Privacy Policy
Last updated: 2026-09-29
Service: Kalkulator Remontu AI (Renovation Calculator AI)
URL: https://kalkulatorremontu.web.app
Data Controller: Marek Papis, sole proprietorship under Gmbi Marek Papis, registered at ul. Pomorska 70 m. 10, 91-409 Lodz, Poland, Tax ID (NIP): 9820319917, e-mail: airenovationcalculator@gmail.com
Effective Date: January 1, 2026
Last Amended: September 29, 2026
1. Data Controller
- The data controller for personal data processed in connection with the Service is Marek Papis, operating under Gmbi Marek Papis, ul. Pomorska 70 m. 10, 91-409 Lodz, Poland, NIP: 9820319917 (hereinafter: "Controller").
- Contact regarding data protection: airenovationcalculator@gmail.com.
- The Controller has not appointed a Data Protection Officer (DPO). All data protection inquiries should be directed to the Controller.
- This Policy also covers the websites kalkulatorremontu.pl and airenovationcalculator.com (free calculators and information about the Service).
2. Purposes and Legal Bases for Processing
The Controller processes personal data on the following legal bases (Article 6(1) GDPR):
2.1 Performance of Contract (Art. 6(1)(b) GDPR)
- Account registration and management,
- Provision of Service features (cost calculator, project management),
- Payment and PRO Subscription processing,
- Points system management,
- Project sharing between Users,
- Data export and import,
- Complaint handling.
2.2 Legitimate Interest (Art. 6(1)(f) GDPR)
- Service security (Firebase App Check),
- Establishment, exercise, or defense of legal claims,
- Fraud detection and prevention.
2.3 Consent (Art. 6(1)(a) GDPR)
- Analytics and marketing cookies, including Google Analytics and Microsoft Clarity on the websites kalkulatorremontu.pl and airenovationcalculator.com,
- Marketing communications (email),
- AI data processing (photo and description analysis via OpenAI).
2.4 Legal Obligation (Art. 6(1)(c) GDPR)
- Retention of billing data in accordance with tax regulations,
- Response to requests from public authorities.
3. Scope of Data Processed
3.1 User Profile Data
| Data | Purpose |
|---|---|
| Email address (email) | Authentication, communication, account verification |
| Name (name) | User identification, personalization |
| Phone number (phone) | Contact (optional) |
| Country (country) | Service localization, default "PL" |
| City (city) | Localization and regional price matching |
| Address (address) | Contact data (optional) |
| Notes (notes) | Additional user information |
3.2 Company Data (Company Accounts)
| Data | Purpose |
|---|---|
| Company type flags (isCompany, isBuildingCompany, isArchitectCompany, isDeveloperCompany, isAdvertCompany) | Categorization and profile display |
| Service categories (categories) | Company service classification |
| Tax ID (taxId) | Tax identification |
| Website (www, wwwInternal) | Company profile |
| Profile photos (photoUrl, photoIconUrl) | Profile visualization |
| Price deviation from average (pricesDeviationFromAvg) | Price analytics |
| Number of quotes (companyQuotedTimes) | Company statistics |
3.3 Account and Status Data
| Data | Purpose |
|---|---|
| PRO status (isPro, proTillDate) | Subscription management |
| Points balance (pointsLeft) | Internal payment system |
| Account type (isAnonymous, isEmailVerified) | Account management |
| Last activity (lastSeen, lastEstimate) | Security, inactive account cleanup |
| First login flag (isFirstLogin) | User onboarding |
| Profile visibility (show, isOpenForClients, isOpenForEstimate) | Visibility control |
3.4 Financial and Rating Data
| Data | Purpose |
|---|---|
| Payment history (payments) | Transaction records |
| User rating (rating, extRating, extRatingUrl, ratings) | Rating and reputation system |
| Free days (daysFree1D, daysFree1W, daysFree1M, daysFree3M, daysMinimum) | Labour pricing management |
3.5 Consent Data
| Data | Purpose |
|---|---|
| Cookie consent (isCookieAccepted, cookieConsentDate, cookieConsentVersion) | Legal compliance (GDPR, ePrivacy) |
| Marketing consent (isMarketingConsentAccepted, marketingConsentDate, marketingConsentVersion) | Direct marketing |
3.6 Project Data
- Renovation project descriptions (names, statuses, notes),
- Room configurations (dimensions, types),
- Lists of materials, labour, and equipment (names, quantities, prices),
- Project and item photos,
- Sharing data (email addresses of co-users).
3.7 AI Analysis Requests and Anonymous Users
- AI Analysis requests — the description submitted to OpenAI and the result returned, stored with the Account identifier, kept for 12 months from the analysis. A result saved in a Project is kept until the Project or Account is deleted.
- Anonymous Users — Projects are not saved to the server until registration. We store the temporary Account identifier and Points balance, technical data needed for the free usage limit (a hash of the browser fingerprint, IP address, visit times, the anonymous Account identifier) and, if AI Analysis is used, the description submitted to OpenAI and its result. Usage-limit data is kept for 12 months from the last visit; its legal basis is our legitimate interest in preventing abuse of the free limit (Art. 6(1)(f) GDPR).
- Export, import, photos and sharing of Projects require registration.
- Review import (Company PRO Accounts) — the address of the review page and the reviews retrieved (text and author name), with the Account identifier, kept for 12 months from the import. Reviews the company approves are saved in its profile and deleted with the Account.
4. Cookies
4.1 Types of Cookies
Essential
Required for the Service to function properly. No consent needed.
- Firebase authentication session,
- Firebase App Check token,
- Cookie preferences (consent version).
- Client panel cookie (cp_…) on the panel pages only: remembers that a studio's client has already entered their e-mail address (section 16). It holds no e-mail address or name and expires after 30 days, or sooner when the link expires or is revoked.
Analytics
Require consent. Used to analyze how the Service is used.
- Google Analytics (traffic measurement, user behavior, visit sources).
- Microsoft Clarity on the websites kalkulatorremontu.pl and airenovationcalculator.com (session recordings and heatmaps).
Marketing
Require consent. Used for marketing communications.
- Conversion tracking (when active).
4.2 Managing Cookies
- Users can manage cookie preferences in the Service settings (Settings > Cookie Settings).
- Consent for analytics and marketing cookies is voluntary and can be withdrawn at any time.
- Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Cookie preferences are versioned (cookieConsentVersion) to track changes.
- On the websites kalkulatorremontu.pl and airenovationcalculator.com, analytics cookies (Google Analytics, Microsoft Clarity) are set only after consent in the banner. Consent can be changed or withdrawn at any time with the "Cookie settings" link in the page footer; withdrawing it removes those cookies.
5. Third-Party Data Processing
5.1 Firebase / Google Cloud
- Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Services: Firestore (database), Firebase Authentication (auth), Firebase Storage (file storage), Cloud Functions (server logic), Firebase App Check (security)
- Data location: EU: database in the eur3 region (Belgium and the Netherlands), files in the EU multi-region
- Transfer basis: Google participates in the EU-U.S. Data Privacy Framework. Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR are also in place.
- More information: https://firebase.google.com/support/privacy
5.2 Stripe
- Provider: Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA
- Purpose: Payment processing (cards, BLIK, P24), subscription management
- Data scope: Email address, payment data (processed exclusively by Stripe), transaction amounts, payment history
- Data location: Data may be processed in the USA and EU
- Transfer basis: Stripe participates in the EU-U.S. Data Privacy Framework and uses SCCs.
- More information: https://stripe.com/privacy
5.3 OpenAI
- Provider: OpenAI, LLC, San Francisco, CA, USA
- Purpose: AI analysis — processing project photos and text descriptions to generate cost estimates
- Data scope: Project photos, text descriptions submitted for AI analysis
- Data location: OpenAI servers in the USA
- Transfer basis: Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR
- Note: Data submitted for AI analysis is processed by OpenAI according to their API data usage policies (https://openai.com/policies/api-data-usage-policies). Data submitted via the API is not used by default to train OpenAI models. The Controller keeps the submitted description and the result for 12 months (section 3.7).
- More information: https://openai.com/privacy
5.4 Google Analytics
- Provider: Google LLC
- Purpose: Traffic analysis, effectiveness measurement, understanding user behavior
- Data scope: Anonymized visit data, browser, device, location (country/city), navigation paths
- Processing basis: User consent (analytics cookies)
- More information: https://policies.google.com/privacy
5.5 Microsoft Clarity
- Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA
- Purpose: Session recordings and heatmaps on the websites kalkulatorremontu.pl and airenovationcalculator.com, to find what visitors struggle with
- Data scope: Clicks, scrolling and page interactions, device and browser data; photos added to the wall colour tool are masked
- Processing basis: User consent (analytics cookies)
- Transfer basis: Microsoft participates in the EU-U.S. Data Privacy Framework and uses SCCs.
- More information: https://privacy.microsoft.com/privacystatement
5.6 Vercel
- Provider: Vercel Inc., based in the USA
- Purpose: Hosting of the websites kalkulatorremontu.pl and airenovationcalculator.com, including the client panel (section 16); the server's technical logs record the IP address
- Data location: Servers in Frankfurt (EU)
5.7 OpenStreetMap
- Provider: OpenStreetMap Foundation, United Kingdom
- Purpose: The map with a company's location on its profile in the company catalogue. The visitor's browser loads map tiles from tile.openstreetmap.org when a visitor opens a company profile that has a map.
- Data scope: IP address, browser data and the name of the website's domain (not the address of the page)
- Processing basis: The Controller's legitimate interest in showing where a company works (Art. 6(1)(f) GDPR)
- Transfer basis: European Commission adequacy decision for the United Kingdom (Art. 45 GDPR)
- More information: https://osmfoundation.org/wiki/Privacy_Policy
6. Data Subject Rights (GDPR)
Under the GDPR, Users have the following rights:
6.1 Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation of whether your data is being processed and to access your data and information about the processing.
6.2 Right to Rectification (Art. 16 GDPR)
You have the right to request correction of inaccurate or completion of incomplete personal data. Some data can be updated directly in the Service settings (Settings > User Data).
6.3 Right to Erasure (Art. 17 GDPR)
You have the right to request deletion of your personal data. This can be exercised by:
- deleting your Account in the Service settings (Settings > Delete Account),
- sending a request to airenovationcalculator@gmail.com.
6.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request restriction of processing in cases specified in Art. 18 GDPR.
6.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, machine-readable format. The Service enables export of project data to PDF and XLS formats.
6.6 Right to Object (Art. 21 GDPR)
You have the right to object to processing based on the Controller's legitimate interest (Art. 6(1)(f) GDPR), including profiling.
6.7 Right to Withdraw Consent (Art. 7(3) GDPR)
You may withdraw consent for data processing at any time, which does not affect the lawfulness of processing carried out before the withdrawal. Consent can be withdrawn by:
- changing cookie settings in the Service,
- sending a message to airenovationcalculator@gmail.com.
6.8 Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a supervisory authority. For Users in Poland: Prezes Urzedu Ochrony Danych Osobowych (PUODO), ul. Stawki 2, 00-193 Warszawa, https://uodo.gov.pl.
7. Data Retention Periods
| Data Category | Retention Period |
|---|---|
| Account data (profile, settings) | Until Account deletion by the User or automatic deletion of an unused Account (below) |
| Project data | Until Project or Account deletion |
| Payment data | 5 years from the end of the tax year (legal obligation) |
| Analytics data (Google Analytics) | 14 months |
| Microsoft Clarity data (websites) | Session recordings up to 30 days, other data up to 13 months |
| Security logs | 12 months |
| Anonymous accounts | 1 day from last activity |
| AI Analysis requests (description and result) | 12 months from the analysis |
| Usage-limit data for Anonymous Users (browser fingerprint hash, IP address, visit times, Account identifier) | 12 months from the last visit |
| Review import log (Company PRO Accounts: review page address, reviews retrieved, Account identifier) | 12 months from the import |
| Accounts with an unconfirmed e-mail address | 7 days from last activity |
| Registered accounts without PRO, unused | 30 days from last activity; after 20 days we send an e-mail naming the deletion date |
| Consent records (cookie, marketing) | Until consent withdrawal or Account deletion |
After the retention period, data is deleted or anonymized.
Automatic deletion of unused Accounts:
- Deletion runs once a day, at night, so an Account is removed in the first nightly run after the period in the table has passed.
- Last activity is the latest of: Account creation, sign-in, session refresh while the Service is open (about once an hour, so simply viewing counts too) and saved changes. For registered Accounts it also includes using or buying Points and other people using Projects the owner has shared with them.
- A registered Account with a confirmed e-mail address is deleted only after a reminder has been sent, and not before the date that reminder names (10 days after the e-mail). Any activity after the reminder cancels it; signing in is enough to keep the Account.
- Never deleted automatically: Accounts with an active PRO Subscription, administrator Accounts, and Accounts from which Points or a PRO Subscription were ever purchased.
- Deleting an Account removes its Projects, photos and sharing records. Payment data is kept for the period required by law (table above). AI Analysis requests, review import logs and usage-limit data are not removed with the Account: they are deleted when their 12 months pass, or earlier on request to airenovationcalculator@gmail.com.
8. International Data Transfers
- User data is primarily stored in the EU on Firebase/Google Cloud servers: the database in the eur3 region (Belgium and the Netherlands), files in the EU multi-region.
- Some data may be transferred outside the European Economic Area (EEA) in connection with the following services:
- Google LLC (USA) — under the EU-U.S. Data Privacy Framework,
- Stripe, Inc. (USA) — under the EU-U.S. Data Privacy Framework and SCCs,
- OpenAI, LLC (USA) — under Standard Contractual Clauses (SCCs),
- Microsoft Corporation (USA, Microsoft Clarity on the websites) — under the EU-U.S. Data Privacy Framework and SCCs,
- OpenStreetMap Foundation (United Kingdom, the map on company profiles) — under the European Commission's adequacy decision for the United Kingdom (Art. 45 GDPR).
- In all cases of data transfer outside the EEA, appropriate safeguards are applied in accordance with Art. 46 GDPR, including Standard Contractual Clauses approved by the European Commission.
9. Profiling and Automated Decision-Making
- The Service uses User data for analytical purposes (Google Analytics), including:
- analysis of user behavior within the Service,
- measurement of feature effectiveness,
- content adaptation based on location (country/city).
- The Service does not make decisions based solely on automated processing that would produce legal effects or similarly significantly affect the User (Art. 22 GDPR).
- AI analysis (OpenAI) generates estimates based on provided data, but results are presented only as suggestions — the final decision rests with the User.
10. Data Security
The Controller implements the following technical and organizational measures to protect personal data:
- Encryption in transit — all communication occurs over HTTPS (TLS).
- Authentication — Firebase Authentication with email verification.
- Application security — Firebase App Check protects against unauthorized access.
- Payment security — Stripe PCI DSS Level 1 (highest certification level).
- Access control — Firestore Security Rules restrict data access.
- Data separation — User data is logically separated in the database.
- Automatic deletion — unused Accounts are deleted automatically: anonymous after 1 day, with an unconfirmed e-mail address after 7 days, registered without PRO after 30 days without activity, with an e-mail reminder after 20 days (details in section 7).
- Data minimization — only data necessary for service provision is collected.
11. Children's Privacy
- The Service is not intended for persons under 16 years of age.
- The Controller does not knowingly collect personal data from persons under 16.
- If the Controller becomes aware that data of a child under 16 has been processed without parental or guardian consent, such data will be promptly deleted.
12. California Residents (CCPA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA):
12.1 Right to Know
You have the right to request information about the categories and specific pieces of personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your data.
12.2 Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions provided by law.
12.3 Right to Opt-Out of Sale
We do not sell personal information. However, if this changes, you will have the right to opt out.
12.4 Right to Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.
12.5 Categories of Information Collected
| Category (CCPA) | Examples | Collected |
|---|---|---|
| Identifiers | Email, name, phone, IP address | Yes |
| Commercial information | Payment history, subscription status, Points balance | Yes |
| Internet activity | Pages visited, features used, analytics data | Yes |
| Geolocation | Country, city (user-provided) | Yes |
| Professional information | Company name, Tax ID, business type | Yes (Company Accounts) |
| Visual information | Photos uploaded to projects | Yes |
12.6 How to Exercise CCPA Rights
To exercise your rights, contact us at airenovationcalculator@gmail.com. We will respond within 45 days.
12.7 Authorized Agents
You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority.
13. Changes to This Privacy Policy
- The Controller reserves the right to modify this Privacy Policy.
- Registered Users will be notified of material changes via email or in-Service notification at least 14 days before the changes take effect.
- The current version of the Privacy Policy is always available in the Service.
- The date of the last update is indicated at the beginning of this document.
- Amended with effect from September 29, 2026: the OpenStreetMap map on company profiles (5.7 and 8).
- Amended with effect from September 28, 2026: the studio client panel (section 16), Vercel hosting among the processors (5.6), the panel cookie (4.1) and the location of Firebase data (5.1 and 8).
14. Contact
For questions regarding data protection, please contact:
Gmbi Marek Papis
ul. Pomorska 70 m. 10, 91-409 Lodz, Poland
NIP: 9820319917
E-mail: airenovationcalculator@gmail.com
Supervisory authority (Poland):
Prezes Urzedu Ochrony Danych Osobowych (PUODO)
ul. Stawki 2, 00-193 Warszawa
https://uodo.gov.pl
For California residents, you may also contact the California Attorney General:
https://oag.ca.gov/privacy
15. Chrome Extension — Kalkulator Remontu
This section applies to the Chrome browser extension "Kalkulator Remontu — Dodaj produkt", which allows adding products from online stores to the Kalkulator Remontu application.
15.1 Browser Permissions
The extension requires the following browser permissions:
| Permission | Purpose |
|---|---|
| activeTab | Read product data (name, price, image) from the currently open tab, only after the User clicks the extension icon |
| scripting | Inject the side panel into the online store page |
| storage | Persist login session and User preferences |
| contextMenus | Context menu on text selection (assign to fields: dimension, catalog number, notes) |
| notifications | Display a notification when the extension cannot operate on a restricted page (e.g. browser system pages) |
| host_permissions (<all_urls>) | The extension must work on any online store website, as Users shop across many different domains. This permission is also required to download product images and upload them to Firebase Storage. |
15.2 Data Collected by the Extension
- Only product data explicitly selected by the User: name, price, image, page URL, catalog number, supplier.
- Data is stored in the same Firebase account as the web application.
- The User initiates every data save action manually (by clicking "Save").
15.3 What the Extension Does NOT Do
- Does NOT collect browsing history.
- Does NOT monitor User activity on websites.
- Does NOT use Google Analytics or any other analytics.
- Does NOT send data to third parties other than Firebase (Google).
- Does NOT run in the background — it activates only when the User opens the panel.
16. Studio Client Panel
An architecture studio with a PRO account can share a Project with its client through a link to the client panel (at kalkulatorremontu.pl/panel/… or airenovationcalculator.com/client-panel/…). In the panel the client views the items the studio selected, accepts or rejects them and adds comments. The client does not edit the Project and does not create an Account in the Service.
16.1 Controller
The controller of the client's data in the panel is the studio that sent the link. Gmbi Marek Papis processes this data on the studio's behalf, under the data processing agreement in the Terms of Service for PRO accounts (chapter 19). The studio is responsible for informing its client.
16.2 What data and why
- The client's e-mail address. The studio enters it when it creates the link. The panel compares it with the address the client gives on entry, so that a forwarded link does not open the Project for someone else. A mistyped address is not stored.
- The client's decisions and comments (acceptance, rejection, comment text, time). This is the purpose of the panel: the studio sees the client's answer in the application.
- Activity log. We record who entered the panel, changed a decision or added a comment: which link, when, and a shortened IP address (the first three numbers of an IPv4 address, the first three groups of an IPv6 address). This settles who decided what and when, and shows whether an outsider used the link. Only the studio sees the log.
- Attempt counters. To stop anyone guessing links and addresses, we count attempts from one IP address per hour. The counter holds no IP address, only a cryptographic hash of it (HMAC with a secret key) that cannot be turned back into the address. The counter deletes itself after about 2 hours.
- Session cookie (cp_…). Remembers that the client has already entered the e-mail address, so the panel does not ask on every visit. It holds only the Project and link identifiers, no e-mail address or name. It is necessary for the panel to work, so it needs no consent. It expires after 30 days, or sooner when the link expires or the studio revokes it.
The panel pages have no analytics or advertising cookies, no Google Analytics, Microsoft Clarity or Vercel Analytics. Search engines do not index the panel pages, and the pages do not pass their address (referrer) to other websites.
16.3 Legal basis
For the studio: performance of its contract with the client and its legitimate interest in documenting what was agreed (Art. 6(1)(b) and (f) GDPR). For Gmbi Marek Papis: the data processing agreement with the studio. Protecting the panel against abuse (attempt counters and the log) is based on legitimate interest (Art. 6(1)(f) GDPR).
16.4 Who else has access
The data is stored in Google Firebase (Firestore) on servers in the European Union, and the panel pages are hosted by Vercel (servers in Frankfurt). Both companies are our processors (section 5).
16.5 How long
- The link works until the date the studio set, and the studio can revoke it at any time. After it expires or is revoked the link stops working, but the decisions, comments and log stay with the Project as the record of what was agreed.
- Panel data is deleted together with the Project: when the studio deletes the Project or its Account.
- Attempt counters: about 2 hours.
16.6 The client's rights
The client may request access to their data, its correction, deletion or restriction of processing, and may object. The quickest way is through the studio that sent the link: the studio deletes the link or the Project. The client can also write to us at airenovationcalculator@gmail.com. We pass the request to the studio, and if it does not respond, we handle it ourselves. The client may also lodge a complaint with a supervisory authority; in Poland, the President of the Personal Data Protection Office (PUODO).