This policy sets out how the data of users of the “Pempol” mobile application (the “App”) and of the pempol.com website (the “Website”) is processed.
The data controller is Grzegorz Szwed Development, ul. Twarda 18, 00-105 Warsaw, Poland, VAT ID (NIP): 5223280335, contact e-mail: info@amamable.com (the “Controller”).
Depending on how the App is used, we may process the following data:
This data may constitute data concerning health, so we process it only on the basis of your explicit consent (Art. 9(2)(a) GDPR), given in the App before it is first saved; we record when the consent was given. It is used solely to calculate a daily calorie requirement and compare it with the calories of planned meals (how we calculate is described below, under “How we calculate calories”) — not for profiling, advertising or training AI models. By entering the data of people without an account, including children, you confirm that you are entitled to provide it (e.g. as their parent or guardian). Other members of your family see your calculated or entered calorie requirement in the App, but not your body data; the data of people without an account can be seen and edited by all family members. You can withdraw your consent at any time in the App (Settings → Household & calories) — withdrawal deletes your body data and the data of people without an account assigned to your account, without affecting the lawfulness of processing before withdrawal.
All the calculations described below are deterministic — the same data always gives the same result — and do not use artificial intelligence models.
This is not automated decision-making. The calculations above are estimates displayed in the App; they do not produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). We do not use them to profile you for marketing, do not use them for advertising and do not share body data or calorie requirements with third parties — they are stored only by our hosting provider (Microsoft Azure, section 9), acting on our behalf. The legal basis remains your explicit consent described above, and withdrawing it deletes this data.
Section 5 covers the detail. We neither receive nor store your store login, password or cookies.
Step-by-step guidance through a recipe, together with the timer, runs entirely on your device and collects no data — see section 6.
If you sign in with a Google or Apple account, all we receive from those providers is your e-mail address and a confirmation of identity (a token). We get no access to your contacts, files or any other data held in those accounts. How Google and Apple process data is governed by their own privacy policies.
We process data for the following purposes:
The legal basis for processing is, as applicable: necessity for the performance of a contract (Art. 6(1)(b) GDPR), the Controller's legitimate interest (Art. 6(1)(f) GDPR) or the user's consent (Art. 6(1)(a) GDPR). Data for calculating calorie requirements is processed only on the basis of explicit consent (Art. 9(2)(a) GDPR).
The App may ask for camera permission (android.permission.CAMERA) and access to the photo library only when you choose one of the features below yourself. Using them is entirely optional.
Photos are not used for biometric identification. The AI model receives a photo only to read a recipe or products from it; the content passed on is not used to train models.
You can withdraw the permissions at any time in your device’s system settings — the only effect is that these features can no longer use the camera or photo library.
The shopping agent (a premium feature) adds the items of your shopping list to the basket of a supported online grocery store. The store opens in a browser window inside the App, in your own session — you sign in directly with the retailer, and Pempol neither receives nor stores your store login, password or cookies.
To decide the next click, the App sends to our server, and from there to a language model (the Microsoft Azure OpenAI service): the name of the list item, a simplified snapshot of the store page visible at that moment (text, buttons, form fields) and a condensed history of the steps so far. If your data is visible on the open store page — a name in the account header, say, or a delivery address — it will be part of that snapshot. The snapshot serves only to decide the next action: we do not store it once the request completes, and it is not used to train models.
What we do store permanently:
The agent moves only within the pages of the permitted store and only fills the basket. It never signs in for you, never enters personal, address or payment data, and never places an order — where the page requires any of that, it stops and hands control back to you. These rules live in the App's code, not in the model's editable instructions. Purchases are made on the store's terms and under its privacy policy; with respect to your data the store is an independent controller, and Pempol is not a party to that transaction.
Cooking mode — step-by-step guidance through a recipe, the timer and the hint listing the ingredients for the current step — runs entirely on your device, on the text of a recipe you already have in the App. Nothing about it is sent to our server, and it uses no AI models, no microphone and no camera. While you cook, the App keeps the screen awake and vibrates the device when the timer runs out.
Data is stored on Microsoft Azure servers in the Poland Central region (European Economic Area).
Account-related data is stored for as long as you use the App and for as long as is necessary to meet legal obligations or pursue claims.
Technical data (logs, telemetry) is stored for a maximum of 12 months, unless the law requires a longer period.
Shopping lists may additionally be cached locally on your device so that they work without internet access.
You can delete your account together with all its data at any time (profile including your profile photo, recipes and their photos, meal plans, shopping lists, activity history, and the shopping agent data tied to the account: remembered product matches and usage accounting). Records that were never linked to an account — the agent's run log and the price observations (section 5) — do not allow you to be identified and stay in the database until their own retention periods expire.
The quickest way is in the App itself: menu → Profile → “Delete account” — the data is deleted immediately. You can also send a message from the e-mail address linked to the account to info@amamable.com with the subject “Account deletion” — we will delete the account and its data within 30 days and confirm it to you. Once deleted, the data cannot be recovered. Step-by-step instructions: pempol.com/delete-account.html.
Data we are legally required to retain (e.g. accounting records) may be kept longer — strictly to the extent necessary.
Data may be passed to the following categories of recipient:
In every case we pass on only the data necessary for that purpose. We do not sell user data.
The pempol.com website uses cookies to analyse traffic (Google Analytics) — only after consent is given in the cookie banner. Consent can be withdrawn by clearing cookies in the browser. The mobile App itself uses no cookies.
If you give a separate, voluntary consent to this, we will process your e-mail address in order to send you Pempol marketing messages — information about news, recipes and promotions. The legal basis is your consent (Art. 6(1)(a) GDPR and Art. 10 of the Polish Act on Providing Services by Electronic Means). Consent to marketing is independent of accepting this Privacy Policy and of using the app — you can withdraw it at any time by clicking “Unsubscribe” in the footer of every message or by turning off the marketing consents in the app settings. Withdrawing consent does not affect the lawfulness of the processing carried out before the withdrawal. To handle the mailing we use the Brevo platform (Sendinblue GmbH), which processes the data on our behalf as a processor within the European Union.
You have the right to:
To exercise these rights, contact the Controller at the e-mail address given in section 1.
You also have the right to lodge a complaint with the competent supervisory authority (in Poland: the President of the Personal Data Protection Office).
Providing personal data is voluntary, but the absence of some data may make certain features of the App unusable (for example, without an e-mail address an account cannot be created, and without allergen information allergens cannot be filtered out of the meal plan).
The Controller applies technical and organisational measures to protect the data processed, appropriate to the risk to users' rights and freedoms, in particular: encryption in transit (HTTPS), storing passwords only as hashes, restricted access to data, and protection of the cloud infrastructure.
This privacy policy may be updated from time to time. Users will be informed of material changes through a notice in the App or on the website.
Version: 3.0.1 | Date: 17 September 2026
Questions about this privacy policy? Contact us: info@amamable.com