מדיניות פרטיות
עודכן לאחרונה: 23 ביולי 2026
מדיניות זו מסבירה כיצד אפליקציית "אירועי מודיעין ליומן", המופעלת על ידי משה כהן - פשוטומציה ("האפליקציה"), אוספת ומשתמשת במידע. שאלות ניתן לשלוח ל־moshexx@gmail.com.
המידע שאנו אוספים
- מזהה חשבון Google וכתובת הדוא״ל שנמסרו בתהליך ההתחברות.
- אסימון רענון של Google, הנשמר בהצפנת AES-256-GCM ומאפשר סנכרון מתמשך.
- קטגוריות אירועים שנבחרו, העדפת סנכרון אוטומטי ומועד הסנכרון האחרון.
- מזהי האירועים הציבוריים ומזהי אירועי היומן שהאפליקציה יצרה, לצורך מניעת כפילויות, עדכון וביטול.
- קובצי cookie חיוניים בלבד לצורך אבטחת ההתחברות וה-session.
כיצד אנו משתמשים בנתוני Google
האפליקציה משתמשת בהרשאת calendar.events.owned רק כדי ליצור, לעדכן ולמחוק ביומן הראשי שבבעלות המשתמש אירועים שהאפליקציה עצמה מנהלת. האפליקציה אינה קוראת, מציגה, מנתחת או משתפת אירועים קיימים אחרים ביומן.
השימוש במידע המתקבל מ־Google APIs עומד במדיניות Google API Services User Data Policy, לרבות דרישות Limited Use.
שיתוף וספקי שירות
המידע האישי משמש להפעלת השירות בלבד ואינו נמכר. התשתית מופעלת באמצעות Google לצורך OAuth ו־Calendar, Vercel לצורך אחסון והרצת האפליקציה, ו־Supabase לצורך מסד הנתונים. ספקים אלה מעבדים מידע רק לצורך אספקת השירות.
סיווג האירועים נעשה על מידע ציבורי מאתר העירייה. נתוני חשבון Google, אסימונים ותוכן היומן אינם מועברים ל־Anthropic, למודל בינה מלאכותית או ל־Firecrawl.
הגשת אירועים על ידי עסקים ומארגנים
בטופס הגשת האירוע (/submit-event) נאספים פרטי הגוף המארגן ואיש הקשר - שם העסק, שם איש הקשר, טלפון ודוא״ל. פרטים אלה משמשים אך ורק לצורך בדיקת ההגשה ויצירת קשר בנוגע אליה, ואינם מתפרסמים באתר, אינם מוחזרים בממשקי ה-API הציבוריים ואינם מועברים לצד שלישי. פרטי האירוע עצמו - שם, תיאור, מועדים, מקום, מחיר ותמונה - מיועדים לפרסום לאחר אישור.
לצורך הגנה מפני שימוש לרעה נשמר גיבוב (hash) חד־כיווני של כתובת ה-IP בתוספת מלח סודי. כתובת ה-IP עצמה אינה נשמרת. מתמונה שמועלית מוסרים אוטומטית נתוני ה-EXIF, לרבות נתוני מיקום ומצלמה, לפני השמירה. אימות אנושי מתבצע באמצעות Cloudflare Turnstile.
שמירה, אבטחה ומחיקה
המידע נשמר כל עוד החשבון מחובר או כל עוד הוא נחוץ להפעלת השירות. אסימוני Google מוצפנים במנוחה, והגישה לנתונים מוגבלת לשרת האפליקציה. אין מערכת מאובטחת לחלוטין, אך אנו נוקטים אמצעים סבירים להגנת המידע.
ניתן להסיר את כל האירועים שהאפליקציה הוסיפה, או לבחור "נתק חשבון ומחק נתונים". פעולה זו מבטלת את אסימון Google ומוחקת את פרטי המשתמש, ההעדפות, היסטוריית הסנכרון והמיפוי לאירועי היומן. אם אין גישה לחשבון, ניתן לבקש מחיקה בדוא״ל.
שינויים במדיניות
מדיניות זו עשויה להתעדכן עם שינוי השירות או הדין. תאריך העדכון האחרון יוצג בראש העמוד. שינוי מהותי באופן השימוש בנתוני Google יפורסם לפני כניסתו לתוקף.
Privacy Policy
Last updated: July 23, 2026
This policy explains how “Modi'in Events to Calendar,” operated by Moshe Cohen - Pashutomatzia (the “App”), collects and uses information. Contact: moshexx@gmail.com.
Information we collect
- Your Google account identifier and email address.
- An AES-256-GCM encrypted Google refresh token for ongoing synchronization.
- Selected event categories, auto-sync preference, and last synchronization time.
- Public event IDs and IDs of calendar events created by the App, used for deduplication, updates, and removal.
- Essential cookies used only to secure OAuth and your signed-in session.
Use of Google user data
The App uses the calendar.events.owned permission solely to create, update, and delete App-managed events in the user's owned primary calendar. It does not read, display, analyze, or share unrelated existing calendar events.
Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Service providers and sharing
Personal information is used only to provide the service and is not sold. Google provides OAuth and Calendar services, Vercel hosts and runs the App, and Supabase provides the database. These providers process information only as needed to deliver their services.
Event classification uses public municipal information. Google account data, tokens, and calendar content are not sent to Anthropic, any AI model, or Firecrawl.
Event submissions by businesses and organizers
The event submission form (/submit-event) collects organizer and contact details: business name, contact name, phone, and email. These are used solely to review the submission and to make contact about it, and are never published on the site, never returned by any public API, and never shared with third parties. The event details themselves - title, description, dates, venue, price, and image - are intended for publication once approved.
To prevent abuse we store a one-way hash of the submitter's IP address combined with a secret salt; the address itself is never stored. EXIF metadata, including location and camera data, is stripped from uploaded images before storage. Human verification is performed with Cloudflare Turnstile.
Retention, security, and deletion
Information is kept while the account remains connected or as needed to operate the service. Google tokens are encrypted at rest and data access is restricted to the App server. No system is completely secure, but reasonable safeguards are used.
Users can remove all events added by the App or choose “Disconnect account and delete data.” This revokes the Google token and deletes the user profile, preferences, sync history, and calendar mappings. Deletion can also be requested by email if account access is unavailable.
Changes
This policy may be updated when the service or law changes. The date above will be revised, and material changes to Google user data practices will be disclosed before taking effect.