Your kitchen, your data. Here's what we hold.
What goes into Sugo, what we do with it, who else touches it, and how to get it back or get it deleted. Plain language, no legalese padding.
Who we are
Sugo is made by Sugo Kitchen Co., based in Oakland, California, United States. We are the controller of the information described on this page. For anything about it, including access and deletion requests, write to hello@sugo.kitchen.
This policy covers the Sugo app and the sugo.kitchen website. The rules for using Sugo are on the terms page.
Who Sugo is for
Sugo is intended for people 13 and older. We don't knowingly create accounts for, or collect information from, children under 13.
Some countries in the EU and UK set the age of digital consent higher, up to 16. Where that applies, use Sugo only if you meet the age where you live, or have your parent or guardian agree for you. If you believe a child has signed up, email hello@sugo.kitchen and we'll remove the account.
What we collect
Account data: your email address, sign-in identifiers, and any profile details you add, such as name, avatar, and the household you belong to.
Content you put in: recipes you import or write, photos and screenshots you upload, pantry items, meal plans, shopping lists, cookbooks, notes, ratings, cook-party photos, your messages to the cooking assistant, and your messages to support.
Imports: when you import from a link, we fetch that page. When you upload a photo, screenshot, or document, we process that file to pull the recipe out of it.
Bringing a library over from another recipe app: if you migrate your library from another recipe app, how that works depends on the app. Some are imported from an export file you choose, and nothing about your account there ever reaches us. Others have no export, so you sign in through Sugo instead: your password for that app is sent to their sign-in service once, exchanged for an access token, and then discarded. We never store your password for another app, and we never store their access token in our database: it is encrypted and held by your device for the couple of hours the migration takes. We record that you confirmed the account is yours, and which app it was for, and nothing else about it. We are not affiliated with, or endorsed by, any of those apps.
Audio and voice: the cooking assistant and hands-free cook mode use your microphone while they are listening, and a cook party carries live voice between the people in it. Separately, if you turn on the setting that helps "Hey Sugo" improve, which is off unless you switch it on, Sugo uploads short clips of about two seconds recorded around the wake word and uses them to improve its wake-word model. Those clips go to private storage, tagged with your account so we can find and delete them on request. The voice profile that recognises you is built and kept on your device and is never uploaded.
Camera and face detection: photos you take of recipes and pantry items, and camera video during a cook party if you turn your camera on. If you turn on hands-free cook mode, Sugo reads the camera to spot a wink, a mouth opening, or where your eyes are pointed, so you can move through steps without touching the screen. That analysis happens entirely on your device. No face data, facial geometry, or camera imagery is uploaded or stored for it, and the feature is off unless you switch it on. The section below sets out exactly what is read and what happens to it.
Diagnostic data: app version, device type, language, crash reports, performance traces, and basic usage events, so we can fix bugs and see which features earn their place.
Website data: sugo.kitchen uses cookieless analytics to count page views. The site sets one cookie, sugo_locale, and only once you pick a language, so it remembers your choice. There are no advertising or cross-site tracking cookies.
Face data and the TrueDepth camera
Hands-free cook mode lets you move through recipe steps with a wink, by opening your mouth, or by looking towards the edge of the screen, so you can keep cooking with dirty hands. On an iPhone or iPad that has one, this uses Apple's ARKit face tracking, which runs on the TrueDepth camera. On Android it uses on-device face detection through Google's ML Kit. This section describes that feature and nothing else.
The feature is off until you turn it on. Turning it on takes you through a short setup that explains what it does, asks for camera permission, and asks you to perform a wink and a mouth-open so you can see for yourself what is being read. It runs only while you are on a recipe's cook mode screen with the feature enabled, and it stops the moment you leave that screen or switch away from the app.
What is read: how closed each of your eyelids is, how far your jaw is open, and the direction your eyes are pointed relative to your head. These arrive as numbers describing movement. Sugo does not build, request, or receive a face map, a depth map, or any other model of the shape of your face.
Where it is processed: entirely on your device, and only in memory. No camera frame is displayed, recorded, written to storage, or sent anywhere. Nothing derived from the camera leaves your device. Sugo has no server-side component for this feature and could not receive this data if it wanted to.
How long it is kept: it is not kept. Each reading is used to decide whether a step should advance and is discarded immediately. Nothing about your face is stored on your device, in your account, or on our servers. The only thing saved is a setting recording that you switched the feature on, which stays on that device and is never attached to your account.
Who it is shared with: nobody. Face data is never shared with, sold to, or disclosed to any third party. It is never used for advertising or marketing, never used to identify or authenticate you, never matched against any other person, and never used to train AI models, ours or anyone else's. It is not shared with the AI providers listed above, who receive no camera data at all.
How to turn it off: switch off the hands-free chip at the top of the cook mode screen, or withdraw camera access for Sugo in your device settings. Either one stops it immediately, and Sugo keeps working normally without it. You can also revoke camera permission without ever having turned the feature on.
Face ID and biometrics
Sugo does not use Face ID, Touch ID, or any other biometric authentication, and does not ask your device to verify who you are. The face tracking described above is a motion sensor for hands-free cooking, not a way of recognising you: it cannot tell one person from another, and it creates no biometric template, faceprint, or identifier of any kind.
Because nothing identifies you, there is no face record to request, correct, or delete. If you want the feature to stop, turning it off is the whole of it.
What we don't collect
We don't collect precise location, your contacts, health records, or card numbers. Payment details go straight to the app store or the payment processor and never reach us.
We don't sell your information, we don't share it with advertisers or data brokers, and we don't use cross-app tracking identifiers, which is why iOS App Tracking Transparency doesn't apply to Sugo.
How we use it
To run the features you're using: parse imported recipes, match ingredients against your pantry, suggest substitutions, build shopping lists, drive cook mode, run cook parties, render shared cookbooks for the people you invite, and answer your support requests.
To keep Sugo working: diagnose crashes, measure performance, prevent abuse, and apply the limits that come with your plan.
To improve Sugo: understand which features get used, and, only if you opt in, improve the "Hey Sugo" wake-word model using the voice clips described above.
We do not use your recipes, photos, or messages to train general-purpose AI models, ours or anyone else's.
AI features
Several features send the relevant content to AI providers so they can do their job: pulling a recipe out of a link, photo, or video; the cooking assistant; substitution and dish suggestions; ingredient lookups; and generated cover art.
The providers we currently use for this are OpenAI, Groq, and Cerebras. Live cook-party audio and video runs through LiveKit.
These providers act on Sugo's behalf under contracts that limit them to processing content for us. Where a provider offers terms that keep your content out of their own model training, we take those terms.
AI features are optional. The rest of Sugo works without them, and AI output can be wrong: see the terms page for what that means when you're actually cooking.
Who else processes your data
Google Cloud: hosting, database, and file storage, in the United States.
Supabase: account sign-in and authentication.
OpenAI, Groq, Cerebras: the AI features described above.
LiveKit: live audio and video during a cook party.
RevenueCat and Stripe: subscription management, and payments for subscriptions bought directly from us.
Apple and Google: app distribution, push notifications, and payments for subscriptions bought through their stores.
PostHog: first-party product analytics and session diagnostics. Not shared with ad networks.
Sentry: crash and performance monitoring.
Resend: transactional email, such as your sign-in link.
Vercel: hosting and cookieless analytics for the sugo.kitchen website.
Sharing and visibility
You choose what to share. Cookbook sharing, household membership, cook parties, and any public share link you create are visible to the people you invite, or to anyone holding the link. If you make something public, treat it as public.
Everyone in a household can see and edit the recipes, pantry, plans, and lists shared with it. Removing someone stops their access from that point on. It does not unsee what they already saw, and it does not reach copies they made.
How long we keep it
Your content stays until you delete it or close your account.
Delete your account from Settings → Account → Delete account. That removes your recipes, pantry, plans, shopping lists, cookbooks, notes, and profile from the live service within 30 days. Encrypted backups roll off within 90 days. If you'd rather we did it for you, email hello@sugo.kitchen and we'll handle it on the same timeline.
If you contributed wake-word clips, email hello@sugo.kitchen and we'll purge the clips tied to your account.
Some records outlive the account where the law requires it, such as payment and tax records held by our payment processors.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Deletion is self-service in Settings → Account. For anything else, email hello@sugo.kitchen and we'll respond within 30 days.
If you're in the EU or UK, the GDPR applies. Our legal bases are: performing our contract with you, for the features you asked for; legitimate interests, for keeping Sugo secure and working; your consent, for the optional wake-word clips and any marketing email; and legal obligation where one applies. You can withdraw consent at any time in the app, and you can complain to your local data-protection authority.
If you're in California, the CPRA applies. We do not sell or share personal information as those terms are defined there, and we won't treat you differently for exercising your rights.
Where your data is processed
Sugo's servers are in the United States, and the providers listed above process data there and in other countries. If you use Sugo from outside the United States, your information is transferred there.
For transfers out of the EU, UK, and Switzerland we rely on the European Commission's standard contractual clauses, or on a provider's own certification where it has one.
Security
Data is encrypted in transit and at rest. Access to production systems is limited to people who need it. Sensitive files, including voice clips and private images, are held in storage that cannot be served publicly.
No service can promise perfect security, and we won't pretend otherwise. If we ever have a breach affecting your data, we'll tell you and the relevant regulator as the law requires.
Changes
If we change anything material here, we'll update the effective date at the top and tell you in the app or by email before it takes effect. The current version always lives at sugo.kitchen/privacy.
Contact
Questions, access requests, deletion requests, or anything else: hello@sugo.kitchen.
Sugo Kitchen Co., Oakland, California, United States.
Put one good dinner on the table.
Sugo is on the App Store for iPhone, iPad and Mac, on Google Play for Android, and in any browser at app.sugo.kitchen. It is free to start, so start saving the recipes you actually cook.