Kitchen Kiosk

Privacy policy

Effective September 20, 2026

Kitchen Kiosk is a wall display for a family kitchen and the companion phone app that manages it (together, "Kitchen Kiosk"). It is operated by an individual developer ("we", "us"), not a company, for a single household and the people that household invites. There is no advertising business behind it: your data is never sold, rented, or used to target ads.

What we collect

Account information

Your email address and a password, held by Amazon Cognito. Cognito stores the password as a salted hash; we never see it. We also keep an internal sign-in identifier and the display name you chose, tied to your household.

What the household puts in the app

Google Calendar (only if you connect it)

When you choose to connect a Google account, Kitchen Kiosk requests exactly one Google permission: https://www.googleapis.com/auth/calendar.readonly. It is read-only: we cannot create, change, or delete anything in your Google account. We do not request your profile, your email address from Google, or your contacts. From that permission we receive and store:

Technical information

The backend's Lambda functions write ordinary application logs: errors and sync progress, which can include your account's internal identifier and counts of events. Logs are kept for 30 days. The apps and the backend include no analytics, advertising, crash-reporting, or tracking libraries, and set no advertising identifiers.

On your own devices

The companion app keeps your sign-in tokens in the phone's secure storage and a cache of the household's board on the phone. A wall display keeps its device token and the same kind of cache in its own storage. Removing the app, or wiping the display, removes them.

How we use it

That is the whole list. We do not profile you, sell data, or build advertising audiences.

AI processing

Kitchen Kiosk does not send your calendar, notes, chores, or any other content to an AI model, and none of it is used to train one.

Who else touches the data

These are the services that process data on our behalf or that the app talks to:

We disclose data to no one else unless the law requires it. There is no corporate parent, investor, or data broker to share it with; if the project is ever handed to someone else, you will be told before your data moves.

Google API Services — limited use

Kitchen Kiosk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely: calendar data is used only to display your own schedule in Kitchen Kiosk. It is not transferred to anyone except as needed to provide that feature, is never used for advertising, is never sold, and is never used to train, improve, or personalize AI or machine-learning models. No person reads it except when you ask us to help with a specific problem, or where the law requires it.

Storage, security, and location

The database is in the United States (AWS us-east-1); the backend and sign-in run in the United States (AWS us-east-2). Everything travels over HTTPS. The apps reach the backend with short-lived access tokens; a wall display reaches it with its own device token. The database connection string and Google's client secret are sealed with AWS KMS and are never in the code or in plaintext configuration; the Hearth grant is additionally encrypted inside the database. Google's access and refresh tokens are stored in the database without a separate layer of encryption, and access to the database is limited to the backend and its operator. No system is perfectly secure, and we cannot promise otherwise.

Keeping and deleting

Your choices

You can see what is on the board at any time, edit or delete it, connect or disconnect Google Calendar whenever you like, and ask us for a copy of what we hold about you at zdean94@gmail.com.

Children

Kitchen Kiosk is not directed to children under 13, and children do not have accounts. An adult may add a child's first name, age, and chores to the household board; that is information the adult chose to put on their own household's board, where the household's members and the wall display can see it. We do not knowingly collect information from a child directly. If you believe we have, write to us and we will delete it.

Changes

If this policy changes, the effective date above changes with it, and a material change will be announced in the companion app before it takes effect.

Contact

zdean94@gmail.com