מדיניות פרטיות

1. מי אנחנו

Aglamazo היא אפליקציה לניהול פיננסי לעצמאים ולעסקים קטנים, בכתובת aglamazo.com.

בעל השירות ואחראי על המידע: יעקב אגלמז, ע.מ 012680286.
יצירת קשר בנושאי פרטיות: support@aglamaz.com

1א. בקצרה — שלושה דברים שחשוב לדעת מיד

  1. הנתונים הפיננסיים שלך נשמרים בדפדפן שלך, לא בשרת שלנו.
  2. חשבוניות וקבלות שאתה מעלה נשלחות לספק בינה מלאכותית חיצוני (Google Gemini, ובמקרה של כשל Anthropic Claude) כדי לחלץ מהן את הפרטים. המסמך עצמו נשלח — עם השמות, מספרי העוסק והסכומים שבו. פירוט מלא בסעיף 5.
  3. גיבוי לענן הוא בבחירתך, ומתבצע תחת חשבון Google שלך.

2. העיקרון: המידע נשאר אצלך

Aglamazo היא אפליקציית local-first. הנתונים הפיננסיים שלך נשמרים בדפדפן שלך (IndexedDB), לא בשרת שלנו. אין לנו מסד נתונים מרכזי שמחזיק את הספרים שלך.

מהמידע יוצא מהמכשיר שלך רק במקרים המפורטים להלן — גיבוי לענן שלך, שיתוף שבחרת בו, וחילוץ נתונים ממסמכים. כל אחד מהם מתואר במפורש.

3. איזה מידע האפליקציה מטפלת בו

  • תנועות בנק וכרטיסי אשראי — תאריך, סכום, תיאור, בית עסק, וסיווג שאתה קובע.
  • מסמכים פיננסיים — חשבוניות וקבלות שאתה מעלה או שנמשכות מהמייל: שם ספק, מספר מסמך, סכום, מע"מ, ח.פ/ע.מ.
  • פרטי עסק — שם, מספר עוסק, שותפים ואחוזי חלוקה ביניהם.
  • פרטי התחברות ל-Ypay — מזהה וסוד לקוח של מעבד התשלומים, כולל זוגות נפרדים לסביבת בדיקות ולסביבת ייצור. נשמרים מקומית בלבד, בתוך רשומת העסק במכשיר שלך.
  • הגדרות — מפתחות API, העדפות תצוגה, נושאי הכנסה והוצאה.

4. הרשאות Google — מה בדיוק אנחנו מבקשים ולמה

הרשאהמה היא מאפשרתלמה היא נדרשת
drive.fileגישה רק לקבצים שהאפליקציה עצמה יצרה או שפתחת דרכהשמירת החשבוניות והקבלות שהעלית, כדי שיהיו זמינות בכל מכשיר
gmail.modifyקריאה, ארגון, מחיקה ושליחה של דואראיתור אוטומטי של קבלות שהתקבלו במייל, סימונן, וארגונן בתוויות
calendar.readonlyקריאה בלבד של אירועי יומןשיוך זמן עבודה לפרויקטים

drive.file איננה גישה ל-Drive שלך. האפליקציה אינה יכולה לראות, לקרוא או למחוק קבצים שלא נוצרו על ידה.

מדוע gmail.modify ולא הרשאת קריאה בלבד: האפליקציה מסמנת קבלות שטופלו, מסדרת אותן בתוויות, ושולחת מסמכים בשמך. פעולות אלה מחייבות הרשאת כתיבה. היא אינה קוראת דואר שאינו קשור לקבלות ואינה שולחת דואר ללא פעולה יזומה שלך.

Google API Services User Data Policy — שימוש מוגבל

השימוש של Aglamazo במידע שהתקבל מממשקי Google, והעברתו לכל יישום אחר, כפופים ל- Google API Services User Data Policy, לרבות דרישות ה-Limited Use.

בפרט: איננו משתמשים במידע מ-Gmail או מ-Drive לצורך פרסום, איננו מוכרים אותו, ואיננו מעבירים אותו לצדדים שלישיים למעט לצורך אספקת השירות עצמו כמתואר בסעיף 5.

5. עיבוד מסמכים באמצעות בינה מלאכותית — הסעיף החשוב ביותר

כאשר אתה מעלה חשבונית או קבלה, המסמך נשלח לספק בינה מלאכותית חיצוני כדי לחלץ ממנו את הפרטים.

  • Google Gemini (דגם gemini-2.5-flash) — ספק ראשי.
  • Anthropic Claude (דגם claude-sonnet-5) — נבחר כגיבוי, אם החילוץ הראשון נכשל.

מה נשלח: המסמך עצמו — קובץ PDF או תמונה — הכולל את שם הספק, שמך או שם עסקך, מספר עוסק, סכומים, מע"מ ופרטי השירות שנרכש.

מה חוזר: הפרטים המחולצים, שנשמרים במכשיר שלך.

זהו העיבוד היחיד שבו תוכן פיננסי שלך מגיע לצד שלישי שאינו אתה. הוא מתבצע רק כאשר אתה מעלה מסמך או מבקש חילוץ ממייל.

מה עושים הספקים עם המסמך — אומת 09/09/2026

  • Google Gemini — המפתח של Aglamazo מוגדר בפרויקט עם חיוב פעיל (Paid tier). בתנאי Google לשירותים בתשלום, ההנחיות והקבצים שנשלחים אינם משמשים לשיפור המוצרים שלהם. הם נשמרים לזמן מוגבל אך ורק לצורך זיהוי הפרות של מדיניות השימוש.
  • Anthropic Claude — קלט ופלט נמחקים בתוך 30 יום, ואינם משמשים לאימון מודלים ללא הרשאה מפורשת.

מקורות: Gemini API — חיוב ורמות שירות · Anthropic — שמירת נתונים ב-API

6. גיבוי בענן

אם תפעיל גיבוי בענן, הנתונים מסונכרנים ל-Firebase Firestore תחת חשבון Google שלך.

אסימוני ההרשאה של Google אינם נכללים בגיבוי — הם נשמרים מקומית בלבד ומוסרים מכל כתיבת גיבוי, כדי שמכשיר אחד לא יוכל לדרוס את הרשאות הגישה של מכשיר אחר.

7. שיתוף מכוון — מי עוד רואה את המידע שלך

Aglamazo מאפשרת שיתוף יזום. אלה אינם דליפות; אלה תכונות שאתה מפעיל.

  • משק בית משותף — הגיבוי משותף עם בן/בת הזוג, באמצעות סיסמה משותפת לכל עסק. מרגע ההפעלה, הצד השני רואה את הנתונים הפיננסיים המשותפים.
  • שותפים בעסק — שותף רשום רואה את מסך ההתחשבנות: הכנסות, הוצאות וחלוקת הרווח.

8. מדידה

האתר משתמש ב-Vercel Analytics לנתוני שימוש מצטברים (עמודים נצפים, ביצועים). הוא אינו אוסף את תוכן הנתונים הפיננסיים שלך.

אין באפליקציה כלי ניטור שגיאות או אנליטיקה נוספים.

9. שמירה ומחיקה

הנתונים נשמרים כל עוד הם במכשיר שלך. מחיקת נתוני הדפדפן מוחקת אותם — הם אינם מוחזקים אצלנו.

הגיבוי המוצפן בענן ניתן למחיקה לבקשתך, ואנו נמחק אותו. פנה ל-support@aglamaz.com.

מסמכים שנשמרו ב-Google Drive שלך נשארים בבעלותך וניתנים למחיקה ישירות מ-Drive.

מחיקה היא מחיקה. רשומה שמחקת אינה חוזרת בסנכרון הבא.

10. אבטחה

הנתונים נשמרים במכשיר שלך ומוגנים באמצעי האבטחה של הדפדפן ומערכת ההפעלה. גיבוי בענן מוגן על ידי חשבון Google שלך. שיתוף משק בית מוגן בסיסמה משותפת.

אחריותך: מי שיש לו גישה למכשיר או לחשבון Google שלך יכול להגיע לנתונים.

11. זכויותיך

מכיוון שהנתונים אצלך, הגישה והתיקון הם ישירים — דרך האפליקציה. לכל שאלה, בקשת מחיקה או תלונה: support@aglamaz.com.

12. שינויים

נעדכן עמוד זה עם כל שינוי מהותי, ונציין את תאריך העדכון האחרון.

עדכון אחרון: 09/09/2026


Privacy Policy — Aglamazo (English)

1. Who we are

Aglamazo is a personal-finance and small-business bookkeeping application at aglamazo.com, operated by Yaakov Aglamaz (Israeli business ID 012680286). Privacy contact: support@aglamaz.com

2. The principle: your data stays with you

Aglamazo is local-first. Your financial data is stored in your own browser (IndexedDB), not on our servers. We operate no central database of your books. Data leaves your device only in the cases described below.

3. What data the app handles

Bank and credit-card transactions; financial documents (invoices and receipts, including supplier name, document number, amounts, VAT and business IDs); business details including partners and their profit-share percentages; Ypay payment-processor credentials (client id and secret, with separate sandbox and production pairs), stored locally only, on the business record on your device; and settings including API keys and categories.

4. Google permissions

ScopeGrantsWhy
drive.fileAccess only to files this app created or you opened with itStoring your uploaded invoices and receipts
gmail.modifyRead, organize, delete and send mailFinding receipts in your mail, labelling them as handled, sending documents at your instruction
calendar.readonlyRead-only calendar eventsAttributing working time to projects

drive.file is not access to your Drive: the app cannot see, read or delete files it did not create.

gmail.modify rather than read-only because the app marks receipts as handled, organizes them into labels, and sends documents at your request — all of which require write access. It does not read mail unrelated to receipts, and sends nothing without your action.

Limited Use disclosure

Aglamazo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail or Drive data for advertising, do not sell it, and do not transfer it to third parties except as required to provide the service, as described in section 5.

5. AI document processing — the most important section

When you upload an invoice or receipt, the document is sent to a third-party AI provider to extract its details.

  • Google Gemini (gemini-2.5-flash) — primary.
  • Anthropic Claude (claude-sonnet-5) — fallback, used only when the first extraction fails.

What is sent: the document itself — a PDF or image containing supplier name, your name or business name, business ID, amounts, VAT and a description of what was purchased. What returns are the extracted fields, stored on your device.

This is the only processing in which your financial content reaches a third party other than you, and it happens only when you upload a document or request extraction from mail.

What the providers do with the document — verified 2026-09-09

  • Google Gemini — Aglamazo's key sits in a project with billing enabled (paid tier). Under Google's paid-service terms, prompts and files sent to the API are not used to improve their products; they are retained for a limited period solely to detect Prohibited Use Policy violations.
  • Anthropic Claude — inputs and outputs are deleted within 30 days, and are never used for model training without express permission.

Sources: Gemini API billing and tiers · Anthropic API and data retention

6. Cloud backup

If you enable cloud backup, data syncs to Firebase Firestore under your own Google account. Google OAuth tokens are excluded from backups — held device-locally and stripped from every backup write, so one device cannot overwrite another's access.

7. Deliberate sharing

  • Shared household — the backup is shared with a spouse via a per-business shared password; once enabled, they see the shared financial data.
  • Business partners — a registered partner sees the settlement screen: income, expenses and profit split.

8. Analytics

The site uses Vercel Analytics for aggregate usage data (page views, performance). It does not collect the content of your financial data. No other analytics or error-reporting tools are integrated.

9. Retention and deletion

Data persists while it is on your device; clearing browser data deletes it. If cloud backup is enabled you must also delete the backup, and you may contact us to request deletion. Documents stored in your Google Drive remain yours and can be deleted directly from Drive.

A deletion is a deletion. A record you delete does not come back on the next sync.

10. Security

Data is held on your device under your browser's and operating system's protections; cloud backup is protected by your Google account; household sharing by a shared password. Anyone with access to your device or Google account can reach the data.

11. Your rights

Because the data is yours and held by you, access and correction are direct, through the app. For any question, deletion request or complaint: support@aglamaz.com.

12. Changes

We will update this page on any material change and note the date of the last update.

Last updated: 09/09/2026