Privacy Policy
Last updated:
This policy describes what SushiFlow does with personal data. It describes the service as it actually works today: a free tool with no payments, no advertising and no analytics or tracking scripts of any kind.
1. Who runs SushiFlow
SushiFlow is operated by Serhii Turchyn, an individual based in Ukraine (“we”, “us”). There is no registered company behind the service at present, so the operator is the controller of the personal data described here and is personally answerable for it.
Questions about this policy, requests about your data, and complaints: hello@sushiflow.app.
2. What we collect
- Account data — your email address, your name and picture if your profile has them, and which sign-in method you used. Accounts are handled by our authentication provider, Clerk. We never see or store your password.
- What you create in the app — ingredients, rolls, sets, categories, your own purchase prices, saved items, and any photos you upload. Each record is stored against your user id, which is how the app knows it is yours.
- Kitchen display data — if you mint a tablet link, we store the link token, a hash of the PIN you set (never the PIN itself) and a count of failed attempts so the tablet can lock after repeated failures.
- Technical data — IP address, browser and request logs kept by our hosting provider for security and debugging, plus the device and sign-in records Clerk keeps to protect your account.
We collect nothing about your restaurant’s customers, and the app has no field intended for that. Please do not put other people’s personal data — staff, customers, suppliers’ employees — into free-text fields or photos. Those fields are not built for it and this policy does not cover it.
3. Why we use it, and on what basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Running your account and storing your recipes and costings | Account data, your content | Performance of a contract — Art. 6(1)(b) |
| Keeping accounts and kitchen tablets secure: sign-in, PIN lockouts, abuse handling | Account, technical and kitchen display data | Legitimate interests — Art. 6(1)(f) |
| Showing content you chose to publish in the public catalogue, labelled with your display name | Display name, the published content | Your consent, given by publishing — Art. 6(1)(a) |
| Reviewing published submissions before they appear to others | The published content and its author id | Legitimate interests — Art. 6(1)(f) |
| Answering your emails | Whatever the email contains | Legitimate interests — Art. 6(1)(f) |
| Meeting legal obligations if we are required to | As required | Legal obligation — Art. 6(1)(c) |
We do not profile you, do not make automated decisions with legal effect about you, do not run advertising, and do not sell or rent personal data to anyone.
4. What becomes public when you publish
Everything you create is private to your account by default. Publishing a roll or a set is an explicit choice, and it makes that item visible to anyone — including visitors who are not signed in — and eligible to be indexed by search engines, because published items are listed in our sitemap. Published items are labelled with your display name from your account.
You can unpublish or delete an item at any time and it leaves the catalogue. Search engines may hold a cached copy for some time afterwards, which is outside our control.
5. Who else handles the data
We use a small number of providers to run the service. They process data on our instructions only, under their own data processing terms.
| Provider | What it does | Where |
|---|---|---|
| Clerk | Accounts, sign-in, sessions, account security records | United States |
| Neon | The PostgreSQL database holding your content | The region the database is hosted in |
| Amazon Web Services (S3) | Storage for images you upload | The AWS region of our bucket |
| Vercel | Hosting, content delivery and request logs | Global edge network |
Some of these are outside Ukraine and the EEA. Those transfers rely on the providers’ standard contractual clauses or equivalent safeguards. We share data with no one else, except where the law obliges us to.
7. How long we keep it
Your account and your content are kept until you delete them. Settings offers both “delete all my content” and “delete my account”. Deleting the account removes the account record at Clerk and purges your rolls, sets and ingredients along with the images they used, whether you delete it from inside the app or from your account portal.
One honest exception: if something you made is in use by content that is not yours — an ingredient inside somebody else’s published roll — the automatic purge stops rather than breaking their recipe, and the removal is completed by hand. In that case your data can survive a short time beyond your deletion request.
Hosting and authentication logs expire on our providers’ own schedules, typically within weeks. Database backups roll off on their own cycle.
8. Your rights
Under the Ukrainian Law on Personal Data Protection and, where it applies, the GDPR, you have the right to:
- know what data we hold about you and get a copy of it
- correct anything inaccurate — most of it you can edit yourself in the app
- have your data erased
- restrict or object to certain processing
- receive your data in a portable format
- withdraw consent, for example by unpublishing content you had published
Most of this you can do directly in Settings. For anything else, email hello@sushiflow.app — we answer within 30 days.
If you think we have handled your data wrongly, you can complain to the Ukrainian Parliament Commissioner for Human Rights, or — if you are in the EEA — to your local data protection authority.
9. Security
The site is served over HTTPS. Passwords and two-factor authentication are handled by Clerk and never reach our servers. Kitchen tablet PINs are stored only as hashes, the tablet’s cookie is cryptographically signed and can be revoked from the app, which invalidates every tablet you provisioned at once.
No service is perfectly secure. If you find a vulnerability, please email hello@sushiflow.app rather than disclosing it publicly, and we will fix it as fast as we can.
10. Children
SushiFlow is a professional tool for people working in food service and is not intended for children. We do not knowingly collect data from anyone under 18. If a child’s data has ended up here, tell us and we will delete it.
11. Changes to this policy
We will update this page and change the date at the top when anything changes. Significant changes will also be announced in the app. Continuing to use SushiFlow after a change means the updated policy applies to you.