Privacy policy
Effective September 20, 2026
Kitchen Kiosk is a wall display for a family kitchen and the companion phone app that manages it (together, "Kitchen Kiosk"). It is operated by an individual developer ("we", "us"), not a company, for a single household and the people that household invites. There is no advertising business behind it: your data is never sold, rented, or used to target ads.
What we collect
Account information
Your email address and a password, held by Amazon Cognito. Cognito stores the password as a salted hash; we never see it. We also keep an internal sign-in identifier and the display name you chose, tied to your household.
What the household puts in the app
- The household's name and the people on the board: a first name, an optional age, a color, and whether each is an adult or a child. Adults enter this for their children; children do not sign in.
- Chores (titles, which days, who they are assigned to or rotate between) and the dates they were checked off.
- Family notes: the text, who posted it, and when it was checked off.
- Display settings, and each paired wall display's name, the time it last connected, and a device token, which we store only as a SHA-256 hash.
Google Calendar (only if you connect it)
When you choose to connect a Google account, Kitchen Kiosk requests exactly one Google
permission:
https://www.googleapis.com/auth/calendar.readonly. It is read-only: we
cannot create, change, or delete anything in your Google account. We do not request your
profile, your email address from Google, or your contacts. From that permission we
receive and store:
- The list of calendars your account can read: each one's name and Google's identifier.
- For the calendars you switch on, their events: title, description, location, start and end, whether it is an all-day event, and its status. We do not store attendees or attachments. A calendar's history is synced back about 90 days, and its upcoming events follow as they change.
- The OAuth access and refresh tokens Google issues to us, kept in the same database as the rest of the household's data, and the records of the push-notification channels we open with Google so we hear about changes.
Technical information
The backend's Lambda functions write ordinary application logs: errors and sync progress, which can include your account's internal identifier and counts of events. Logs are kept for 30 days. The apps and the backend include no analytics, advertising, crash-reporting, or tracking libraries, and set no advertising identifiers.
On your own devices
The companion app keeps your sign-in tokens in the phone's secure storage and a cache of the household's board on the phone. A wall display keeps its device token and the same kind of cache in its own storage. Removing the app, or wiping the display, removes them.
How we use it
- To show the household its own calendar, chores, meals, and notes on the wall and in the companion app.
- To keep the service working and secure, and to reply when you write to us.
That is the whole list. We do not profile you, sell data, or build advertising audiences.
AI processing
Kitchen Kiosk does not send your calendar, notes, chores, or any other content to an AI model, and none of it is used to train one.
Who else touches the data
These are the services that process data on our behalf or that the app talks to:
- Amazon Web Services (Ohio, us-east-2) — the backend runs on AWS Lambda behind API Gateway; sign-in is Amazon Cognito; a message queue (SQS) carries Google's change notifications, which name a user and a calendar but contain no event content; AWS KMS protects the keys that seal our secrets; CloudWatch holds the logs.
- Neon (AWS, N. Virginia, us-east-1) — the managed PostgreSQL database that holds everything listed above.
- Google — the source of your calendar data if you connect it, through the Google Calendar API.
- Hearth, a recipe app run by the same developer — if the household connects it, the backend keeps an encrypted grant and asks Hearth for today's meals and the shopping list when the wall needs them. That content is fetched on demand, not stored here.
- The U.S. National Weather Service (api.weather.gov) — a wall display requests the forecast for one fixed location directly from NWS. No account or household data is sent, though NWS sees the display's IP address, as any website does.
We disclose data to no one else unless the law requires it. There is no corporate parent, investor, or data broker to share it with; if the project is ever handed to someone else, you will be told before your data moves.
Google API Services — limited use
Kitchen Kiosk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: calendar data is used only to display your own schedule in Kitchen Kiosk. It is not transferred to anyone except as needed to provide that feature, is never used for advertising, is never sold, and is never used to train, improve, or personalize AI or machine-learning models. No person reads it except when you ask us to help with a specific problem, or where the law requires it.
Storage, security, and location
The database is in the United States (AWS us-east-1); the backend and sign-in run in the United States (AWS us-east-2). Everything travels over HTTPS. The apps reach the backend with short-lived access tokens; a wall display reaches it with its own device token. The database connection string and Google's client secret are sealed with AWS KMS and are never in the code or in plaintext configuration; the Hearth grant is additionally encrypted inside the database. Google's access and refresh tokens are stored in the database without a separate layer of encryption, and access to the database is limited to the backend and its operator. No system is perfectly secure, and we cannot promise otherwise.
Keeping and deleting
- The household's chores, notes, and people stay until someone deletes them. Chores and notes can be deleted in the companion app at any time.
- Switching off a calendar in the companion app stops syncing it and deletes the events we stored from it.
- Disconnecting Google Calendar (Kiosk tab → Sources → Disconnect Google Calendar) stops the notification channels with Google, deletes your calendars and every event we stored, deletes your Google tokens, and revokes our access with Google. It does not touch the rest of your account. You can also revoke access yourself from your Google Account's third-party access page; that stops future syncing, and the stored copy stays until you disconnect in the app or ask us to delete it.
- Deleting your account or the household's data. There is no delete button in the app yet. Write to the address below and we will delete your login, your Google connection and calendar data, and, if you ask for the whole household, its people, chores, and notes, within 30 days. Data removed from the database can remain in the database provider's short point-in-time history for a few hours (currently six) before it is gone for good.
- Logs roll off on their own after 30 days.
Your choices
You can see what is on the board at any time, edit or delete it, connect or disconnect Google Calendar whenever you like, and ask us for a copy of what we hold about you at zdean94@gmail.com.
Children
Kitchen Kiosk is not directed to children under 13, and children do not have accounts. An adult may add a child's first name, age, and chores to the household board; that is information the adult chose to put on their own household's board, where the household's members and the wall display can see it. We do not knowingly collect information from a child directly. If you believe we have, write to us and we will delete it.
Changes
If this policy changes, the effective date above changes with it, and a material change will be announced in the companion app before it takes effect.