FOODBOYZ AI
YOUR DATA.
Notes on the protected workspace.
As of 11 September 2026. In addition, the Privacy notice of FOODBOYZ GmbH.
Controller and contact
FOODBOYZ GmbH, Bült 2, 48143 Münster. Contact for access, correction, export or deletion: info@foodboyz.com.
Account and operations data
In the protected workspace, name, email address, a password hash, company assignment and permissions are stored. Restaurant profiles, menus, recipes, prices, tasks, notes, documents and settlement drafts are stored when you create them. They serve the administration of your operation. Please do not enter unnecessary personal, health or payment data.
Access and hosting
The database sits outside the publicly reachable website folder on the existing Hostinger hosting. Members see only released companies. Owners manage team and data; managers edit operations data; employees have read access. FOODBOYZ administrators can grant internal access; this is logged.
Sessions and security
A technically required session cookie keeps the sign-in. It is limited to the AI area, protected via HTTPS and not readable by JavaScript. Sign-in ends after 30 minutes of inactivity or at the latest after twelve hours. Password reset revokes existing sessions. Protection values against repeat attempts are derived cryptographically and removed after expiry at the next request.
Invites and password reset
Invite links are created by the owner and passed on in person. They are valid for 24 hours. Password-reset links are sent on request by email via the existing Hostinger mail service, are valid for 30 minutes and can be used only once. A hash of the token is stored.
Local assistant and brand finder
The brand finder still processes your kitchen details locally in the browser. The local workspace assistant uses stored dishes, calculations and tasks of the selected operation. No external AI provider is called.
Optional text AI
The OpenAI connection is off at first. It can only be activated with a server-side API key and an approved budget. Each text-AI request first asks your consent to send the message and up to 30 dishes with descriptions, prices and costing. Address, team data, tasks, internal notes and documents are not attached automatically. Please do not put such data in the message either.
The connection uses the OpenAI Responses API with response storage off (store=false). This is not a promise of complete non-storage at the provider; in particular its rules on security logs apply. Information: OpenAI data processing. Before activation FOODBOYZ must clarify the matching provider, processing and transfer agreements.
Retention and export
Assistant messages and answers are not stored as a chat history. A text is stored lastingly as a document only if you take it over and save it. Usage counts, token amounts and cost estimates are kept up to 400 days, change logs up to 90 days. Expired records are cleaned at the next request.
Business data remain until they are deleted. You can delete individual menus, dishes, tasks, documents and settlement drafts; owners can export company data. Restaurant profiles can be archived. For full deletion of a company or account, contact FOODBOYZ. Statutory retention duties and separately managed backups must be taken into account.