מדיניות פרטיות
גרסה 1.1 · עודכן לאחרונה: 29 בספטמבר 2026
מי אנחנו
Ricibo ("האפליקציה", "השירות", "אנחנו") היא אפליקציה עצמאית לניהול קבלות. אנחנו בעלי מאגר המידע ומנהליו לצורך חוק הגנת הפרטיות, התשמ"א-1981, ואפשר להשיג אותנו בכתובת שלמטה בכל עניין שקשור למידע שלך.
לכל שאלה, בקשה או תלונה בנושא פרטיות: support@ricibo.com. אפשר גם דרך טופס "עזרה ותמיכה" באפליקציה.
מה המסמך הזה אומר בקצרה
אנחנו שומרים את הקבלות שלך כדי שתוכל למצוא אותן, לדעת מתי אחריות או חלון החזרה נגמרים, ולעקוב אחרי הוצאות. כדי לקרוא צילום של קבלה אנחנו שולחים אותו לשירות בינה מלאכותית של Google. אנחנו לא מוכרים את המידע שלך ולא מעבירים אותו למפרסמים. בתוכנית החינמית מוצגות מודעות. אפשר לייצא את כל המידע שלך או למחוק אותו לגמרי מתוך ההגדרות.
איזה מידע אנחנו אוספים
מידע שאתה מוסר לנו
- תוכן הקבלות שלך — הצילומים, קובצי ה-PDF וחשבוניות המס שאתה מעלה, והנתונים שחולצו מהם: שם העסק, תאריך, סכום, פריטים, אמצעי תשלום, מספר סידורי, תנאי אחריות והחזרה.
- מה שאתה כותב בעצמך — הערות, תיוגים, רשימות קניות, שמות של פריטים ותיקונים ידניים לנתונים שחולצו.
- פרטי חשבון — כתובת אימייל, וכשאתה נרשם דרך Google או Apple גם השם ותמונת הפרופיל שהספק מוסר לנו. סיסמה, אם בחרת להירשם עם אימייל, נשמרת אצל ספק האימות שלנו בצורה מוצפנת חד-כיוונית ואנחנו לא רואים אותה.
- פניות תמיכה — הנושא, תוכן ההודעה וההתכתבות שנוצרת בעקבותיה.
- העדפות — שפה, מטבע, ערכת נושא, הגדרות תזכורות ואבטחה.
מידע שנוצר מעצם השימוש
- מזהה חשבון פנימי, מועדי יצירה ועדכון של כל רשומה.
- מוני מכסה (כמה סריקות ניצלת החודש, כמה אחסון תפוס) ומוני הגבלת קצב, שנועדו למנוע שימוש לרעה.
- רשומות תפעוליות על כל ריצת חילוץ: מתי רצה, כמה זמן לקחה, כמה עלתה ואם נכשלה. הקובץ עצמו לא נשמר ברשומה הזו.
- רשומות על מנוי ותשלומים שהתקבלו מספק התשלומים.
מידע מהמכשיר
- טוקן התראות — רק אם הפעלת תזכורות. משמש כדי לשלוח את ההתראה למכשיר שלך.
- מזהה פרסום — רק בתוכנית החינמית, ורק אם אישרת את בקשת המעקב של iOS (App Tracking Transparency). אם סירבת, המודעות ממשיכות להופיע אבל בלי התאמה אישית בין אפליקציות.
- דיווחי תקלות — כשהאפליקציה קורסת נשלח דיווח טכני (סוג המכשיר, גרסת מערכת ההפעלה, מסלול השגיאה). הדיווחים מוגדרים אצלנו כך שלא ייאסף מידע אישי מזהה יחד איתם.
- מזהים לצורך מניעת ניצול לרעה — כתובת ה-IP, מזהה המכשיר ומחרוזת הלקוח נשמרים אך ורק כגיבוב חד-כיווני מלוח (salted hash). לא ניתן לשחזר מהם את הערך המקורי, ואנחנו לא שומרים את הערך המקורי בשום שלב. הם משמשים להגבלת קצב ולזיהוי ניצול לרעה של תוכנית ההפניות, ולשום דבר אחר.
אנחנו לא אוספים מיקום, אנשי קשר, יומן, מיקרופון, או פרטי כרטיס אשראי.
למה אנחנו משתמשים במידע, ועל סמך מה
- לספק את השירות — לשמור, לחפש ולהציג את הקבלות שלך. המידע: תוכן הקבלות והחשבון. הבסיס: ביצוע החוזה איתך.
- לקרוא קבלה מצילום ולחלץ ממנה נתונים. המידע: הצילום או הקובץ. הבסיס: ביצוע החוזה איתך.
- לשלוח תזכורות על אחריות וחלון החזרה. המידע: תאריכים מהקבלה, טוקן ההתראות. הבסיס: הסכמתך, שניתנת להסרה בהגדרות.
- לאכוף מכסות ולמנוע שימוש לרעה. המידע: מונים ורשומות תפעוליות. הבסיס: אינטרס לגיטימי בהגנה על השירות.
- לחייב ולנהל מנוי. המידע: רשומות מנוי. הבסיס: ביצוע החוזה איתך.
- להציג מודעות בתוכנית החינמית. המידע: מזהה פרסום, אם אישרת. הבסיס: הסכמתך.
- לשפר את המוצר ולאתר תקלות. המידע: נתוני שימוש מצרפיים ודיווחי קריסה. הבסיס: אינטרס לגיטימי.
- לענות לפניות תמיכה. המידע: תוכן הפנייה. הבסיס: ביצוע החוזה איתך.
חילוץ נתונים בעזרת בינה מלאכותית
כדי לקרוא קבלה, הצילום או הקובץ נשלחים לשירות Google Gemini לצורך עיבוד. אותו שירות מפעיל גם את "שיחה עם הקבלות", ובמקרה הזה נשלחים גם פרטי הקבלות הרלוונטיות לשאלה ששאלת.
מה שחשוב לדעת:
- הקבלה נשלחת לעיבוד ומוחזרת כנתונים. לפי תנאי ה-API העסקי של Google, התוכן לא נשמר אצלם מעבר לזמן העיבוד ואינו משמש לאימון מודלים.
- החילוץ אינו מדויק ב-100%. ייתכנו טעויות בסכומים, בתאריכים ובתנאי אחריות. אתה יכול לתקן כל שדה ידנית, וכדאי לבדוק כל נתון שמשמש אותך לצורך אמיתי.
- אם אינך רוצה שקבלה מסוימת תעבור עיבוד כזה — פשוט אל תעלה אותה.
מודעות
מודעות מוצגות רק בתוכנית החינמית. מי שמנוי בתשלום, או שחשבונו סומן כפטור, לא רואה מודעות כלל. המודעות מסופקות על ידי Google AdMob: באנר בתחתית המסך ומודעת ביניים אחרי כל סריקה שלישית בערך.
ב-iOS נשאלת בפעם הראשונה אם אתה מאשר מעקב בין אפליקציות. סירוב הוא תשובה תקפה לחלוטין — המודעות ימשיכו להופיע, פחות מותאמות אישית, וכל שאר האפליקציה מתנהגת בדיוק אותו דבר.
אנליטיקה ודיווח תקלות
- PostHog — נתוני שימוש מוצריים (אילו מסכים נפתחים, אילו פעולות מבוצעות), מקושרים למזהה החשבון הפנימי שלך ולא לשמך או לאימייל.
- Sentry — דיווחי קריסה ושגיאה, מוגדר שלא לצרף מידע אישי מזהה.
שני השירותים האלה פעילים רק כשהוגדר עבורם מפתח; בבנייה שאין בה מפתח, שום דבר לא נשלח.
מידע שאתה משתף עם אחרים
רשימת קניות אפשר לשתף עם משתמשים אחרים. מרגע ששיתפת, מי שהוזמן רואה את תוכן הרשימה ואת השינויים שלך בה. הקבלות שלך עצמן אינן משותפות בשום שלב — רק הרשימה.
בתוכנית ההפניות, מי שהזמנת רואה שהגעת דרכו רק במידה שהמערכת מציגה זאת; אנחנו לא חושפים לו את פרטיך.
תשלומים
מנויים נרכשים דרך App Store או Google Play ומנוהלים דרך RevenueCat. אנחנו לא רואים ולא שומרים פרטי כרטיס אשראי — החנות מטפלת בתשלום ומדווחת לנו רק על מצב המנוי (איזו תוכנית, ממתי, האם פעילה).
למי המידע נמסר
אנחנו לא מוכרים מידע ולא מעבירים אותו לצד שלישי למטרות שיווק. אנחנו כן נעזרים בספקים הבאים, כל אחד למטרה מוגדרת:
- Supabase — אירוח בסיס הנתונים, הקבצים והאימות. באיחוד האירופי (eu-central-1).
- Google Gemini — חילוץ נתונים מקבלות ושיחה עם הקבלות. על תשתית Google.
- Google AdMob — הצגת מודעות בתוכנית החינמית. על תשתית Google.
- RevenueCat, Apple ו-Google — עיבוד וניהול מנויים. ארה"ב, או לפי החנות שבה רכשת.
- Expo — משלוח התראות למכשיר. ארה"ב.
- PostHog — אנליטיקה מוצרית.
- Sentry — דיווחי קריסה.
בנוסף נמסור מידע אם נידרש לכך בצו שיפוטי או לפי דין, או כדי להגן על זכויותינו או על בטיחות משתמשים.
העברת מידע אל מחוץ לישראל
המידע שלך מאוחסן באיחוד האירופי, וחלק מהספקים שלמעלה פועלים בארצות הברית. ההעברה נעשית בהתאם לתקנות הגנת הפרטיות (העברת מידע למאגרים שמחוץ לגבולות המדינה), התשס"א-2001, ובהסתמך על התחייבויות חוזיות של הספקים לרמת הגנה הולמת.
כמה זמן אנחנו שומרים את המידע
- קבלות, פריטים, אחריות ומנויים — כל עוד החשבון פעיל. אנחנו לא מוחקים קבלות בגלל גילן: אחריות והחזרות נמשכות שנים, וזו בדיוק מטרת השירות. אתה יכול למחוק כל קבלה בכל רגע, והמחיקה סופית.
- קבצים (צילומים, PDF, חשבוניות מס) — נשמרים יחד עם הקבלה ונמחקים איתה. לכל תוכנית מכסת אחסון; כשהיא מלאה תתבקש למחוק קבלות או לשדרג.
- קובצי PDF שהאפליקציה מייצרת — נמחקים אוטומטית אחרי 3 ימים. אפשר לייצר אותם מחדש בכל עת.
- חשבון אורח — מידע של אורח שלא נרשם נמחק אוטומטית 24 שעות אחרי היצירה, כולל הקבצים.
- מחיקת חשבון — יש חלון חרטה של 10 ימים שבו אפשר לבטל. בסיומו כל המידע והקבצים נמחקים לצמיתות בתהליך אוטומטי שרץ מדי לילה.
- חשבונות לא פעילים — לא נמחקים בגלל חוסר פעילות. אם תחזור אחרי שנים, הקבלות שלך יחכו לך.
- מוני הגבלת קצב — נמחקים לאחר יממה.
- גיבויים — הספק מבצע גיבוי תקופתי של בסיס הנתונים ושומר אותו עד 7 ימים. מידע שנמחק עשוי להישאר בגיבוי עד לפרק הזמן הזה ואז נעלם גם משם.
הזכויות שלך
לפי חוק הגנת הפרטיות ותיקון 13 לו, ובאופן כללי:
- עיון — לראות איזה מידע מוחזק עליך. מההגדרות אפשר לייצא את כל המידע שלך בקובץ אחד, מיד ובלי לפנות אלינו.
- תיקון — לתקן מידע שגוי. כל שדה בקבלה ניתן לעריכה ידנית.
- מחיקה — למחוק קבלה בודדת, למחוק את כל התוכן שלך בפעולה אחת ("מחיקת נתונים") בלי לסגור את החשבון, או למחוק את החשבון כולו.
- חזרה מהסכמה — לכבות תזכורות, לשנות את הגדרות המעקב במערכת ההפעלה, או להפסיק להשתמש בשירות.
- התנגדות ותלונה — לפנות אלינו, ואם התשובה אינה מספקת, לרשות להגנת הפרטיות.
אם אתה נמצא באזור הכלכלי האירופי, עומדות לך בנוסף הזכויות לפי GDPR, לרבות הזכות לניידות ולהגבלת עיבוד. פנה אלינו ונטפל בבקשה.
איך מממשים: דרך ההגדרות באפליקציה, או במייל אל support@ricibo.com. נשיב תוך 30 יום.
אבטחת מידע
- כל גישה לנתונים עוברת בקרת הרשאות ברמת השורה בבסיס הנתונים (Row Level Security), כך שחשבון אחד אינו יכול לקרוא נתונים של חשבון אחר — גם לא בעקבות באג בצד הלקוח.
- התעבורה מוצפנת ב-TLS, והמידע מוצפן במנוחה אצל ספק האחסון.
- אפשר להפעיל נעילת אפליקציה בהגדרות, שדורשת Face ID / טביעת אצבע / קוד מכשיר לפני שהקבלות מוצגות. הבדיקה מתבצעת במכשיר בלבד ואנחנו לא מקבלים שום נתון ביומטרי.
- אפשר להגדיר שהתראות לא יציגו פרטים רגישים במסך הנעול.
שום מערכת אינה חסינה לחלוטין. אם תתרחש אצלנו אירוע אבטחה שעלול לפגוע בך, נודיע לך ולרשויות כנדרש בדין.
ילדים
השירות אינו מכוון לילדים ואיננו אוספים מידע על ילדים ביודעין. אם התברר לך שילד מסר לנו מידע, פנה אלינו ונמחק אותו.
שינויים במדיניות
נוסח המדיניות מנוהל בגרסאות. כשנפרסם גרסה חדשה עם שינוי מהותי, נבקש את הסכמתך מחדש באפליקציה. הגרסה שאישרת ומועד האישור נשמרים אצלנו.
יצירת קשר
Ricibo support@ricibo.com
Privacy Policy
Version 1.1 · Last updated: 29 September 2026
Who we are
Ricibo (the "app", the "service", "we", "us") is an independent receipt-keeping app. We are the owner and manager of the database for the purposes of the Israeli Protection of Privacy Law, 5741-1981, and you can reach us at the address below about anything to do with your data.
For any privacy question, request or complaint: support@ricibo.com. You can also use the "Help & support" form inside the app.
The short version
We store your receipts so you can find them, know when a warranty or return window runs out, and track what you spend. To read a photographed receipt we send it to a Google AI service for processing. We do not sell your data and we do not hand it to advertisers. The free tier shows ads. You can export everything you have, or delete all of it, from Settings.
What we collect
What you give us
- Your receipt content — the photos, PDFs and tax invoices you upload, and the data extracted from them: merchant, date, total, line items, payment method, serial numbers, warranty and return terms.
- What you write yourself — notes, tags, shopping lists, item names and any manual corrections to extracted data.
- Account details — your email address, and, if you sign in with Google or Apple, the name and profile picture that provider gives us. A password, if you signed up with email, is held by our authentication provider as a one-way hash; we never see it.
- Support requests — the subject, the message and the conversation that follows.
- Preferences — language, currency, theme, reminder and security settings.
What using the service generates
- An internal account identifier, and creation/update timestamps on each record.
- Quota counters (scans used this month, storage in use) and rate-limit counters, which exist to prevent abuse.
- Operational records of each extraction run: when it ran, how long it took, what it cost, whether it failed. The file itself is not kept in that record.
- Subscription and payment records received from our payment provider.
From your device
- A push token — only if you have turned reminders on. It is what lets a notification reach your device.
- An advertising identifier — free tier only, and on iOS only if you allowed tracking when asked (App Tracking Transparency). If you declined, ads still appear, just without cross-app personalisation.
- Crash reports — when the app crashes we receive a technical report (device model, OS version, the code path that failed). Our crash reporting is configured not to attach personally identifying information.
- Identifiers used to prevent abuse — your IP address, device identifier and client string are stored only as a salted one-way hash. The original value cannot be recovered from it, and we never store the original at any point. They are used for rate limiting and for detecting abuse of the referral programme, and for nothing else.
We do not collect location, contacts, calendar, microphone, or card details.
Why we use it, and on what basis
- Run the service — store, search and show your receipts. Data: receipt content and account. Basis: performance of our contract with you.
- Read a receipt from a photo and extract its data. Data: the photo or file. Basis: performance of our contract with you.
- Send reminders about warranties and return windows. Data: dates from the receipt, your push token. Basis: your consent, withdrawable in Settings.
- Enforce quotas and prevent abuse. Data: counters and operational records. Basis: our legitimate interest in protecting the service.
- Bill and manage a subscription. Data: subscription records. Basis: performance of our contract with you.
- Show ads on the free tier. Data: advertising identifier, if you allowed it. Basis: your consent.
- Improve the product and find faults. Data: aggregate usage data and crash reports. Basis: legitimate interest.
- Answer support requests. Data: the content of your request. Basis: performance of our contract with you.
AI-assisted extraction
To read a receipt, the photo or file is sent to Google Gemini for processing. The same service powers "chat with your receipts", where the details of the receipts relevant to your question are also sent.
What matters here:
- The receipt is sent for processing and comes back as data. Under Google's business API terms, that content is not retained beyond processing and is not used to train models.
- Extraction is not 100% accurate. Totals, dates and warranty terms can be read wrong. Every field is editable by hand, and anything you actually rely on is worth checking.
- If you would rather a particular receipt were not processed this way, simply do not upload it.
Ads
Ads appear on the free tier only. Paying subscribers, and accounts marked as comped, see none at all. Ads are served by Google AdMob: a banner at the bottom of the screen, and an interstitial after roughly every third scan.
On iOS you are asked once whether you allow cross-app tracking. Declining is a fully supported answer — ads keep appearing, less personalised, and everything else in the app behaves identically.
Analytics and crash reporting
- PostHog — product usage (which screens open, which actions run), tied to your internal account identifier rather than to your name or email.
- Sentry — crash and error reports, configured not to send personally identifying information.
Both only run when a key has been configured for them; in a build without one, nothing is sent.
Data you share with others
A shopping list can be shared with other users. Once you share it, the people you invited can see its contents and your changes to it. Your receipts themselves are never shared — only the list.
In the referral programme, the person who invited you learns only what the system displays about a referral; we do not disclose your details to them.
Payments
Subscriptions are bought through the App Store or Google Play and managed through RevenueCat. We never see or store card details — the store handles payment and reports only your subscription state to us (which plan, since when, whether it is active).
Who we share data with
We do not sell data and we do not pass it to third parties for marketing. We do rely on the following providers, each for a defined purpose:
- Supabase — database, file storage and authentication hosting. In the European Union (eu-central-1).
- Google Gemini — receipt extraction and receipt chat. On Google infrastructure.
- Google AdMob — serving ads on the free tier. On Google infrastructure.
- RevenueCat, Apple and Google — processing and managing subscriptions. US, or per the store you bought from.
- Expo — delivering push notifications. US.
- PostHog — product analytics.
- Sentry — crash reporting.
We will also disclose data where a court order or the law requires it, or to protect our rights or users' safety.
Transfers outside Israel
Your data is hosted in the European Union, and some of the providers above operate in the United States. Transfers are made in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Abroad), 5761-2001, relying on the providers' contractual commitments to an adequate level of protection.
How long we keep it
- Receipts, items, warranties and subscriptions — for as long as your account is active. We do not delete receipts because they are old: warranties and returns run for years, and keeping them is the point of the service. You can delete any receipt at any time, and that deletion is final.
- Files (photos, PDFs, tax invoices) — kept with the receipt they belong to and deleted with it. Every plan has a storage quota; when it is full you will be asked to delete receipts or upgrade.
- PDFs the app generates — deleted automatically after 3 days. You can regenerate them at any time.
- Guest accounts — the data of a guest who never registers is deleted automatically 24 hours after creation, files included.
- Account deletion — there is a 10-day grace window in which you can cancel. After it, all data and files are permanently deleted by an automated nightly process.
- Inactive accounts — are not deleted for inactivity. Come back after years and your receipts are still there.
- Rate-limit counters — deleted after a day.
- Backups — our provider takes periodic database backups and keeps them for up to 7 days. Deleted data may persist in a backup for that window and then disappears from there too.
Your rights
Under the Protection of Privacy Law (including Amendment 13), and generally:
- Access — to see what is held about you. Settings will export everything you have into a single file, immediately, without asking us.
- Correction — to fix data that is wrong. Every receipt field is editable by hand.
- Deletion — delete a single receipt, delete all of your content in one action ("clear data") without closing the account, or delete the account entirely.
- Withdraw consent — turn reminders off, change tracking permission in your OS settings, or stop using the service.
- Object and complain — write to us, and if our answer is unsatisfactory, to the Israeli Privacy Protection Authority.
If you are in the European Economic Area, you additionally have GDPR rights, including portability and restriction of processing. Write to us and we will handle the request.
How to exercise them: in the app's Settings, or by email to support@ricibo.com. We respond within 30 days.
Security
- Every read and write passes through row-level security in the database, so one account cannot read another's data — not even through a client-side bug.
- Traffic is encrypted with TLS, and data is encrypted at rest by our storage provider.
- You can turn on App Lock in Settings, which requires Face ID, a fingerprint or your device passcode before receipts are shown. That check happens entirely on your device; we receive no biometric data.
- You can set notifications not to reveal sensitive details on a locked screen.
No system is perfectly secure. If a security incident occurs that could affect you, we will notify you and the authorities as the law requires.
Children
The service is not directed at children, and we do not knowingly collect data about them. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
This policy is versioned. When we publish a new version with a material change, we will ask you to accept it again in the app. The version you accepted and when you accepted it are recorded.
Contact
Ricibo support@ricibo.com