Pacelli — Privacy Policy

Effective date: 2026-04-28  ·  Contact: juancarlos.celis92@gmail.com

Pacelli (the "App", "we") is a household management app that helps families share tasks, plans, lists, a calendar, an inventory, a house manual, and an in-app AI assistant. Privacy is a core feature, not an afterthought — most content you create is end-to-end encrypted on your device before it ever leaves it.

This policy tells you exactly what we collect, why, where it lives, and how to delete it.

1. Who is the data controller?

Juan Carlos Celis Pinto, sole developer of Pacelli, is the data controller under the GDPR. You can contact us at juancarlos.celis92@gmail.com.

We are based in Ireland and the App is offered worldwide.

2. The two storage modes

During onboarding you choose where your data lives:

You can switch modes at any time and wipe your cloud data with one tap (see "Burn all data" below).

3. What we collect and why

3.1 Account data (Firebase Authentication)

When you sign in we receive from your chosen identity provider:

Used to identify you across devices and to scope access to your household. Stored as long as your account exists.

3.2 Household content (encrypted)

Tasks, subtasks, checklists, plans, calendar entries, inventory items, house-manual entries, AI chat messages, attachments metadata, feedback text. All human-readable fields are AES-256-CBC encrypted on-device with your household key before they reach the server. Without that key the ciphertext is meaningless to us, to Google, and to anyone with database access.

3.3 Diagnostics and feedback (optional, encrypted)

If you submit feedback or if the app records a diagnostic event (an error or warning), the message text and any context are encrypted with your household key before being stored. We use this to improve the App; we cannot read it without your household key.

3.4 Push notifications

If you enable notifications we send a Firebase Cloud Messaging device token to Apple Push Notification service or to Google Firebase. We do not include sensitive content in notification payloads.

3.5 Photos, camera, and Google Drive

If you attach a photo or use the barcode scanner, the App accesses your camera or photo library. The image data is processed on-device. If you choose to back attachments to Google Drive, the file is uploaded to your own Google Drive account under a Pacelli folder; we never receive a copy.

3.6 AI Assistant

If you connect a third-party AI provider (Anthropic Claude, Google Gemini, or OpenAI ChatGPT), your API key is stored in your device's secure keychain (iOS Keychain / Android Keystore) and only that provider receives your prompt. We do not proxy or log AI requests.

3.7 What we do NOT collect

4. Encryption details

5. Sub-processors

Sub-processorPurposeRegion
Google FirebaseAuthentication, Firestore database, Cloud Functions, Cloud MessagingEU multi-region
AppleSign in with Apple, push notificationsWorldwide
GoogleGoogle Sign-In, optional Google Drive attachmentsWorldwide
Your chosen AIIn-app AI Assistant (only if you connect one)Provider's region

6. Data retention and "Burn all data"

7. Your rights (GDPR)

You have the right to: access, rectification, erasure, restriction, portability, and to object to processing. Use the in-app export and burn features for portability and erasure, or email us at juancarlos.celis92@gmail.com for any other request — we will respond within 30 days.

You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).

8. Children

Pacelli is not directed at children under 13. If you believe a child has created an account, please contact us and we will delete it.

9. Changes to this policy

When we change this policy we will update the Effective date above and post the new version at the same URL. Material changes will also surface in-app on next launch.