Privacy · the site and the app

What this site and this app know about you

Almost nothing, and the useful version of that sentence is the one you can check rather than the one you have to believe. This page describes exactly what happens when you read sahotchicken.com or open the iOS app — including the one place a third party genuinely sees something, which is the company that serves you these files.

Effective August 19, 2026

The short version

We collect nothing about you, so there is nothing to lose, sell or hand over

There is no account, no login, no password, no newsletter, no comment section, no contact form, no shopping cart and no paywall. There is no analytics package, no tag manager, no advertising network, no tracking pixel, no session recorder, no A/B testing tool and no crash reporter. Nothing about your visit is stored by us, and nothing is sold, shared, rented or traded, because there is nothing to sell.

The iOS app goes one step further than a promise: it contains no networking code at all. It cannot send anything anywhere, whether we want it to or not.

That is a large claim, so the next three sections say how it is checked rather than asking you to take our word for it — and the section after those says what our hosting provider sees, which is the part a policy like this usually leaves out.

The website

This page loads nothing from anywhere else

Every file your browser fetches while reading this site comes from this domain. There is no request to Google, no font pulled from a font service, no script from a CDN, no embedded video, no map iframe, no social share button and no comment widget. Those are the things that do the tracking on a normal website, and none of them is here.

Everything your browser requests to render this page
WhatFrom where
The page itselfsahotchicken.com
One stylesheetsahotchicken.com
The typefacessahotchicken.com
The photographssahotchicken.com
The mark in your browser tabnothing is fetched
Anything else, from anyone

The site runs one piece of JavaScript, written by us and printed inline in the page you already have: about thirty lines that filter the ranked list when you type in the search box or press a filter key. It never leaves your browser and it sends nothing. The search box is not a form and has nothing to submit to.

Every absolute web address in this site’s output is an ordinary link you can choose to click, and there are a great many of them, because every figure we print links back to the record it came from. Not one of them is loaded on your behalf.

The exception

Cloudflare serves this site, and Cloudflare sees your request

This is the honest part, and it is why this page is longer than “we collect nothing”.

sahotchicken.com is hosted on Cloudflare Pages. Every request for every page passes through Cloudflare’s network before it reaches a file of ours, and to route it Cloudflare necessarily receives what any web server receives: your IP address, which page you asked for, your browser’s user-agent string, and the time you asked. Cloudflare processes that as our infrastructure provider, under its own terms and retention policy. We do not receive it. There is no analytics dashboard on this account and no report anyone here reads.

Cloudflare also adds three things to what you receive that are not in anything we build. We did not write them, they are not in our source, and they appear on every page:

Added by Cloudflare at the edge · observed on the live site 2026-08-21
WhatWhat it does
email-decode.min.js Cloudflare’s Email Address Obfuscation. It rewrites the email addresses we print into an encoded form and adds a small script that turns them back into a working link in your browser. Its purpose is to stop address-harvesting bots reading them off the page. It does not identify you.
challenge‑platform Cloudflare’s bot detection. A hidden one-pixel frame loads a script that reads properties of your browser to tell an automated client from a person. This is the one item on this page we would call a real trade-off, and we would rather name it than let you find it in the page source.
Network Error Logging A response header asking your browser to report failed requests back to Cloudflare. It is configured to report errors only, not successful page views.

Saying “we ship no third-party code” and stopping there would be true of our repository and false of your browser, and your browser is the version that matters. So: what Cloudflare does with request logs is governed by Cloudflare’s privacy policy and, for the account serving this site, its customer data processing addendum. Cloudflare documents the cookies its products may set here; we observed no cookie set on the page response itself, and we set none of our own, ever.

If we ever turn any of that off, or Cloudflare’s behaviour changes, this section changes with it.

The app

The iOS app cannot phone home, and that is checkable

The entire guide ships inside the app — every establishment, every inspection, every violation finding, every award. Nothing is fetched while you read, which is why it works with one bar of signal in a car park, and a guide update arrives as an app update.

The strongest thing we can tell you about it is structural rather than a promise. The app is not linked against any networking framework. Running otool -L — the standard tool for listing what a compiled binary depends on — against the built app reports only Apple system frameworks and the Swift runtime. There is no CFNetwork, no Network.framework, no analytics SDK, no advertising SDK, no crash reporter, and no third-party code of any kind. A program with no networking library linked into it has no mechanism to send anything anywhere. That is not a policy we could quietly change; it is a property of the binary, and it is why the App Store privacy label says Data Not Collected in every category.

What the app keeps, on your phone

  • The places you saved — a list of health-permit licence numbers, nothing more.
  • Whether you switched re-inspection alerts on.
  • The most recent inspection date it has already shown you for each saved place, so it can tell when a newer one arrives.

All of it lives in the app’s own sandbox on your device. There is no copy anywhere else, because there is nowhere else.

What it never does

  • No account, no login, no email address, no phone number.
  • No advertising identifier, no tracking, no fingerprinting.
  • No push token, no server, no sync, no backup to us.
  • No reading of your contacts, photos, calendar, microphone or camera — it asks for none of them.

Location, if you ask for it

The app requests location for exactly one reason: to sort the guide by how far away each place is when you choose Nearest. It never asks on launch and never asks unless you press that. If you decline, everything else in the app works identically.

When you do grant it, the coordinate is used in memory to order a local array and is then discarded. It is never written to disk, never stored in the app’s preferences, never attached to anything, and — because there is no networking code — cannot leave the device. The app also asks iOS for kilometre-level accuracy rather than precise positioning, and it measures to the centre of a ZIP code, so even in memory it is not a fine-grained position. You can revoke it at any time in iOS Settings, and the app carries on.

Tapping for directions hands Apple Maps or Google Maps the business’s name and address as a search term. Nothing about you is included in that handoff — not your position, not an identifier. What happens after the maps app opens is covered further down this page.

Notifications, if you switch them on

The re-inspection alert is a local notification. When an app update brings a newer inspection date for somewhere you saved, your phone compares the guide inside the app against what it last showed you and posts the notification itself. There is no push server, no device token and no account, and permission is requested only at the moment you turn the toggle on. Leave it off and nothing else changes.

Leaving this site

Once you follow a link, someone else’s policy applies

This site links out constantly and on purpose — to the Metro Health inspection portal, to City of San Antonio 311, to Texas DSHS, to the publications that gave out the awards we report, to restaurants’ own ordering pages, and to Apple Maps or Google Maps for directions. Checking our work means going and reading the record, and we would rather you did.

We do not control any of those destinations and we receive nothing back when you click. The moment your browser loads one of their pages, their privacy policy governs and ours stops. Mapping, delivery and ordering services in particular are in the business of knowing where you are and what you bought; that is a reason to read theirs, not a reason for us to hide the link.

The other direction

What we publish about businesses is a different question, and a fair one

This site collects nothing about readers and publishes a great deal about restaurants. Those are two different things, and the second one deserves a straight answer rather than silence in a document titled privacy.

Everything published here is public record about a commercial establishment, not personal information about a private person: health inspection results and the inspector’s written findings, City of San Antonio 311 service requests, awards published by named publications, and the date a Texas sales-tax permit was issued. Every figure links back to the record it came from, and the formula that turns those records into a score is published in full. We publish no inspector’s name, no complainant’s name, and no customer’s name, because none of those is what this guide is about.

We also decline to publish several things we could. No Yelp, Google, TripAdvisor or Facebook ratings, because we are not licensed to republish them. No claim that anyone ever got sick anywhere. No photograph of any business, because a picture beside a score is an editorial claim the record does not support.

Three limits on that record are stated wherever it appears and are worth repeating here: an inspection score describes one visit on one day and is not a standing condition; a 311 case is a phone call filed against an address, not a finding against a business; and absence of data is never rendered as a finding — no inspection on record means no score, never a zero.

If a record about your business is wrong, we will fix it. Email us with the correction, we will check it against the source, and we will correct it within 48 hours — whether or not you are a customer, and without asking you to buy anything. How to request a correction.

Keeping and deleting

How long we keep things, and how to make it stop

Apple requires every app’s privacy policy to explain its retention and deletion practices and how a reader revokes consent. Ours is short because there is very little to describe.

WhatHow long it is kept, and how to end it
This website We hold no reader data at all, so there is nothing to retain and nothing to delete. Request logs are Cloudflare’s, held under Cloudflare’s retention policy linked above, and we cannot read them.
The app Everything it stores is on your phone. Un-save a place and its entry is gone. Delete the app and every trace goes with it — there is no server copy to ask us about.
Location Never stored, so nothing to delete. Revoke it at any time in iOS Settings, under Privacy & Security → Location Services — or simply never press Nearest.
Notifications Turn the toggle off inside the app, or revoke the permission in iOS Settings. Nothing was ever sent anywhere to be withdrawn.
If you email us Then we have your email address and whatever you chose to put in the message, for as long as it takes to deal with it. You are not added to any list, because there is no list. Ask us to delete the correspondence and we will.

There is no account to close and no “download my data” request worth making, because the only data that exists is on your own device and already yours.

The law

Which privacy laws apply to us, and why the answer is none of them

The two a Texas publisher with a national readership would be asked about are California’s CCPA/CPRA and the Texas Data Privacy and Security Act. Both turn on thresholds. We are below all of them, and it is worth showing the arithmetic rather than asserting the conclusion.

California. The CCPA applies to a for-profit business that has gross annual revenue over $25 million, or buys, sells or shares the personal information of 100,000 or more California residents or households, or derives 50% or more of its annual revenue from selling California residents’ personal information. A business meeting none of the three is not covered. Viking Net LLC meets none, and two of them are not close: the number of readers whose personal information we buy, sell or share is zero.

Texas. The Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541, in effect since 1 July 2024) applies to an entity that conducts business in Texas or serves Texas residents, and processes or engages in the sale of personal data, and is not a small business as defined by the U.S. Small Business Administration. We are the first of those, and not the second or the third. The one duty the Act does place on a small business regardless — §541.107, that it may not sell sensitive personal data without consent — we satisfy in the only way available to someone holding none: we sell nothing.

So neither statute currently imposes an obligation on us, and the reason is worth being precise about. It is not that we found an exemption to shelter under. It is that we do not process personal data, which is the condition both laws are actually written to regulate.

The rights those laws create — to know, to access, to correct, to delete, to opt out of sale or targeted advertising — we would honour on request anyway, and honouring them takes one sentence: there is nothing of yours for us to produce, correct, delete or refrain from selling. Global Privacy Control and Do Not Track signals are respected trivially, because there is no tracking to switch off. If any of that ever stops being true — if this site gains an account system, a newsletter, or an analytics tool — this page changes before the feature ships, not after.

Housekeeping

The remaining small print, kept small

Children. We do not knowingly collect information from anyone of any age, because we do not collect information. The app carries no advertising, no in-app purchases and no third-party content, and it is rated for general audiences.

Third parties receiving your data. There are none, other than Cloudflare as described above. We share nothing with anyone, we have no data-sharing agreements, and if that ever changes this page will name the party and what they get before it happens.

Changes. If this policy changes, the effective date at the top changes with it and this section will say what moved. We will not quietly re-date it.

Who to write to. Viking Net LLC publishes SA Hot Chicken. Questions about this page, about anything we hold, or about a record we publish: email us.

One thing this page is not. It is written by the people who built this site and this app, not by a lawyer, and it is not legal advice to you or to us. It is a factual description of what the site and the app actually do, checked against the build output, the live site and the compiled app binary on the date below. If you find something on this page that does not match what you observe, tell us and we will correct it — that request gets the same 48 hours as any other correction.

Effective August 19, 2026 · Checked August 21, 2026