מדיניות פרטיות

1.0.0 · 2026-09-21

איזה מידע אנו מחזיקים עליכם, לשם מה, מי עוד רואה אותו, וכיצד לקבלו בחזרה או למחקו.

מי מחזיק במידע שלכם

CalFit היא בעלת המאגר ובעלת השליטה במידע האישי המתואר כאן, ומקום מושבה בישראל. בכל עניין הנוגע למדיניות זו, לרבות בקשה לעיין במידע או למחוק אותו, כתבו אלינו לכתובת omri@dicori.co.il ונשיב לכם.

מדיניות זו נכתבה כדי שתיקרא, לא כדי שתישרד. אם משפט כלשהו בה אינו ברור, זו תקלה ששווה להודיע לנו עליה.

איזה מידע אנו אוספים

רק מה שהאפליקציה זקוקה לו כדי לפעול. אין כאן פרסום, אין פיקסל מעקב, ואין כלי ניתוח של צד שלישי שקורא את מידע הבריאות שלכם.

מידע בריאות, ומה קורה אם תסרבו

מרבית המידע שלעיל הוא מידע בריאות, שהדין מסווג כמידע בעל רגישות מיוחדת ומגן עליו בקפדנות רבה יותר מאשר על כתובת או שם. אנו מעבדים אותו אך ורק בהסכמתכם המפורשת, שאותה נבקש בנפרד ובלשון ברורה ולא נטמין אותה באישור המסמכים האלה.

אינכם מחויבים על פי דין למסור לנו דבר מכל אלה. מסירת המידע היא מרצון.

מה עולה לכם הסירוב, בלשון פשוטה: ללא תאריך לידה, מין, גובה, משקל ורמת פעילות לא ניתן לחשב יעד קלורי או יעד חלבון ולא ניתן לייצר תוכנית, ולכן לא יהיה לאפליקציה מה להציע לכם. ללא תשובות שאלון הבריאות לא נוכל להחיל את מגבלות הבטיחות, ולא נייצר תוכנית ללא מידע זה. סירוב לפריטים שאינם חובה, דהיינו החיבור לפלטפורמת הבריאות, תצלומי המזון וההסכמה לשיפור המוצר שלהלן, עולה לכם באותה תכונה בלבד ולא מעבר לכך.

תוכלו לחזור בכם מההסכמה בכל עת, והחזרה מההסכמה אינה הופכת את מה שנעשה קודם לכן לבלתי חוקי. היא מפסיקה את העיבוד מאותו רגע, ותוכלו למחוק את כל המידע במקביל.

לשם מה אנו מעבדים אותו

לכל מטרה בסיס משפטי משלה, ובסיס שניתן למטרה אחת אינו משתרע על מטרה אחרת.

סיוע בשיפור המוצר, שהוא מרצון

הידיעה אילו תוכניות אכן עבדו היא מה שמשפר את התוכניות. כדי ללמוד זאת עלינו לשמור רישום של מבנה התוכנית ושל התוצאה שהניבה, על פני משתמשים רבים.

נבקש זאת מכם בנפרד, האפשרות כבויה עד שתפעילו אותה, ותוכלו לכבות אותה שוב מתי שתרצו. סירוב אינו משנה דבר באפליקציה שתקבלו. אין מדובר בתנאי לשימוש בשום דבר, ולא יהיה.

אם תפעילו אותה, המידע שיוצא מהחשבון שלכם מנוקה תחילה: טווח גילים במקום תאריך לידה, טווח גבהים במקום גובה, היעד שלכם, גרסת התוכנית והתוצאה. ללא שם, ללא דואר אלקטרוני, ללא מזהה חשבון, ללא טקסט חופשי וללא תצלום. אם תחזרו בכם או תמחקו את החשבון בהמשך, גם רישומים אלה יימחקו.

תצלומי מזון

אם תצלמו ארוחה כדי שהאפליקציה תזהה אותה, התצלום נשלח לשרת שלנו ומשם לספק בינה מלאכותית שמחזיר רשימת מאכלים. כך התכונה פועלת, ואין גרסה שלה שבה התצלום נשאר במכשיר שלכם.

אנו מחייבים את אותו ספק לעבד את התצלום ולא לשמור דבר, ולא להשתמש בו לאימון המודלים שלו. איננו שומרים את התצלום לאחר שהזיהוי הוחזר, אלא אם בחרתם לשמור אותו יחד עם הרישום.

מה שהמודל מחזיר הוא הצעה. היא נבדקת מול נתוני המזון המאומתים שלנו לפני שהיא הופכת למספר ביום שלכם, והיא עלולה להיות שגויה. אל תצלמו דבר שלא הייתם רוצים לשלוח.

Apple Health ו־Health Connect

החיבור כבוי עד שתאשרו אותו, האישור ניתן לכל סוג נתונים בנפרד, ותוכלו לבטלו בהגדרות המערכת מבלי להודיע לנו. אנו קוראים אך ורק את הסוגים שאישרתם, וכותבים בחזרה רק את האימונים, השקילות, המים והאנרגיה התזונתית שלכם.

מידע שנקרא מ־Apple Health אינו משמש לפרסום, אינו נמכר, אינו משותף עם סוחרי מידע ואינו מאוחסן ב־iCloud. Apple אוסרת זאת מכל וכל, וכך גם אנחנו.

מי עוד רואה אותו

איננו מוכרים את המידע שלכם ואיננו משתפים אותו כדי שגורם אחר ישווק לכם. מספר קטן של ספקים מעבד אותו עבורנו, בהתאם להסכם, ואך ורק לפי הוראותינו.

היכן המידע מאוחסן

הספקים שלנו פועלים ברחבי העולם, ולכן ייתכן שהמידע שלכם יעובד מחוץ למדינתכם. כאשר הוא יוצא מהאזור הכלכלי האירופי או מישראל, ההעברה נעשית מכוח החלטת נאותות או מכוח תניות חוזיות סטנדרטיות, ואנו מבקשים מהספקים לשמור את המידע באזור אירופי כאשר הם מציעים זאת.

כמה זמן אנו שומרים אותו

הפרופיל, התוכנית וההיסטוריה הרשומה שלכם נשמרים כל עוד החשבון קיים, משום שכל תכלית האפליקציה היא ההיסטוריה. מחיקת החשבון מוחקת אותם.

לאחר המחיקה, גיבויים מוצפנים שעדיין מכילים עותק נמחקים בתוך 30 יום. דיווחי שגיאה נשמרים 90 יום. רישומים שאנו חייבים לשמור על פי דין, כגון רישום של תשלום, נשמרים לתקופה שאותו דין מחייב ולא מעבר לה.

תצלום מזון אינו נשמר לאחר החזרת הזיהוי, אלא אם שמרתם אותו בעצמכם יחד עם הרישום.

מה תוכלו לדרוש

הזכויות האלה שלכם, השימוש בהן ללא תשלום, ואנו משיבים בתוך 30 יום. לעולם אינכם נדרשים לנמק.

כיצד המידע מוגן

כל המידע עובר בהצפנה ונשמר בהצפנה. כללי הגישה נאכפים בשרת כך שחשבון יכול להגיע למידע שלו בלבד ולא לדבר מעבר לכך, וכללים אלה נבדקים אוטומטית בכל גרסה ולא נסמכים על אמון.

כל מידע רגיש הנשמר במכשיר שלכם מאוחסן במחסן המפתחות של המערכת ולא בקובץ רגיל. שום אבטחה אינה מושלמת, ואם אירוע אבטחה יעמיד אתכם בסיכון נודיע לכם ולרשות, ללא דיחוי.

קטינים

האפליקציה מיועדת לבגירים ואיננו מחזיקים ביודעין מידע על מי שטרם מלאו לו 18. אם נודע לכם שלקטין יש חשבון, כתבו לנו ונמחק אותו.

שינויים במדיניות זו

נעדכן מדיניות זו ככל שהאפליקציה תשתנה. הגרסה והתאריך בראש המסמך מציינים במה אתם קוראים. אם נבקש אי פעם להשתמש במידע שלכם למטרה חדשה, נבקש את הסכמתכם מחדש ולא נרחיב בשקט הסכמה ישנה.


Privacy Policy

1.0.0 · 2026-09-21

What we hold about you, why, who else sees it, and how to get it back or erased.

Who holds your data

CalFit is the controller of the personal data described here, and is established in Israel. For anything in this policy, including a request to see or delete your data, write to omri@dicori.co.il.

This policy is written to be read, not to be survived. If a sentence in it is unclear, that is a fault worth telling us about.

What we collect

Only what the app needs in order to work. There is no advertising here, no tracking pixel, and no third party analytics reading your health information.

Health data, and what happens if you refuse

Most of the above is health data, which the law treats as a special category and protects more strictly than an address or a name. We process it only with your explicit consent, which we ask for separately and in plain words rather than burying it in an acceptance of these documents.

You are not legally obliged to give us any of it. Providing it is voluntary.

What refusing costs you, plainly: without a date of birth, sex, height, weight and activity level, no calorie or protein target can be calculated and no plan can be produced, so the app has nothing to offer you. Without the health screening answers we cannot apply the safety limits, and we will not generate a plan blind. Refusing the optional items, which are the health platform connection, food photographs and the improvement consent below, costs you only that feature and nothing else.

You can withdraw consent at any time, and withdrawing does not make what we did beforehand unlawful. It stops the processing from that point, and you can delete everything alongside it.

Why we process it

Each purpose has its own basis, and a basis given for one purpose does not extend to another.

Helping us improve, which is optional

Knowing which plans actually worked is how the plans get better. To learn that we would need to keep a record of the shape of a plan and the result it produced, across many people.

We ask for this separately, it is off until you turn it on, and you can turn it off again whenever you like. Refusing changes nothing about the app you get. It is not a condition of using anything, and it never will be.

If you do turn it on, what leaves your account is stripped first: an age band rather than a birth date, a height band rather than a height, your goal, the plan version and the outcome. No name, no email, no account identifier, no free text and no photograph. If you later withdraw or delete your account, those records are removed too.

Food photographs

If you photograph a meal so the app can identify it, that photograph is sent to our server and from there to an artificial intelligence provider that returns a list of foods. This is how the feature works, and there is no version of it that keeps the photograph on your phone.

We require that provider to process the photograph and retain nothing, and not to use it to train its own models. We do not keep the photograph after the identification returns unless you chose to save it with the entry.

What the model returns is a suggestion. It is checked against our own validated food data before it becomes a number in your day, and it can be wrong. Do not photograph anything you would not want to send.

Apple Health and Health Connect

The connection is off until you grant it, it is granted per data type, and you can revoke it in the system settings without telling us. We read only the types you allowed, and we write back only your workouts, weights, water and dietary energy.

Data read from Apple Health is never used for advertising, never sold, never shared with a data broker and never stored in iCloud. Apple forbids all of that outright, and so do we.

Who else sees it

We do not sell your data and we do not share it for anyone else to market to you. A small number of suppliers process it on our behalf, under contract, and only on our instructions.

Where it is stored

Our suppliers operate internationally, so your data may be processed outside your country. Where it leaves the European Economic Area or Israel, it moves under an adequacy decision or under standard contractual clauses, and we ask suppliers to keep data in a European region where they offer one.

How long we keep it

Your profile, plan and logged history are kept while your account exists, because the whole point of the app is the history. Delete the account and they go.

After deletion, encrypted backups still holding a copy expire within 30 days. Error reports are kept for 90 days. Records we must keep by law, such as a record of a payment, are kept for the period that law requires and for no longer.

A food photograph is not kept after the identification returns, unless you saved it with the entry yourself.

What you can ask for

These rights are yours, they are free to use, and we answer within 30 days. You never have to explain why.

How it is protected

Everything travels encrypted and is stored encrypted. Access rules are enforced on the server so that an account can reach its own data and nothing else, and those rules are tested automatically on every release rather than trusted.

Anything sensitive kept on your device sits in the platform keychain rather than in an ordinary file. No security is perfect, and if a breach ever puts you at risk we will tell you and the authority, promptly.

Children

The app is for adults and we do not knowingly hold data about anyone under 18. If you believe a minor has an account, write to us and we will delete it.

Changes to this policy

We will update this policy as the app changes. The version and date at the top tell you which one you are reading. If we ever want to use your data for something new, we will ask you again rather than quietly widen an old consent.