Pemlo

Privacy Policy

Effective date: August 29, 2026

This Privacy Policy explains how Pemlo handles information through the Pemlo iOS app, cloud service, marketing site, Customer Portal, support, the optional AI Assistant and connected AI hosts that you authorize.

1. Our roles

Pemlo determines how account, authentication, security, support, diagnostic and AI-consent information is handled to operate and protect the service.

A Business using Pemlo determines which client, job, document, recipient and related commercial information it enters or shares. That Business is responsible for having a lawful reason to use that information and for giving any notices or obtaining any permissions its relationship with the affected people requires. Pemlo handles that information to provide the service to the Business.

If you receive a Customer Portal link, the Business that sent it is responsible for the underlying Estimate, Invoice and commercial relationship. Pemlo provides the technical Portal.

2. Information we handle

CategoryExamples
Account and authenticationName, sign-in email, Apple or Google identity reference, account preferences, session and security records, app and device identifiers, IP address and request metadata.
Business and client recordsBusiness names and profiles; client names, contact details and addresses; job scope, notes and optional precise work location.
Documents and financial instructionsEstimate and Invoice revisions, line items, taxes, numbering, notes, terms and PDFs; bank-transfer instructions and Business-entered Cash or Bank settlement records. Pemlo does not hold or move payment funds.
Customer Portal activityPrivate-link access and security metadata, recipient-entered name, drawn signature, acknowledgement and actions such as acceptance, change request or decline, together with timestamps and document snapshot identifiers.
SupportYour email, messages, support references and the information you choose to provide when asking for help or reporting a privacy or security issue.
SubscriptionsProvider, product and environment; normalized purchase, renewal, grace, expiry, refund or revoke status; minimized encrypted and keyed subscription-chain evidence; App Account Token; assignment history; and reconciliation metadata. Pemlo verifies signed Apple evidence but does not retain raw StoreKit JWS in application records or analytics.
Analytics and diagnosticsApp version, device and operating-system information, app-instance identifiers, permitted product-use events, crash traces and performance or diagnostic information collected through Firebase Analytics and Crashlytics in enabled distributions.
AI consent and useYour grant or revocation decision, notice version and timestamp; when permission is current and you send a request, the message and the minimum Business records needed to answer it. If you explicitly choose voice input, the completed recording and resulting transcript are processed only to produce editable composer text.
Connected AI hostsThe requesting host and client name, granted scopes, connection and revocation timestamps, selected Business context and minimized security/audit records. When you use a connected host, Pemlo returns only the authorized Business records, structured results or PDFs needed for the tool call you requested.

Information you select on your device

Pemlo accesses a Contact, Photo or File only after you choose it through the system picker. Selected Contact fields may prefill client data that is saved only when you confirm. In Release 1, selected Photo and File bytes are used on the device to prepare a preview and metadata; Pemlo does not claim that those bytes are uploaded to the cloud until the upload feature is enabled.

The marketing pages use no JavaScript, forms or cookies. The Customer Portal uses no advertising trackers, analytics cookies, customer account or browser storage. A complete private Portal link may remain in browser history; anyone who has it may receive the access granted by the sender, so keep it private.

3. How we use information

4. AI Assistant

When you choose to use the AI Assistant, Pemlo asks for explicit permission before sending personal data to OpenAI. The notice identifies OpenAI, United States processing, the information to be sent and the purpose. The Privacy Policy is not a substitute for that permission.

After you grant the current notice, a message you submit and the minimum Business records needed to answer it may be sent to OpenAI in the United States. Pemlo uses a dedicated US API project, sends Responses requests with store:false, and keeps provider data sharing or training disabled. OpenAI may retain separate abuse-monitoring logs for text requests for up to 30 days. Pemlo does not claim Zero Data Retention.

When you explicitly tap voice input, Pemlo records a completed message of up to two minutes and sends that recording to Pemlo and OpenAI audio transcription to produce editable text. It is not always listening, does not translate the recording, does not automatically send the transcript to the AI Assistant, and cannot execute an action until you review the text and separately press Send. Pemlo does not retain raw audio on its servers or in Business records. The temporary on-device recording is removed after success, cancel, logout, consent revocation or discard; a failed upload remains only for an explicit Retry or Discard in the current flow.

The Release 1 in-app AI Assistant path does not use Conversations, Files, Remote MCP, realtime voice, speech-to-speech, text-to-speech or photo input. The in-app AI Assistant provides proposals and suggestions for human review and does not autonomously create, revise, send, share, pay, delete or void anything. A separately authorized external-host connection is described below and does not reuse this AI Assistant permission.

You can decline permission, grant it later, or revoke it in Personal Profile. Revocation blocks new AI requests. It does not make previously created provider logs disappear immediately; those expire under the stated provider period. A change to provider, region, retention or training posture, or notice version requires new permission.

5. Connected AI hosts

When you choose to connect Pemlo to ChatGPT or another compatible AI host, Pemlo shows the requesting client, the requested read/write scopes and the account-wide Business-access boundary before you approve the OAuth connection. The host receives its own revocable Pemlo connection credentials; it does not receive your Google credential or Pemlo mobile-app session.

A connected host may request authorized Client, Job, Price Book, Estimate, Invoice, payment-link, Customer Portal, statistics and PDF information for exactly one selected Business at a time. The host processes your prompts and the Pemlo tool results it receives under the host's own terms and privacy policy. Do not place information in a host conversation unless you are authorized to share it with that host.

Write access does not let the host bypass Pemlo authorization. Pemlo first returns an exact review, the host asks for your approval, and Pemlo rechecks the current User, Business, Membership, scope, record version and action before execution. Pemlo does not expose account or Business deletion, arbitrary data export, code execution, autonomous payment or payment verification through this connection.

You can revoke a connection in Pemlo. Revocation blocks new tool calls and refreshes, but it does not delete information already included in the host's conversation or records; use that host's controls and privacy terms for its copy. Connecting an external host is separate from granting or revoking the in-app AI Assistant permission above.

6. Service providers and sharing

Pemlo does not sell personal information, serve advertising or use information for cross-app tracking. We disclose information only as needed to provide, secure and support the service, respond to a valid legal request, protect rights and safety, or complete a business transfer subject to appropriate safeguards.

PartnerPurpose and information
AppleiOS distribution and platform services, Sign in with Apple when selected, and Pemlo Pro purchase, subscription management, Restore and billing lifecycle. Apple receives information under its own terms and privacy practices.
Google Sign-InAuthentication when selected, including the Google identity information needed to complete sign-in.
Firebase Analytics and CrashlyticsEnabled app analytics, crash reporting, diagnostics and symbolication. Pemlo does not integrate an advertising SDK or request the advertising identifier for these services.
DigitalOceanProduction compute, database and private object-storage infrastructure used to host Pemlo data.
OpenAIAI Assistant text processing and, after an explicit voice action, completed-recording transcription in the United States, only after the separate current permission described above.
Connected AI host selected by you, including ChatGPTAuthorized tool requests and the scoped Pemlo records, structured results or PDFs returned for those requests after you connect the host. The host handles its conversation and received results under its own terms and privacy policy.

These providers may process information in the United States and other locations where they operate, subject to their contracts and applicable protections.

7. Retention, security and account deletion

Pemlo retains active account and Business information while needed to provide the service and for the documented security, support and operational periods that apply to each record. We minimize access and use technical and organizational safeguards appropriate to the information. No system is completely secure, and Pemlo does not promise absolute security.

When an account-deletion request is accepted, access is blocked immediately and active User-owned data is purged within 30 days. A sole-owned Business and its records are deleted. Records belonging to a shared Business remain for the continuing Business, while the former user is shown as Deleted user. A receipt that contains no personal or Business data may be kept for up to 90 days to report deletion status. Provider-side data follows the applicable provider period, including the OpenAI period described above.

Deleting a Pemlo account does not cancel an Apple subscription or stop Apple billing. The app provides Manage Subscription, and deletion may continue without cancellation. Pemlo removes the live User billing link and entitlement but may retain minimized encrypted and keyed provider-chain, status, fraud-prevention, audit and idempotency evidence for the subscription lifecycle and dispute period. A later explicit Restore can associate a currently verified Apple subscription with the then-signed-in Pemlo User; it does not restore deleted Pemlo data.

8. Your choices and requests

You can review or correct account and Business information in the app. You can request access, correction or deletion, withdraw AI permission in Personal Profile, revoke an external-host connection under Pemlo MCP, or contact support@pemlo.app. We may need to verify the request and may direct a request about Business-controlled client or document data to the responsible Business.

Pemlo is intended for people with the legal capacity and Business authority needed to use the service. It is not directed to children. Do not provide another person’s information unless you are authorized to do so.

9. Changes

We may update this Policy as Pemlo changes. We will post the updated effective date and provide additional notice when a change materially affects how information is handled.

10. Contact

For privacy questions or requests, email support@pemlo.app.