← חזרה לדף הבית

מדיניות פרטיות

עדכון אחרון: ספטמבר 2026 | InControl · מופעל על ידי בעליו כאדם פרטי

תקציר: InControl היא מערכת לניהול עסק ו-CRM, המופעלת על ידי בעליה כאדם פרטי — אין מאחוריה תאגיד רשום. אנחנו לא מוכרים מידע, לא משתפים עם צדדים שלישיים, ולא אוספים מידע ממשתמשים שאינם מורשים.

1. מה אנחנו אוספים

המערכת עובדת עם הנתונים הבאים:

2. שימוש במידע

המידע משמש אך ורק להפעלת תכונות המערכת: ניהול משימות, עיבוד מיילים, ויצירת הצעות מחיר. אנחנו לא משתמשים במידע לפרסום, שיווק, או כל מטרה אחרת.

3. אבטחת מידע

4. שירותי צד שלישי

4א. שימוש בנתוני Google (Limited Use)

InControl ניגשת לנתוני Gmail, Google Calendar ו-Google Tasks אך ורק בהרשאת המשתמש המפורשת, ורק כדי לספק למשתמש את שירותי העוזרת (קריאת/יצירת אירועים, תזכורות, סיכום מיילים, משימות) הנראים לעין בתוך האפליקציה.

השימוש שלנו במידע המתקבל מ-Google APIs יציית ל-Google API Services User Data Policy, לרבות דרישות ה-Limited Use. בפרט: איננו מוכרים נתוני Google; איננו משתמשים בהם לפרסום; איננו מעבירים אותם לצדדים שלישיים מלבד לצורך אספקת השירות, עמידה בחוק, או בהסכמת המשתמש; ובני אדם אינם קוראים את הנתונים אלא בהסכמה מפורשת, לצורך אבטחה/דיבוג, או כנדרש בחוק. אסימוני הגישה נשמרים מוצפנים, והמשתמש יכול לנתק את החיבור בכל עת.

שימוש ב-AI: נתוני Google מעובדים על-ידי מודל שפה (Anthropic Claude API) אך ורק כדי לספק את תכונות העוזרת למשתמש עצמו (סיכום מייל, יצירת אירוע, טיוטת תשובה). נתוני המשתמש אינם משמשים לאימון או שיפור מודלים — לא על-ידינו ולא על-ידי Anthropic, שתנאי ה-API שלה אוסרים אימון על קלט/פלט של לקוחות.

Limited Use Disclosure (English): InControl's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Google user data is used solely to provide user-facing assistant features requested by the user (reading and summarizing the user's own email, creating calendar events and tasks, saving reply drafts). It is not sold, not used for advertising, and not used to develop, improve, or train generalized AI/ML models. Data processed via the Anthropic Claude API is subject to terms that prohibit training on customer API inputs and outputs.

4ב. שמירת מידע ומחיקה (Data Retention & Deletion)

5. זכויות המשתמש

בהתאם לחוק הגנת הפרטיות הישראלי ותקנות ה-GDPR:

6. עוגיות (Cookies)

המערכת משתמשת בעוגיות חיוניות בלבד — לשמירת מצב ההתחברות (session) ולאבטחה (מניעת CSRF). עוגיות אלה הן HttpOnly ואינן נגישות לקוד JavaScript בדפדפן. איננו משתמשים בעוגיות פרסום, מעקב, או אנליטיקה של צד שלישי.

7. יצירת קשר

בעל השליטה במידע (data controller) ומפעיל השירות הוא בעליה של InControl, כאדם פרטי — לא תאגיד רשום, ולפיכך אין למערכת ח.פ. או כתובת רשומה.

לשאלות בנושא פרטיות ולמימוש הזכויות שלעיל: yishaihershko835@gmail.com

Privacy Policy — English version

InControl ("we") is an AI business assistant ("Dana") that works over WhatsApp and the web. This section summarizes the policy above in English; the two versions say the same.

What we access

How we use it

Only to provide the assistant's features to you. Emails and messages are processed by a language model (Anthropic Claude API) solely to perform the action you asked for; your data is not used to train models, by us or by Anthropic.

Google API Services User Data Policy (Limited Use)

InControl's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not transfer it to third parties except as needed to provide the service, to comply with law, or with your consent. Humans do not read it except with your explicit consent, for security or debugging, or as required by law.

Sharing

Service providers that process data on our behalf: Anthropic (AI processing), Google (the APIs you connect), Supabase (database), Vercel (hosting), Meta WhatsApp Business (message delivery), ElevenLabs (optional text-to-speech). Nothing is sold.

Security

All traffic uses HTTPS/TLS. Google OAuth tokens are stored encrypted (AES-256-GCM). The database is encrypted at rest, every table enforces row-level security, and access is limited to authorized users by role.

Retention and deletion

Google tokens are deleted as soon as you disconnect Google (in the app settings or in your Google account). Operational data is kept while the account is active and deleted when it closes or on request. Full deletion requests: yishaihershko835@gmail.com, handled within 30 days.

Contact

Privacy questions and data requests: yishaihershko835@gmail.com.