Effective [EFFECTIVE DATE REQUIRED]. Hey Bistro is a product of Tomorrow Group LLC. Restaurant information is treated as the restaurant's confidential information: it belongs to the restaurant, is kept separate from other restaurants, and is used only to provide Hey Bistro.
1. Introduction
Hey Bistro is a cloud service for restaurants, operated by Tomorrow Group LLC (“Tomorrow Group,” “we,” “us”). Restaurants (“Customers”) create an organization and locations, invite their team, upload restaurant information, and let authorized staff ask an AI assistant questions about it.
This policy explains what information we collect, how we use and share it, and the choices available. It covers our website at https://heybistro.com and the Hey Bistro application.
Two roles. For the content a restaurant puts into Hey Bistro and the information about its team (“Customer Data”), we act on the restaurant's behalf and under its instructions (as a “service provider” or “processor”). The restaurant decides who is invited and what is uploaded. For information about our own customers' accounts, billing and use of our website, we decide how it is used.
2. Information We Collect
Information you or your restaurant provide
- Account information: name, email address and password. Passwords are passed securely to our authentication provider (Supabase Auth), which stores them only in hashed form. We do not store passwords.
- Membership information: the organizations and locations you belong to, your role (owner, manager or employee), your position (for example server or bartender), and whether your access is active.
- Invitations: the name, email address, role and position a manager enters to invite someone.
- Restaurant details: organization and location names, address, phone, website, time zone and cuisine type.
- Restaurant content: documents and information the restaurant uploads or enters. See section 3.
- Questions and answers: questions staff ask Hey Bistro (typed or spoken) and the answers provided. See sections 4 and 5.
Information created as you use Hey Bistro
- Usage records: for each question or voice request, the time, the AI model used, token counts, the size of an audio recording or the length of text read aloud, and whether the answer came from the restaurant's documents. These records are used for metering, rate limits and restaurant analytics.
- Activity records (audit log): records of administrative actions, such as invitations (including the invitee's email address), membership changes, document changes and group changes.
- Online status: whether you currently have Hey Bistro open, shared live with coworkers at the same location. It is not stored.
- Technical information: our hosting and database providers record standard request information such as IP address, browser type, time and the page or service requested.
Billing information
When an owner subscribes, payment details are entered on pages hosted by Stripe. We receive and store the Stripe customer and subscription identifiers, the plan, subscription status, renewal date and any discount applied. See section 16.
3. Restaurant Content
Restaurants can upload PDF, Word (.docx), Excel (.xlsx), CSV, text and Markdown files, such as menus, recipes, wine and cocktail lists, allergen guides, training material and policies, up to 25 MB per file. They can also post announcements and set up talk groups.
To make this information searchable by the assistant, Hey Bistro:
- stores the original file in private storage that only authorized managers of that location can download;
- extracts the text on our own servers and splits it into short sections;
- creates a numerical representation (an “embedding”) of each section so relevant sections can be found by meaning. This step sends the section text and the document title to our AI provider (section 5);
- stores the sections and embeddings in our database, labeled with the restaurant and location they belong to.
Your restaurant owns its content. Our use of it is limited to providing and supporting the service, as set out in our Terms of Service.
4. Employee and User Information
Within a restaurant, access depends on role:
- Coworkers at the same location can see each other's first name and last initial, position, online status and talk-group membership.
- Managers and owners can see their staff's names, email addresses, roles, positions and status, and pending invitations. They see usage totals, such as how many questions were asked and how many people asked.
- Managers and owners also see the wording of questions Hey Bistro could not answer, grouped by topic, so they can add the missing information. These are shown without the name of the person who asked.
- Managers cannot open an employee's conversations with Hey Bistro. Each person's questions and answers are visible only to them in the app.
- Owners can also see the activity log described in section 2.
5. AI Processing
Hey Bistro's AI features are provided through the OpenAI API. To answer a question, information has to be sent to OpenAI for processing. We send what the feature needs to work:
| Feature | What is sent to OpenAI | Model |
|---|---|---|
| Making documents searchable | The text of each document section and the document's title and section heading | text-embedding-3-small |
| Finding relevant information | The question (and, for follow-ups, a rewritten version of it) | text-embedding-3-small |
| Understanding follow-ups and recipe questions | The question and up to three previous questions and answers from the same conversation | gpt-5.4-nano |
| Answering | The question, up to six relevant sections of the restaurant's documents (with titles), up to three previous questions and answers from the conversation, and the restaurant's name | gpt-5.4-mini |
| Asking by voice | The audio recording of the spoken question | gpt-4o-mini-transcribe |
| Reading answers aloud | The text of the answer | gpt-4o-mini-tts |
We do not include employees' names, email addresses or account identifiers in these requests. Information of that kind reaches OpenAI only if it appears in the restaurant's documents or in what someone types or says. Retrieval is limited to the asking person's own location and to documents they are permitted to use.
AI answers can be wrong or incomplete. Hey Bistro shows the source of restaurant-specific answers and tells staff to confirm allergy and dietary answers with the kitchen.
6. AI Training and Model Improvement
Processing is not training. Sending a question and relevant document sections to OpenAI so it can produce an answer is processing on our behalf. Using that data to train or improve OpenAI's general models would be a separate use.
- According to OpenAI's published API data controls, data sent to the OpenAI API is not used to train or improve OpenAI's models unless the organization explicitly opts in to share it.
- Our OpenAI organization has not opted in. As of [DATE SETTINGS LAST VERIFIED], our organization's data-sharing settings (model feedback sharing, evaluation and fine-tuning data sharing, and sharing of API inputs and outputs) are disabled, and API call logging is disabled in its data retention settings.
- Provider retention: OpenAI states that, by default, it keeps abuse-monitoring logs for up to 30 days for the chat, embeddings and text-to-speech services we use, and does not keep that data for the speech transcription service. We have not been approved for OpenAI's Zero Data Retention program, so this temporary retention applies.
- Tomorrow Group does not train AI models on restaurant content, questions or answers, and does not sell or share them for anyone else to train on.
These statements apply to OpenAI, the only AI provider Hey Bistro currently uses. If we add another, we will update this policy first.
7. Voice and Push-to-Talk Data
- Asking by voice: while the talk button is held, the device records the question. The recording is sent to OpenAI to be converted to text. Hey Bistro does not store the audio. The resulting text is saved as the question, like a typed one, and is visible only to the person who asked.
- Reading answers aloud: the answer text is sent to OpenAI, which returns generated speech. It is played on the device and not stored by Hey Bistro.
- Talking to coworkers (push-to-talk between staff) is not yet available. Before it launches, we will update this policy to describe how that audio is handled.
- Headsets: a Bluetooth headset works as an ordinary microphone and speaker. Hey Bistro does not currently integrate with any headset manufacturer's software or services.
- Talk sounds and destination settings are stored only on your device.
8. How We Use Information
- to provide Hey Bistro: accounts, restaurant content, search, AI answers, voice features, announcements and team tools;
- to control access according to each person's organization, location and role;
- to meter usage, apply rate limits, and show restaurants their own usage and knowledge-gap analytics;
- to process subscriptions and payments;
- to secure the service, prevent abuse, and investigate problems;
- to communicate about accounts, such as sign-in links and important service notices;
- to comply with legal obligations and enforce our Terms.
10. Service Providers (Subprocessors)
| Provider | Purpose | Information it receives |
|---|---|---|
| Supabase | Database, file storage, authentication (including sign-in emails) and live connections | All information stored by Hey Bistro, including restaurant content, embeddings, questions and answers, and account information |
| OpenAI | AI answers, search embeddings, speech-to-text and text-to-speech | As described in sections 5 and 6 |
| Stripe | Subscriptions and payments | Organization name, billing contact, payment details entered on Stripe's pages, the location name for each subscription, and our internal organization and location identifiers |
| [HOSTING PROVIDER REQUIRED] | Hosting the website, application and document processing | Requests passing through the application, including questions and answers in transit, and standard request logs |
Data is stored in [DATA STORAGE REGION REQUIRED]. The landing page also displays photographs loaded from Unsplash, which receives visitors' IP address and browser information, but no restaurant information.
11. Data Isolation Between Restaurants
Each restaurant's information is kept separate from every other restaurant's, and within a restaurant, access depends on location and role. Our safeguards include:
- row-level security on every database table, checked against the signed-in person's active membership and role;
- private file storage where downloads and uploads are limited to that location's managers;
- search and AI retrieval limited, inside the same database query, to the asking person's location and to the documents their role may use;
- live connections (such as online status) limited to members of that location;
- server-side checks on every sign-in and account action;
- automated tests that try to access another restaurant's data and confirm they are refused.
No system is perfect, but these controls are designed so that one restaurant cannot view or receive another's information.
12. Data Retention
We keep information for as long as the restaurant's account is active, unless it is deleted sooner:
- Documents: kept until deleted. Archiving removes a document from answers and staff view but keeps it so it can be restored. When a document is replaced, earlier versions of the file are kept in its history.
- Questions and answers: kept with their cited excerpts until deleted. There is currently no automatic time-based deletion.
- Usage and activity records: kept until the restaurant's data is deleted.
- Billing records: kept as long as needed for accounting, tax and legal purposes.
- Voice recordings and read-aloud audio: not stored by Hey Bistro (see section 7).
- OpenAI: as described in section 6.
- Backups and provider logs: copies may remain in backups for up to [BACKUP RETENTION PERIOD REQUIRED], and in our providers' request logs for up to [LOG RETENTION PERIOD REQUIRED].
13. Data Deletion
In the app, managers can archive documents and remove team members. Self-service permanent deletion of documents, locations and organizations is not yet available.
To delete data, an owner can contact us at [PRIVACY EMAIL REQUIRED]. We will verify the request and delete the requested restaurant information, including stored files, extracted text, embeddings, conversations and their cited excerpts, within [DELETION TIMEFRAME REQUIRED], except where we must keep information for legal, accounting or security reasons. Deleted information may remain in backups until they expire (section 12).
Employees who want their account or conversations deleted can contact their restaurant or us. Deleting an account removes that person's memberships and their conversations with Hey Bistro.
14. Security
We use administrative, technical and organizational safeguards appropriate to the information we handle, including:
- encrypted connections (HTTPS) between your device and Hey Bistro;
- encryption of stored data provided by our database host;
- the access controls described in section 11;
- secret keys kept on our servers only, with the most privileged database key limited to verified payment notifications;
- short-lived links for file downloads;
- limits on how often questions and voice requests can be made;
- checking uploaded files' real format and rejecting files with macros;
- treating restaurant documents strictly as information, never as instructions, when the AI answers;
- a record of administrative actions.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a security incident affecting your information, we will notify you as required by law.
16. Payment Processing
Subscriptions are processed by Stripe. Payment card details are entered on Stripe's hosted checkout and billing pages and are handled by Stripe; Hey Bistro does not receive or store full card numbers. We store the Stripe customer and subscription identifiers, plan, status, renewal date and discount description so we can show billing status and provide access. Stripe processes payment information under its own privacy policy.
17. Children's Privacy
Hey Bistro is a workplace tool for restaurants. It is not directed to children, and it is not intended for anyone under 13. Restaurants are responsible for inviting only people who may lawfully use it. If we learn we have collected personal information from a child under 13, we will delete it.
18. U.S. State Privacy Rights
Depending on where you live, you may have rights to access, correct or delete personal information, and to know how it is used and shared. We do not sell personal information or share it for cross-context behavioral advertising.
Where we hold information on behalf of a restaurant, we will refer your request to that restaurant or help it respond. To make a request, contact us at [PRIVACY EMAIL REQUIRED]. We will not discriminate against you for exercising your rights.
19. International Users
Hey Bistro is operated from the United States and intended for restaurants in the United States. If you use it from elsewhere, your information will be processed in [DATA STORAGE REGION REQUIRED] and by the providers in section 10, which may be subject to different data protection laws.
20. Changes to This Privacy Policy
We may update this policy as Hey Bistro changes. We will post the new version here with a new effective date and, for material changes, notify account owners by email or in the app before the change takes effect.
21. Contact Information
Tomorrow Group LLC
[BUSINESS ADDRESS REQUIRED]
Privacy questions and requests: [PRIVACY EMAIL REQUIRED]