Privacy Policy
Effective 31 August 2026
Kimchi is a training, knowledge and team-communication platform for hospitality teams, made by Kimchi BV (“Kimchi”, “we”, “us”). This policy explains what personal data we collect when you use the Kimchi web app (app.usekimchi.com), the Kimchi mobile app for iOS and Android, and this website; why we collect it; who we share it with; and what your rights are.
The short version
- Kimchi is a workplace tool. Your employer (or the business that invited you) sets up the workspace and decides what goes into it. For that data your employer is the “controller” under the GDPR and we process it on their behalf.
- We don't sell your data and we don't use it for advertising. There are no third-party analytics or advertising trackers in the Kimchi apps.
- AI features send content to AI model providers. When you use the assistant or an AI-generated feature, the relevant text, files, photos or videos are sent to Google (Gemini) and Anthropic (Claude) models via OpenRouter to produce the result. They are not allowed to use your content to train their models.
- Your data lives in the EU. Our servers, databases and uploaded files are in EU data centres. A few service providers are in the US; we use recognised safeguards for those transfers.
- You're in control. You can ask for access, correction or deletion at any time — see your rights.
1. Who we are
The company responsible for Kimchi is:
Kimchi BV in oprichting (a Belgian company under formation)
Belgium
Email: privacy@usekimchi.com
2. Who is responsible for your data
There are two situations, and it matters which one applies.
Your employer's workspace. When you use Kimchi as a member of an organisation — for example the restaurant group you work for — that organisation decides which data is entered into Kimchi, who can see it and how long it is kept. Under the GDPR it is the data controller, and we are the data processor acting on its instructions under a data processing agreement. This covers your profile, your trainings, your messages, checklists, shift data and everything else inside the workspace.
Our own processing. We are the data controller for the things we do in our own name: creating accounts and keeping logins secure; keeping the service running, safe and reliable (server logs, error reports); answering support and demo requests; communicating with the businesses that buy Kimchi; and the visitors to this website.
If you have a question about how your employer uses Kimchi — for instance why a certain field was filled in, or who in your team can see your training results — please contact them first. We will help them respond.
3. What data we collect
3.1 Data you or your employer provide
| Category | What it includes |
|---|---|
| Account & profile | First and last name, email address, phone number (if you were invited by SMS), password (stored only as a salted hash — we can never see it), profile photo, interface language, job role and groups, the locations and teams you belong to. Your employer may optionally add a date of birth, home address, gender (“male”, “female” or “prefer not to say”) and a short description of your role. |
| Content you create | SOPs, trainings, recipes, checklists (including photos taken as proof of completion), projects and tasks, comments, quiz answers, files you upload, and any text or images you add to posts. |
| Messages | Direct messages, group chats, announcements, posts, polls and your votes, reactions, and photo or video attachments. Messages are encrypted in transit and at rest but are not end-to-end encrypted (see who in your workspace can see what). |
| Training records | Which trainings and onboardings were assigned to you, your progress, completion dates and quiz scores. |
| Notes by managers | Your employer can record an evaluation note about an employee. This is your employer's data; we store it for them. |
| AI conversations | The questions you ask Kimchi, any files, photos or dictated text you attach, and the answers (see AI features). |
| Demo bookings | If you book a demo through this website: your name, email address, anything else you enter in the booking form, and the time you pick. Scheduling runs on Cal.com (see cookies). |
| Support | Whatever you send us when you ask for help, including screenshots. |
3.2 Data generated when you use Kimchi
| Category | What it includes |
|---|---|
| Technical data | IP address, browser type, operating system, device model, app version and the time of each request, kept in server logs for security and troubleshooting. |
| Activity data | When you last opened Kimchi, which trainings you completed, when you read a message (read receipts) or viewed a post. |
| Notifications | A push-notification token for your device, the device model name (e.g. “iPhone 15 (ios)”) and a record of the notifications sent to you. |
| Error reports | If the app crashes or hits an error, a report (stack trace, device and OS, app version, a pseudonymous user ID) is sent to our own error-monitoring server — not to a third party. It is configured not to include your name or email. |
| AI usage records | For each AI request we record the model used, token counts and cost, linked to your user and organisation ID, so we can monitor quality and costs. |
3.3 Data from integrations your employer connects (optional)
Your employer decides whether to connect any of these. If they do, we receive:
| Integration | Data we receive | Used for |
|---|---|---|
| Strobbo (staff planning) | Employee name, email, mobile number, role, employment statute, language, and shift schedules (date, start/end, location, remarks). | Creating your account and invitation, and showing the right checklists and reminders to the people who are on shift. |
| Google Drive | The files in the folder your employer connects. | Using those documents as knowledge sources for SOPs, trainings and the AI assistant. |
| Google Business Profile / online reviews | Public Google reviews of your employer's locations — reviewer name, text, rating and date — collected via Google and a review-collection service. | Spotting recurring issues and suggesting trainings or SOP updates. |
3.4 Device permissions (mobile app)
The Kimchi app asks for these permissions, each only when you first use the related feature:
- Camera and photo library — to take or attach photos and videos to messages, checklists and your profile.
- Microphone and speech recognition — to dictate questions to the AI assistant.
- Notifications — to send you push notifications.
You can decline or revoke any of them in your device settings; the rest of the app keeps working. The app does not ask for your location, contacts or calendar.
4. AI features
Kimchi includes an AI assistant and several AI-generated features: training generation from documents, summaries, checklist-photo evaluation, video transcription and project planning. Here is how your data is handled:
- What is sent. When you use an AI feature, the content the feature needs — your question, the SOPs, files or messages it uses as context, and any attached documents, photos or videos — is sent to a large language model to produce the result.
- Who processes it. We route requests through OpenRouter, Inc. (USA) to models from Google (Gemini) and Anthropic (Claude). These providers process your content only to generate the response. Under their terms for business customers they may not use your content to train their models, and they do not keep it beyond what is needed to run the service and prevent abuse.
- Web search. If your employer enables “Let Kimchi search the web”, your question may also be sent to a web-search service via OpenRouter, and Kimchi will cite the pages it used. This is off by default.
- Dictation. If you dictate a question in the mobile app, the audio is transcribed by your phone's own speech-recognition service (Apple on iOS, Google on Android) under that company's privacy terms. Only the resulting text is sent to Kimchi.
- Stock images. Images suggested for trainings come from Unsplash. Only the search keywords are sent, never your personal data.
- What we keep. Your questions and the AI's answers are stored in your workspace so you can come back to them and your employer can review how the assistant is used.
- A note on accuracy. AI output can be wrong or incomplete. Treat it as a draft to be checked — especially for food-safety matters.
5. Why we use your data, and the legal basis
| Purpose | Legal basis |
|---|---|
| Providing Kimchi to your employer's workspace — accounts, content, messages, trainings, checklists, notifications, integrations, AI features | We act on your employer's instructions as processor (Art. 28 GDPR). Your employer's own basis is usually its contract with you and its legitimate interest in training and coordinating its team (Art. 6(1)(b) and (f)). |
| Creating and securing your account; preventing abuse; keeping logs and error reports; fixing bugs | Our legitimate interest in running a secure, reliable service (Art. 6(1)(f)). |
| Sending service emails and SMS — invitations, password-reset codes, reminders, mentions, task updates and digests | Performance of the service (Art. 6(1)(b)) and our legitimate interest in keeping you informed about your workspace (Art. 6(1)(f)). |
| Answering your support requests | Our legitimate interest in helping you (Art. 6(1)(f)). |
| Answering demo requests and talking to prospective customers | Steps you ask us to take before entering a contract (Art. 6(1)(b)) and our legitimate interest in selling our service (Art. 6(1)(f)). |
| Using your camera, microphone, photo library or push notifications | Your consent, given through the device permission (Art. 6(1)(a)). You can withdraw it in your device settings at any time. |
| Monitoring AI usage and cost per organisation | Our legitimate interest in operating the AI features reliably and billing correctly (Art. 6(1)(f)). |
| Keeping contract and billing records with business customers | Legal obligation under Belgian commercial and tax law (Art. 6(1)(c)). |
We do not use your data for automated decisions that have legal or similarly significant effects on you.
6. Who we share data with
We never sell personal data. We share it only with:
People in your workspace. Colleagues can see your name, photo and role and what you post or send them; managers and admins can see more — see who in your workspace can see what.
Service providers (sub-processors) that help us run Kimchi. Each is bound by a contract that limits what they may do with the data. They fall into these categories:
- hosting and infrastructure providers that run our servers, databases and this website, in EU data centres;
- storage of uploaded files, photos and videos, in EU data centres;
- the AI routing and model providers described in AI features;
- delivery providers for our emails, SMS messages and push notifications;
- a scheduling service for demo calls booked through this website;
- a service that collects the public reviews of connected locations;
- map-tile and embedded-video services in the web app — your browser talks to those directly, which reveals your IP address to them;
- and the third-party tools your employer chooses to connect (see integrations).
The full, current list of our sub-processors — who they are, what each one does and where it processes data — is part of the data processing agreement we conclude with each business customer, and customers can request it at any time via privacy@usekimchi.com.
Authorities and others when the law requires it, for example to comply with a legal obligation, a court order, or to protect the rights, property or safety of our users or others.
A buyer or successor if Kimchi BV is involved in a merger, acquisition or sale of assets. We will tell you before your data becomes subject to a different privacy policy.
7. Where your data is stored and international transfers
Kimchi's servers, database and uploaded files are in EU data centres. Some of our service providers are based in the United States or may access data from there. For those transfers we rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses with additional safeguards. You can ask us for a copy of the relevant safeguards.
8. Who in your workspace can see what
- Colleagues can see your name, profile photo, role and locations; the messages you send them; your posts, comments and reactions; your votes in polls (polls are not anonymous); and, in group chats, whether you have read a message.
- Managers and admins of your organisation can additionally see your full profile (including any optional fields your employer filled in), your training progress and scores, your checklist submissions, when you were last active, shift data from a connected planner, and any evaluation notes they have written.
- Direct messages can only be opened by the people in the conversation. Admins cannot read your direct messages through Kimchi.
- Our team. A small number of our engineers can access stored data — including messages — when it is strictly necessary for support, security or legal reasons. We do not read your messages for any other purpose.
Messages and files are encrypted on the way to and from Kimchi and while stored, but they are not end-to-end encrypted.
9. How long we keep your data
| Data | Retained |
|---|---|
| Your account, profile and workspace content | For as long as your employer's workspace exists and you are a member of it. When your employer removes you, your profile is deleted. Some content you created for the team (for example SOPs, or messages in shared conversations) may remain in the workspace, no longer linked to your name, because the team still needs it. |
| A whole workspace | When a business customer's contract ends, we delete the workspace and all its data within 90 days, unless the customer asks us to delete it sooner or we must keep specific records by law. |
| Server logs and error reports | Up to 90 days. |
| SMS and email delivery records | As long as the related account exists, for troubleshooting and cost reconciliation. |
| Support conversations | Up to 2 years after the request is closed. |
| Contract and billing records with business customers | As long as Belgian commercial and tax law requires (generally 7 to 10 years). |
| Backups | Deleted data may persist in encrypted backups for up to 30 days before it is overwritten. |
10. How we protect your data
- All traffic is encrypted with TLS (HTTPS/WSS); files are encrypted at rest by our storage provider.
- Passwords are hashed with Argon2. We never store or see your password in clear text.
- On mobile, your login token is kept in the operating system's secure storage (iOS Keychain / Android Keystore).
- Every record is scoped to an organisation; role-based permissions control who can see and change what.
- Access to production systems is limited to a small number of engineers and protected by strong authentication.
- We don't run third-party analytics or advertising scripts in the apps, so no tracking data leaves Kimchi.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify your employer and, where required, you and the supervisory authority.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data (“right to be forgotten”);
- restrict how we process your data;
- receive your data in a portable, machine-readable format;
- object to processing based on our legitimate interests;
- withdraw consent at any time (for example a device permission), without affecting processing that happened before;
- complain to a supervisory authority.
How to exercise them. For data inside your employer's workspace, your employer is the controller — please ask your workspace admin, who can update your profile or remove your account directly in Kimchi. For anything else, or if you'd rather come to us, email privacy@usekimchi.com. We'll respond within one month (this may be extended by two further months for complex requests, and we'll tell you if so). We may ask you to verify your identity first.
Deleting your account. Ask your workspace admin to remove you, or email us at privacy@usekimchi.com from the address linked to your account. We delete your account and personal data within 30 days, except where your employer is legally required to keep specific records.
Supervisory authority. Our supervisory authority is the Belgian Data Protection Authority: Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, Belgium — www.gegevensbeschermingsautoriteit.be. You may also complain to the data protection authority in the EU country where you live or work.
12. Cookies and local storage
This website. These pages are served as static files and set no cookies at all. The cookie notice you may have answered stores your choice in your browser's local storage, on your device only; we currently load no analytics scripts either way, and if we ever add any they will only run after you have accepted. One exception you opt into by using it: booking a demo loads the Cal.com scheduling widget, which sets its own cookies under Cal.com's privacy policy. It is not loaded until you open the booking.
Web app (app.usekimchi.com). We only use strictly necessary first-party cookies, which is why you don't see a cookie banner there:
| Cookie | Purpose | Lifetime |
|---|---|---|
sessionid | Keeps you logged in | Session / up to 2 weeks |
csrftoken | Protects forms against cross-site request forgery | 1 year |
kitchr_sidebar_minimized | Remembers whether you collapsed the sidebar | 1 year |
There are no analytics, advertising or social-media cookies. Trainings that embed a YouTube video load that video from YouTube, which may set its own cookies when you play it.
Mobile app. The app stores your login token and your preferences on your device; it does not use cookies or advertising identifiers.
13. Children
Kimchi is a workplace tool intended for people who are old enough to work. It is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has been given a Kimchi account, tell us and we will remove it.
14. Changes to this policy
We may update this policy as Kimchi evolves. We will post the new version here with a new effective date, and for material changes we will notify you in the app or by email before they take effect.
15. Contact
Questions, requests or concerns about privacy: privacy@usekimchi.com, or by post to Kimchi BV, Belgium.