Privacy Policy
Last updated: [DATE]
This Policy explains what Herald ("we," "us," "our," operated by [YOUR BUSINESS/LLC NAME]) collects, why, and what you can do about it. There are two different people this Policy covers: business owners who create an account, and anonymous customers who scan a QR code at a participating business. We treat these very differently, described below.
What we collect from business owners (account holders)
| Data | Why we collect it |
|---|---|
| Email address, password (stored as a one-way hash, never in plain text) | To create and secure your account |
| Business name, owner name, business address, core product | To personalize the Service and generate your customer-facing QR pages |
| Daily customer counts, sales figures, and any notes you write | To compute your business's baseline and generate directives |
| Your walk-around item list (e.g. "Radio," "Table 3") and which sticker number is bound to each | To route QR scans to the right feedback page |
| Your business hours, schedule | To know when the Service is relevant to your business |
| Your recipe (the ingredient list you enter during setup) — stored encrypted, see the section below | So the AI can notice when a recipe change lines up with a change in your numbers |
| Payment confirmation (which plan, when — never your card number, which goes straight to Stripe) | To keep a record that you've paid |
| Push notification subscription, if you opt in | To send you reminders and alerts you asked for |
Your recipe — collected, but encrypted so no person can read it
This changed on 2026-07-23, and we're saying so plainly rather than quietly. Earlier versions of this app promised your recipe was never sent to our servers at all. We reversed that, deliberately: the recipe is the single most useful thing your AI can watch — "did a recipe change move your numbers?" is the exact question this product exists to answer — and it couldn't do that without ever seeing the recipe.
Here's exactly how it's protected, grounded in the real code, not just a promise:
- Your recipe is encrypted before it is stored (AES-256-GCM, an authenticated encryption standard). What sits in our database is ciphertext — a raw database read, a leaked backup, or our own admin export shows scrambled bytes, not your ingredients.
- It is decrypted only momentarily, in server memory, for exactly one purpose: generating your own business's directives. The decrypted text is never included in anything our servers send back over the network, never written to a log, and when a recipe change is recorded in your change history, that record is itself encrypted too.
- No human ever sees your stored recipe in plaintext — not staff, not anyone at Herald. There is no view, export, or admin tool that displays it decrypted, and the app has no screen that reads it back. (A directive shown to you may name an ingredient you changed — "removing the brown sugar cost you 4 customers" — that's the feature doing its job, and it's only ever shown to you, on your own logged-in account.)
- It is never shown to anyone else, never shared, and never sold. It exists only to power your own account's insights.
- The encryption key lives only on our servers as configuration — it is never present in the app your browser runs, and it is never stored alongside the encrypted data itself.
What we collect from anonymous customers (QR scans)
Customers scanning a QR code at a participating business do not create an account and are never asked for their name, email, or any identifying information. We collect:
- Their answers to short feedback questions (e.g. whether they got the business's core product, a price they say they paid, free-text comments about a specific item)
- Timestamps for our "wait time" feature, if a business uses it (when someone tapped "I sat down" and "food arrived") — no identity attached, just two timestamps
- IP address, used only to prevent abuse (rate-limiting), never stored long-term as part of any customer profile
The business owner never sees a customer's exact words. Individual comments are never shown verbatim to the business owner — only an AI-generated summary of patterns across multiple customers. This is a real, enforced design choice, not just a promise: the code that builds the owner's view never includes raw customer text.
How business data is processed on a business's behalf
If you're a business owner, the anonymous feedback your own customers submit is processed by us on your behalf, to generate the insights you see. We act as a data processor for that customer feedback — we don't sell it, share it with other businesses, or use it for any purpose beyond generating your own business's insights and improving the Service generally.
Third parties who process data with us
| Who | What they see |
|---|---|
| Vercel (hosting) and Vercel KV / Upstash (database) | All account and customer-feedback data, as our infrastructure providers |
| Anthropic (AI provider) | Business setup info, logged notes, customer feedback text, and — solely while generating your own directives — your recipe's ingredient list (decrypted for that processing only, per the recipe section above); never a customer's raw comment shown back to you verbatim from that same processing |
| Stripe (payments) | Your payment/card details directly — we never receive or store your card number |
| Web push services (browser/OS push infrastructure) | Only what's needed to deliver a notification you opted into, if you enabled that |
We do not sell your data to advertisers or data brokers.
How long we keep data, and data loss
We keep account and business data for as long as your account is active. We do not currently offer an automated way to export or permanently delete all your data on request — if you want your account and its data removed, contact us at [SUPPORT EMAIL] and we'll handle it manually. In plain terms: as an early-stage service, we don't yet have a formal backup system, so while we take reasonable care, we can't guarantee against data loss from a technical failure.
Your choices
- You can request a copy of your account data, or ask us to delete it, at [SUPPORT EMAIL].
- You can turn off push notifications at any time in your device's settings.
- Anonymous customers have nothing to request deletion of that could identify them, since we never collect identifying information from them in the first place.
Children's privacy
The Service is intended for business owners operating a food & beverage business, not children. We don't knowingly collect data from anyone under 18 as an account holder.
Changes to this Policy
If we materially change what we collect or how we use it, we'll update this page and, where required, notify you directly.
Contact
Questions about this Policy, or a data request? Reach us at [SUPPORT EMAIL].