Back to home page

Wersja polska

Pempol Privacy Policy

Effective date: 17 September 2026 (version 3.0.1). This English text is a translation of the Polish original; in case of discrepancy, the Polish version prevails.

1. General provisions

This policy sets out how the data of users of the “Pempol” mobile application (the “App”) and of the pempol.com website (the “Website”) is processed.

The data controller is Grzegorz Szwed Development, ul. Twarda 18, 00-105 Warsaw, Poland, VAT ID (NIP): 5223280335, contact e-mail: info@amamable.com (the “Controller”).

2. Scope of the data processed

Depending on how the App is used, we may process the following data:

Account data:

  • e-mail address (when registering by e-mail or signing in with Google/Apple),
  • user name (set to the e-mail address by default; it can be changed),
  • password — stored only in hashed form; when signing in with Google or Apple we store no password at all.

Profile data and dietary preferences:

  • the number of people in the household,
  • selected allergens and dietary preferences — provided voluntarily and used solely to filter recipes and build the meal plan,
  • the App language,
  • a profile photo and a short description (bio) on your author profile — provided voluntarily. Other App users can see them on your author profile, and the photo also next to recipes you publish. We store them together with your other data (section 7); you can change or remove them at any time in the App (Settings → Author profile), and we also delete them when you delete your account. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) — providing the author profile feature, which you use voluntarily.

Data for calculating calorie requirements (optional):

  • year of birth, sex, height, weight, activity level and a daily calorie requirement entered by hand — yours and those of people without an account whom you add to your household (e.g. children),
  • who a planned meal is for (household members and number of guests).

This data may constitute data concerning health, so we process it only on the basis of your explicit consent (Art. 9(2)(a) GDPR), given in the App before it is first saved; we record when the consent was given. It is used solely to calculate a daily calorie requirement and compare it with the calories of planned meals (how we calculate is described below, under “How we calculate calories”) — not for profiling, advertising or training AI models. By entering the data of people without an account, including children, you confirm that you are entitled to provide it (e.g. as their parent or guardian). Other members of your family see your calculated or entered calorie requirement in the App, but not your body data; the data of people without an account can be seen and edited by all family members. You can withdraw your consent at any time in the App (Settings → Household & calories) — withdrawal deletes your body data and the data of people without an account assigned to your account, without affecting the lawfulness of processing before withdrawal.

How we calculate calories (algorithms):

All the calculations described below are deterministic — the same data always gives the same result — and do not use artificial intelligence models.

  • Recipe calories and macronutrients are calculated on our server from the recipe’s ingredients. For each ingredient we take the average of the product label data for that ingredient collected in our database or, if there is none, a reference value from the public USDA FoodData Central or Open Food Facts databases. An AI model helps us match reference values to ingredients, but only outside the App (offline), and a human reviews and approves every value before it is used. Quantities in kitchen measures (e.g. a tablespoon, a piece) are converted to grams using conversion factors for the given ingredient (liquids without a factor: 1 ml = 1 g), solely for this calculation. An ingredient with no data or no conversion factor is left out — never counted as zero. We show the result only when the included ingredients make up at least 60% of the mass of the ingredients that could be converted to grams and are not fewer than those left out; otherwise the recipe is marked “no data”. Values entered by hand on the recipe always take precedence over calculated ones.
  • The daily calorie requirement is calculated on our server from year of birth, sex, height, weight and activity level. Age is the current year minus the year of birth. For people aged 19 or over we use the Mifflin-St Jeor formula multiplied by an activity factor (from 1.2 for a sedentary lifestyle to 1.9 for very high activity). For people under 19 we use the Estimated Energy Requirement (EER) equations for children and adolescents published by the US Institute of Medicine (2005) — they take into account age, sex, weight, height and activity, and for children under 3 only weight. The result is rounded to 10 kcal. A requirement entered by hand always takes precedence over the calculation; if any of these data is missing, we assume 2000 kcal. We count the same for every guest.
  • The day target in the plan is the sum of the requirements of the people eating that day’s meals (each person counted once) plus 2000 kcal for each guest. The App compares it with the calories of the planned meals (number of servings × calories per serving) and displays the result. The comparison is for display only — it does not change portion sizes (one person is always one serving), the generated meal plan, shopping lists or anything else.

This is not automated decision-making. The calculations above are estimates displayed in the App; they do not produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). We do not use them to profile you for marketing, do not use them for advertising and do not share body data or calorie requirements with third parties — they are stored only by our hosting provider (Microsoft Azure, section 9), acting on our behalf. The legal basis remains your explicit consent described above, and withdrawing it deletes this data.

Content created in the App:

  • recipes (names, ingredients, preparation steps, optional photos of dishes),
  • meal plans (the calendar),
  • shopping lists, including the e-mail addresses of people a list is shared with.

Shopping agent data (a premium feature):

  • the names of the shopping list items the agent is run for, and the outcome of each one (added / not found / skipped),
  • a simplified snapshot of the store page open in the App — processed on the fly to decide the next click,
  • the remembered “list item = store product” match for your account and that store.

Section 5 covers the detail. We neither receive nor store your store login, password or cookies.

Cooking mode:

Step-by-step guidance through a recipe, together with the timer, runs entirely on your device and collects no data — see section 6.

Technical and diagnostic data:

  • the version of the operating system and of the App,
  • anonymized usage events (e.g. opening a screen) and error logs — used solely to improve stability and usability.

Signing in with Google and Apple:

If you sign in with a Google or Apple account, all we receive from those providers is your e-mail address and a confirmation of identity (a token). We get no access to your contacts, files or any other data held in those accounts. How Google and Apple process data is governed by their own privacy policies.

3. Purposes of processing

We process data for the following purposes:

  • creating and running your user account in the App;
  • storing recipes, building meal plans and generating shopping lists — on the basis of the data you enter (the App runs on deterministic algorithms; user content is not used to train artificial intelligence models);
  • sharing shopping lists with the people you choose;
  • running the shopping agent — deciding the next action on the store page, remembering “list item = product” matches and accounting for the monthly pool of items (section 5);
  • improving the operation and security of the App (logs, telemetry, error reporting), including the success rate of the shopping agent on the basis of a run log that carries no user identifier;
  • handling user requests and communication related to the App;
  • meeting the Controller's legal obligations.

The legal basis for processing is, as applicable: necessity for the performance of a contract (Art. 6(1)(b) GDPR), the Controller's legitimate interest (Art. 6(1)(f) GDPR) or the user's consent (Art. 6(1)(a) GDPR). Data for calculating calorie requirements is processed only on the basis of explicit consent (Art. 9(2)(a) GDPR).

4. The App's access to the camera and photo library

The App may ask for camera permission (android.permission.CAMERA) and access to the photo library only when you choose one of the features below yourself. Using them is entirely optional.

  • Recipe photo — you add it to your recipe and we display it alongside that recipe.
  • Profile photo — we display it on your author profile (section 2).
  • Recipe import from a photo (Premium) — we send the photo of a recipe page or of a dish through our server to an AI model (Microsoft’s Azure OpenAI service, section 9), which reads the recipe from it. In the mobile app, the same photo is then saved as the photo of the newly created recipe — you can remove it like any other recipe photo.
  • Quick inventory (Premium) — we send the photo of your fridge or cupboard through our server to an AI model (Azure OpenAI), which returns a list of the products visible in it. The photo serves only that one request: we store neither the photo nor the recognised product list — the list exists only on the App’s screen, and your activity history records just the number of products recognised.

Photos are not used for biometric identification. The AI model receives a photo only to read a recipe or products from it; the content passed on is not used to train models.

You can withdraw the permissions at any time in your device’s system settings — the only effect is that these features can no longer use the camera or photo library.

5. The shopping agent

The shopping agent (a premium feature) adds the items of your shopping list to the basket of a supported online grocery store. The store opens in a browser window inside the App, in your own session — you sign in directly with the retailer, and Pempol neither receives nor stores your store login, password or cookies.

To decide the next click, the App sends to our server, and from there to a language model (the Microsoft Azure OpenAI service): the name of the list item, a simplified snapshot of the store page visible at that moment (text, buttons, form fields) and a condensed history of the steps so far. If your data is visible on the open store page — a name in the account header, say, or a delivery address — it will be part of that snapshot. The snapshot serves only to decide the next action: we do not store it once the request completes, and it is not used to train models.

What we do store permanently:

  • the “list item = store product” match — tied to your account and that store, so that next time the same product goes into the basket without asking the model; you overwrite it by choosing “Search differently” in the App;
  • usage accounting — the item name, the store, the outcome and the source of the charge, needed to run the monthly pool of items;
  • the run log — a condensed step history and the outcome of an item, stored without any user identifier and used solely to improve the agent's success rate; deleted after 90 days (we keep at most the 500 most recent runs per store);
  • price observations — the product name and the price displayed on the store page, likewise with no link to your account.

The agent moves only within the pages of the permitted store and only fills the basket. It never signs in for you, never enters personal, address or payment data, and never places an order — where the page requires any of that, it stops and hands control back to you. These rules live in the App's code, not in the model's editable instructions. Purchases are made on the store's terms and under its privacy policy; with respect to your data the store is an independent controller, and Pempol is not a party to that transaction.

6. Cooking mode

Cooking mode — step-by-step guidance through a recipe, the timer and the hint listing the ingredients for the current step — runs entirely on your device, on the text of a recipe you already have in the App. Nothing about it is sent to our server, and it uses no AI models, no microphone and no camera. While you cook, the App keeps the screen awake and vibrates the device when the timer runs out.

7. Data storage

Data is stored on Microsoft Azure servers in the Poland Central region (European Economic Area).

Account-related data is stored for as long as you use the App and for as long as is necessary to meet legal obligations or pursue claims.

Technical data (logs, telemetry) is stored for a maximum of 12 months, unless the law requires a longer period.

Shopping lists may additionally be cached locally on your device so that they work without internet access.

8. Account and data deletion

You can delete your account together with all its data at any time (profile including your profile photo, recipes and their photos, meal plans, shopping lists, activity history, and the shopping agent data tied to the account: remembered product matches and usage accounting). Records that were never linked to an account — the agent's run log and the price observations (section 5) — do not allow you to be identified and stay in the database until their own retention periods expire.

The quickest way is in the App itself: menu → Profile → “Delete account” — the data is deleted immediately. You can also send a message from the e-mail address linked to the account to info@amamable.com with the subject “Account deletion” — we will delete the account and its data within 30 days and confirm it to you. Once deleted, the data cannot be recovered. Step-by-step instructions: pempol.com/delete-account.html.

Data we are legally required to retain (e.g. accounting records) may be kept longer — strictly to the extent necessary.

9. Recipients of the data

Data may be passed to the following categories of recipient:

  • Microsoft Azure — hosting of the application, the database and files (Poland Central region, EEA);
  • Google and Apple — solely for handling sign-in, if you use it;
  • Microsoft (the Azure OpenAI service, Poland Central region) — solely for AI-based features, including recipe import from a photo and quick inventory (section 4) and the shopping agent (section 5); the content passed on serves only to carry out that one request and is not used to train models;
  • the online stores the shopping agent works with (including Frisco and Chefs Culinar) — to the extent that you use their service yourself in the App's window; with respect to that data the store is an independent controller and applies its own privacy policy;
  • payment and subscription providers (Google Play / App Store) — if you use the paid version of the App;
  • bodies entitled to it under the law (e.g. public authorities).

In every case we pass on only the data necessary for that purpose. We do not sell user data.

10. Cookies on the Website

The pempol.com website uses cookies to analyse traffic (Google Analytics) — only after consent is given in the cookie banner. Consent can be withdrawn by clearing cookies in the browser. The mobile App itself uses no cookies.

11. Marketing and newsletter

If you give a separate, voluntary consent to this, we will process your e-mail address in order to send you Pempol marketing messages — information about news, recipes and promotions. The legal basis is your consent (Art. 6(1)(a) GDPR and Art. 10 of the Polish Act on Providing Services by Electronic Means). Consent to marketing is independent of accepting this Privacy Policy and of using the app — you can withdraw it at any time by clicking “Unsubscribe” in the footer of every message or by turning off the marketing consents in the app settings. Withdrawing consent does not affect the lawfulness of the processing carried out before the withdrawal. To handle the mailing we use the Brevo platform (Sendinblue GmbH), which processes the data on our behalf as a processor within the European Union.

12. Your rights

You have the right to:

  • access your data and obtain a copy of it;
  • rectify (correct) your data;
  • erase your data (the “right to be forgotten”);
  • restrict processing;
  • data portability;
  • object to the processing of your data;
  • withdraw consent (to the extent that processing is based on consent) — withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise these rights, contact the Controller at the e-mail address given in section 1.

You also have the right to lodge a complaint with the competent supervisory authority (in Poland: the President of the Personal Data Protection Office).

13. Providing data is voluntary

Providing personal data is voluntary, but the absence of some data may make certain features of the App unusable (for example, without an e-mail address an account cannot be created, and without allergen information allergens cannot be filtered out of the meal plan).

14. Data security

The Controller applies technical and organisational measures to protect the data processed, appropriate to the risk to users' rights and freedoms, in particular: encryption in transit (HTTPS), storing passwords only as hashes, restricted access to data, and protection of the cloud infrastructure.

15. Changes to this privacy policy

This privacy policy may be updated from time to time. Users will be informed of material changes through a notice in the App or on the website.

Version: 3.0.1 | Date: 17 September 2026

Questions about this privacy policy? Contact us: info@amamable.com