import a recipe — by pasting a link, pasting recipe text, or sharing a page to SUCRE from another app — the app sends to our server:

  • the link you provided, or the text you pasted, and
  • where relevant, the original social-media link the text came from.

That is the entire content of the request. No account identifier, device identifier, advertising identifier or name is attached, because SUCRE does not have any.

Purpose: to fetch the page (when you provide a link) and turn the source into a structured recipe that SUCRE can save.

Legal basis: performance of the contract — providing the feature you asked for (Art. 6(1)(b) GDPR). The transfer is not an optional extra: without it the import feature cannot work at all. That is also why we do not ask for separate consent, and why there is no consent to withdraw. If you would prefer that nothing leaves your device, do not use the import feature; every other part of SUCRE works without it.

Retention: our server does not save the recipe content, the link, or the finished recipe. It holds the request in memory only for as long as it takes to answer it. This is a commitment, not merely a description of how the current version happens to behave — if it ever changes, we will update this policy before the change goes live. See section 6 on server logs, which are a separate matter.

4.2 Recipe photos

When a recipe has a photo, your device downloads that image directly from the website or platform hosting it, so it can be shown offline later. As with opening any web page, that means the hosting service can see your device's IP address and that a request was made. This request does not go through our servers and carries no SUCRE identifier.

4.3 Opening the original source

If you tap to view a recipe's original page, iOS opens it in your browser. From that point the site you visit is responsible for its own data handling.

4.4 Nothing else

SUCRE makes no other network requests with your data. In particular there is no telemetry call, no crash-reporting upload, and no "phone home" on launch.


5. Who else is involved

5.1 Providers who process data for us

Two providers act as processors on our behalf under Art. 28 GDPR. They may only do what we instruct them to do.

ProviderWhat they receiveWhyHow long they keep it
Render (hosting, USA)The import request itself, your device's IP address as the network connection, and our server's operational log linesRuns our import serverLogs are deleted automatically after the retention window of our hosting plan — at most 30 days. Nothing else is stored.
Anthropic (AI model, USA)The recipe text taken from your link, or the text you pastedTurns the source into a structured recipeAnthropic deletes API inputs and outputs within 30 days. If its automated safety systems flag a request, it may keep that request for up to two years, and the related classification scores for up to seven years.

Three things are worth stating plainly about the Anthropic step:

  • The request contains the recipe source text only. It does not include your name, an account identifier, a device identifier, or your IP address.
  • Your text is not used to train AI models. Anthropic's commercial terms prohibit training on customer content, and we have not opted into anything that would change that.
  • We use Anthropic's own API directly. There is no reseller, cloud marketplace or other intermediary between our server and Anthropic, so no additional company sees your text.

5.2 Sites and platforms we read from

To read a recipe you asked us to import, our server has to contact whoever publishes it.

SourceWhat it receivesWhen
The website you imported fromA request for the page at the link you gave usYou paste or share a web link
Google (YouTube Data API)The identifier of the videoYou import a YouTube link
TikTokThe link of the postYou import a TikTok link
Meta / InstagramThe link of the postYou import an Instagram link

These are not our processors. They are independent services we read from, and each handles what it receives under its own privacy policy. Two consequences matter to you:

  • Your device's IP address is not disclosed to them when you import. Our server makes the request, so they see our server — not you.
  • Recipe photos work the other way round. Your device downloads those directly from the host, so the host does see your device's IP address (section 4.2).

5.3 Apple

Apple processes purchases of SUCRE Pro (section 7) and makes your device backup (section 3). For both, Apple is an independent controller under its own privacy policy, not our processor.

5.4 Transfers outside the EU/EEA

Render and Anthropic are US companies, so this processing may take place outside the EEA. Both relationships are governed by a data-processing agreement that incorporates the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914:

  • Render's Data Processing Addendum applies through our agreement with Render.
  • Anthropic's Data Processing Addendum is incorporated into the commercial terms that govern our direct use of its API, and additionally covers transfers to the United Kingdom and Switzerland.

Each provider remains answerable to us for its own sub-processors.

You can ask us for details of these safeguards at privacy@sucreapp.com.

We do not sell your data, and we do not share it with data brokers or advertisers.


6. Server logs

Our import server writes short operational log lines so we can tell whether the service is working. These deliberately do not contain your recipe content or the link you imported.

A log line contains:

  • what kind of source was involved (for example: a web page, a social post, or pasted text)
  • whether the request succeeded or failed, and a general error category
  • a rough size band for the source text — not the text
  • the website domain only, never the full address, never the path, and never anything after a ? or #
  • a random reference number for the request, which is not linked to you or your device

The full address you imported, the text you pasted, and any authentication values are never written to these logs. This is enforced in the code and covered by automated tests.

Separately, our hosting provider records standard platform access logs, which include IP addresses, as almost all web infrastructure does.

How long logs are kept. Both kinds of log are deleted automatically by Render once the retention window of our hosting plan passes. That window is at most 30 days. We do not copy these logs anywhere else and we do not stream them to any external logging service, so when that window passes they are gone — including from our reach.

Legal basis. Keeping short-lived logs is our legitimate interest in running the service reliably, diagnosing faults and protecting it from abuse (Art. 6(1)(f) GDPR). We designed what goes into them precisely so that this interest costs you as little as possible: no content, no full addresses, no identifier for you.


7. Purchases and SUCRE Pro

SUCRE Pro is sold as an auto-renewing subscription through the Apple App Store.

Apple handles the entire purchase. We never see your payment details, your Apple Account, or your name. SUCRE only asks Apple whether a valid subscription exists, and unlocks Pro features if it does. We store no purchase records — not on your device, and not on our servers.

Because your purchase history belongs to Apple and not to us, erasing your SUCRE data does not cancel your subscription and does not delete anything at Apple. Your subscription can be restored at any time with "Restore Purchases", and managed or cancelled in your Apple subscription settings.

Apple's handling of purchase data is governed by Apple's own privacy policy.


8. Notifications

If you use Bake Mode timers, SUCRE schedules local notifications on your device. These are created and delivered by iOS; nothing is sent to us or through any server.

By default, a timer notification says only that a SUCRE timer has finished. It does not name the recipe or the step, so nothing about what you are cooking appears on a locked screen.

If you would rather see the detail, you can turn on Settings → Show recipe details in notifications. This is off by default, including for people updating from an earlier version.


9. Analytics

SUCRE contains a small internal event list used during development. It is not connected to any analytics provider and does not transmit anything. There is no third-party analytics SDK in the app.

If analytics are ever introduced, this policy will be updated before that happens. As a safeguard, the event structure cannot carry what you typed: a search is recorded only as a rough length band and a rough result-count band, never the words you searched for. Recipe titles, links, captions and ingredients are not part of any event.


10. Tracking, advertising and cookies

  • SUCRE does not track you across apps or websites.
  • SUCRE does not use the advertising identifier (IDFA) and does not ask for tracking permission.
  • SUCRE contains no advertising, and no advertising or attribution SDKs.
  • SUCRE contains no analytics or crash-reporting SDKs.
  • The app is not a website and does not use cookies.

This is declared in the app's privacy manifest, which states that no tracking occurs.


11. Children

SUCRE is a general-audience cooking app. It is not directed at children, has no child-focused features, and does not knowingly process data from children.

You should be at least 16 years old to use SUCRE. If you are younger than that, please use it only with the agreement of a parent or guardian. We apply one age everywhere rather than a different one per country: 16 is the strictest of the ages that commonly apply, so a single rule covers everyone.

If you believe a child has used SUCRE in a way that concerns you, note that SUCRE holds no account and no profile — everything the child entered is on their own device and can be removed in one step (section 13). If you think we hold anything else, write to privacy@sucreapp.com.


12. Your data-protection rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to data portability. You may also lodge a complaint with a supervisory authority — in our case the data-protection authority of Rhineland-Palatinate, Germany, or the authority where you live.

In practice, the shape of these rights for SUCRE is unusual, and we want to be straightforward about it:

  • Your recipe library is not ours to give you or delete. It is on your device, and we have no copy. You control it completely, including deleting all of it at once (section 13).
  • We hold no account for you, so there is nothing to log into and no profile to export.
  • What we may hold is limited to the short-lived logs described in section 6, and the two kinds differ:

    • Our own import-server log lines exclude your content and carry no identifier for you at all, so we cannot connect them to a person.
    • The platform access logs written by our hosting provider do contain IP addresses. An IP address is personal data, but with no account to match it against we are in practice still unable to tell whose it is, and both kinds are deleted within the window in section 6.

    For both, we may therefore be unable to act on an access or erasure request (Art. 11 GDPR). We consider this a privacy benefit rather than an obstacle.

  • Emails you send us are held in our mailbox so we can reply — see below for how long.

How to make a request, and what happens then

Write to privacy@sucreapp.com. That mailbox is read by the operator named in section 2 — there is no ticketing system and no third party in between.

We will answer within one month of receiving your request. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month that we are doing so and why (Art. 12(3) GDPR). Our answer is free of charge.

We may ask you for enough detail to work out which data is yours. As explained above, for server logs there is usually nothing we can link to you at all — in that case we will say so plainly rather than ask you to prove an identity we could not match anyway (Art. 11 GDPR).

Emails you send us — to privacy@sucreapp.com or support@sucreapp.com — stay in our mailbox for as long as we need them to deal with your request and to be able to show that we dealt with it, and are deleted 12 months after the matter is resolved. We keep correspondence longer only where the law requires it, or where we still need it to establish, exercise or defend a legal claim.

Legal basis for handling your message: where you are exercising a data-protection right, we are under a legal obligation to deal with it (Art. 6(1)(c) with Art. 12 GDPR). For any other message, it is our legitimate interest in answering people who write to us and in keeping a record of what we answered (Art. 6(1)(f) GDPR).

If you are outside the EU/EEA

  • United Kingdom. The same rights apply under the UK GDPR. You may complain to the Information Commissioner's Office (ico.org.uk).
  • Switzerland. The same rights apply under the Swiss Federal Act on Data Protection. You may contact the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
  • California and other US states. SUCRE does not sell or share personal information, does not use it for cross-context behavioural advertising, and does not process sensitive personal information. There is therefore nothing to opt out of. We do not treat anyone differently for exercising a privacy right.

13. Deleting your data

Settings → Erase All SUCRE Data permanently deletes, from your device:

  • all recipes, and every cached recipe photo (including any left over from earlier deletions)
  • all collections
  • your entire shopping list
  • your entire meal plan
  • your bake history
  • your name and all preferences
  • onboarding and checklist progress
  • any shared link still waiting to be imported
  • all pending and already-delivered SUCRE timer notifications

SUCRE then returns to the state of a fresh installation. The action asks you to confirm first, tells you honestly if any part could not be deleted, and does not claim success unless every step completed.

Deleting the app from your device also removes this data.

As explained in section 7, your Apple purchases are not affected — this is deliberate, so that erasing your data never costs you a subscription you paid for.

Note that erasing local data cannot remove entries from server or hosting logs that were already written. Those logs do not contain your recipe content or the addresses you imported.


14. Security

Requests between the app and our server use encrypted HTTPS connections. Your recipe data is stored inside SUCRE's own app container, which iOS isolates from other apps. The Share Extension shares a single, private storage area with the app solely to hand over a link you chose to share; that value is removed as soon as it is used.

Links opened from outside SUCRE are validated against a strict list before anything happens, so a malformed or unexpected link cannot cause the app to act on it.

No system is perfectly secure, but we do not hold a database of user content, which substantially limits what any incident could expose.


15. Changes to this policy

If we change how SUCRE handles data, we will update this policy and change the date at the top. Significant changes — in particular any introduction of analytics, accounts, or cloud sync — will be described before they take effect.


16. Contact

privacy@sucreapp.com — privacy questions and data-protection requests support@sucreapp.com — help with the app

Hakim Bahdo, trading as Vitality Sphere Auf der Au 6, 54296 Trier, Germany

SUCRE

Save any recipe. Make it yours.

Contact

  • support@sucreapp.com
  • privacy@sucreapp.com

Legal

  • Privacy Policy (app)
  • Datenschutzerklärung (App)
  • Website Privacy
  • Website-Datenschutz
  • Legal notice / Impressum
  • Support

SUCRE is a product of Hakim Bahdo, trading as Vitality Sphere, Auf der Au 6, 54296 Trier, Germany. SUCRE is a brand, not a separate company.

© 2026 Hakim Bahdo. This site sets no cookies and runs no analytics.