Legal

Privacy Policy

Effective date: September 8, 2026  ·  Last updated: September 8, 2026

1. Introduction

Butler Technology Concepts, LLC d/b/a BBQuill ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, the sources we collect it from, how and why we use it, who we share it with, how long we keep it, and the rights you have over your personal information when you use our websites and mobile apps (the "Service").

The table in Section 4 is a summary "notice at collection": it lists the categories of personal information we collect, their sources, the purposes we use them for, the categories of recipients we disclose them to, and how long we keep each category. The sections that follow add detail.

2. Information We Collect

Categories of sources. We collect personal information from you directly; automatically from your device and browser; from payment platforms; and from analytics and infrastructure providers acting on our behalf. We have no third-party integrations to connect today (Section 10), so there is no connected service to collect from.

We collect information you provide directly:

  • Account information: email address, name (optional)
  • Approximate location — a general area, never a precise position — if you choose to share it, so we can show the weather around a cook
  • Cook records: dates and times, cooker and probe temperatures, wraps, spritzes, fuel additions, notes, and photos
  • Your equipment and pantry: cookers, thermometers, rubs, wood, sauces, and fuel
  • Files you upload: cook photos and chat images, which may include vendor, cost, and product details
  • Messages, prompts, and photos you submit to the AI assistant
  • Messages you send our support team, and the name and email address you give us when you do — you can contact support without an account, and if you do, that address is the only way we have to answer you
  • Payment information: subscriptions are processed by the app store or payment processor you buy through. We receive subscription and transaction status — not full payment card numbers
  • Usage and preference data: area unit preference, subscription status, and notification preferences

We also collect information automatically:

  • Log data: IP address, browser type, pages visited, timestamps
  • Device data: device type and operating system
  • Mobile push tokens: if you enable notifications in our mobile apps, a device push token used to deliver reminders and alerts
  • Cookies, product analytics, and similar tracking technologies (see Section 12)
  • Diagnostics: when the app crashes or hits an error, it sends us a report — the error, a stack trace, and where in the app it happened. In our mobile apps that report also carries your operating system and its version, the app version and build, which JavaScript engine it was running on, and whether it was running React Native's newer internal architecture; the web app sends none of that. Reports are recorded against your account so we can tell a problem that is yours from one everyone is hitting. Before a report is stored we replace any email address in it, and strip the path and query string from any web address; we cannot promise to catch every secret an error message might quote, so treat a stack trace as text we hold. Section 13 says how long we keep them.

Early-access list. While BBQuill is in private early access, you can ask to be notified when it opens. If you do, we collect:

  • Your email address, and your name if you choose to give one
  • Your IP address and browser user-agent at the moment you submit, kept as a record that the request came from you
  • Which page or button you signed up from, and any campaign parameters in the link that brought you to us — unless you have opted out of non-essential tracking, in which case we store none of them

We use it to email you when your access is ready, and occasionally to say what shipped. We do not sell or share it. Every message carries a one-click unsubscribe, which stops all email to that address; you can also email [email protected] to be removed from the list entirely. Entries we never invite, and entries that unsubscribe, are deleted automatically 18 months after you join. Note that an early-access entry is not an account — if you later create one and delete it, tell us if you also want the list entry removed.

Sensitive information. Of the information we handle, your account login credentials may be treated as “sensitive” under some laws. We use them only to provide and secure the Service. We do not sell sensitive information, use it to infer characteristics about you, or use it to profile you in furtherance of decisions that produce legal or similarly significant effects.

We do not ask for or use precise geolocation. Any location you choose to share is an approximate area, used to show local weather conditions around a cook — no feature needs to know exactly where you are, and none is planned. We never take a location from your photos either; see Section 8.

One honest qualification, because “we do not collect it” would be too strong: a photo you upload is stored as the file you chose, and a camera may have written GPS coordinates into that file before we ever saw it. Small images are stored exactly as sent rather than re-encoded, so those tags can persist inside the image. Apart from the capture time described in Section 8, we never use them, never index them, and never work out where you were from them — but they sit inside a file we hold, and saying otherwise would be inaccurate. Section 8 covers what we do and do not do with photo metadata.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and improve the Service
  • Personalize your experience and deliver relevant features
  • Generate cooking guidance and AI-powered suggestions
  • Analyze photos you upload when you ask the assistant about them
  • Provide local weather context for a cook
  • Deliver notifications, reminders, and weather-based alerts by email and mobile push
  • Process payments and manage your subscription
  • Send transactional emails (e.g., account confirmation, password reset)
  • Maintain security, prevent abuse, and troubleshoot problems
  • Comply with legal obligations and enforce our Terms of Service
  • Analyze aggregate usage patterns to improve the Service

4. Categories of Information We Collect, Use, and Disclose

This table summarizes, by category, what we collect, where it comes from, why we use it, who we disclose it to, and how long we keep it. "Disclose" here means sharing with service providers that process data on our behalf under contract; it does not mean we sell your information (see Section 11).

CategorySourcesPurposesCategories of recipientsRetention
Account & profile (email, optional name, preferences, consents)YouCreate and operate your account; authentication; support; identify you in our own product analytics unless you opt out (§12)Hosting & database providers; email delivery providers; product-analytics providersLife of your account; deleted on account deletion
Equipment & pantry (cookers, thermometers, rubs, wood, sauces, fuel)YouTrack what you cook on and with; tailor guidance to your setupHosting & database providers; AI providers when you use AI featuresLife of your account; deleted on account deletion
Cook records (cooks, items, probe & cooker temperatures, timeline entries, notes)YouMaintain your cook log and generate guidanceHosting & database providers; AI providers when you use AI featuresLife of your account; deleted on account deletion
Approximate location (only if you choose to share it)You; your device, with permission — never without itLocal weather conditions to put a cook in contextHosting & database providers; weather data providersLife of your account; deleted on account deletion
Uploaded files (cook photos, chat images — and, for a photo, the date and time it was taken, read from the file)YouVisual history of a cook; AI-assisted analysis when you request itHosting & storage providers; AI providers when you ask for analysisLife of your account; on account deletion the records go immediately and the stored images are queued for erasure by an hourly job
AI assistant & chat data (messages, prompts, generated guidance)You; generated by the ServiceProvide the AI Pitmaster and remember context within a conversationHosting & database providers; AI providersLife of your account (no automatic purge); deleted on account deletion
Payment & subscription status (status/entitlements only — card details stay with the processors)App stores and payment processorsManage your subscription and entitlementsApp stores and payment processorsTransaction records retained by the processors per their legal/tax obligations
Usage, device & log data (IP address, device/browser, events, analytics)Your device/browser; analytics SDKsSecurity, troubleshooting, and understanding/improving the ServiceProduct-analytics providers; hosting, CDN & edge-security providersOperational logs: up to 90 days, then deleted or aggregated. Analytics: see §13
Diagnostics (crash and error reports: the error, a stack trace, and where in the app it happened — plus, in our mobile apps, your operating system and its version, the app version and build, which JavaScript engine it ran on, and whether it was running React Native's new architecture)Your device or browser, automatically when the app hits an errorFind, diagnose and fix crashes and errors, and keep the Service workingHosting & database providers; email delivery providersRecorded against your account and kept 90 days from the last time we saw the same error, then deleted; deleting your account removes the link to you straight away
Marketing attribution (ad click identifiers such as gclid, utm_* campaign tags, and Google Ads conversion cookies)The URL you arrive on from an ad or campaign link; the Google Ads tag (gtag.js)Measure which ads/keywords lead to signups (ad effectiveness)Advertising-measurement providers, for our own ad-conversion measurement only, if and when we run adsAd-click cookies on your device: up to ~90 days (Google's default); the click ID kept with your signup: while your account is active. See §12
Push notification tokensYour device (when you enable notifications)Deliver reminders and alertsPush delivery providers, including your device platform's push serviceUntil you sign out or delete your account, or the token becomes invalid
Early-access list (email, optional name, signup IP & user-agent as consent record, campaign source)You, when you ask to be notified before launchTell you when your access is ready; occasional product updatesHosting & database providers; email delivery providers; bot-protection providersDeleted automatically 18 months after you join if never invited or if you unsubscribe; sooner on request
Support communications (your message, and the name and email address you give us — including when you have no account)YouRespond to your requests and keep support recordsHosting & database providers; email delivery providers; bot-protection providersUp to 24 months after your last message, unless we need it longer to resolve a dispute or meet a legal obligation
Social login identifiers (if you sign in with Google or GitHub)Google, GitHub (the provider you choose)Authenticate youAuthentication providers; the sign-in provider you chooseLife of your account; deleted on account deletion

5. Data Storage and Security

We host your data with cloud service providers — database, authentication and storage — and apply reasonable administrative, technical, and physical safeguards designed to protect personal information. These include Row-Level Security so each user can access only their own data, encryption in transit (TLS), and encryption at rest. Access to personal information is limited to personnel and service providers who need it to operate the Service.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. Service Providers and Subprocessors

We do not sell your personal information. We share it only with service providers that process it on our behalf under contract, and where required by law. By category of recipient:

  • Cloud hosting, database, authentication & storage
  • Web hosting, content delivery, edge security & bot protection
  • AI providers: the assistant and guidance, photo and document analysis when you ask for it, and AI-powered web and product lookups
  • Product analytics
  • Advertising measurement: conversion tracking for our own ad campaigns, if and when we run them — see Section 12
  • App stores & payment processors
  • Email & push notification delivery
  • Weather data (when weather ships — see Section 9)
  • Sign-in providers, if you choose to connect one
  • Fonts: self-hosted; no third-party font service is contacted

This policy commits to the categories above rather than to a fixed list of companies. We change vendors from time to time — adding one, replacing one, or dropping one within a category — and that does not change what we collect, why we collect it, who may see it, or your rights, so it is not a revision of this policy. Adding a new CATEGORY of recipient, or a new purpose, is a change to this policy and is handled the way Section 16 describes.

Want to know exactly which companies we use today? Email us at [email protected] and we will tell you.

We may also disclose information:

  • For legal requirements: when required by law or to protect our rights
  • In business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you

7. AI Features and Data Use

Butler Technology Concepts, LLC d/b/a BBQuill uses AI models (including third-party AI APIs) to generate cooking recommendations and to analyze photos you upload (such as an image of a cook in progress). Our AI subprocessors fall into two roles: the model providers behind the assistant and photo analysis, and a search provider for web and product lookups. When you use AI features, relevant portions of your cook data (e.g., your cookers and pantry, recent cooks, and any approximate location you have shared) and the photos you submit are sent to those providers to generate a response. Section 6 explains why this policy names roles rather than companies, and how to ask us which companies they are today.

We access these providers through their API/business tiers, and we rely on the data controls those tiers provide — under which your inputs and outputs are not used to train their models. Providers may retain content for a limited period to operate the service and to monitor for abuse or safety, as set out in their own terms; the exact period is theirs to state, not ours, and the personal information they receive remains governed by those terms. We do not use your content to train or fine-tune our own models, and we will not without asking you first.

Before any of your data is sent to an AI provider, we ask you to agree to a disclosure naming the providers and the data shared, and we record which version of that disclosure you agreed to. Until you do, AI features do not run — the check is enforced on our servers, not just in the app, so declining cannot be bypassed.

8. Photos and Media

Photos you upload are stored with our cloud storage provider and protected by the safeguards described in Section 5. They are used to help you track your cooks' visual history and, when you request it, for AI-assisted analysis. As with other content, photos may be processed by our storage and AI service providers acting on our behalf (see Sections 6 and 7); we do not otherwise share your photos with third parties.

Photo metadata (EXIF). When you add a photo from your device, BBQuill reads the metadata block your camera wrote into the file in order to find two things in it: the date and time the photo was taken, and the time-zone offset recorded alongside it when the camera wrote one. Reading the block is how those two are found, and that same block can also hold camera settings and, where your camera recorded them, GPS coordinates. We extract those two values for one purpose: to date the photo correctly in the cook's timeline, so a picture you took at the pit and added afterwards is filed at the moment you took it rather than the moment you added it.

What we keep is a timestamp. The capture time goes onto the photo's record. The record we create for a photo is short: which cook it belongs to, an optional caption, its file type and size, when it was added, and that capture time. The photo itself is stored as the image file you uploaded, and the metadata your camera wrote travels inside that file — Section 2 explains what that means.

We never work out where you were from a photo. If your camera wrote GPS coordinates into the file, BBQuill never extracts those coordinates, so it does not derive a location from them, does not copy them onto the photo's record, and no feature in the Service acts on them. The same is true of your camera's telemetry — the make and model of the camera, and the exposure settings it recorded. Nothing about a photo is used to determine where you were.

Note that the image file you upload may still contain the metadata your camera wrote into it, and photos large enough to be resized before upload are re-encoded, which typically discards it.

9. Location

BBQuill does not ask for your location today. Neither app requests a location permission, and nothing in the Service records where you are.

We describe it here because weather is a feature we intend to add: outdoor conditions change how a cook runs, and being able to look back at what the weather was doing is part of what a cook log is for. If and when that ships, this is the commitment it will be held to:

  • Approximate area only. Enough to know the weather where you are cooking — a general area, or a place you type in. We will not collect a precise position, because nothing we are building needs one.
  • Only if you choose to share it. It will be optional, and the Service will work without it.
  • Used for weather and the record of a cook — not for advertising, not sold, and not shared to build a profile of you.
  • Never derived from your photos. We never derive a location from image metadata; see Section 8.

Whatever we share with a weather provider to answer “what was it doing there?” is protected by the safeguards in Section 5.

10. Connected Services & Integrations

BBQuill currently offers no optional third-party integrations to connect. If we add any — for example a thermometer that reports readings automatically — this section will describe exactly what is exchanged with the provider, and connecting will always be your choice.

Any third-party service you connect in future is governed by its own privacy policy. We are not responsible for the privacy practices of services you choose to connect.

11. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights — for example under the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and similar U.S. state privacy laws (such as those in Virginia, Colorado, Connecticut, and Utah):

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict certain processing
  • Data portability (receive your data in a machine-readable format)
  • Withdraw consent where processing is based on consent
  • Opt out of the "sale" or "sharing" of personal information (see Section 12)
  • Not receive discriminatory treatment for exercising your rights

Some of these rights may not be available in every jurisdiction or may be limited where an exception applies — for example, where we must keep information to comply with a legal obligation, ensure security, or detect and fix errors.

How to exercise your rights. You can download your data at any time from Settings → Account → Export your data in the web app at bbquill.com — on a phone, open bbquill.com in a browser and sign in there. It is one JSON file holding your cooks and their timelines, cookers, pantry, cook plans, meals, recipes, reminders, Pitmaster conversations and your settings. Every file it references is listed, each with a one-hour download link when we can issue one; if we cannot issue one for a file, the export still lists it and marks it unavailable rather than failing (how to export your data). It is free on every plan. Your sign-in details — the email address and any linked provider — are held by our authentication provider rather than in that file, so ask us if you need them.

You can delete your account and data at any time in the app (see our deletion instructions), or contact us about any of the rights above at [email protected].

Verification. To protect your information, we verify requests using the email address associated with your account and, where needed, by asking you to confirm information we already hold. We will not use information you provide for verification for any other purpose.

Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written permission and may still ask you to verify your own identity directly.

Timing and appeals. We will respond within the time required by applicable law (generally 30–45 days), and we may extend that period where the law permits, with notice to you. If we decline your request, you may appeal by replying to our decision or emailing [email protected] with the subject "Privacy Appeal"; where applicable law provides, you may also contact your local data protection authority or attorney general.

12. Cookies, Analytics & "Do Not Sell or Share"

We use cookies and similar technologies in the following ways:

  • Strictly necessary / essential: session and security cookies needed for the Service to function (for example, to keep you signed in). These cannot be turned off through the Service.
  • Analytics: we use product-analytics tools to understand how the Service is used — which features are used and where users hit errors — so we can improve it.
  • Advertising measurement: we do not currently run any ad campaign, and the Google tag is not loaded. If we do run search ads, we measure which ads lead to signups using Google Ads conversion tracking — the Google tag (gtag.js). When you arrive from one of our ads, Google sets first-party cookies on your device (for example, _gcl_*) to remember the ad click (such as a gclid), and if you later sign up we report that as a conversion to Google Ads. We also read the click identifier and any utm_* campaign tags from the URL for the same measurement in our product analytics. We would use all of this solely to measure which of our own ads led to signups. For visitors who have not opted out, loading the tag sends Google a measurement signal — the page load and the ad-click cookie — in addition to the later signup conversion; we instruct Google to treat it as non-personalized, and we do not build advertising profiles or audiences, retarget you, or serve personalized ads across other sites.

We do not use cookies or analytics for cross-context behavioral advertising, we do not serve targeted or personalized ads, and we do not sell your personal information, as those terms are defined under California and other U.S. state privacy laws. The limited conversion-measurement reporting described above is used only to gauge the effectiveness of our own ads — not to advertise to you — but depending on your state it may be considered “sharing.” The Your Privacy Choices control below — and the Global Privacy Control browser signal — stop the Google tag from loading on your device, so no measurement or conversion data is sent. You can also email [email protected] and we will exclude you from ad-conversion reporting. You can manage personalized Google advertising in Google’s Ad Settings.

You can control cookies through your browser settings; for general information about cookies and how to manage or disable them, visit allaboutcookies.org. You can opt out of non-essential analytics and ad-conversion sharing using the Your Privacy Choices control below, in the mobile app under Settings → Privacy, or by emailing [email protected]. While you are signed in, the choice is saved to your account and applies everywhere you sign in, including the mobile app; made while signed out, it applies to that browser or device. We honor the Global Privacy Control (GPC) browser signal: when your browser sends a GPC signal, we automatically treat you as opted out of non-essential analytics and ad-conversion sharing. Disabling certain cookies may prevent parts of the Service from working.

Your Privacy Choices

You can opt out of non-essential product analytics and the ad-conversion measurement (the “sharing” described above). Strictly necessary cookies that keep you signed in and the Service secure are not affected.

This choice is saved on this browser. Sign in to apply it to your account and every device you use, or enable Global Privacy Control in your browser. You can also email [email protected].

13. Data Retention

We keep personal information for as long as your account is active or as needed to provide the Service, then delete it as described below. Retention by category is also summarized in the table in Section 4.

  • Account and content data (profile, cookers, cook history, AI chats): kept for the life of your account. We do not automatically purge this data; when you delete your account it is deleted immediately and permanently from our live systems.
  • Uploaded images (cook photos, chat images): the records that point at them are deleted with your account immediately, which makes the images unreachable from the Service straight away. The stored files themselves are erased by a separate scheduled job rather than in the same request. That job runs hourly, so erasure normally follows within hours; the guarantee we can actually make is the structural one — by design no image outlives that job's next successful run.
  • Backups: residual copies in routine, encrypted backups are purged on our normal backup-rotation schedule, no later than 90 days after deletion.
  • Operational and security logs (request and rate-limit records including IP address, and the diagnostic reports described in Section 2): kept for up to 90 days for security and troubleshooting, then deleted or aggregated. A diagnostic report is kept for 90 days from the last time we saw the same error, so a fault that keeps happening stays visible while it is still happening; deleting your account removes the link between those reports and you straight away. Two things sit outside that window, and we would rather name them than round them off: the counters behind rate limits and assistant quotas, which last as long as the window they count plus a margin — a few days for the daily ones, a few months for the monthly assistant-usage counters — and which hold no message content; and the early-access signup consent record, whose own period is in the Section 4 table.
  • Product analytics: analytics events are linked to an identifier for your account while your account is active. When you delete your account, we also ask our analytics provider to delete your analytics profile on a best-effort basis; aggregate, de-identified metrics that are not linked to you may remain. You can also ask us to delete your analytics data by emailing [email protected].
  • Billing and subscription records: if you purchased a subscription, our payment processors retain transaction records as required for tax, accounting, and fraud-prevention purposes.
  • Support communications: if you contacted support, we keep your message and the name and email address you gave us in our own systems — for up to 24 months after your last message, unless we need it longer to resolve a dispute or meet a legal obligation. You can contact support without an account, and if you do, that address is the only way we can reach you. Deleting your account unlinks your tickets from it but does not remove the messages; you can ask us to delete them by emailing [email protected].
  • Legal holds: we may retain limited information where required to comply with a legal obligation or to resolve a dispute.

For step-by-step deletion instructions, see our account & data deletion page.

14. International Data Transfers

We are based in the United States, and our service providers may process and store your information in the United States and in other countries where they operate. These countries may have data-protection laws that differ from those in your jurisdiction. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers of personal information out of your region.

15. Children's Privacy

The Service is intended for adults and you must be at least 18 years old to create an account. The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18, including children under 13 as defined by the U.S. Children's Online Privacy Protection Act (COPPA). If you believe a minor has provided us with personal data, please contact us and we will delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the effective date and last-updated date above. If you have an account, material changes will be communicated by requiring re-acceptance upon your next login.

17. Complaints

If you have a complaint about how we use your personal information, please contact us first at [email protected] so we can try to resolve the issue. If you are in the European Union or the United Kingdom, you also have the right to lodge a complaint with your local data-protection regulator (for example, the UK Information Commissioner's Office). California residents may contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210 or (916) 445-1254.

18. Contact Us

If you have questions or concerns about this Privacy Policy, contact us at: [email protected].