Privacy Policy
Effective Date: April 30, 2026
This Privacy Policy describes how Pacali Inc. (“we,” “our,” or “us”) collects, uses, processes, shares, and protects Your information when You use the Pacali mobile application, website, and related services (collectively, the “Service”). By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
1. Interpretation and Definitions
Capitalized terms used in this Policy have the meanings assigned below:
- Account — the unique profile created for You to access the Service.
- Application — the Pacali mobile application.
- Company / We / Us / Our — Pacali Inc., a German Sole Proprietorship, Am Hellweg 10, 32105 Bad Salzuflen, Germany.
- Health Data — information relating to Your physical characteristics, health, nutrition, goals, or activity. This constitutes sensitive personal data under applicable privacy laws.
- Personal Data — information that identifies or can reasonably be linked to an individual.
- Service — the Pacali mobile application, website (pacali.app), and related services.
- Usage Data — data collected automatically through use of the Service.
- User Content — photos, images, text, food entries, recipes, or other inputs You upload.
- You — the individual accessing or using the Service.
2. Types of Data We Collect
2.1 Personal Data You Provide: Account information (name, email, password, profile photo), contact information (email).
2.2 Health & Fitness Data: Weight, height, age, gender, activity level, steps, sleep, workouts and runs, distance, pace, active energy burned, food and nutrition logs, nutrition goals, dietary preferences, allergies, and progress photos. This is sensitive personal data. We process it only with your explicit, affirmative opt-in consent (GDPR Art. 9(2)(a)).
2.2.1 Apple Health & Health Connect: With your explicit permission, Pacali reads and/or writes health and fitness data through Apple Health (HealthKit) on iOS and Health Connect on Android — including steps, weight, sleep, workouts, distance, and active energy. We access this data only to display your activity and sync the nutrition and workout data you log in Pacali. We do not use Apple Health or Health Connect data for advertising, and we do not share it with third parties for advertising or data-broker purposes. You can revoke this access at any time in your device's Apple Health or Health Connect settings.
2.3 User Content: Food photos for calorie analysis, progress photos, text entries, food logs, recipes. We may use anonymized or aggregated food images to improve our AI models. Progress photos are never used for model training.
2.4 Location Data: When you use the run tracker feature, we collect precise GPS location data to record your route, distance, pace, and elevation. Location access is requested only when you start a run and is governed by your device's permission settings. You may disable location permissions at any time in your device settings, which will disable the run tracker feature.
2.5 Usage Data: Device type, OS, app version, device identifiers, IP address, timestamps, features used, crash logs.
2.6 Cookies and Tracking Technologies: Cookies, web beacons, mobile advertising identifiers (IDFA, Android ID).
3. How We Use Your Data
- 3.1 To provide and improve the Service: food identification, nutrition tracking, personalization, account management, security.
- 3.2 To improve AI and computer vision models: anonymized/aggregated food images only, not linked to identity.
- 3.3 Communications: service notifications, support responses, newsletters (with consent).
- 3.4 Marketing (optional): promotional emails with opt-out option.
- 3.5 Legal and compliance: fraud prevention, legal obligations, rights protection.
- 3.6 Business transfers: data may transfer in mergers/acquisitions.
4. Legal Bases for Processing (GDPR)
- Consent: For Health Data (Art. 9(2)(a)) and marketing (Art. 6(1)(a)).
- Contract Performance: To provide the Service (Art. 6(1)(b)).
- Legitimate Interests: Improving/securing the Service (Art. 6(1)(f)).
- Legal Obligations: Compliance (Art. 6(1)(c)).
5. How We Share Personal Data
We do not sell Your Personal Data. We may share with:
- Cloud Infrastructure: Supabase (primary cloud backend for database, authentication, and storage), AWS, and Google Cloud. Your data is stored on Supabase's servers, not locally on your device.
- Subscription & Paywall: Superwall (subscription management and paywall presentation). Superwall may receive device identifiers and subscription status to manage access to premium features.
- Payment Processors: Stripe, Apple Pay, Google Pay for processing subscription payments.
- Analytics: Google Analytics and Firebase for usage analytics and crash reporting.
- AI/ML Services: Third-party AI services for food recognition, nutrition analysis, and AI chat features.
- Business Transfers: During mergers/acquisitions.
- Legal Compliance: Law enforcement when legally required.
- With Your Consent: Third-party integrations you authorize.
- Aggregated/Anonymized Data: For analytics, research, and marketing.
6. User Content and License Rights
You grant Pacali a worldwide, royalty-free, sublicensable license to use Your User Content to operate and improve the Service. We do not publicly display Your photos without explicit consent. Progress photos are never used for model training.
7. Retention of Data
We keep your data only as long as it is needed to provide the Service:
- Account & Health/Fitness Data: Retained for as long as your account exists. When you delete your account, this data is permanently deleted from our active systems within 30 days.
- Diagnostics & crash logs: Retained for up to 90 days.
- Usage/Analytics Data: Retained in aggregated or de-identified form for up to 13 months.
- Backups: Residual copies may persist in encrypted backups for a short period and are overwritten on our standard backup cycle.
- Legal holds: Some records may be kept longer where required by law.
8. International Data Transfers
Data may be transferred internationally. For EEA/UK transfers, we rely on the EU-US Data Privacy Framework, Standard Contractual Clauses, or explicit consent.
9. Your Privacy Rights
GDPR rights: Access, Rectification, Erasure, Restriction, Data Portability, Withdraw Consent, Object, Lodge Complaint.
CCPA rights: Right to Know, Opt-Out of Sale (we don't sell data), Non-Discrimination.
Exercise via app settings or email akremagency@gmail.com. Response within 30 days (45 for CCPA).
10. Deleting Your Personal Data
You can delete your account and all associated personal data — including health & fitness data, progress photos, food logs, and profile data — at any time:
- In the app: open Settings → Account → Delete Account and confirm. The deletion is processed within a few seconds and your sign-in session is destroyed immediately.
- By email: contact akremagency@gmail.com from the address associated with your account. We will verify the request and complete the deletion within 7 days.
- On the web: see our account deletion page for step-by-step instructions.
Your account and personal data are permanently deleted from our active systems no later than 30 days after the request. Some records may persist only where retention is required by law, and residual copies in encrypted backups are removed on our standard backup cycle.
11. Data Security
We use SSL/TLS encryption in transit and at rest, access controls, anonymization/ pseudonymization, regular security audits, and employee training to protect your data.
12. Children's Privacy
Service is not intended for users under 18. We do not knowingly collect data from children under 18. Contact akremagency@gmail.com if you have concerns.
13. Changes to This Privacy Policy
Updates will be posted with a revised effective date. Material changes will be notified via the app or email.
14. Contact Us
Email: akremagency@gmail.com
Mailing Address: Alex Kem, Am Hellweg 10, 32105 Bad Salzuflen, Germany