מדיניות פרטיות (Privacy Policy)
תאריך עדכון אחרון: 22 ביוני 2026
מדיניות פרטיות זו מגדירה ומסדירה את האופן שבו פלטפורמת Tovora (להלן: "הפלטפורמה" או "השירות") אוספת, מעבדת, מאחסנת ומגינה על המידע האישי ונתוני הבריאות של משתמשיה. המדיניות מנוסחת ומיושמת בהתאמה מלאה לתקנות הגנת המידע האירופיות (GDPR), חוק הגנת הפרטיות, התשמ"א-1981 של מדינת ישראל, ומדיניות המשתמשים הרשמית של גוגל (Google API Services User Data Policy).
השירות מופעל ומנוהל על ידי Idane Amar, מרעננה, ישראל (להלן: "המפעיל"). לכל פנייה, בירור או מימוש זכויות בנושאי פרטיות ואבטחת מידע, ניתן ליצור קשר ישיר בכתובת הדוא"ל: jon.idane6@gmail.com.
1. סוגי המידע הנאספים ומקורותיהם
1.1 מידע הנמסר מרצון על ידי המשתמש
- פרטי רישום וניהול חשבון: שם משתמש, סיסמה מוצפנת ומאובטחת באמצעות מנגנון הצפנה חד-כיווני בלתי הפיך (Cryptographic Hash), שפת ממשק מועדפת ומועד יצירת החשבון.
- פרופיל מדדים פיזיולוגיים ותזונתיים: גיל, גובה, משקל עדכני, מין ביולוגי, רמת פעילות גופנית מוגדרת ומטרות תזונתיות ממוקדות (כגון גירעון קלורי, שמירה על הקיים או העלאת מסת שריר).
- תכני מדיה וארוחות: קבצי תמונות המועלים על ידי המשתמש באופן יזום לצורך ניתוח חזותי אוטומטי של רכיבי המנה וערכיה התזונתיים.
- נתוני מעקב מפורשים: פריטי מזון, רכיבים שמורים, יומן אימונים מפורט (תרגילים, סטים, משקלים והישגים אישיים - PR) ומידע רקע אישי המוזן בממשק המאמן הווירטואלי ("About Me").
1.2 נתוני צד שלישי – אינטגרציית Google Health (בכפוף לאישור מפורש)
במידה והמשתמש בוחר לחבר באופן פעיל את חשבון ה-Google Health שלו, הפלטפורמה תבצע איסוף נתונים מוגבל ומינימלי, המיועד אך ורק לצורך סנכרון ותיאום דינמי של תקציב הקלוריות היומי:
- ספירת צעדים יומית (Daily Step Count).
- מדד אנרגיה פעילה שנשרפה במהלך אימונים (Active Calories Expended).
הבהרה: השירות אינו מבצע פעולות כתיבה או שינוי של נתונים בתוך תשתית Google Health, ואינו מבקש גישה לנתונים רפואיים או אישיים אחרים (כגון קצב לב, מדדי שינה, היסטוריה רפואית או מיקום גיאוגרפי). המשתמש רשאי לבטל אינטגרציה זו בכל עת ובאופן מיידי דרך תפריט הגדרות האפליקציה.
1.3 נתוני אינטראקציה וטקסט קולי
תוכן התכתובות וקובצי השמע (הקלטות קוליות) מול המאמן הווירטואלי מבוסס ה-AI נשמרים במערכת באופן מאובטח. שמירת מידע זו חיונית לצורך שימור הקשר השיחה (Context Retention), הבנת מגמות ארוכות טווח והענקת ליווי מותאם אישית ורציף.
1.4 מידע טכני ואנליטי אוטומטי
לצורך הגנת סייבר, מניעת הונאות וניתוח ביצועים אגרגטיבי (ללא זיהוי אישי), המערכת מתעדת כתובות IP (הנשמרות לפרק זמן מוגבל של עד 7 ימים בלבד), סוג דפדפן ומאפייני מכשיר הקצה.
2. מטרות עיבוד המידע ושיתוף עם צדדים שלישיים
2.1 עיבוד מבוסס בינה מלאכותית (AI Processing)
על מנת לספק את הניתוחים התזונתיים וההכוונה המקצועית, נתונים תזונתיים, קבצי תמונות והקלטות קוליות מועברים בצורה מוצפנת ומאובטחת אל ממשקי ה-API הרשמיים של Google Gemini. העיבוד מבוצע תחת תנאי הפרטיות הרשמיים של Google לפיתוח ארגוני, ונתוני המשתמש אינם משמשים לאימון מודלים ציבוריים של צד ג'.
2.2 התחייבות קטגורית לאי-מסחור בנתונים
המפעיל מתחייב באופן מוחלט ובלתי מסויג: אנו לא מוכרים, לא משכירים, לא משתפים ולא עושים כל שימוש מסחרי, שיווקי או פרסומי בנתוני הבריאות, במדדים הפיזיולוגיים או במידע האישי של המשתמשים עם שום גורם צד שלישי. כלל המידע משמש אך ורק לצורך הפעלת השירות ואספקת הערך למשתמש הקצה.
2.3 ספקי תשתית מורשים
המידע נשמר ומעובד באמצעות ספקי תשתיות ענן מובילים תחת חוזי אבטחה קפדניים:
- Render Inc: מארחת את שרתי האפליקציה ומסדי הנתונים בסטנדרט אבטחה מחמיר.
- Cloudflare: מספקת הגנת סייבר (WAF), ניתוב DNS מאובטח ושירותי הצפנה קצה לקצה עבור הדומיין tovora.app.
- Cloudflare R2: אחסון גיבויים מוצפנים של בסיס הנתונים לצרכי התאוששות מאסון (Disaster Recovery) בלבד.
3. אבטחת מידע וארכיטקטורת אחסון
המידע בפלטפורמה נשמר בסביבה וירטואלית מבודדת ומאובטחת על גבי שרתי Render. הגישה למסד הנתונים חסומה לחלוטין לרשת האינטרנט החיצונית ומתאפשרת אך ורק לתהליך השרת הפנימי של האפליקציה. כל תעבורת הנתונים מוצפנת מקצה לקצה באמצעות פרוטוקול HTTPS ותעודות SSL רשמיות מטעם Let's Encrypt.
גישה לנתונים האישיים מתאפשרת אך ורק למשתמש הרלוונטי באמצעות אימות פרטי הכניסה הייחודיים לו. המפעיל אינו ניגש באופן יזום לנתוני משתמשים, למעט במקרים חריגים של קבלת בקשה מפורשת לתמיכה טכנית או תחת חובה שיפוטית מוסמכת.
4. זכויות המשתמש ושליטה במידע
בהתאם לתקנות ה-GDPR ולחוק הגנת הפרטיות הישראלי, מוענקות למשתמש זכויות מלאות על נתוניו, אותן הוא יכול לממש באופן עצמאי או בפנייה למפעיל:
- זכות העיון והגישה: אפשרות לצפות בכל רגע נתון בכל המידע שנאסף ונשמר אודותיו.
- זכות התיקון והעדכון: יכולת לערוך, לעדכן ולתקן כל נתון או מדד פיזיולוגי ישירות מתוך פרופיל המשתמש.
- הזכות לניידות נתונים (Data Portability): אפשרות לייצא ולהוריד עותק מלא ומבני של כל נתוני המערכת ההיסטוריים כקובץ JSON, ישירות מתפריט ההגדרות.
- הזכות להגשת תלונה: זכות לפנות לרשות להגנת הפרטיות במשרד המשפטים בישראל, או לרשות הרלוונטית במקום מגוריו.
5. מחיקה מוחלטת וקבועה מהמערכת (Right to Erasure — GDPR Article 17)
הפלטפורמה דוגלת בשקיפות מלאה ומאפשרת למשתמש לממש את "הזכות להישכח" בצורה עצמאית ומיידית, ללא צורך באישור או פנייה לשירות הלקוחות. בתפריט הגדרות ← Danger Zone, לחיצה על כפתור "מחק את החשבון שלי לצמיתות" ואישור הפעולה תבצע הסרה מיידית ובלתי הפיכה של המידע הבא:
- פרטי החשבון, קובצי הפרופיל והגדרות המערכת.
- כל היסטוריית יומן התזונה, רכיבי המזון, והאימונים שנשמרו.
- כל קובצי המדיה (תמונות ארוחות) והקלטות השמע מהשרתים הפיזיים.
- היסטוריית הצ'אט והתכתובות המלאה מול המאמן הווירטואלי.
- ביטול וניתוק מוחלט (Revoke) של טוקני הגישה מול שירותי Google Health.
הסרת הנתונים מבסיס הנתונים הפעיל היא מיידית. מחיקה מלאה משכבות הגיבוי המוצפנות תושלם באופן אוטומטי בתוך 24 שעות.
6. הגנת פרטיות של קטינים
השירות מיועד ומאושר לשימוש עבור משתמשים בני 18 ומעלה (או בני 16-17 בכפוף לליווי ואישור הורה או אפוטרופוס חוקי). הפלטפורמה אינה אוספת ביודעין מידע מקטינים מתחת לגיל 16. במידה ויתגלה כי נאסף מידע השייך לקטין מתחת לגיל 16 ללא הסמכה חוקית, המערכת תבצע מחיקה מנהלתית מיידית של החשבון וכלל נתוניו.
7. העברת נתונים בינלאומית
לצורך אספקת השירות, הנתונים מאוחסנים על גבי שרתי חברת Render בארצות הברית ומעובדים על ידי ממשקי גוגל (Google Gemini) בארצות הברית. ספקים אלו מחויבים ומסמיכים עצמם תחת תקני אבטחה בינלאומיים מחמירים ומנגנוני העברת מידע חוקיים ותקינים התואמים את דרישות האיחוד האירופי.
8. שינויים ועדכונים במדיניות הפרטיות
המפעיל שומר לעצמו את הזכות לעדכן או לשנות מדיניות פרטיות זו מעת לעת על מנת לשקף שינויים טכנולוגיים או רגולטוריים. במידה ויבוצעו שינויים מהותיים המשפיעים על זכויות המשתמש, תפורסם הודעה בולטת (Banner) בממשק האפליקציה טרם כניסת השינויים לתוקף. תאריך העדכון בראש העמוד ישונה בהתאם.
9. יצירת קשר ובירורים
למימוש זכויותיך, לשאלות או להעלאת הערות בנוגע למדיניות זו, ניתן לפנות לממונה הפרטיות בדוא"ל: jon.idane6@gmail.com. אנו מתחייבים לבחון כל פנייה ולספק מענה רשמי בתוך 7 ימי עסקים.
Privacy Policy
Last Updated: June 22, 2026
This Privacy Policy defines and governs how the Tovora platform (hereinafter: "the Platform" or "the Service") collects, processes, stores, and protects the personal and health data of its users. This policy is formulated in strict compliance with the EU General Data Protection Regulation (GDPR), the Israeli Privacy Protection Law, 5741-1981, and Google's API Services User Data Policy.
The Service is operated and managed by Idane Amar, based in Ra'anana, Israel (hereinafter: "the Operator"). For any privacy-related inquiries, data rights requests, or security concerns, please contact us directly at: jon.idane6@gmail.com.
1. Information We Collect
1.1 Information Provided Voluntarily by the User
- Account Management Details: Username, password (secured via an irreversible cryptographic hash function), interface language preference, and account creation date.
- Biometric & Nutritional Profile: Age, height, current weight, biological sex, defined physical activity level, and specific nutritional goals (e.g., caloric deficit, weight maintenance, or muscle hypertrophy).
- Media & Visual Dietary Logs: Image files explicitly uploaded by the user for the purpose of automated computer-vision analysis of meal ingredients and macronutrient values.
- Explicit Data Entries: Custom food items, saved ingredients, detailed workout logs (exercises, sets, weights, and personal records), and personal background information provided directly to the virtual coach.
1.2 Third-Party Data – Google Health Integration (Subject to Explicit Consent)
If the user actively chooses to connect their Google Health account, the Platform will perform a strictly limited data retrieval, intended solely for the dynamic synchronization of the daily caloric budget:
- Daily Step Count.
- Active Calories Expended during recorded workouts.
Google API Limited Use Disclosure: Tovora's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. We do not write or modify data within the Google Health ecosystem, nor do we request access to sensitive medical data (e.g., heart rate, sleep data, or geolocation). The user may revoke this integration at any time via the app's settings.
1.3 Interaction & Voice Data
The content of textual correspondence and audio recordings with the AI virtual coach is securely stored. This retention is essential for preserving conversational context, understanding long-term user trends, and delivering continuous, personalized guidance.
1.4 Automated Technical & Analytical Data
For cybersecurity, fraud prevention, and aggregate performance analysis (without personal identification), the system temporarily logs IP addresses (retained for a maximum of 7 days), browser types, and device characteristics.
2. Data Processing & Third-Party Sharing
2.1 Artificial Intelligence Processing (AI Processing)
To provide advanced nutritional analysis and professional guidance, dietary data, images, and voice recordings are securely and encrypted transmitted to the official Google Gemini APIs. This processing operates under Google's enterprise privacy terms. User data is strictly not used to train public third-party AI models.
2.2 Categorical Commitment to Non-Commercialization
The Operator commits absolutely and unconditionally: We do not sell, rent, share, or make any commercial or advertising use of your health data, physiological metrics, or personal information with any third party. All data is utilized exclusively for operating the Service and delivering direct value to the end-user.
2.3 Authorized Infrastructure Providers
User data is stored and processed using top-tier cloud infrastructure providers under strict security agreements:
- Render Inc: Hosts the application servers and databases under rigorous security standards in the US.
- Cloudflare: Provides cybersecurity (WAF), secure DNS routing, and end-to-end encryption for the tovora.app domain.
- Cloudflare R2: Stores encrypted database backups strictly for Disaster Recovery purposes.
3. Data Security and Storage Architecture
Data within the Platform is housed in an isolated, secure virtual environment on Render servers. Database access is entirely blocked from the public internet and restricted solely to the internal application server process. All data transit is end-to-end encrypted via the HTTPS protocol using official Let's Encrypt SSL certificates.
Access to personal data is granted exclusively to the authenticated account owner. The Operator does not proactively access user data, except in exceptional cases requiring explicit technical support or under a binding legal mandate.
4. User Rights and Data Control
In accordance with the GDPR and Israeli privacy laws, users are granted comprehensive rights over their data, which can be exercised independently or by contacting the Operator:
- Right of Access: The ability to view all collected and stored personal data at any time.
- Right to Rectification: The ability to independently edit, update, or correct any physiological metric directly within the user profile.
- Right to Data Portability: The option to export and download a complete, structured historical record of all system data as a JSON file, accessible via the settings menu.
- Right to Lodge a Complaint: The right to file a grievance with the Israeli Privacy Protection Authority or the relevant regulatory body in the user's jurisdiction.
5. Right to Erasure (GDPR Article 17)
The Platform champions absolute transparency and empowers users to exercise their "Right to be Forgotten" instantly and independently. Navigating to Settings → Danger Zone and executing the "Delete my account permanently" function will trigger the immediate and irreversible removal of the following:
- Account credentials, profile files, and system settings.
- The entire dietary log, custom ingredients, and workout history.
- All media files (meal photos) and audio recordings from physical servers.
- The complete chat and interaction history with the virtual coach.
- The automatic revocation of access tokens related to Google Health services.
Removal from the active database is instantaneous. Complete purging from encrypted backup layers is executed automatically within 24 hours.
6. Protection of Minors
The Service is strictly intended for users aged 18 and older (or individuals aged 16-17 operating under the active supervision and consent of a legal guardian). The Platform does not knowingly collect information from minors under the age of 16. Should it be discovered that data belonging to a minor under 16 has been collected unlawfully, the system will execute an immediate administrative deletion of the account and all associated data.
7. International Data Transfers
To provide the Service, data is stored on Render's servers in the United States and processed by Google's APIs (Google Gemini) in the United States. These providers comply with stringent international security standards and employ lawful data transfer mechanisms (such as Standard Contractual Clauses) compliant with EU requirements.
8. Modifications to this Privacy Policy
The Operator reserves the right to amend or update this Privacy Policy periodically to reflect technological or regulatory advancements. In the event of material changes affecting user rights, a prominent notice (Banner) will be displayed within the application interface prior to the changes taking effect. The "Last Updated" date at the top of this document will be modified accordingly.
9. Contact Information
For the exercise of your rights, questions, or comments regarding this policy, please contact our Privacy Officer via email at: jon.idane6@gmail.com. We are committed to reviewing all inquiries and providing an official response within 7 business days.