One thing worth knowing about your kitchen, every morning.
It reads the cameras you already have and compares today against your own normal — not a benchmark, not another kitchen. Most mornings it tells you nothing unusual happened, which is the answer you are actually paying for. It never names anyone. It cannot hear. Faces are destroyed on a box in your kitchen, before anything is written to a disk.
What you get
A sentence, in the morning, about yesterday.
Three numbers come out of the video, per zone you care about — the pass, prep, the wash, the walk-in door. How many people were in it. How long each of them stayed. And whether either of those was unusual for that zone at that time of the week.
“The pass was busier than usual between 18:45 and 19:20 — about 3.1× your usual Friday evening. It was also holding people longer than usual.”
“Nothing unusual today.”
It compares you to you
Normal is learned per zone, per fifteen minutes, with weekdays and weekends pooled separately. A Tuesday lunch is measured against your Tuesday lunches. One chaotic Saturday does not move the baseline — we use medians, so an outlier stays an outlier instead of becoming the new normal.
It reports, it does not explain
We can tell you the pass stayed crowded for thirty-five minutes. We cannot tell you why, and we will not guess. We do not see tickets, order times or covers. You were standing there; we were not. Every operator converts the observation into a cause faster and more accurately than we could.
It arrives with the first coffee
Yesterday's line, sent the next morning, because service does not end when the calendar day does and an evening send cuts off the busiest hour. Email, or a webhook into whatever you already use. The email carries a link, never footage.
Set expectations early
For the first three weeks it says “still learning”.
There is no way around this and we would rather you hear it now than discover it on day two. The baseline needs to have seen a given fifteen-minute slot on enough separate days before it has an opinion about it. Until then, that slot reports that it is still learning your kitchen, and it means it.
Roughly three weeks of ordinary service, and it starts talking. That window is not wasted: it overlaps the silent week the compliance side needs anyway, so it is one wait rather than two.
The part your team will ask about
It cannot be turned into a tool for watching people.
The first question a cook asks is whether this is about them. The honest answer is no, and it is no because of how the thing is built, not because of a policy we could quietly change next quarter.
- No insight is ever about a person. Findings key on a zone and a span of time. There is no per-employee report, no ranking, no “whoever was at prep was idle for forty minutes”. The software has no way to produce that sentence, and a test in our build fails if anyone ever teaches it one.
- No face recognition, no identification, no biometric template. Not disabled — never built. The internal reference for “a person” is regenerated with the date folded into it, so the same cook on Monday and on Tuesday is two unrelated references. The key that would connect them lives in memory for one shift and is never written down. We cannot re-identify anyone afterwards. Not “we would decline to” — we cannot.
- Nothing here may drive hiring, firing or discipline. That is our position and it is written into the pilot agreement. California is actively legislating on automated decisions about workers, and a product that cannot output a ranking about an employee is a much shorter conversation with your lawyer than one that can.
- It does not listen. Audio is refused where the video stream is opened, so the camera is never asked to send it. In California, recording a confidential conversation without everybody's consent is a crime rather than a fine, so this is a hard control and not a setting.
- Seeing a number and opening footage are different permissions. A shift manager can be given the daily report and the counts without being able to open a single clip. Every access to footage lands in a tamper-evident log.
Where the privacy work happens
On a box in your kitchen, before anything is stored.
Order matters more than intention here. Blurring a face after the frame has been written to a disk is not privacy, it is tidying up. So both destructive steps run on the small box that sits in your building, on the frame in memory, before it reaches storage of any kind.
-
In your kitchen — step 1
Regions you nominated are filled in solid: the ticket rail with customer labels on it, the rota board with full legal names, the KDS screen. Filled, not blurred — blurred text stays readable.
-
In your kitchen — step 2
Faces are found and blurred. Only then does the frame reach a disk, the network, or anything that keeps it. No audio was ever acquired.
-
Then, and only then
The redacted, blurred frame is analysed, and what is kept is counts and time spans. Your raw frames never leave the building.
The first two boxes are on your premises. We verify this against the bytes actually stored, not against a diagram — twice now, that check has caught us doing it in the wrong order, and both times we moved the step rather than reworded the claim.
A camera will not start until someone has answered what it must not see
Somebody walks each camera at install and marks the regions to destroy. “Nothing to redact on this one” is a perfectly good answer, but it has to be given: a camera nobody has answered for refuses to start, before it is even opened. There is no flag that switches redaction off.
What is kept, and for how long
Blurred evidence clips are the shortest-lived thing we hold and are deleted after thirty days. Occupancy counts — “2.3 people stood in this polygon at 11:45” — carry no imagery and are the only memory the baseline has. Every category has its own period, enforced by a sweep that also logs what it deleted.
The longer, more technical version — which is the page to forward to whoever reviews this for you.
The thing everybody asks about first
Gloves and hairnets: not shipping, and we will not pretend otherwise.
In development
Hairnet and bare-hand detection is the reason most operators call us, so here is where it honestly stands. We hold it to a fixed bar before it is allowed to raise anything with anyone: at least 90% of the things it flags must be real, and it must catch at least three quarters of what happens — measured on a full held-out shift of real kitchen footage, never on a random handful of frames, because consecutive frames of the same video flatter a model enormously.
Hairnets are close. Bare hands are not there yet: wet skin, clear gloves, blue gloves and a rush all break it in different ways. Until a model clears the bar on footage from your kitchen, it runs silent — logging what it would have said so you can read it, sending nothing to anyone. Hairnets will go live first, on their own.
What you can buy today is the operational picture above. If someone sells you kitchen compliance detection as a finished product, ask them for the precision and recall numbers and how the test split was made.
What a pilot involves
Five things have to be true before a camera turns on.
This is why there is no button on this page that starts a trial. A business cannot begin recording its staff because a form was submitted, and we are not going to build the flow that suggests otherwise.
- A signed pilot agreement. It names us as your service provider, which is the arrangement that keeps the obligations proportionate for you, and it forbids us from using your data for anything other than running the service. We do not monetise footage. There is no other business model hiding behind this one.
- Signage posted in the areas the cameras cover.
- The notice given to your staff. You give it — they are your employees, so it is yours to give. We supply the template and, more usefully, the accurate facts to put in it, because a lawyer cannot tell from the outside that clips expire in thirty days or that a manager account physically cannot open one.
- Every camera declared for what it must not see, as above. This one is not a checklist item we trust you on — the software refuses to start without it.
- A week running silent. It watches and logs and sends nothing, so you can read what it would have said before anyone else does. That week is also the baseline starting to learn.
On hardware: it runs on the CCTV you already have, over your existing network. Reckon on about four camera feeds per small box, and a cupboard or an office shelf to put it on. No GPU, no rewiring, no camera replacement.
For whoever reviews this for you
You are probably about to forward this to a lawyer. Good.
We designed against California first on purpose: it is the strictest regime we intend to operate in, so satisfying it is the constraint rather than an afterthought. The short list of what we designed against, and what follows from each, is on how it works. Two things worth flagging up front, because they usually come up in the first ten minutes:
- Employees are consumers here. The CCPA employee exemption lapsed at the start of 2023, so your kitchen staff have access and correction rights over what is collected, and notice is owed at or before collection — not in a policy nobody reads after the fact.
- One awkward answer, stated deliberately. Because person references are un-linkable by construction, a deletion request for the video analytics cannot be honoured — there is nothing to look up and no key left to look it up with. That is a strong privacy posture and an uncomfortable compliance sentence, and they are the same fact. We put it in front of counsel rather than letting it be discovered during a request.
Nothing on this website is legal advice, and we are engineers rather than attorneys. What we can do is describe exactly what the software does, precisely enough that your own counsel can check it.
Enquire
Tell us about your kitchen.
A real person reads this and replies. It is a conversation, not an onboarding flow — the next step is usually a call about how many cameras you have, where they point, and what you would want a zone to be.