Where this stands right now: Sautero is in an early, invite-only trial. This page describes how we actually handle things today, in plain language. It has not been reviewed by a lawyer yet β treat it as an honest description of current practice, not a polished legal contract. A lawyer review of this exact page is planned before any public launch (see /security/ in the project for the internal draft package). If anything here matters to you, ask directly using the feedback button in the app, or reply to any Sautero email.
Sautero is a kitchen management tool (recipes, prep checklists, ingredient pricing, staff scheduling and time tracking) being tested with a small number of invited kitchens before any public or paid launch. Your kitchen's data is only visible to people you've invited into your kitchen's team β it is not shared with other kitchens using Sautero.
Your email address, used to send you a one-time sign-in code. You can optionally set a password instead, so you don't have to wait for a code every time (Settings β My Profile & Security). If you do, the password is stored by our authentication provider (Supabase) as a salted hash β never as readable text, and never visible to us. If you never set one, no password exists for your account.
If you ask to join without an invite, the app sends your email address to Sautero as an access request. It is stored so a kitchen admin can approve or decline you, and until then it sits in an internal contact list β before you have an account. If you are not approved, nothing further happens with it; you can ask us to delete it at any time.
Added 10 August 2026: a "request to join" option was added on 9 August, and this page did not mention that it stores the email of someone who has no account yet. That is exactly the kind of collection a privacy page must disclose, and the pilot agreement already did β this brings the public page in line.
Corrected 28 July 2026: this page previously said we never ask for or store a password. That was wrong β optional password sign-in has existed for some time. It is fixed here rather than quietly.
On a device that supports it, you can optionally switch on Face ID, Touch ID or Windows Hello so you don't have to type anything to sign in (Settings β My Profile & Security). Your face or fingerprint never leaves that device, and Sautero never receives it β the recognition is done by the device's own operating system, which only tells the app whether it recognised you. What Sautero keeps is a credential for that one device and the sign-in token it unlocks, both held in that device's own browser storage. Removing Face ID from the device, in the same settings screen, deletes both.
Added 4 August 2026: Face ID sign-in shipped in mid-July and this page never mentioned it, although biometrics are precisely the kind of data a page like this exists to describe. Same omission as location (28 July) and camera (30 July), found the same way and fixed the same way.
Recipes, ingredient prices, prep checklist entries, order lists, and anything else you or your team type into Sautero, stored so your kitchen can see and use it.
If your kitchen uses the Working Time feature, it records check-in/check-out times, breaks, and any notes a team member adds to a day. This is genuine employee attendance data. Under Swiss data protection law (nDSG) and similar rules elsewhere, this kind of data deserves extra care:
Sautero does not read your location. Clocking in or out never asks your browser for it, and a time entry has no place to store coordinates (the columns were dropped in db/294). The only thing a time entry can carry about "where" is a yes/no flag, on site, and it is set in exactly one way: the kitchen shows a check-in code that changes every 30 seconds, and if you type the current code when you clock in, the entry is marked on site. No code, no flag β clocking in still works. The flag is shown to you on your own day view; it is not a location and it is not shown to anyone as one.
Changed 2 September 2026: until this date the app took one location reading at clock-in and clock-out (db/63) and your admin saw your hours only if you had switched on "Share My Hours with Admin". Both are gone: no location is read or stored any more, the sharing switch has been removed, and kitchen leaders now see every team member's hours by name (db/320). Because this changes what your employer can see, the consent version was raised and you are asked to read and accept this page again.
Added 28 July 2026: this page did not mention location at all, although the app has stored it since db/63. That was a real omission, not a wording problem.
Corrected 4 August 2026: this page said your attendance and your clock-in location were visible to your kitchen admin, and elsewhere that your hours reached them as an anonymous total. Both were wrong, and wrong in the direction that matters β the database (db/99) has never let an admin read the entries of anyone who had not switched Share My Hours with Admin on, so by default they see nothing of yours at all. The page described more employer visibility than the product actually permits.
The app uses your device's camera in exactly two situations, and only when you open one of them yourself β it never watches in the background.
Your browser or phone asks for camera permission first. If you say no, everything still works β invite codes can be typed by hand, and every scan also accepts a file from your gallery.
Added 30 July 2026: this page described what happens to photos, but never said the word "camera", although QR scanning has used it since the Connections feature existed. Same class of omission as the location note above, fixed the same way.
Photos of recipes, invoices, menus, prep sheets, banquet enquiries and rota sheets that you scan, plus any photo you attach to a recipe. Files you scan are sent for reading (see AI features below); recipe photos and Working Time note attachments are stored so your kitchen can see them.
If your kitchen uses Events, a booking can hold your client's name, phone number, e-mail address and billing instruction, alongside the menu, the guest numbers and the price. That is third-party personal data you entered β it is visible only inside your kitchen, and you are responsible for having a reason to hold it.
Fridge and cooking temperatures, cleaning checklists and label print logs, with the time they were recorded and who recorded them.
We log logins and which parts of the app get opened (not what you do inside them) so we can tell whether the trial is actually being used, and we log JavaScript errors so bugs can be fixed. An error record holds the page address, your browser's user-agent string, the error message and its technical stack trace β and, so that a fault can be traced back to the account and kitchen it happened in, your user ID and your kitchen ID. Both logs are visible only to the Sautero team, never sold or shared.
Corrected 4 August 2026: this section called an error record "technical details only", which was not true β it also carries your user ID and your kitchen ID, so it identifies you. Nothing about what is collected has changed; the description was wrong and is now accurate.
When you use Chef's Assistant, scan a photo, or ask for menu proposals, the relevant text or image is sent to an AI provider through Sautero's own server. You do not need your own API key β Sautero uses its own, which never leaves the server.
Neither provider is permitted to use your content to train their models under the terms Sautero uses. Nothing is sent to either of them unless you press the button that does it.
Corrected 4 August 2026: the two lines above used to list less than what actually leaves. Menu proposals also send the titles of the dishes your kitchen already cooks, not only ingredient names; and picture generation also sends the recipe's main ingredients and plating notes, not only its title and description. Ingredient prices are still never sent, and that was checked in the code rather than assumed.
Anything you save while your account is set to "Personal" (Settings β Account Type) is private to you at the database level β nobody else on your team can read it, not even your kitchen admin, unless you separately choose to share it β by connecting with another chef and turning recipe sharing on. (The "also show my personal recipes here" switch is not one of those ways: it only changes what you see on your own screen while in Company mode, and shares nothing with anyone.) Ingredients work the same way ("My Ingredients" vs. the shared kitchen catalog).
Anything you submit through Settings β Send Feedback, together with your name/email, so we can act on it or follow up. Read only by Sautero's Head Admin.
Your logged Working Time hours appear in Kitchen Reports with your name, visible to your kitchen's leaders (admin, "kitchen reports" or "company admin" permission) β the same people who can read them in Working Time. There is no sharing switch any more; the "Share My Hours with Admin" setting was removed on 2 September 2026. Recipe and Check List counts shown in that report are kitchen-wide totals, not tied to individuals.
Only people who've joined your kitchen's team (via an invite link, QR code, or team join code you control). The Sautero team (currently a single founder) can access data to fix bugs, run migrations, or provide support β never to read your recipes or attendance data for any other reason.
Sautero has one door that is not a normal team membership. An account marked as head admin in the database β today that is the founder's β can join your kitchen for a while, see it exactly as one of your team members sees it, and then leave. It exists so that a problem you report can be looked at in your actual kitchen instead of guessed at from a description, and so that setup help does not require you to hand over your login.
Three limits apply, and each one is enforced in the database rather than promised here:
Added 1 August 2026: this capability shipped on 29 July and this page said nothing about it, while telling you your data is visible to your team. The permanent visit record was built at the same time as this paragraph β before 1 August a visit left no trace at all, so the sentence above would not have been true if it had been written earlier.
Whether you're in the EU (GDPR) or Switzerland (the revised Federal Act on Data Protection, in force since September 2023), you have the right to:
Sautero relies on: your consent for optional features (AI, hours-sharing); performance of the contract between you/your kitchen and Sautero for core features; and legitimate interest for basic security/error logging. We act as the data controller for account data, and the companies listed below act as our data processors. Sautero has not yet signed a separate data-processing agreement with any of them; until it does, what limits them is their own published terms rather than an agreement negotiated for you. Putting those agreements in place is on the list before the trial widens.
Sautero's database, accounts and file storage run on Supabase (a hosted Postgres provider), with servers in the EU. On your own device, Sautero keeps your login session, your language and theme, a random device ID that is not tied to your name, whether you have already seen the tutorial, how you have arranged your own tiles and shelves, and small work-in-progress items such as a running timer or a print queue. If you switch on Face ID or fingerprint sign-in, that device also keeps the credential for it and the sign-in token it unlocks. All of this stays in your browser and goes nowhere except to Sautero itself. Sautero uses no tracking cookies, no advertising and no third-party analytics.
These are every company that processes any part of your data on our behalf. There are no others:
Corrected 4 August 2026: this list named five processors and closed by saying there were no others, while the mail host that receives everything sent to our contact address was not among them. Found by an internal check, not by a complaint.
Corrected 28 July 2026: this page previously named only Supabase and Anthropic. Google, Resend and GitHub were processing data without being listed, which is the single most common and most damaging omission a page like this can have.
Because this is an early trial, this page and the product itself will change as Sautero moves toward a real launch β including a proper legal review of these terms before any public release. If something material changes for you specifically (like new AI data handling), we'll tell you directly, not just quietly update this page.
Sautero is built and operated by a single person. There is no company behind it yet, and this page says so rather than implying otherwise:
Richard Δervenka
Steinauweg 12
3007 Bern
Switzerland
E-mail info@sautero.ch
Sole trader, not entered in the commercial register. No VAT number: Sautero is a free trial and has taken no payments, so the CHF 100,000 registration threshold is not reached. Responsible for the content of this site: Richard Δervenka, address as above.
Questions or requests
Write to info@sautero.ch, use the feedback button in the app, or reply to any Sautero e-mail. Data-protection requests (access, correction, deletion) go to the same address and are answered by the person named above β there is nobody else.