Skip to content
No results
  • Home
  • About
  • How It Works
  • Resources
    • Blog
    • The Operator’s Playbook
    • ROI Calculator
  • Pricing
  • Contact
TheStaffDevApp.comTheStaffDevApp.com
The StaffApp™
  • Home
  • About
  • How It Works
  • Resources
    • Blog
    • ROI Calculator
    • The Operator’s Playbook
  • Pricing
  • Contact
Log In
TheStaffDevApp.comTheStaffDevApp.com
The StaffApp™

Privacy Policy

The StaffApp™
Effective Date: April 15, 2026  |  Last Updated: April 17, 2026

At a glance. We take privacy seriously. Here’s the short version — full details follow.

  • What you give us: account information, billing details, and the staff records you enter into the platform (the “Customer Content”).
  • What we collect automatically: basic usage data and technical information to keep the service running and secure.
  • What we don’t do: we don’t sell your data, we don’t use your staff records to train AI models, we don’t share information with advertisers, and we don’t use your voice recordings to train anyone’s AI.
  • Who’s responsible for what: for business account information, we’re the data controller. For information about your employees, you (the customer organization) are the controller and we are a processor operating on your behalf.
  • Who to contact: support@thestaffdevapp.com, or the contact block at the bottom of this policy.

Contents

  1. Who We Are
  2. Scope
  3. Our Two Roles
  4. Information We Collect
  5. How We Use Information
  6. What We Don’t Do With Your Information
  7. How We Share Information
  8. How Long We Keep Information
  9. Security
  10. Cookies and Similar Technologies
  11. Your Privacy Rights
  12. Children’s Privacy
  13. International Users
  14. Changes to This Policy
  15. Contact Us

1. Who We Are

This Privacy Policy describes how Chef Life Media LLC (“Company,” “we,” “us”), a North Carolina limited liability company headquartered in Asheville, North Carolina, handles information in connection with The StaffApp™ (the “Service”).

2. Scope

This Policy applies to:

  • The marketing website at thestaffdevapp.com
  • The application at app.thestaffdevapp.com
  • Any subdomain operated by Chef Life Media LLC in connection with the Service (e.g., calculate.thestaffdevapp.com)

It does not apply to third-party websites linked from the Service or to the separate websites and services of Chef Life Media LLC (e.g., thecheflifebrigade.com), which have their own privacy policies.

3. Our Two Roles

Under data protection laws, a company can be either a “controller” (decides what information is collected and why) or a “processor” (handles information on behalf of a controller). We operate in both roles depending on the information:

We are a controller of:

  • Your account registration information (as the Account Owner)
  • Your billing and payment information
  • Your communications with our support team
  • Marketing website analytics

We are a processor of, and you (the Customer Organization) are the controller of:

  • Staff Records, including employee names, roles, onboarding plans, performance notes, discipline documentation
  • Voice dictation audio (processed ephemerally) and the resulting transcripts
  • DevCoach conversations and generated outputs
  • Any other information entered into the Service about individuals

This distinction matters because it determines who has what legal obligations toward the employees whose information flows through the platform. If you are an employee whose information is in the Service, your primary point of contact for privacy requests is your employer. We support your employer in fulfilling those requests.

4. Information We Collect

4.1 Information You Provide to Us (Controller Role)

When you create an account: name, business name, email address, password (stored hashed), plan selection.

When you pay for a subscription: billing address and payment method information. Payment card numbers are processed by our payment processor (Stripe) and are not stored on our systems.

When you contact support: your message, the email you send from, and any attachments.

When you sign up for marketing content: email address, name (if provided), and any information you provide on lead generation forms (such as the ROI calculator at calculate.thestaffdevapp.com). These are processed through FluentCRM.

4.2 Information Entered into the Service (Processor Role)

When you and your Authorized Users use the Service, you enter information about your workforce. This includes:

  • Staff identifiers: employee names, roles, departments, hire dates, and any other identifiers you choose to enter
  • Performance information: onboarding plans, manager check-in notes, performance observations
  • Disciplinary documentation: progressive discipline write-ups, incident descriptions, corrective actions, audit trails
  • Voice recordings (if voice dictation is enabled): audio of the dictating user, processed transiently (see Section 7.3)
  • DevCoach interactions: prompts sent to the AI coaching assistant and generated outputs
  • Attachments and files you upload

We act as a processor for this information. We do not decide what information you collect or why — you do, as the Customer Organization.

About DevCoach. All DevCoach frameworks, tools, methodologies, and coaching best practices are derived from the Chef Life coaching system developed by Chef Adam M. Lamb and Chef Life Media LLC. This includes the ZAK framework, progressive discipline guidance, the Successful Chef Leadership Bootcamp curriculum, and the broader library of hospitality leadership principles taught through The ChefLife Brigade. Learn more at cheflifecoaching.com and thecheflifebrigade.com.

4.3 Information Collected Automatically

From all users of the Service:

  • Technical data: IP address, browser type and version, operating system, device type, time zone
  • Usage data: pages viewed, features used, timestamps, referring URLs
  • Error logs: diagnostic information when something goes wrong

From the marketing website:

  • Cookies and similar technologies for analytics and basic session functionality (see Section 10)
  • Form submission data (lead capture through FluentCRM)

5. How We Use Information

5.1 To Operate and Provide the Service

  • Authenticate your account
  • Store and retrieve Customer Content
  • Process payments and send billing communications
  • Provide features including onboarding workflows, check-ins, discipline tracking, DevCoach, and voice dictation

5.2 To Support and Improve the Service

  • Respond to support requests
  • Monitor system performance, detect errors, and investigate security incidents
  • Analyze aggregated, anonymized usage patterns to improve the product
  • Communicate essential service updates

5.3 For Security and Legal Compliance

  • Prevent fraud, abuse, and unauthorized access
  • Enforce our Terms of Service
  • Comply with legal obligations, including responding to lawful requests from authorities
  • Establish, exercise, or defend legal claims

5.4 For Marketing (with your consent where required)

  • Send product announcements and educational content to users who have opted in
  • Respond to lead generation form submissions
  • Deliver the email nurture sequence associated with resources like the ROI calculator

You can unsubscribe from marketing communications at any time using the link in any marketing email.

6. What We Don’t Do With Your Information

We think these deserve explicit statement:

  • We do not sell personal information — not to advertisers, not to data brokers, not to anyone. This applies to both our controller data and Customer Content we process.
  • We do not use Customer Content to train AI models. Not our own models, not our providers’ models. Contractually, our subprocessors (Anthropic for DevCoach, Deepgram for voice dictation) do not train on data submitted through the Service.
  • We do not use voice dictation audio for any purpose beyond transcription. Audio is sent to Deepgram under a zero-retention configuration, transcribed, and discarded. We never write audio to disk on our servers.
  • We do not share Customer Content across customer organizations. Your data is isolated from every other customer’s data by design (row-level security in our database).
  • We do not profile your employees for us. Any profiling, ranking, or evaluation within the Service is performed for you, as controller, by your managers — not by us for our own purposes.

7. How We Share Information

7.1 With Subprocessors

We use third-party service providers to operate the Service. Each is contractually bound to use data only for the specific services we engage them for. Current subprocessors include:

Current subprocessors
Subprocessor Purpose Data Location
Supabase Database, authentication, file storage US (us-east-1)
Vercel Application hosting and edge compute Global edge network
Anthropic PBC Large language model powering DevCoach US
Deepgram, Inc. Voice dictation transcription (zero retention) US
ElevenLabs Inc. Text-to-speech synthesis of DevCoach responses (Listen feature), using a licensed custom voice model of Chef Adam M. Lamb US
Resend, Inc. Transactional email delivery United States
SiteGround Marketing website hosting (WordPress) US
FluentCRM (self-hosted on WordPress) Marketing email and CRM On our infrastructure
Stripe Payment processing US

We will publish an updated list here when subprocessors change. Customer Organizations may request advance notice of new subprocessors handling their Customer Content; the request process is described in our Data Processing Agreement.

7.2 With Your Authorized Users

Customer Content is accessible to Authorized Users of your Customer Organization per the access levels you assign.

7.3 Voice Dictation — Detailed Data Flow

Because voice data warrants specific explanation, here’s what happens end to end:

  1. Audio is captured by your browser when you click the Dictate button.
  2. Audio is transmitted over TLS (encrypted in transit) to our Supabase Edge Function.
  3. Our Edge Function forwards the audio to Deepgram’s API with zero-retention enabled. Zero-retention means Deepgram does not store your audio, does not store the resulting transcript on their systems beyond the API response, and does not use the audio for model training.
  4. Deepgram returns the transcript to our Edge Function.
  5. Our Edge Function inserts the transcript into the intended field and logs a metadata-only record (user ID, duration, character count, timestamp — not the audio, not the transcript text) to our database for audit and rate-limiting purposes.
  6. The audio is discarded from memory. It is never written to persistent storage on our systems.

The audio exists in memory for approximately the duration of transcription (a few seconds). That’s it.

7.4 DevCoach Voice Output (Text-to-Speech) — Detailed Data Flow

Some DevCoach replies can be played aloud using a “Listen” button. The spoken audio is generated by ElevenLabs using a licensed custom voice model of Chef Adam M. Lamb’s voice. The spoken output is AI-generated and does not represent a real-time statement by Chef Lamb.

Here’s what happens when you press Listen:

  1. The text of the DevCoach AI response (only) is transmitted over TLS to ElevenLabs’ API. Your question is never sent to ElevenLabs — only the response the AI generated.
  2. ElevenLabs synthesizes audio using the licensed custom voice model and streams the audio back to your browser.
  3. The audio is played in your browser and is not stored on our systems.
  4. We log a metadata-only record (user ID, timestamp, character count — not the text, not the audio) for audit and rate-limiting purposes.

A note on ElevenLabs retention: Unlike voice dictation, the Listen feature does not operate under a zero-retention configuration. ElevenLabs may retain the submitted text and generated audio in operational logs under their standard retention policy for abuse monitoring and quality purposes. ElevenLabs does not use submitted content to train their models on our plan tier and commits to deleting customer data upon termination. ElevenLabs maintains a comprehensive compliance posture, including SOC 2 Type 2, ISO 27001:2022, ISO 27701:2019, ISO/IEC 42001:2023 (AI management systems), HIPAA, GDPR, and CCPA/CPRA certifications and attestations. Current details are published at elevenlabs.io/trust. If a DevCoach response incidentally repeats a staff name or other Customer Content from the conversation, that text may appear in ElevenLabs’ operational logs for their published retention window. Customers with stricter retention requirements should avoid using the Listen feature on responses that echo sensitive Customer Content, or contact us at legal@thestaffdevapp.com to discuss enterprise-tier arrangements.

7.5 Web Push Notifications

If you opt in to push notifications in your in-app profile settings, notifications are delivered using the Web Push standard. Delivery is signed using the VAPID protocol (Voluntary Application Server Identification) and routed through your browser’s push service (such as Google’s FCM for Chrome and Android, Apple’s APNs for Safari and iOS, or Mozilla’s autopush for Firefox). These browser push services are infrastructure of your browser vendor rather than subprocessors we engage. No notification content is stored on our servers beyond the audit metadata described in Section 8. You can unsubscribe at any time from your profile settings.

7.6 With Professional Advisors

We may share information with legal, accounting, or other professional advisors under confidentiality obligations.

7.7 For Legal and Safety Reasons

We may disclose information if required by law, subpoena, or other lawful process, or if we believe disclosure is necessary to:

  • Protect the rights, property, or safety of Company, our users, or the public
  • Investigate fraud or security incidents
  • Respond to an emergency

Where legally permitted, we will notify the affected Customer Organization before disclosing their Customer Content in response to a legal request.

7.8 In Connection With a Business Transfer

If Company is involved in a merger, acquisition, sale of assets, or bankruptcy, information may be transferred as part of that transaction. We will notify you and honor applicable privacy commitments.

8. How Long We Keep Information

  • Account and billing information: while your account is active, plus 7 years after termination for tax and legal recordkeeping.
  • Customer Content: available for export through the in-app tool for 30 calendar days after termination (the Export Grace Period). From day 31 through day 90, Customer Content is held in dormant retention — not accessible in-app, but available by written request to legal@thestaffdevapp.com for export or reactivation. On day 91, Customer Content is permanently deleted from production systems, and purged from rolling backups within 35 calendar days after permanent deletion. Customers may request a legal hold before day 91 to extend retention; see our Subscription Terms for the legal hold process.
  • Voice dictation audio: never persisted; discarded within seconds of transcription.
  • Transcription metadata (audit logs, no content): 2 years from creation.
  • Support communications: 3 years from last interaction.
  • Marketing email lists: until you unsubscribe, plus a short suppression period to prevent re-messaging.
  • Website analytics: as configured with each analytics provider, typically 14–26 months.

Certain records may be retained longer if required by law or for the establishment, exercise, or defense of legal claims.

9. Security

We maintain administrative, technical, and physical safeguards designed to protect information, including:

  • Encryption in transit (TLS) and at rest (AES-256)
  • Row-level security isolating each customer’s data
  • Role-based access controls within the Service
  • Regular security patching of our platform and dependencies
  • Logging and monitoring of access to production systems
  • Vendor security review before engaging new subprocessors

No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you in accordance with applicable law. See our Security page for more detail.

10. Cookies and Similar Technologies

10.1 Marketing Website (thestaffdevapp.com)

We use cookies for:

  • Essential functionality — session management, security
  • Analytics — privacy-respecting server-side analytics
  • Lead generation — FluentCRM form tracking for visitors who submit forms

We do not currently run third-party advertising cookies. If this changes, we will update this policy and, where required, provide a consent banner.

10.2 Application (app.thestaffdevapp.com)

The application uses only cookies strictly necessary for authentication and session management.

10.3 Your Choices

Most browsers allow you to refuse or delete cookies. Doing so may limit functionality of the Service.

11. Your Privacy Rights

11.1 All Users

You may:

  • Access your account information through the Service or by request
  • Correct inaccurate information
  • Export Customer Content in a machine-readable format
  • Delete your account and associated data (subject to the retention terms in Section 8)
  • Unsubscribe from marketing communications at any time
  • Contact us with privacy questions at privacy@thestaffdevapp.com

11.2 If You Are an Employee in a Customer Organization

If your employer uses The StaffApp™ and your information is stored in the platform as Staff Records:

  • Your primary point of contact is your employer. Your employer is the data controller for that information and decides what to do with it.
  • You may contact us directly at privacy@thestaffdevapp.com and we will either respond or route your request to your employer as appropriate.
  • We will not delete or modify your employer’s records about you without your employer’s authorization, except where required by law.

11.3 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act, including:

  • Right to know what personal information is collected
  • Right to correct inaccurate personal information
  • Right to delete personal information
  • Right to opt out of sale or sharing (we do not sell or share personal information as those terms are defined under CCPA/CPRA)
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising rights

Authorized agents may submit requests on your behalf with verification. For detailed disclosures specific to your jurisdiction or to submit a verifiable request, contact privacy@thestaffdevapp.com.

11.4 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

If GDPR or UK GDPR applies to you, you have rights including access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority. Data transfers to the United States are made under Standard Contractual Clauses or another applicable transfer mechanism, as described in our Data Processing Agreement. For detailed disclosures specific to your jurisdiction or to submit a verifiable request, contact privacy@thestaffdevapp.com.

11.5 Illinois Residents (BIPA)

The Illinois Biometric Information Privacy Act (BIPA) regulates the collection and use of biometric identifiers, which in some interpretations may include voice recordings. We do not store voice recordings, and our speech recognition provider operates under zero-retention; audio exists in memory only for the few seconds required for transcription and is never written to disk on our systems. Customer Organizations operating in Illinois remain responsible for obtaining any written consent required under BIPA before enabling voice dictation for Illinois-based employees. For detailed disclosures specific to your jurisdiction or to submit a verifiable request, contact privacy@thestaffdevapp.com.

11.6 Other States

We monitor and aim to comply with evolving state privacy laws, including in Virginia, Colorado, Connec

Copyright © 2026 - Chef Life Media LLC

  • Our Mission
  • Support
  • Help
  • Legal
  • On Line Status