Apron / Leech Labs

Apron privacy policy

Effective October 11, 2026

Who operates Apron

Apron (listed as Apron: Restaurant Management) is a restaurant operations app operated by Edward Porter under the Leech Labs name. This policy describes the current iOS, Android and connected web app, including optional evidence uploads. Contact us at noreply@apron.management.

Account and restaurant information

When you create an account, we receive your name, email address and password through our authentication service. Passwords are stored as authentication hashes, not as readable passwords. Account identifiers, verification status, sessions and organization memberships support sign-in and access control. Your organization can store restaurant and location information, assigned roles, invitations, checklists and responses, temperature readings, corrective actions, issues, comments, manager handoffs, equipment details, waste records, procedures, document versions and reading acknowledgments. Records may include the author, timestamps and personal information that you choose to enter. Restaurant location names and addresses describe the workplace; the app does not request or read your device GPS location.

Camera, QR scanning and optional uploads

The camera is used to scan station and equipment QR codes and to capture evidence photos when you choose those features. Live QR camera frames are processed on your device. An optional evidence photo is transmitted to private backend storage when you submit it, together with its filename, type, size, organization/location reference and uploader identity. Supported evidence also includes JPEG, PNG, WebP and PDF files. Evidence is made available to authorized members of the restaurant workspace. Avoid uploading unnecessary information about guests, employees or other people. Camera permission can be revoked in device settings. Microphone recording is not enabled.

Information stored on your device

Native sign-in state uses the operating system protected storage through Expo SecureStore. Local preferences and any local demo workspace use device storage. The fictional Harbor Kitchen demo, when enabled, keeps its operations on that device and has a reset option. Production builds use the connected backend, and real saved restaurant records are sent to it. Clearing or uninstalling the app does not delete connected accounts, shared restaurant records, exported files or independent backups.

Service data and SDKs

Authentication can record session information such as device/browser user-agent and network address when available. Our backend records operational audit events and account-based anti-abuse information. Application error logging records error names; hosting and infrastructure providers may process request and diagnostic information to operate their services. Android QR scanning uses Google ML Kit. Google states that ML Kit processes image inputs and results on the device, but sends SDK utilization/performance metrics to Google and may contact Google for updates and compatibility information. See Google ML Kit Terms & Privacy and its data-disclosure documentation. Apron has no configured advertising SDK, cross-app advertising tracking, third-party product analytics SDK, cloud generative-AI processing, in-app purchases or payment collection in this candidate. Restaurant reports and operational summaries are features using your workspace records.

Why we use information

We use information to authenticate users, verify email, reset passwords, enforce workspace access, synchronize restaurant operations, save and retrieve evidence, provide reports and acknowledgments, maintain an audit history, prevent abuse, troubleshoot failures and respond to support requests. Email messages are sent for verification and password reset. If you contact support, we receive and use the details you include to respond. We do not sell your personal information or use it for advertising tracking.

Sharing and service providers

Your restaurant organization controls who can access its shared workspace through assigned roles and location access. We use Neon for application execution, authentication data, database access and private evidence infrastructure, including its configured S3-compatible storage. Hostinger provides the application HTTPS gateway, public pages and email service. Infrastructure uses cloud services such as AWS. Google processes ML Kit SDK metrics on Android under its own practices. These services process information to provide their functions. Data may be processed outside your country. We may disclose information when legally required or to protect the service and its users. Exported reports and files that you choose to share are under your and your organization’s control.

Security

Connections to the configured app/backend use HTTPS. Accounts require email verification. Workspace data and evidence access are checked against authenticated sessions and organization/location permissions; evidence downloads use time-limited links. Database, storage and email credentials are kept on the server. These measures reduce risk but do not guarantee absolute security. Protect your account password, device and any files you export.

Retention and deletion

The current service stores connected accounts, restaurant records, audit history and uploaded evidence; it has no automatic account deletion or fixed automatic record-expiry period implemented. Shared operational history remains available to authorized organization members. We do not promise a retention duration that has not been established. Copies in infrastructure backups or provider logs may persist under the provider’s applicable practices. To ask about access, correction or deletion, contact noreply@apron.management and your organization administrator. An automatic account-deletion control is not currently available. The treatment of shared records and attribution after account deletion is still being established; a request does not guarantee that deleting your account will delete your organization’s shared records.

Your choices and contact

You can decline optional evidence uploads, revoke camera permission, sign out, ask your organization administrator to correct restaurant information, and contact noreply@apron.management for privacy questions or requests. Do not send passwords, verification links or sensitive restaurant evidence in a support email. Apron is intended for workplace restaurant operations rather than children. This public policy page does not run advertising or analytics scripts. We will update this page and its effective date when our practices change.

Google ML Kit Terms & Privacy · Google Privacy Policy