מדיניות פרטיות
1. פרטי בעל השירות
שם השירות: Mime. אתר: mime.co.il. בעלים: עומר לוי, חולון, ישראל.
איש קשר להגנת פרטיות: support@mime.co.il.
2. סוגי המידע הנשמר
Mime שומרת אך ורק מידע ששלחת אליה במפורש דרך WhatsApp:
- הודעות טקסט שכתבת.
- הקלטות קוליות. אלו מומרות לטקסט באופן אוטומטי, וקובץ ההקלטה המקורי נשמר מוצפן בחשבונך לצד התמליל, כדי שתוכל לבקש אותו בחזרה.
- תמונות שצירפת. נשמרים הקובץ המקורי, הכיתוב שכתבת, והטקסט שנקרא מתוך התמונה (OCR) כשהדבר אפשרי. השירות אינו מנתח או מתאר את הנראה בתמונה מעבר לקריאת הטקסט.
- מסמכים שצירפת (PDF, Word, Excel). נשמרים הקובץ המקורי והטקסט שחולץ מהם.
- אנשי קשר ומיקומים ש-WhatsApp העבירה דרך פונקציית השיתוף הילידית.
- מספר ה-WhatsApp שלך, הנשמר באופן מאובטח לצורך ניתוב ההודעות אליך; לזיהוי פנימי משמש בנוסף גיבוב קריפטוגרפי חד-כיווני (HMAC) של המספר.
- העדפות לשוניות ודקדוקיות שהגדרת או שזוהו אוטומטית.
- אם בחרת לחבר יומן (Google Calendar): אסימוני הגישה (OAuth tokens) של החיבור וכתובת המייל של חשבון היומן, מוצפנים תחת מפתח ההצפנה האישי שלך. ראו סעיף 7.
- אם הפעלת את "המעגל" (שיתוף מורשה): רשימת האנשים שהרשית לשלוח לזיכרון שלך, וסטטוס ההסכמה שלהם.
מידע שאינו נאסף: רשימת אנשי הקשר במכשירך, היסטוריית גלישה, מיקום פיזי בזמן אמת, מידע ביומטרי, נתונים פיננסיים, או כל מידע שלא העברת באופן יזום דרך הודעת WhatsApp.
3. מטרות העיבוד והעילות החוקיות
עיבוד המידע נשען על העילות הבאות לפי GDPR סעיף 6 ולפי חוק הגנת הפרטיות:
- קיום חוזה (Art. 6(1)(b) GDPR): שמירה ואחזור של המידע ששמרת.
- אינטרס לגיטימי (Art. 6(1)(f) GDPR): אבטחת השירות, מניעת ניצול לרעה, איכות תפעולית.
- חובה חוקית (Art. 6(1)(c) GDPR): שמירת רשומות חיוב לתקופות הקבועות בחוק.
- הסכמה (Art. 6(1)(a) GDPR): תזכורות, סקירה יומית, ופניות שיווקיות. ניתן לחזור בך מההסכמה בכל עת.
המידע אינו מעובד לצורכי פרסום ממוקד, אינו מועבר למטרות מסחריות לצדדים שלישיים, ואינו משמש לאימון מערכות חיצוניות.
4. אמצעי אבטחה
- הצפנה במנוחה. כל פריט תוכן מוצפן עם מפתח ייחודי למשתמש, באלגוריתם תעשייתי מקובל (AES-256-GCM).
- הצפנה בתעבורה. כל התקשורת מצופנת ב-TLS 1.3.
- בידוד משתמשים. אין למשתמש אחד אפשרות לראות תוכן של משתמש אחר. הבידוד נאכף הן ברמת מסד הנתונים והן ברמת ה-API.
- מיקום שרתים. מסד הנתונים מתארח באיחוד האירופי.
- בקרת גישה. גישה למידע מוצפן מתועדת ברישום שאינו ניתן לשינוי.
- הצעדים תואמים את תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017, ואת Art. 32 GDPR.
5. גישה למידע
רק את/ה. אף נציג של השירות אינו קורא את התוכן המוצפן שלך באופן שגרתי. גישה מנהלית לתוכן דורשת תסריט חירום (חקירת אבטחה, צו שיפוטי) ומתועדת. אין שיתוף של תוכן עם:
- מפרסמים. אין מודל פרסומי בשירות.
- צדדים שלישיים מסחריים. אין מכירת מידע.
- חברות הקשורות לספקי השירות הטכניים, מעבר למינימום הטכני הנדרש (ראו סעיף 6).
"המעגל" (שיתוף מורשה ביוזמתך): ניתן להרשות לאנשים ספציפיים לשלוח תוכן לזיכרון שלך, בכפיפות להסכמתם המפורשת. חבר מעגל יכול אך ורק לשלוח תוכן אליך — הוא לעולם אינו רואה, מחפש או מקבל את הזיכרון שלך. ניתן להסיר הרשאה בכל עת.
6. ספקי שירות טכניים
השירות מסתייע בכמה ספקים טכניים, כל אחד לפונקציה ספציפית, תחת הסכם עיבוד נתונים (DPA) לפי Art. 28 GDPR ותחת Standard Contractual Clauses ככל שרלוונטי:
- Meta Platforms (WhatsApp Business Cloud API). ניתוב הודעות בין מכשירך לבין שרתי השירות.
- Supabase. אחסון מסד הנתונים והפעלת קוד צד-שרת, באיחוד האירופי (פרנקפורט, גרמניה).
- Anthropic. מודל שפה המטפל בהבנת הבקשות שלך, תחת תנאי Zero Data Retention (הספק התחייב חוזית לא לשמור את הקלט לאחר העיבוד ולא לעשות בו שימוש לכל מטרה אחרת).
- Groq. המרת הקלטות קוליות לטקסט. ההקלטה נשלחת להמרה והספק אינו שומר אותה לאחר החזרת התמליל.
- Mistral AI. קריאת טקסט (OCR) מתמונות וממסמכים, באיחוד האירופי.
- Voyage AI. יצירת ייצוגים מתמטיים (embeddings) המאפשרים חיפוש בזיכרון שלך. מעובד בארה"ב תחת DPA ו-Standard Contractual Clauses (ראו סעיף 8).
- Amazon Web Services (AWS KMS). ניהול מפתחות ההצפנה האישיים, באיחוד האירופי.
- Hetzner. אירוח אתר התדמית הסטטי mime.co.il. האתר אינו מכיל את תוכן הזיכרון שלך.
- ImprovMX. ניתוב מייל לכתובת התמיכה. רק מיילים ששלחת לכתובת התמיכה נחשפים בפניו.
- Google LLC. אך ורק עבור משתמשים שבחרו ביוזמתם לחבר את היומן שלהם (ראו סעיף 7). ללא חיבור יזום — אין כל העברת מידע אליה.
הוספה או החלפה של ספק שירות מהותי תפורסם בעמוד זה לפחות 14 יום לפני כניסתה לתוקף.
7. חיבור יומן (Google Calendar)
ניתן, ביוזמתך בלבד, לחבר לשירות את היומן האישי שלך — Google Calendar. ללא חיבור יזום שלך, השירות אינו ניגש לשום מידע אצל Google.
- למה יש גישה. לאירועי היומן שלך בלבד: קריאה חופשית, ויצירה, עדכון או מחיקה של אירוע — אך ורק לאחר אישור מפורש שלך לכל פעולה בנפרד.
- למה אין גישה. לא ל-Gmail, לא לקבצים (Drive), ולא לאנשי הקשר של Google. הרשאות אלו אינן מתבקשות כלל.
- מה נשמר. אסימוני הגישה של החיבור (OAuth refresh/access tokens) וכתובת המייל של חשבון היומן — מוצפנים תחת מפתח ההצפנה האישי שלך, באותו מנגנון המגן על שאר הזיכרון שלך.
- זימון משתתפים. אם ביקשת במפורש להזמין משתתף לאירוע, ההזמנה הרשמית נשלחת על-ידי ספק היומן (Google) לכתובת המייל שמסרת. כתובת מייל של איש קשר נשמרת אצלך רק אם ביקשת לשמור אותה, באנשי הקשר שלך בשירות.
- ניתוק. הפקודה /calendar disconnect מוחקת את האסימונים השמורים ומבטלת את ההרשאה גם אצל הספק עצמו.
השימוש במידע המתקבל מ-Google API כפוף למדיניות Google API Services User Data Policy, לרבות דרישות ה-Limited Use: המידע משמש אך ורק למתן הפיצ'ר שביקשת, אינו מועבר לאף גורם אחר, אינו משמש לפרסום, ואף אדם אינו קורא אותו אלא בהסכמתך או כנדרש בחוק. ההצהרה המחייבת בנוסחה המקורי:
MIME's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. העברות בינלאומיות
מסד הנתונים הראשי מתארח באיחוד האירופי. העברות מחוץ ל-EEA מתבצעות אך ורק עם ספקי השירות המפורטים בסעיף 6 ולפי מנגנון העברה תקין לפי Art. 44-49 GDPR (Standard Contractual Clauses + Transfer Impact Assessment). ישראל מוכרת על-ידי נציבות האיחוד האירופי כמדינה בעלת רמת הגנה מספקת (החלטת התאמה, 2011).
9. תקופות שמירה
- חשבון פעיל. המידע נשמר כל עוד החשבון פעיל ולמשך 30 יום נוספים מסיומו.
- חשבון לא פעיל. אם החשבון לא נעשה בו שימוש במשך 6 חודשים, נשלחת התראה. ללא תגובה תוך 30 יום, החשבון נמחק לצמיתות.
- מחיקה לבקשת המשתמש. תוך 30 יום מקבלת הבקשה והשלמת אימות הזהות. ראו עמוד מחיקת נתונים.
- רשומות חיוב. 7 שנים, לפי חובת השמירה לפי תקנות מס הכנסה.
10. זכויות המשתמש
לפי סעיפים 13 ו-14 לחוק הגנת הפרטיות ו-Art. 12-22 GDPR, ניתן בכל עת:
- זכות עיון. לקבל העתק של כל המידע שלך תוך 30 יום מאימות הזהות.
- זכות תיקון. לעדכן מידע שגוי.
- זכות מחיקה (Right to be forgotten). ראו עמוד מחיקת נתונים.
- זכות לניידות מידע. קבלת המידע בפורמט קריא במכונה.
- זכות התנגדות. לבקש להפסיק עיבוד מסוים בלי לבטל את החשבון.
- זכות תלונה. לרשות להגנת הפרטיות במשרד המשפטים, ישראל, או לרשות הגנת הנתונים במדינת מגוריך באיחוד האירופי.
11. בקשת מחיקה
הזכות למחיקה מוגנת בחוק. את ההוראות המלאות לבקשת מחיקה תמצא בעמוד מחיקת נתונים.
12. הודעה על אירוע אבטחה
במקרה של דליפת מידע משמעותית נודיע ל:
- הרשות להגנת הפרטיות (PPA) בישראל, תוך 24 שעות מרגע גילוי האירוע, לפי תיקון 13 לחוק.
- הרשות המפקחת באיחוד האירופי תוך 72 שעות (Art. 33 GDPR).
- נושאי המידע הנפגעים, ללא דיחוי, אם האירוע גבוה-סיכון.
13. קטינים
השירות אינו מיועד למשתמשים מתחת לגיל 16. הורה או אפוטרופוס שנודע לו ששירותו של קטין נצרך, מוזמן לפנות ל-support@mime.co.il והחשבון יימחק ללא דיחוי.
14. שינויים במדיניות
שינויים מהותיים יודעו לפחות 14 יום מראש דרך הודעת WhatsApp ובדף זה.
15. דין שיפוט וקשר
הדין החל הוא הדין הישראלי. סמכות השיפוט הבלעדית נתונה לבתי המשפט המוסמכים בתל אביב-יפו, מבלי לגרוע מזכויות של תושבי האיחוד האירופי לפנות לבית משפט במדינתם.
שאלות, בקשות זכויות, או תלונות. support@mime.co.il.
Privacy Policy
1. Service operator
Service: Mime. Site: mime.co.il. Owner: Omer Levi, Holon, Israel.
Privacy contact: support@mime.co.il.
2. Categories of data collected
Mime stores only data you explicitly send via WhatsApp:
- Text messages you wrote.
- Voice notes. Converted to text automatically, with the original audio file kept encrypted in your account alongside the transcript, so you can ask for it back.
- Photos you attached. The original file, your caption, and the text read from the image (OCR) where possible are stored. The service does not analyze or describe the visual content beyond reading text.
- Documents (PDF, Word, Excel). The original file and the extracted text are stored.
- Contacts and locations passed via WhatsApp's native sharing.
- Your WhatsApp number, stored securely to route messages to you; a one-way cryptographic hash (HMAC) of the number is additionally used for internal identification.
- Language and grammatical-gender preferences you set or that were detected automatically.
- If you chose to connect a calendar (Google Calendar): the connection’s OAuth tokens and the calendar account’s email address, encrypted under your personal encryption key. See section 7.
- If you enabled the Circle (authorized sharing): the list of people you authorized to send into your memory, and their consent status.
Not collected: your device contact list, browsing history, real-time physical location, biometric data, financial data, or anything not actively passed through WhatsApp.
3. Processing purposes and legal bases
Processing relies on the following bases under Art. 6 GDPR and the Israeli Privacy Protection Law:
- Performance of a contract (Art. 6(1)(b) GDPR): storing and retrieving content you saved.
- Legitimate interest (Art. 6(1)(f) GDPR): service security, abuse prevention, operational quality.
- Legal obligation (Art. 6(1)(c) GDPR): billing records retention.
- Consent (Art. 6(1)(a) GDPR): reminders, daily review, marketing communications. Withdrawable at any time.
Data is not used for targeted advertising, commercial third-party transfers, or training of external systems.
4. Security measures
- Encryption at rest. Each content item is encrypted with a user-unique key using industry-standard algorithms (AES-256-GCM).
- Encryption in transit. All communication uses TLS 1.3.
- Tenant isolation. One user cannot access another user's content. Isolation is enforced at both database and API layers.
- Server location. Primary database hosted in the European Union.
- Access control. Administrative access to encrypted content is recorded in an immutable audit log.
- Measures align with the Israeli Privacy Protection (Information Security) Regulations, 5777-2017, and Art. 32 GDPR.
5. Access
Only you. No service representative routinely reads your encrypted content. Administrative access requires an emergency context (security investigation, judicial order) and is logged. No sharing of content with:
- Advertisers. There is no ad model.
- Commercial third parties. No data sales.
- Affiliates of technical providers beyond the minimum required to operate the service (see section 6).
The Circle (authorized sharing you initiate): you may authorize specific people to send content into your memory, subject to their explicit consent. A Circle member can only send content to you — they never see, search, or receive your memory. Authorization can be removed at any time.
6. Technical service providers
The service relies on a small number of technical providers, each performing a specific function, under a Data Processing Agreement consistent with Art. 28 GDPR and Standard Contractual Clauses where applicable:
- Meta Platforms (WhatsApp Business Cloud API). Message routing between your device and our servers.
- Supabase. Database hosting and server-side code execution, in the European Union (Frankfurt, Germany).
- Anthropic. Language model handling your requests under Zero Data Retention terms (the provider is contractually committed not to retain your input after processing and not to use it for any other purpose).
- Groq. Voice-to-text transcription. Audio is sent for transcription and is not retained by the provider after the transcript is returned.
- Mistral AI. Text reading (OCR) from images and documents, in the European Union.
- Voyage AI. Generation of mathematical representations (embeddings) that enable search within your memory. Processed in the United States under a DPA and Standard Contractual Clauses (see section 8).
- Amazon Web Services (AWS KMS). Management of the personal encryption keys, in the European Union.
- Hetzner. Hosting of the static website mime.co.il. The website holds none of your memory content.
- ImprovMX. Email routing for the support address. Sees only emails you send to the support address.
- Google LLC. Only for users who actively chose to connect their calendar (see section 7). Without an initiated connection — no data is transferred to it.
Any material addition or replacement of a provider will be posted here at least 14 days before taking effect.
7. Calendar connection (Google Calendar)
You may, at your own initiative only, connect your personal calendar to the service — Google Calendar. Without a connection you initiate, the service accesses no data at Google.
- What is accessed. Your calendar events only: free reading, and creating, updating, or deleting an event — solely after your explicit confirmation of each individual action.
- What is not accessed. Not Gmail, not files (Drive), and not Google contacts. These permissions are never requested.
- What is stored. The connection's OAuth refresh/access tokens and the calendar account's email address — encrypted under your personal encryption key, using the same mechanism that protects the rest of your memory.
- Inviting attendees. If you explicitly asked to invite an attendee to an event, the official invitation is sent by the calendar provider (Google) to the email address you supplied. A contact's email address is stored only if you asked to save it, in your own contacts within the service.
- Disconnection. The /calendar disconnect command deletes the stored tokens and revokes the authorization at the provider as well.
Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: the data is used only to provide the feature you requested, is never transferred to any other party, is never used for advertising, and is never read by a human except with your consent or as required by law. The binding English-language disclosure appears in the Hebrew version of this page.
8. International transfers
The primary database is hosted in the European Union. Transfers outside the EEA occur only with the providers listed in section 6 and only under a valid transfer mechanism per Art. 44-49 GDPR (Standard Contractual Clauses plus Transfer Impact Assessment). Israel is recognized by the European Commission as providing an adequate level of protection (adequacy decision, 2011).
9. Retention
- Active account. Data retained while the account is active and 30 days after termination.
- Inactive account. After 6 consecutive months of inactivity, a notice is sent. Without response within 30 days, the account is permanently deleted.
- Deletion on user request. Within 30 days of identity verification. See the data deletion page.
- Billing records. 7 years, per Israeli tax retention law.
10. Your rights
Under sections 13 and 14 of the Privacy Protection Law and Art. 12-22 GDPR:
- Right of access. Receive a copy of all your data within 30 days of identity verification.
- Right of rectification. Update inaccurate data.
- Right to erasure (Right to be forgotten). See the data deletion page.
- Right to data portability. Receive your data in a machine-readable format.
- Right to object. Stop specific processing without closing the account.
- Right to complain. To the Israeli Privacy Protection Authority, or to your local EU Data Protection Authority.
11. Requesting deletion
The right to erasure is protected by law. Full instructions for requesting deletion are on the data deletion page.
12. Security incident notification
In case of a material data breach we will notify:
- The Israeli Privacy Protection Authority (PPA), within 24 hours of discovery, per Amendment 13 to the Law.
- The relevant EU supervisory authority within 72 hours (Art. 33 GDPR).
- Affected data subjects, without undue delay, if the incident is high-risk.
13. Minors
The service is not intended for users under 16. A parent or guardian who learns a minor uses the service is invited to contact support@mime.co.il for prompt account deletion.
14. Changes to this policy
Material changes are notified at least 14 days in advance via WhatsApp and on this page.
15. Governing law and contact
This document is governed by Israeli law. Exclusive jurisdiction lies with the competent courts of Tel Aviv-Yafo, without prejudice to GDPR rights of EU residents to file suit in their country of residence.
Questions, rights requests, or complaints. support@mime.co.il.
