← Back to Sacred Donuts

Privacy Notice

Clear boundaries for a small food community.

Last updated August 28, 2026 · Measurement notice version 2026-08-26-v2

What Sacred Donuts handles

Sacred Donuts handles the account information needed to sign you in, the public profile and food content you choose to publish, and the operational records needed to run and protect the service.

For a small invited cohort, Sacred Donuts also uses limited first-party product measurement to understand whether people activate, publish reliably, return, discover food, and start a share.

Sacred Donuts uses Vercel Web Analytics on Production pages to understand daily site reach. This separate service supplies anonymous page-view and daily visitor totals. It is not joined to Sacred Donuts accounts or first-party product events.

What product measurement records

The measurement system can record bounded events such as account creation, completion of a public handle, a signed-in session, a publish attempt and outcome, a photo-attachment outcome, opening a named product surface, and starting a share.

Events use a random pseudonymous actor ID. The private map between that ID and an account is stored separately and is available only to the service.

What product measurement does not record

Measurement events do not contain your email address, public handle, captions or notes, photo files or paths, search text, precise location, raw page parameters, raw IP address, or raw browser user-agent string.

Neither the first-party measurement system nor Vercel Web Analytics uses analytics cookies or a persistent anonymous visitor ID. Vercel derives an anonymous visitor hash that resets daily. Sacred Donuts does not use session replay or advertising trackers.

Before a page view is sent to Vercel, Sacred Donuts removes query strings and fragments, allows only known public routes, drops unknown and private routes, and replaces city, invite, account, content, and catalog identifiers with redacted route patterns.

Vercel may aggregate the redacted route pattern, timestamp, referring URL or origin, general location, device type, operating system, and browser. Sacred Donuts strips its own page paths when one of its pages is the referrer. An external referring page may supply its path according to that site’s browser policy. Sacred Donuts receives aggregate traffic counts, not an identity or a visitor-to-account link.

Purpose and access

The measurements are used only to evaluate site reach, activation, posting reliability, retention, and discovery during the MVP. They are not used for advertising or sold to another company.

Approved Sacred Donuts operators can view restricted exact-count summaries, including the daily anonymous visitor count. For account-growth review, they can also see the account or attempt time, current confirmation state, and a public handle when one has been claimed. The operator view does not show email addresses, provider identities, raw account or measurement IDs, private content, or individual product activity. Ordinary accounts cannot access the operator view, and raw events are not available through it.

Private beta feedback

When you send the in-product beta feedback form, Sacred Donuts privately stores your message and any screenshot you choose to attach. Approved operators can review it, and an email notification may alert them that new feedback arrived.

Feedback includes your public handle when available, the product route, a general device and browser class, the app environment and build, the time, and whether you permit follow-up. It does not include your email address, precise location, raw browser user-agent string, or unrelated photo-library content.

Feedback and screenshots stay linked to your account and are removed when that account is deleted. Screenshots are stored in a private bucket, and approved operators open them through short-lived links in the restricted inbox.

The new-feedback email contains only the feedback category, submission time, app environment, and a link to the restricted inbox. It does not contain your message, screenshot, public handle, product route, or device details.

Retention, exclusion, and deletion

Raw measurement events, including excluded test evidence, are retained for 90 days. Recognizable bots, test accounts, fixtures, seed data, and non-organic archive or official content are excluded from product counts.

Vercel filters recognizable automated traffic and provides a 12-month Web Analytics reporting window for the current Pro plan. Its daily visitor hash expires after 24 hours. Vercel may retain aggregated data longer under its published plan terms.

If a Sacred Donuts profile is deleted, its private measurement mapping and associated raw events are deleted with it. First-party raw measurement data is not exported through the operator dashboard. Vercel Web Analytics is anonymous and is not connected to the profile deletion path.

Requests and changes

During the directly supported invited cohort, use the private invitation or support channel through which you received access to request account-data access, export, correction, or deletion. A durable public privacy contact is required before Sacred Donuts expands beyond that directly supported cohort.

If this notice, the event dictionary, retention period, access model, or measurement provider changes materially, Sacred Donuts will update this notice before using the changed system.