Privacy Policy
What Skillet collects about you, why, who else sees it, how long it is kept, and how to have it deleted.
Effective October 1, 2026
The short version
- Skillet is a tool restaurants use to run their kitchens. If you use it, it is almost always because your employer, or a restaurant you do work for, invited you.
- Most of what it holds is a record of work: a workflow run, a temperature reading, a photo of a cleaned hood, a note. That record says who did the work and when, because a record that cannot say that is not worth much to an inspector or an insurer.
- The Mobile app reads your location once, when you start a workflow run, and never in the background. You can say no and keep working.
- We do not sell personal information. We do not show ads. We do not track you across other apps or websites.
- You can delete your account from inside the app. The work you recorded stays with the restaurant, without your name on it.
Who we are, and whose data this is
Skillet is run by Aaron Lozhkin ("Skillet", "we", "us"). This policy covers the Skillet Mobile app for iPhone, the Skillet website and Console, and the pages anybody can open without an account: the page a QR code opens, the form for notes from outside, and the vendor check-in page.
Inside a restaurant's account, the restaurant decides. Each restaurant that uses Skillet (an "organization") decides who to invite, which workflows to run, what to record and how long to keep it. For that information we act as the organization's service provider, or processor: we store it and work on it only to run Skillet for them. Your employer's own privacy notice covers how it uses the records it keeps about your work, and questions about those records are best sent to your employer first. We will help them answer.
For your account itself, we decide. We are responsible (the controller) for your sign-in, security records, our own emails to you, the website, and anything you send us directly, such as a support email or a request for a demo.
What we collect
Your account. Your name, email address and, if you add them, a phone number and a profile picture. Your language, time zone and date format. Your password is stored only as a one-way hash, and sign-in codes are kept for a day. If your organization signs in through its own identity provider (single sign-on), we receive the identifier it gives us.
What your organization records about your job. Your role, whether you are an employee, a contractor or a vendor, which locations and teams you belong to, and who you report to. If your organization uses them, your shift hours, and your hourly rate and logged minutes for labor costs.
The work you do. The work orders you are given, each workflow run you start and finish and when, every answer you give (readings, choices, typed text), the photos, videos, files and signatures you add, notes, messages and reactions in the Inbox, and the reason when you say "I can't do this". Photos come from your camera, or from your photo library when you choose one.
Where you were, once per workflow run. When you start a workflow run in the iPhone app, it asks the phone for your location once, accurate to about ten metres, and stores it with the run so the record shows the work was done at the location. The same reading is used as the finishing point. It is never read in the background, never continuously, and never when the app is closed. If you say no, the run goes on without it, and you can change your answer at any time in your phone's Settings.
How the work went. While a workflow run is open, the app notes when you reached each step, answered it, paused, or left the app and came back, with the app version. Managers use this to see which steps take longest.
Your phone. A notification token so we can send you notifications, an identifier the app makes for itself when it is installed, the app version, the kind of device (for example "iPhone"), and whether you have allowed notifications and location. Your managers can see whether notifications and location are on, so they know when a work order may not have reached you. We do not collect your phone's advertising identifier.
What you say out loud. When you dictate an answer or a note in the Mobile app, your phone turns speech into text, on the phone itself where the phone supports that (otherwise Apple's speech service does it). We receive the text, not the sound.
What you ask the AI assistant. Your questions, its answers, and any photo you show it are kept as a conversation only you can see. To answer, the assistant reads records you already have access to, and sends your question and those records to an AI provider (see "Who else sees it"). In the Console you can also talk to the assistant by voice; that audio goes to a voice provider and a written transcript is kept with the conversation.
From people without an account.
- A note from outside (sent through a QR code or a location's public page) carries the name, email address, room or unit, and the words and answers the sender types. It goes to the restaurant it is addressed to.
- A vendor checking in on a restaurant's vendor page gives a name and company, and the times they arrive and leave, with any photos they take as proof of the work.
- A QR code scanned without an account is counted, with no name attached.
- Somebody who asks us for a demo on our website gives a name, email, organization, job title and phone number, and we keep the browser type it was sent from.
Automatically, to keep things safe and working. To slow down people who try to guess codes or flood a form, we note the IP address a request came from for up to two days. Our database provider records the IP address and browser of each signed-in session, which you can see under your own account. Our hosting provider keeps short request logs. The audit log records who changed which record and when; it does not store IP addresses.
Cookies. The Console and website use cookies that keep you signed in and remember which organization and locations you are looking at. If we turn on product analytics for the Console (see below), it sets its own cookie. We use no advertising cookies.
Why we use it
- To run the service your organization signed up for: showing you your work, recording what you did, and letting the right people see it.
- To keep the record your organization may be required to keep, and to produce the reports and PDFs it asks for.
- To send the notifications and emails the service depends on: a work order for you, a code to sign in, a report somebody scheduled.
- To answer when you ask the AI assistant something.
- To keep the service secure, stop abuse, and find and fix what is broken.
- To understand how the product is used so we can improve it.
- To send our own emails about Skillet: getting started, new features, billing. Every one has an unsubscribe link.
- To follow the law and answer lawful requests.
If you are in the European Economic Area or the United Kingdom, the legal bases are: performing the contract with your organization or with you (running the service); our legitimate interests and your organization's in keeping an accurate record of kitchen work, keeping the service secure and improving it; your consent, for location and for the camera and microphone, which you can withdraw at any time in your phone's Settings; and legal obligations.
What we never do
- Sell personal information, or share it for advertising that follows you across other websites and apps.
- Show ads, in the Mobile app or anywhere else.
- Track you across apps and websites owned by other companies. The Mobile app contains no advertising, analytics or attribution software from anybody else.
- Read your location in the background, or more than once per workflow run.
- Use your organization’s records for anything other than running Skillet for that organization.
Who else sees it
People in your organization. That is the point of the product. Managers see the work their people record, including when and where a workflow run started. Workers see their own work and what their organization shares with them.
People your organization sends it to. Your organization can share a report or a link, email a scheduled report, or send alerts to its own Slack, Microsoft Teams or other systems. What goes there is your organization's choice.
Companies that run parts of Skillet for us. Each receives only what its job needs, works on our instructions, and is bound by its terms with us to protect the data and not use it for its own purposes:
- Supabase
- What it does for us: Database, file storage and sign-in, in the United States (Oregon)
- What it receives: Everything described above
- Vercel
- What it does for us: Runs the website, the Console and the service that draws PDFs, in the United States
- What it receives: Requests and their IP addresses, and the data passing through them
- Resend
- What it does for us: Sends email
- What it receives: Your email address and the message; tells us whether it was delivered, opened or clicked
- Apple and Google
- What it does for us: Deliver notifications to phones and browsers
- What it receives: A notification token and the notification itself
- DeepSeek
- What it does for us: The AI model behind the assistant, step help, message translation, insights and suggested fixes
- What it receives: Your question, any photo you show it, the records it reads to answer, and the records the automatic uses below send it. DeepSeek is based in China and its own privacy policy says it stores data there.
- ElevenLabs
- What it does for us: Voice for the assistant in the Console
- What it receives: What you say to it and its reply, as audio and as text. It keeps its own transcript.
- OpenAI
- What it does for us: Turns speech into text when you dictate in the Console
- What it receives: The short recording you dictate
- TypeSafe
- What it does for us: Ranks what needs a manager’s attention first
- What it receives: Equipment names, finding titles and the text of notes; it answers with numbers only
- Google Maps
- What it does for us: Finds addresses and a photo of the front of each location
- What it receives: The address being typed or saved
- Stripe
- What it does for us: Takes payment from organizations
- What it receives: The billing contact and card details, entered with Stripe; we never see the card number
- PostHog
- What it does for us: Product analytics in the Console, when we turn it on
- What it receives: Pages viewed and buttons pressed, with your account identifier, name and email
- Sentry
- What it does for us: Error reports from the Console, when we turn it on
- What it receives: What went wrong and on which page, with IP addresses removed
| Company | What it does for us | What it receives |
|---|---|---|
| Supabase | Database, file storage and sign-in, in the United States (Oregon) | Everything described above |
| Vercel | Runs the website, the Console and the service that draws PDFs, in the United States | Requests and their IP addresses, and the data passing through them |
| Resend | Sends email | Your email address and the message; tells us whether it was delivered, opened or clicked |
| Apple and Google | Deliver notifications to phones and browsers | A notification token and the notification itself |
| DeepSeek | The AI model behind the assistant, step help, message translation, insights and suggested fixes | Your question, any photo you show it, the records it reads to answer, and the records the automatic uses below send it. DeepSeek is based in China and its own privacy policy says it stores data there. |
| ElevenLabs | Voice for the assistant in the Console | What you say to it and its reply, as audio and as text. It keeps its own transcript. |
| OpenAI | Turns speech into text when you dictate in the Console | The short recording you dictate |
| TypeSafe | Ranks what needs a manager’s attention first | Equipment names, finding titles and the text of notes; it answers with numbers only |
| Google Maps | Finds addresses and a photo of the front of each location | The address being typed or saved |
| Stripe | Takes payment from organizations | The billing contact and card details, entered with Stripe; we never see the card number |
| PostHog | Product analytics in the Console, when we turn it on | Pages viewed and buttons pressed, with your account identifier, name and email |
| Sentry | Error reports from the Console, when we turn it on | What went wrong and on which page, with IP addresses removed |
Some of this happens without anybody opening the assistant. Skillet sends records to the AI model on its own to write insights about how work is going (equipment names, finding titles and a week of totals), to suggest a fix for a finding, and to translate a message for a teammate who reads another language. If your organization would rather none of its words or photos reach an AI provider, write to privacy@skilletfm.com and we will turn these off for it.
If the law requires it. We disclose information when a valid legal process requires it, and we tell the organization concerned unless we are not allowed to.
If Skillet changes hands. If Skillet is sold or merged, the information goes with it, under this policy, and we will say so here first.
Where it is kept
Skillet's database and files are in the United States, in Amazon Web Services' Oregon region, run by Supabase. The website runs on Vercel in the United States. When you use the AI assistant, your question and the records it reads are processed by DeepSeek, which is based in China. If you use Skillet from outside the United States, your information is transferred to these countries and handled under this policy.
How long we keep it
Records of work stay for as long as your organization has its account. A record of what happened in a kitchen is the thing a restaurant uses Skillet for, and it may be required by law or by an insurer to keep it. Records are not edited after they are submitted, and removing one hides it rather than erasing it, so the history stays honest. When an organization ends its agreement, it can ask us for a copy of its data and ask us to delete it, and we will.
Some things are kept for a short, fixed time:
- IP addresses and email addresses used to stop abuse
- Kept for: 2 days
- Sign-in codes
- Kept for: 1 day after they expire
- Invitations
- Kept for: 14 days to accept
- A visit token on the vendor page
- Kept for: Until the vendor checks out
- A document your organization removed
- Kept for: 30 days, then the file is deleted
- Notification tokens a phone has stopped accepting
- Kept for: Removed the next time delivery fails
| What | Kept for |
|---|---|
| IP addresses and email addresses used to stop abuse | 2 days |
| Sign-in codes | 1 day after they expire |
| Invitations | 14 days to accept |
| A visit token on the vendor page | Until the vendor checks out |
| A document your organization removed | 30 days, then the file is deleted |
| Notification tokens a phone has stopped accepting | Removed the next time delivery fails |
Your AI assistant conversations, your account details and the record of how a workflow run went are kept while your account exists. Copies in our providers' backups expire on their own schedule.
Deleting your account
In the Mobile app, open your profile and press Delete account. In the Console, open Settings, then My account. Or read how to delete your account without installing anything. It happens immediately:
- Your sign-in is deleted and every device is signed out.
- Your email address and profile picture are removed, and your name becomes “Removed person”.
- You leave every organization you belonged to, and your phones stop receiving notifications.
What stays. The work you recorded (workflow runs, answers, photos, messages, the place a run started) stays with the organization it was done for, shown as done by a removed person. The organization may be required to keep it, and a record with pieces quietly missing is a record nobody can trust.
What the button does not remove yet. Your phone number, shift hours and pay rate if your organization recorded them, your notification settings, your AI assistant conversations, and the image file of your old profile picture. Write to privacy@skilletfm.com after deleting your account and we will remove them by hand.
If you are the only owner of an organization that still has other people in it, make somebody else an owner first, so nobody is left locked out.
Your choices and your rights
On your phone. You can turn off the camera, microphone, location and notifications for Skillet in your phone's Settings at any time. Only the feature that needs each one stops working.
Asking us. Wherever you live, you can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to privacy@skilletfm.com from the email address on your account. We will check it is really you, and answer within 30 days. If the information is part of an organization's records, we may pass your request to that organization, because it decides what happens to its records. You can also send someone to ask on your behalf, with your written permission. We will never treat you differently for asking.
California. In the past 12 months we have collected the categories below, from you, from your organization, and from your phone. We used them for the purposes in "Why we use it" and disclosed them only to the people and companies in "Who else sees it". We have not sold or shared personal information for cross-context behavioral advertising, and we do not knowingly sell or share the information of anybody under 16. We use precise location and account sign-in details only to provide the service and keep it secure, so there is nothing for you to limit. You have the right to know, delete and correct, and the right not to be discriminated against for using them.
- Identifiers
- Examples: Name, email, phone number, account and device identifiers, IP address
- Kept: While the account exists; IP addresses 2 days
- Professional or employment information
- Examples: Role, employment type, locations, shift hours, pay rate, the work you record
- Kept: While the organization has its account
- Precise geolocation
- Examples: Where a workflow run started, in the iPhone app
- Kept: With the record of the run
- Audio, visual and similar
- Examples: Photos, videos, signatures; voice in the Console’s assistant
- Kept: With the record
- Internet or other activity
- Examples: How a workflow run went, pages used in the Console, sign-in sessions
- Kept: While the account exists
| Category | Examples | Kept |
|---|---|---|
| Identifiers | Name, email, phone number, account and device identifiers, IP address | While the account exists; IP addresses 2 days |
| Professional or employment information | Role, employment type, locations, shift hours, pay rate, the work you record | While the organization has its account |
| Precise geolocation | Where a workflow run started, in the iPhone app | With the record of the run |
| Audio, visual and similar | Photos, videos, signatures; voice in the Console’s assistant | With the record |
| Internet or other activity | How a workflow run went, pages used in the Console, sign-in sessions | While the account exists |
Other US states. If you live in a state with its own privacy law (such as Colorado, Connecticut, Oregon, Texas or Virginia), you have similar rights. If we turn down your request, write back to privacy@skilletfm.com with "Appeal" in the subject and a different person will look at it again and answer within 45 days. If you still disagree, you can contact your state's attorney general.
European Economic Area and United Kingdom. You also have the right to object to how we use your information, to restrict it, to take it with you, and to withdraw consent, and to complain to your data protection authority.
Children
Skillet is a tool for people at work. It is not meant for anybody under 16 and we do not knowingly collect information from them. If you believe we have, write to privacy@skilletfm.com and we will delete it.
Keeping it safe
Everything travels encrypted, and the database and files are encrypted where they are stored. The database itself decides, row by row, who may read what, so one organization cannot see another's records even if something else goes wrong. Photos and files open through links that expire within an hour; a link in an emailed report lasts a week. Passwords and PINs are stored only as hashes. No system is perfectly secure; if a breach puts your information at risk, we will tell the organizations affected, you, and the regulators the law requires, as quickly as we can.
Changes to this policy
When we change this policy we change the date at the top. If a change matters, for example a new kind of information or a new company that receives it, we will tell organization owners before it takes effect.
Contact
Questions, requests and complaints about privacy go to privacy@skilletfm.com. Skillet is run by Aaron Lozhkin.