AfterUpAfterUp
  • פיצ'רים
  • תמיכה
  • הורדה

מדיניות פרטיות

גרסה 3.1 | תאריך תחילה: 2 בספטמבר 2026 | מחליפה את גרסה 3.0

המפעילה ובעלת השליטה במאגר המידע: מונולוקו בע"מ (Monoloco Ltd.), ח.פ. 516332269, מנחם מדמון 45, תל אביב-יפו 6767634, ישראל

פניות בענייני פרטיות: support@afterup.co.il

שפות: מסמך זה מתפרסם בעברית, באנגלית וברוסית. למשתמשים בישראל הנוסח העברי הוא המחייב. מחוץ לישראל הנוסח האנגלי גובר על כל תרגום אחר.

מסמכים קשורים: תנאי השימוש (https://afterup.io/terms), מחיקת חשבון (https://afterup.io/delete-account), תקני בטיחות ילדים (https://afterup.io/child-safety), הצהרת נגישות (https://afterup.io/accessibility).

0. בקצרה (תקציר לא מחייב) והודעה לפי סעיף 11 לחוק הגנת הפרטיות

0.1 בקצרה

  • AfterUp היא אפליקציה חברתית למבוגרים (18+) שבה יוצרים "תוכנית" (Plan), מתאימים בין משתתפים ומשוחחים בצ'אט. כדי שזה יעבוד אנחנו מעבדים פרטי חשבון, פרופיל, תמונות, העיר שלכם, תוכניות שיצרתם או הצטרפתם אליהן, והודעות.
  • מיקום: כשהרשאת המיקום פעילה, האפליקציה שולחת לשרת את מיקום המכשיר רק בזמן שימוש (לא ברקע) ורק בפעולות שדורשות אותו: קביעת העיר, יצירת תוכנית חופשה (מיקום המוצא נשמר) ותיקון מקום שלא נמצא במפה. אנו עשויים לשמור את המיקום האחרון הידוע כדי להציג לכם תוכניות ואנשים בסביבה ומרחק משוער; משתמשים אחרים לעולם אינם רואים את מיקומכם, רק עיר או מרחק מעוגל. מיקום תוכנית מוצג לכולם מטושטש (כ-500 מטר); הכתובת המדויקת נחשפת רק למשתתפים שהמארח אישר.
  • תג האימות הוא אופציונלי. אתם שולחים סלפי בתוך האפליקציה לפי ההנחיה שעל המסך, וחבר צוות שלנו בודק אותו ידנית מול תמונות הפרופיל שלכם ומול חשבון רשת חברתית שקישרתם בפרופיל (אינסטגרם/פייסבוק, אם הוספתם; אופציונלי, אך מסייע לבדיקה). הסלפי נשמר באחסון פרטי רק עד ההחלטה ונמחק עם סיום הבדיקה, ובכל מקרה בתוך 30 יום. לא נעשה שימוש בהתאמת פנים אוטומטית לצורך התג.
  • צ'אט אינו מוצפן מקצה לקצה. הודעות נשמרות עד מחיקת החשבון. גישה של הצוות שלנו להודעות מוגבלת לצורכי בטיחות וטיפול בדיווחים, אבטחה, תמיכה לבקשתכם, תפעול ודרישות חוק, ומתועדת. התראה על הודעה חדשה עשויה לכלול תצוגה מקדימה שלה, שעוברת דרך ספק ההתראות (Google / Apple).
  • אנחנו לא מוכרים מידע אישי. אנחנו משתמשים בספקים (אחסון, מדיה, ניטור שגיאות, אנליטיקס, התראות, רכישות, מפות) ומודדים את קמפייני הפרסום שלנו: האפליקציה מטמיעה את ה-SDK של AppsFlyer (שותף מדידה למובייל) ב-iOS ובאנדרואיד, הרושם את ההתקנה, סשנים ואירוע השלמת הרשמה עם פרטי מכשיר ואפליקציה (ב-iOS מזהה הספק IDFV ו-Apple SKAdNetwork; באנדרואיד מזהה הפרסום של Google) ומדווח דיווחי ייחוס לשותפי הפרסום שלנו Meta ו-TikTok; השרת שלנו שולח ל-Meta אירוע אחד בעת השלמת ההרשמה, עם מזהים מגובבים; והאתר טוען את Meta Pixel. האפליקציה אינה מטמיעה SDK של Meta או של TikTok, AppsFlyer אינה מקבלת שם, טלפון או אימייל, איננו קוראים את ה-IDFA ואיננו מציגים בקשת מעקב. נכון למועד זה האירועים נשלחים לכל משתמש, ללא שכבת הסכמה מקדימה (לאיחוד האירופי ולבריטניה שכבת הסכמה ממתינה להפעלה); ניתן להתנגד, לבקש שנפסיק שימושים עתידיים ולבקש שהמידע יימחק, ובאנדרואיד לאפס או להגביל את מזהה הפרסום.
  • משתמשים בישראל שקיבלו קלפים יכולים לפדות את ערכם תמורת העברה בנקאית. לצורך כך אנו אוספים, פעם אחת, צילום מסמך זיהוי, סלפי ופרטי בנק; הצוות שלנו בודק אותם ידנית, הם נשמרים באחסון פרטי, ונשמרים כנדרש לפי דיני המס ואיסור הלבנת הון בישראל (בדרך כלל 7 שנים). פירוט בסעיף 3.17.
  • מחיקת חשבון זמינה באפליקציה, באתר (https://afterup.io/delete-account) ובמייל. עם הבקשה הפרופיל מוסתר ועובר אנונימיזציה והסטוריז נמחקים; התחברות בתוך 30 יום מבטלת את המחיקה ומשחזרת את החשבון, הפרופיל ויתרת המטבעות (סטוריז שנמחקו עם הבקשה אינם משוחזרים); לאחר מכן המידע נמחק לצמיתות, למעט מידע שעלינו לשמור לפי דין.
  • יש לכם זכות עיון, תיקון, מחיקה, העתק של המידע, התנגדות, הגבלה וביטול הסכמה. פונים ל-support@afterup.co.il ואנחנו עונים בתוך המועד הקבוע בדין החל (בישראל בדרך כלל בתוך 30 יום).
  • התראות פוש על פעילות בחשבונכם, על חידושים באפליקציה ועל מה שקורה סביבכם הן חלק מהשירות; ניתן לכבות אותן בהגדרות המכשיר בלבד (אין כרגע מסך לניהול התראות בתוך האפליקציה). SMS ודוא"ל שיווקיים נשלחים רק בהסכמה נפרדת שאינה מסומנת מראש ומסומנים "פרסומת"; ניתן להסיר בכל עת במייל או במענה "הסר" ל-SMS.

0.2 הודעה לפי סעיף 11 לחוק הגנת הפרטיות, התשמ"א-1981

  • חובה או רשות: אינכם חייבים על פי חוק למסור לנו מידע. מסירת פרטי חשבון ופרופיל בסיסיים (מספר טלפון, תאריך לידה, מגדר, שם תצוגה, לפחות שתי תמונות, עיר, העדפות תוכנית, מקומות ברשימת המשאלות) היא תנאי לפתיחת חשבון ולשימוש בשירות, מפני שבלעדיהם לא ניתן להתאים ביניכם לבין תוכניות ומשתמשים. מסירת מידע אחר (תשובות לשאלות פרופיל, קישורים לרשתות חברתיות, גובה, עיסוק, שפות, קליפ מוזיקה, טלפון ליצירת קשר, תג אימות, הסכמה לדיוור) היא וולונטרית ואינה תנאי לשימוש.
  • המטרות: הפעלת השירות (חשבון, פרופיל, תוכניות, התאמות, צ'אט, סטוריז, מטבעות AfterCoins), בטיחות ומניעת הונאה, מתן תמיכה, שיפור המוצר ומדידת שיווק, ועמידה בחובות חוקיות. פירוט בסעיף 5.
  • למי המידע נמסר ולאילו מטרות: למשתמשים אחרים לפי הגדרות הפרטיות שלכם (סעיף 7.2); לספקים המעבדים מידע עבורנו (אחסון, מדיה, אנליטיקס, ניטור שגיאות, התראות, רכישות, מפות, בדיקות תמונה) ולספקים הפועלים כבעלי שליטה עצמאיים (חנויות האפליקציות) - טבלה בסעיף 7.1; ל-Meta, ל-AppsFlyer ול-TikTok לצורך מדידת פרסום (סעיף 3.13); לבנק שלנו לצורך ביצוע תשלומי פדיון קלפים (סעיף 3.17); לרשויות כשהחוק מחייב.
  • תוצאות הסירוב: בלי המידע הבסיסי לא ניתן לפתוח חשבון או להשתמש בחלק מהיכולות (למשל בלי הרשאת מיקום לא תוצג המפה סביבכם). סירוב למידע וולונטרי אינו מונע שימוש בשירות.
  • בעלת השליטה במאגר המידע ודרכי הקשר: מונולוקו בע"מ, ח.פ. 516332269, מנחם מדמון 45, תל אביב-יפו 6767634; support@afterup.co.il.
  • זכות עיון ותיקון: לפי סעיפים 13 ו-14 לחוק עומדת לכם זכות לעיין במידע שעליכם שבמאגר, ולבקש לתקנו או למחקו אם אינו נכון, שלם, ברור או מעודכן. אופן המימוש בסעיף 11.
  • מידע בעל רגישות מיוחדת: אנו מעבדים נתוני מיקום ותוכן שאתם בוחרים לשתף העשוי לחשוף את צנעת חייכם. למיקום נדרשת הרשאת מכשיר ייעודית; תוכן אינטימי - לפי בחירתכם מה לכתוב ולהעלות. איננו משתמשים במידע זה לפרסום. פירוט בסעיף 4.
  • מידע שהועבר מהאזור הכלכלי האירופי (EEA): מידע של משתמשים מהאזור הכלכלי האירופי נשמר יחד עם שאר המידע, ולכן אנו מיישמים על המאגר כולו את תקנות הגנת הפרטיות (הוראות לעניין מידע שהועבר לישראל מהאזור הכלכלי האירופי), התשפ"ג-2023: צמצום, מחיקה כשאין עוד צורך, דיוק, וזכויות עיון, תיקון ומחיקה לכל המשתמשים. איננו מוחקים חשבונות אוטומטית בשל חוסר פעילות; אם נחליט לעשות זאת נודיע מראש.

1. מי אנחנו

1.1 בעלת השליטה במאגר המידע (ה"חברה", "AfterUp", "אנחנו"): מונולוקו בע"מ, חברה ישראלית, ח.פ. 516332269, מנחם מדמון 45, תל אביב-יפו 6767634, ישראל.

1.2 דרכי קשר לענייני פרטיות: support@afterup.co.il (ציינו בנושא "פרטיות"). ניתן גם לפנות דרך הצ'אט עם חשבון התמיכה של AfterUp באפליקציה.

1.3 ממונה על הגנת הפרטיות: ענייני פרטיות מטופלים על ידי צוות הפרטיות של החברה; ממונה על הגנת הפרטיות ימונה כנדרש בדין ויפורסם כאן. יצירת קשר: support@afterup.co.il (נושא: "פרטיות" או "Privacy").

1.4 נציג באיחוד האירופי (GDPR סעיף 27): טרם מונה. השירות טרם מוצע למשתמשים באיחוד האירופי או באזור הכלכלי האירופי (EEA); נציג לפי סעיף 27 ל-GDPR וסעיף 13 לתקנת השירותים הדיגיטליים ימונה ויפורסם כאן לפני שהשירות יוצע שם.

נציג בבריטניה (UK GDPR סעיף 27): טרם מונה. השירות טרם מוצע למשתמשים בבריטניה; נציג לפי סעיף 27 ל-UK GDPR ימונה ויפורסם כאן לפני שהשירות יוצע שם.

1.5 ברזיל (LGPD): ערוץ הפנייה לאחראי (encarregado) הוא support@afterup.co.il.

1.6 קנדה / קוויבק: פרטי "האחראי על הגנת המידע האישי" מפורטים בסעיף 15.3.


2. תחולה והגדרות

2.1 מדיניות זו חלה על אפליקציית AfterUp ל-iOS ול-Android, על אתר afterup.io (לרבות קישורי קמפיין תחת go.afterup.io ודפי נחיתה), ועל התקשורת שלכם איתנו (תמיכה, מיילים). היא אינה חלה על עיבוד שמבצעים צדדים שלישיים עצמאיים: חנויות האפליקציות (Apple, Google), מקומות בילוי או מארחים שאליהם הגעתם, או משתמשים אחרים בכל הנוגע למה שהם עושים מחוץ לאפליקציה.

2.2 הגדרות קצרות:

  • "מידע אישי" - כל מידע המזהה אתכם או יכול לזהות אתכם, במישרין או בעקיפין.
  • "תוכנית" (Plan) - מפגש או פעילות שמשתמש (ה"מארח") יוצר באפליקציה, ומשתמשים אחרים מבקשים להצטרף אליו. מי שהמארח אישר הוא "משתתף מאושר". "התאמה" (Match) נוצרת כאשר בקשת הצטרפות מאושרת.
  • "סטורי" - תוכן (תמונה או וידאו) שמשתמש משתף לפרק זמן מוגבל.
  • "מטבעות AfterCoins" ("AC") - מטבע וירטואלי פנימי שנרכש דרך חנויות האפליקציות או מתקבל כבונוס. בהמשך המסמך: "AC".
  • "קלפים" - פריטים וירטואליים שניתן לקבל ממשתמשים אחרים (שליחת קלפים מושבתת כיום; ראו סעיף 3.8).
  • "תג אימות" - סימון בפרופיל המעיד שסלפי אימות ששלחתם נבדק ידנית על ידי הצוות שלנו ונמצא תואם לתמונות הפרופיל שלכם (ולחשבון רשת חברתית מקושר, אם סופק) במועד הבדיקה. אינו אימות זהות או גיל.
  • "ספק" - צד שלישי שמספק לנו שירות. "מעבד" הוא ספק שמעבד מידע עבורנו ולפי הוראותינו בלבד; ספקים אחרים (למשל חנויות האפליקציות) פועלים כבעלי שליטה עצמאיים לפי תנאיהם. הסיווג מופיע בטבלה בסעיף 7.1.
  • "תנאי השימוש" - תנאי השימוש של AfterUp בכתובת https://afterup.io/terms.

3. המידע שאנו אוספים - לפי יכולת באפליקציה

3.1 חשבון והתחברות

  • מספר טלפון - המזהה הראשי של החשבון. מאומת בקוד חד-פעמי (OTP) ב-SMS הנשלח דרך מערכת ההזדהות שלנו (Supabase Auth) וספק שליחת SMS (למשל Twilio).
  • התחברות עם Apple / Google - אם תבחרו בכך, נקבל מהספק מזהה משתמש וכתובת אימייל (Apple עשויה למסור כתובת ממסר). גם אז נדרש אימות טלפון.
  • נתוני אבטחת חשבון - כתובת IP ומועד ההתחברות האחרונה, מונה התחברויות, אירועי התנתקות ורישומי אבטחה.
  • גרסת תנאים ומדיניות שאישרתם, מועד האישור, שפת התצוגה והסכמות נוספות (ראו 3.14).

3.2 פרופיל

מה שאתם ממלאים בפרופיל, וחלקו מוצג למשתמשים אחרים (ראו 7.2):

  • פרטים בסיסיים: שם תצוגה, מגדר, תאריך לידה (משמש לאכיפת גיל 18+, להצגת גילכם ולסינון לפי טווח הגילאים שמארח הגדיר לתוכנית), ביו, עיר מגורים (נקודת מרכז העיר, לא כתובת), מדינה.
  • תמונות: בין 2 ל-9 תמונות פרופיל. לכל תמונה נשמרים כתובת האחסון, מיקום בגלריה, טביעת אצבע דיגיטלית (hash) לזיהוי כפילויות, סטטוס זיהוי פנים וסטטוס בדיקה.
  • העדפות תוכנית: סוגי התוכניות שמעניינים אתכם (לפחות שניים, למשל אפטר, אוכל, מועדון, חופשה).
  • שאלות פרופיל (Prompts): תשובות קצרות לשאלות שבחרתם (רשות, עד חמש).
  • רשימת משאלות (Wishlist): מקומות שאתם רוצים לבקר בהם, לפי קטגוריות (לפחות שתי קטגוריות עם שני מקומות בכל אחת). לכל מקום נשמרים שם וקואורדינטות של המקום (לא של המיקום שלכם).
  • קליפ מוזיקה: קליפ מתוך ספריית המוזיקה הפנימית שלנו שבחרתם לפרופיל, והעדפות מוזיקה.
  • שדות וולונטריים: גובה, עיסוק, שפות, קישורים לאינסטגרם/פייסבוק, שפת ממשק, וכן טלפון ליצירת קשר ואופן יצירת קשר מועדף. שימו לב: טלפון ליצירת קשר שמילאתם מוצג למשתתפים שאישרתם לתוכנית שלכם (סעיף 7.2); מספר הטלפון של החשבון עצמו אינו מוצג לאיש.
  • הגדרות: פרופיל ציבורי/פרטי, מדיניות הזמנות ישירות, סדר הצגת קטגוריות.
  • נתונים שנוצרים אצלנו על הפרופיל: סטטוס חשבון, סטטוס תג אימות, ניקוד פעילות פנימי (XP), ציון קארמה, מונה אזהרות, מספר עוקבים ונעקבים, מועד פעילות אחרון, מספר גרסת האפליקציה והפלטפורמה שלכם, מדד השלמת הפרופיל.

3.3 מיקום

  • מיקום המכשיר (GPS): נאסף רק כשהאפליקציה בחזית ורק בפעולות שדורשות אותו; אין איסוף מיקום ברקע. לקביעת העיר, המיקום מתורגם במכשיר לעיר, והשרת מקבל את העיר (שם העיר, מדינה, מחוז ונקודת מרכז העיר). ביצירת תוכנית חופשה נשלח לשרת ונשמר מיקום המוצא שלכם (נקודת ה-GPS בעת היצירה) לחישוב מרחק ליעד; בתיקון מקום שלא נמצא במפה נשלח מיקום המכשיר כדי לאתר את המקום. אנו עשויים לשמור את המיקום האחרון הידוע של המכשיר (ללא היסטוריית מיקומים) כדי להציג לכם תוכניות ואנשים בסביבה ומרחק משוער מהם. משתמשים אחרים לעולם אינם רואים את מיקומכם: לכל היותר עיר או מרחק מעוגל. המיקום האחרון נמחק עם החשבון.
  • מיקום תוכנית: כשאתם יוצרים תוכנית אתם בוחרים מקום. אנו שומרים בשרת את הקואורדינטות המדויקות של המקום (לא את מיקומכם) וגם גרסה מטושטשת (כ-500 מטר). הגרסה המטושטשת מוצגת במפה לכולם; הכתובת המדויקת מוצגת רק למשתתפים מאושרים.
  • לסיכום, רמות המיקום: מיקום המכשיר - נשלח לשרת רק בזמן שימוש, לפעולות שלמעלה, ונשמר לכל היותר כמיקום אחרון ידוע; עיר - בשרת ומוצגת בפרופיל; מיקום מדויק של מקום התוכנית - בשרת, נחשף למשתתפים מאושרים; מיקום מטושטש של התוכנית - מוצג לכולם; מרחק מעוגל - מוצג למשתמשים אחרים, אם התכונה פעילה.
  • חיפוש מקומות ומפה: כשאתם מקלידים שם מקום, הטקסט שהקלדתם נשלח לשירות Google Places לצורך השלמה אוטומטית, ושמות ערים נשלחים לשירות Geocoding של Google (המרת שם עיר לקואורדינטות). אריחי המפה נטענים משרתי Mapbox, שמקבלים את כתובת ה-IP שלכם ואת אזור המפה שנצפה. ערכת הפיתוח (SDK) של Mapbox עשויה לאסוף נתוני טלמטריה של שימוש ומיקום לפי מדיניות הפרטיות של Mapbox; תפריט הייחוס של Mapbox (סמל ⓘ) שבמפה כולל את הגדרת הטלמטריה של Mapbox.
  • ניתן לבטל את הרשאת המיקום בהגדרות המכשיר בכל עת; חלק מהיכולות (מפה, תוכניות קרובות) לא יעבדו בלעדיה.

3.4 תוכניות והשתתפות

  • תוכניות שיצרתם: כותרת, תמונת שער, מקום, מיקום מדויק ומטושטש, מדינה, משך, טווח גילאים, ומגדר מועדף למשתתפים. טווח הגילאים והמגדר המועדף הם הגדרות של המארח לתוכנית, והאפליקציה משתמשת בהן כדי לקבוע למי תוצג התוכנית (סעיף 6.2).
  • השתתפות: בקשות הצטרפות, אישורים ודחיות, רשימת משתתפים, הזמנות ישירות.
  • פעולות חברתיות: עוקבים ונעקבים (והיסטוריית ביטול מעקב), "פינג" ששלחתם או קיבלתם, צפיות בפרופיל, דירוגים, לייקים לתמונות, סופר-לייקים (עם מכסה יומית), וחסימות.
  • הערכות וניקוד: יומן XP ופעולות שמזכות בניקוד.

3.5 צ'אט ומדיה

  • הודעות: תוכן ההודעות, השולח, הנמען, מועדים, סטטוס קריאה. צ'אט אישי נפתח לאחר התאמה בתוכנית (ללא התאמה ניתן לשלוח הודעה אחת עד שהצד השני עונה). לכל תוכנית יש צ'אט קבוצתי של המשתתפים.
  • מדיה בצ'אט: תמונות וסרטונים נשמרים אצל ספק המדיה שלנו (Cloudinary). מדיה "לצפייה חד-פעמית" ניתנת לפתיחה פעם אחת אצל הנמען ואינה ניתנת לפתיחה חוזרת לאחר הצפייה או לאחר 4 שעות; הקובץ עצמו נשמר כחלק מההודעה עד מחיקת ההודעה או החשבון; צילום מסך אינו נמנע טכנית, והמדיה אינה מוצפנת מקצה לקצה.
  • התראות על הודעות: התראה על הודעה חדשה עשויה לכלול את שם התצוגה של השולח ותצוגה מקדימה של תחילת ההודעה. תוכן זה עובר דרך ספק ההתראות (Google Firebase Cloud Messaging, וב-iOS גם שירות ההתראות של Apple) כדי להגיע למכשירכם, ועשוי להופיע על מסך נעול. ניתן לכבות התראות בהגדרות המכשיר.
  • העתק מקומי: האפליקציה שומרת עותק מקומי של השיחות במכשיר שלכם כדי לאפשר צפייה לא מקוונת. העותק נמצא במכשיר שלכם ומוסר עם הסרת האפליקציה.
  • הצפנה וגישה: ההודעות מוצפנות בתעבורה (TLS) ובאחסון, אך לא מקצה לקצה. AfterUp יכולה טכנית לגשת להודעות. גישה כזו מוגבלת לצוות מורשה, מתועדת, ונעשית למטרות אלה בלבד: בטיחות וטיפול בדיווחים ובמודרציה, אבטחה ומניעת הונאה, תמיכה לבקשתכם, תפעול ותחזוקה טכנית, ועמידה בדרישות חוק או צו.
  • שמירה ומחיקה: הודעות נשמרות עד מחיקת החשבון לצמיתות. הודעה שמחקתם מסומנת כמחוקה ונעלמת משני הצדדים, והרשומה נמחקת סופית מהשרתים שלנו עם מחיקת החשבון; במכשיר של המשתמש השני עשוי להישמר עותק לא-מקוון. בצ'אט קבוצתי של תוכנית, הודעות ששלחתם עשויות להישאר בקבוצה גם לאחר מחיקת חשבונכם, ללא שמכם (השולח יוצג כ-"Deleted User", משתמש שנמחק).

3.6 סטוריז

  • סטורי שאתם מעלים (תמונה/וידאו, זמן העלאה) מוצג 24 שעות ואז עובר אוטומטית לארכיון הפרטי שלכם באפליקציה, שבו תוכלו לצפות בו, לשחזר אותו או למחוק אותו לצמיתות.
  • אנו שומרים מי צפה ומי הגיב לסטורי שלכם, ומציגים זאת לכם כבעלי הסטורי.
  • קובצי המדיה נמחקים מספק המדיה כשאתם מוחקים סטורי לצמיתות או כשהחשבון נמחק סופית. סטוריז פעילים נמחקים מיד עם בקשת מחיקת חשבון ואינם משוחזרים גם אם ביטלתם את המחיקה.

3.7 AC ורכישות

  • רכישות AC מתבצעות דרך Apple App Store או Google Play. איננו מקבלים ואיננו שומרים מספרי כרטיסי אשראי או פרטי אמצעי תשלום.
  • ממערכת ניהול הרכישות שלנו (RevenueCat) ומהחנויות אנו מקבלים: מזהה המשתמש שלנו, המוצר שנרכש, מזהה העסקה, מחיר ומטבע, החנות ומועד הרכישה.
  • אנו מנהלים יומן פנימי של יתרת ה-AC: רכישות, בונוסים (למשל בונוס הצטרפות), ושימושים (Boost, סופר-לייקים). יומן זה נדרש למניעת הונאות ולפתרון מחלוקות.
  • איננו מציעים כיום מנוי. שדות סטטוס פנימיים ישנים הנוגעים למנוי או ל"פרימיום" אינם בשימוש. אם נציע בעתיד מנוי, נעדכן סעיף זה לפני ההשקה.

3.8 קלפים שהתקבלו

  • שליחת קלפים מושבתת כיום. קלפים שקיבלתם בעבר עדיין מוצגים: סוג הקלף וערכו, מי שלח, ומתי.
  • קלפים הם פריטים וירטואליים. משתמשים בישראל שקיבלו קלפים יכולים לבקש לפדות את ערכם תמורת העברה בנקאית (תנאי השימוש, סעיף 13); המידע שנאסף לצורך זה מתואר בסעיף 3.17. פדיון מחוץ לישראל אינו מוצע כיום; אם וכאשר יוצע, הוא יוסדר בתנאי פדיון נפרדים ויתבצע דרך ספק תשלומים מורשה.

3.9 תג אימות (בדיקת סלפי ידנית)

  • תג האימות אופציונלי. בלעדיו כל שאר יכולות השירות זמינות.
  • התהליך: אתם מצלמים סלפי בתוך האפליקציה לפי ההנחיה שעל המסך (למשל אחיזת פתק עם הטקסט המוצג). חבר צוות שלנו בודק את הסלפי ידנית מול תמונות הפרופיל שלכם ומול חשבון רשת חברתית שקישרתם בפרופיל (כתובת אינסטגרם/פייסבוק, אם סיפקתם; קישור לרשת חברתית הוא אופציונלי, אך מסייע לבדיקה), ומאשר או דוחה את הבקשה. איננו משתמשים בזיהוי פנים (face recognition), בזיהוי ביומטרי, בהשוואת פנים אוטומטית או באיתור פנים אוטומטי לצורך האימות: לא נוצרת תבנית פנים, ושום תוכנה אינה משווה את הסלפי לתמונות שלכם.
  • מה אנחנו שומרים: את הסלפי במאגר אחסון פרטי (private bucket; הוא לעולם אינו מוצג בפרופיל ואינו נכנס לגלריה), סטטוס הבקשה, מועד ההגשה ומועד ההחלטה, וזהות חבר הצוות שבדק.
  • שמירה: הסלפי נשמר רק עד ההחלטה ונמחק עם סיום הבדיקה, ובכל מקרה בתוך 30 יום; רשומת ההחלטה (סטטוס ומועד, ללא הסלפי) נשמרת כהוכחה לתג עד ביטול התג או מחיקת החשבון.
  • תג האימות אינו אימות זהות, גיל או רקע פלילי, ועשוי להישלל.
  • בדיקות תמונה אוטומטיות לכל המשתמשים: כל תמונת פרופיל שמועלית עוברת בדיקה אוטומטית שרואים בה פנים (AWS Rekognition DetectFaces, אזור פרנקפורט, האיחוד האירופי) ובדיקת כפילות מול תמונות קיימות. בדיקת הפנים היא איתור פנים בלבד (face detection) - היא אינה מזהה אף אדם ואינה משווה פנים. בבדיקות אלה לא נשמרת תבנית פנים, אלא רק תוצאה (פנים זוהו / לא זוהו) וטביעת אצבע דיגיטלית של הקובץ.
  • ניתן לבקש מאיתנו בכל עת למחוק את סלפי האימות שלכם ולבטל את התג במייל support@afterup.co.il.

3.10 דיווחים, חסימות ורשומות אכיפה

  • דיווחים שהגשתם או שהוגשו עליכם: הקטגוריה (למשל תוכן לא הולם, הונאה/זיוף, ספאם, בטיחות, הטרדה, תמונה אינטימית שפורסמה ללא הסכמה, אחר), טקסט חופשי, התוכן או הפרופיל המדווח, ומועד. כפתור דיווח קיים בפרופילים, בתוכניות ובהודעות; על סטורי מדווחים דרך הפרופיל של מי שהעלה אותו או במייל.
  • חסימות: מי חסם את מי ומתי (החסימה הדדית ואינה נחשפת לצד השני).
  • רשומות אכיפה: החלטות צוות האכיפה, אזהרות, הסתרות, הקפאות, חסימות, סיבת חסימה, הערות פנימיות, היסטוריית סטטוס חשבון ויומן ביקורת של פעולות צוות האכיפה.
  • דיווחים בקטגוריית "תמונה אינטימית ללא הסכמה" מסומנים אוטומטית לטיפול בעדיפות עם יעד הסרה של עד 48 שעות.

3.11 נתוני מכשיר וטכניים

  • אסימון התראות (FCM), פלטפורמה (iOS/Android), מספר גרסה ומספר בנייה של האפליקציה, שפה.
  • כתובת IP ומועד בהתחברות, מונה התחברויות, אירועי התנתקות.
  • התראות: ספק ההתראות (Google Firebase Cloud Messaging, וב-iOS גם Apple) מקבל את אסימון ההתראות ואת כותרת ותוכן ההתראה, שעשויים לכלול שם תצוגה ותצוגה מקדימה של הודעה (סעיף 3.5).
  • דוחות קריסה ושגיאות (Sentry, שרתים באיחוד האירופי): עקבות השגיאה (stack trace), גרסה, סביבה ומזהה המשתמש הפנימי שלנו (ללא שם, אימייל או IP).
  • טעינת גופנים: האפליקציה טוענת גופנים משרתי Google Fonts, שמקבלים את כתובת ה-IP שלכם בבקשה.

3.12 אירועי אנליטיקס (Mixpanel)

אנו משתמשים ב-Mixpanel (שרתים באיחוד האירופי) כדי להבין איך משתמשים באפליקציה. נכון למועד זה האנליטיקס פועל לכל המשתמשים (ראו 13.1 לגבי בחירה).

  • אירועים: הרשמה, פתיחת אפליקציה, מעבר לרקע, צפייה במסך ומשך הצפייה, התחברות והתנתקות, צפייה בפרופיל, שליחת קלף, רכישת AC, שימוש ב-AC, הפעלת Boost, יצירת תוכנית, שליחת הודעה (סוג הצ'אט והאם כללה מדיה - לא תוכן ההודעה), יצירת סטורי, צפייה בסטורי (כולל מזהה בעל הסטורי), מספר ימים מאז ההרשמה, והגשת דיווח על משתמש שיש לו פרופיל DJ (אנו מתעדים את העיר, הז'אנרים והאם יש קישורים חיצוניים בפרופיל ה-DJ - לא את תוכן הדיווח).
  • פרופיל האנליטיקס: מזהה המשתמש שלנו, שם, מגדר, אימייל וטלפון (אם קיימים), סוג משתמש, סטטוס "פרימיום" פנימי (לא בשימוש), פלטפורמה וגרסת אפליקציה.
  • מה ה-SDK מוסיף אוטומטית: נתוני מכשיר ומערכת הפעלה (דגם, גרסת מערכת, ספק סלולר, שפה, רזולוציה) ומיקום משוער ברמת עיר/אזור הנגזר מכתובת ה-IP.
  • מה לא נשלח: מיקום GPS מדויק, תוכן הודעות, תמונות או סלפי אימות.

3.13 מדידת שיווק (Meta, AppsFlyer, TikTok)

  • באתר: דפי נחיתה וקישורי קמפיין מסוימים טוענים את Meta Pixel, המדווח ל-Meta על צפייה בדף, צפייה בתוכן ולידים, יחד עם עוגיות Meta וכתובת ה-IP שלכם. ראו סעיף 13.2.
  • באפליקציה (AppsFlyer SDK, iOS ואנדרואיד): האפליקציה מטמיעה ב-iOS ובאנדרואיד את ה-SDK של AppsFlyer Ltd. (ישראל), שותף מדידה למובייל, לצורך ייחוס התקנות ומדידת קמפייני הפרסום שלנו ב-Meta וב-TikTok. ה-SDK מאותחל עם פתיחת האפליקציה ורושם אוטומטית את ההתקנה, הפתיחה הראשונה והסשנים; בנוסף אנו שולחים דרכו כיום אירוע מפורש אחד: "השלמת הרשמה" (עם שיטת הרשמה "phone"); ייתכן שנוסיף אירועים כגון השלמת פרופיל, יצירת תוכנית וקבלת הזמנה. איננו שולחים אירועי רכישה או הכנסה, ואיננו מעבירים ל-AppsFlyer שם, טלפון, אימייל או מזהה לקוח שלנו. עם אירועים אלה AppsFlyer מקבלת: ב-iOS את מזהה הספק (IDFV) ונתוני Apple SKAdNetwork (מצרפיים, ללא IDFA; האפליקציה אינה מציגה בקשת מעקב, App Tracking Transparency); באנדרואיד את מזהה הפרסום של Google (GAID) ומזהי מכשיר של אנדרואיד; ובשתי הפלטפורמות את כתובת ה-IP, דגם המכשיר, מערכת ההפעלה והשפה, גרסת האפליקציה, מועד ההתקנה ואירועי פתיחה ראשונה וסשנים. AppsFlyer מדווחת דיווחי התקנה ואירועים (postbacks) לשותפי הפרסום שלנו Meta ו-TikTok לצורך ייחוס: ב-iOS באמצעות SKAdNetwork (מצרפי, ללא מזהה מכשיר), ובאנדרואיד ברמת המכשיר באמצעות מזהה הפרסום. היקף השיתוף עם השותפים: ל-Meta ול-TikTok משותפים רק דיווחי התקנה ואירועים באפליקציה (postbacks) לצורך ייחוס; השבתנו את שיתוף המידע המתקדם (advanced data sharing) ואת ההתאמה המתקדמת (advanced matching) של AppsFlyer, כך שלא נשלחים אליהן דרך AppsFlyer פרטים אישיים מגובבים (כגון אימייל או טלפון). ב-iOS דיווחים אלה הם נתוני SKAdNetwork מצרפיים ללא מזהה מכשיר; באנדרואיד הם נשלחים עם מזהה הפרסום של המכשיר. עבור Meta הפעלנו בנוסף ב-AppsFlyer את ההגדרה "הגבלת השימוש במידע אישי" (CCPA). AppsFlyer שומרת את המידע בארצות הברית (האזור הגלובלי של AppsFlyer); AppsFlyer Ltd. היא חברה ישראלית הפועלת כמעבדת מטעמנו לפי הסכם עיבוד מידע, עם סעיפים חוזיים סטנדרטיים (SCCs) לאחסון בארה"ב ככל שנדרש. אין SDK של TikTok באפליקציה; TikTok מקבלת דיווחי ייחוס דרך AppsFlyer בלבד. ה-SDK שומר מזהים על המכשיר.
  • מהשרת שלנו (Conversions API): כשאתם משלימים את ההרשמה לפרופיל, השרת שלנו שולח ל-Meta אירוע אחד - "CompleteRegistration" - הכולל אימייל, טלפון ומזהה משתמש לאחר גיבוב חד-כיווני (SHA-256), כתובת IP, מחרוזת זיהוי של המכשיר והתוכנה (User Agent), ומזהי עוגיות Meta אם הגעתם מקמפיין. אנו שומרים רק את מועד השליחה. נכון למועד זה האירוע נשלח פעם אחת לכל משתמש שמשלים הרשמה, ללא מנגנון הסכמה מקדים.
  • המטרה: למדוד אילו קמפיינים מביאים התקנות והרשמות, לייעל את קמפייני ההתקנה שלנו ב-Meta וב-TikTok, ולאפשר ל-Meta להימנע מהצגת המודעות שלנו למי שכבר נרשם (החרגת קהל). איננו מעבירים ל-Meta, ל-TikTok או ל-AppsFlyer מידע לצורך שיווק עצמאי שלהן. Meta אינה מקבלת מאיתנו טלפון או אימייל גלויים, אך מידע מגובב ומזהי פרסום עדיין נחשבים מידע אישי.
  • תפקידי Meta, AppsFlyer ו-TikTok: AppsFlyer מעבדת את המידע מטעמנו כמעבדת. לפי תנאי הכלים העסקיים של Meta, Meta Platforms Ireland Ltd. (ובארה"ב Meta Platforms, Inc.) היא בעלת שליטה משותפת איתנו לגבי איסוף האירועים והעברתם, ובעלת שליטה עצמאית לגבי העיבוד שלאחר מכן בשירותיה; עיקרי ההסדר זמינים בתנאי הכלים העסקיים של Meta. TikTok (TikTok Technology Limited באירלנד, ובארה"ב TikTok Inc.) מקבלת את דיווחי הייחוס לפי תנאי המוצרים העסקיים שלה ומעבדת אותם כבעלת שליטה למטרותיה.
  • בחירה: ניתן להתנגד בכל עת במייל support@afterup.co.il - נחדל משליחת אירועי מדידה עתידיים אודותיכם, נורה ל-AppsFlyer למחוק את המידע ונבקש מ-Meta ומ-TikTok למחוק את מה שנשלח אליהן (לתושבי מדינות בארה"ב ראו גם סעיף 15.2 לגבי "אל תמכור או תשתף"). באנדרואיד ניתן גם לאפס או להגביל את מזהה הפרסום בהגדרות Google במכשיר; ב-iOS לא נעשה שימוש ב-IDFA, ולכן אין מה לכבות. למשתמשים באיחוד האירופי ובבריטניה יופעל מנגנון הסכמה מקדים לפני שהשירות ישווק למשתמשים באיחוד האירופי, באזור הכלכלי האירופי (EEA) או בבריטניה; עד אז האירועים (SDK ושרת) נשלחים כמתואר לעיל, וניתן להתנגד כאמור.

3.14 רשומות הסכמה

  • אנו שומרים: גרסת תנאי השימוש ומדיניות הפרטיות שאישרתם, מועד האישור ושפת התצוגה, הסכמה לדיוור שיווקי ומועדה, אזור תנאים, ויומן אירועי הסכמה שלא ניתן לערוך (מקור: חלון הסכמה, מסך התחברות, אימות OTP, הגדרות, שער הסכמה).
  • כשאנחנו משנים את המסמכים באופן מהותי, האפליקציה מבקשת אישור מחדש של הגרסה החדשה.
  • הרשומות נמחקות עם מחיקת החשבון לצמיתות, למעט יומן אישור מינימלי, שנכתב אוטומטית על ידי מסד הנתונים כשאירוע הסכמה נמחק (מזהה משתמש מגובב (SHA-256), סוג האירוע, הגרסה שאושרה, מועד ומקור), שנשמר לתקופת ההתיישנות כהוכחה להסכמה ולהגנה מפני תביעות (סעיף 9).

3.15 תמיכה ופניות

כשאתם פונים אלינו (מייל, צ'אט עם חשבון התמיכה באפליקציה, טפסים באתר) אנו שומרים את תוכן הפנייה, פרטי הקשר שמסרתם והתכתובת, כדי לטפל בפנייה ולשפר את השירות.

3.16 הפניות (Referral)

אם הצטרפתם דרך קוד או קישור הפניה, נשמור בפרופיל את מקור ההפניה. לחיצה על קישור קמפיין או הפניה באתר עשויה להירשם (מועד, כתובת IP, סוג דפדפן) לצורך מדידת קמפיינים; שיוך אוטומטי של לחיצה כזו לחשבון שנפתח לאחר מכן אינו פעיל כיום. תגמולי הפניה הם ניקוד, AC או קלפים בלבד, לעולם לא כסף.

3.17 אימות זהות ופרטי בנק - רק אם תבקשו פדיון קלפים (ישראל)

אם אתם בישראל ומבקשים לפדות קלפים שהתקבלו (הגדרות > ארנק > פדיון), אנו אוספים, לצורך ביצוע התשלום וכנדרש לפי דיני המס ואיסור הלבנת הון בישראל: צילום מסמך זיהוי (קדמי/אחורי), סלפי, שם בעל החשבון ופרטי חשבון בנק (בנק, סניף, מספר חשבון), ורשומות הבקשה (סכום, סטטוס, החלטה ומועד התשלום). אימות הזהות מתבצע פעם אחת; בקשות מאוחרות יותר נשענות עליו אלא אם הפרטים שלכם השתנו. מטרה ובסיס חוקי: ביצוע החוזה (ביצוע הפדיון שביקשתם) ועמידה בחובות חוקיות (מס, איסור הלבנת הון). אחסון וגישה: המסמכים נשמרים במאגר אחסון פרטי (private bucket), הגישה מוגבלת לצוות מורשה, הבקשה נבדקת ידנית על ידי הצוות שלנו, והמסמכים אינם מוצגים למשתמשים אחרים; פרטי הבנק מועברים לבנק שלנו רק לצורך ביצוע ההעברה. שמירה: מסמכי הזהות, פרטי הבנק ורשומות התשלום נשמרים כנדרש לפי דיני המס ואיסור הלבנת הון בישראל, בדרך כלל 7 שנים, ולאחר מכן נמחקים; בקשה שנזנחה או נדחתה נמחקת תוך זמן סביר. פדיון מחוץ לישראל אינו מוצע כיום; אם וכאשר יוצע, הוא יתבצע דרך ספק תשלומים מורשה בתנאים נפרדים, וסעיף זה יעודכן לפני ההשקה.

3.18 טפסים באתר

רשימת ההמתנה וטפסי יצירת קשר באתר אוספים אימייל ו/או טלפון, כתובת IP ופרמטרי קמפיין (UTM). הפרטים נשלחים אלינו במייל דרך שירות Resend ומתקבלים בתיבת דואר של הצוות המתארחת אצל Google (Gmail), ומשמשים ליצירת קשר על ההשקה ולמענה. האתר מאוחסן ב-Vercel, ומשתמש במיקום ברמת מדינה הנגזר מכתובת ה-IP כדי להציג גרסה מקומית של האתר (עוגיית העדפה).

3.19 מידע עליכם שמגיע ממשתמשים אחרים

משתמשים אחרים עשויים ליצור מידע עליכם: דיווחים, חסימות, דירוגים, לייקים, צפיות בפרופיל, בקשות הצטרפות, הודעות אליכם. אנו מעבדים מידע זה לצורך הפעלת השירות והבטיחות, ואיננו חושפים למדווח או למדווח עליו את זהות הצד השני מעבר למה שגלוי ממילא.


4. מידע רגיש וקטגוריות מיוחדות

4.1 הסיווג של מידע כ"רגיש" משתנה לפי הדין. כך אנו מטפלים בסוגים הרלוונטיים:

  • מיקום: נחשב "מידע בעל רגישות מיוחדת" לפי חוק הגנת הפרטיות ו"מידע רגיש" לפי חוקי מדינות בארה"ב; הוא אינו "קטגוריה מיוחדת" לפי GDPR סעיף 9 ואינו מידע רגיש לפי LGPD. מיקום המכשיר נשלח לשרת רק בזמן שימוש ובפעולות המפורטות בסעיף 3.3, ונשמר לכל היותר כמיקום אחרון ידוע; לשרת מגיעה גם העיר; מיקום תוכנית שאתם מארחים נשמר במדויק ומוצג מטושטש. הבסיס: הרשאת מיקום ייעודית במכשיר, שאותה ניתן לבטל בכל עת, וביצוע השירות שביקשתם.
  • תוכן החושף את צנעת חייכם: מה שאתם בוחרים לכתוב או להעלות בפרופיל, בצ'אט ובסטוריז עשוי לחשוף מידע אינטימי. זו בחירה שלכם; איננו מבקשים מידע כזה ואיננו מסיקים ממנו מאפיינים. אנו מעבדים תוכן זה רק כדי לספק את השירות ולאכוף את הכללים.

4.2 איננו שואלים על נטייה מינית ואין בפרופיל שדה כזה. מארח של תוכנית רשאי להגדיר מגדר מועדף למשתתפים בתוכנית שלו; זו הגדרה של התוכנית שקובעת למי היא תוצג, לא נתון על הנטייה של איש.

4.3 איננו משתמשים במידע רגיש לפרסום ואיננו מוכרים אותו. איננו מעבירים מיקום, סלפי אימות, תוכן הודעות, תמונות, ביו, תשובות לשאלות פרופיל, מקומות מרשימת המשאלות או העדפות תוכנית לספקי אנליטיקס או פרסום. פרופיל האנליטיקס ב-Mixpanel מקבל רק את המאפיינים המפורטים בסעיף 3.12: שם תצוגה, מגדר, אימייל וטלפון (אם קיימים), סוג משתמש וסימון "פרימיום" פנימי (לא בשימוש), וכן פלטפורמה וגרסת אפליקציה. ל-Meta נשלחים רק הנתונים המפורטים בסעיף 3.13, ואיננו משתמשים בכלי Meta ליצירת פילוחים על בסיס מאפיינים רגישים.

4.4 הבסיס החוקי: לתוכן פרופיל שבחרתם להציג למשתמשים אחרים - מידע שאתם עצמכם הפכתם לגלוי (GDPR סעיף 9(2)(ה)), ככל שסעיף 9 חל עליו. לתוכן בצ'אט ובסטוריז - אספקת השירות שביקשתם, ובמקרי בטיחות או הגנה משפטית - הדין המתיר זאת (לרבות GDPR סעיף 9(2)(ו)). ניתן לבטל הסכמה בכל עת (סעיף 11.6).


5. מטרות העיבוד, הבסיס החוקי ותקופת השמירה

5.1 טבלת מטרות ובסיסים:

# מטרה מידע בסיס חוקי (GDPR / UK GDPR / LGPD; בישראל: הסכמה מדעת והוראות החוק) שמירה
1פתיחת חשבון, התחברות ואבטחת חשבוןטלפון, OTP, מזהי OAuth, IP ומועד התחברותביצוע חוזה (תנאי השימוש); אינטרס לגיטימי (אבטחה)עד מחיקת החשבון
2הצגת פרופיל והתאמה לתוכניות ולמשתמשיםפרופיל, תמונות, העדפות, שאלות, רשימת משאלות, עיר, גיל, מגדרביצוע חוזהעד מחיקת החשבון
3הצגת מפה, תוכניות ואנשים קרובים ומרחק משוערעיר, הרשאת מיקום, מיקום אחרון ידוע של המכשיר, מיקום מוצא של תוכנית חופשה, מיקום תוכנית מטושטשביצוע חוזה; הרשאת מכשירעיר ומיקום אחרון: עד עדכון/מחיקת החשבון; מיקום מוצא: עם התוכנית
4יצירת תוכניות, בקשות, אישורים, חשיפת כתובת למשתתפים מאושריםנתוני תוכנית, השתתפותביצוע חוזהעד מחיקת התוכנית/החשבון
5צ'אט אישי וקבוצתי, מדיה, סטוריזהודעות, מדיה, סטוריז, צפיותביצוע חוזההודעות: עד מחיקת החשבון; סטוריז: 24 שעות ואז ארכיון עד מחיקה
6רכישת AC ושימוש בהם, Boost, סופר-לייקיםרשומות רכישה, יומן ACביצוע חוזה; חובה חוקית (ראיות חשבונאיות)עד מחיקת החשבון; רשומות חשבונאיות מצטברות ואנונימיות לפי דין
7תג אימות (בדיקה ידנית של סלפי, תמונות פרופיל וחשבון רשת חברתית מקושר)סלפי אימות, חשבון רשת חברתית מקושר (אם סופק), סטטוס הבקשה, החלטת הבדיקהביצוע חוזה (תכונה שביקשתם); אינטרס לגיטימי (אמינות הפרופיל)סלפי: נמחק עם סיום הבדיקה, ובכל מקרה בתוך 30 יום; רשומת החלטה: עד ביטול התג/מחיקה
8בדיקות תמונה אוטומטיות (פנים גלויות, כפילויות)תמונות פרופיל, סטטוס בדיקה, hashאינטרס לגיטימי (אמינות פרופילים, מניעת התחזות); ביצוע חוזהעם התמונה
9בטיחות, מניעת הונאה ואכיפת הכלליםדיווחים, חסימות, רשומות אכיפה, הודעות (לאחר דיווח), מונים וקצביםאינטרס לגיטימי (בטיחות המשתמשים); חובה חוקיתעד מחיקת החשבון, בכפוף לשמירה לפי דין (סעיף 9)
10התראות והודעות שירות (התאמות, הודעות, עדכוני תוכנית)אסימון התראות (FCM), מזהים, תצוגה מקדימה של הודעהביצוע חוזהעד התנתקות/מחיקה
11דיוור שיווקיטלפון/אימייל, הסכמההסכמה (חוק התקשורת סעיף 30א; GDPR 6(1)(א))עד ביטול ההסכמה/מחיקה
12אנליטיקס ושיפור המוצראירועי שימוש (3.12), נתוני מכשיראינטרס לגיטימי (שיפור השירות) עם זכות התנגדות; באיחוד האירופי/בריטניה: הסכמה, משיופעל מנגנון ההסכמה (13.1)אצל הספק לפי הגדרת השמירה בחשבוננו, לכל היותר 5 שנים; נמחק לבקשתכם
13ניטור שגיאות ויציבותדוחות קריסה, מזהה משתמש פנימיאינטרס לגיטימי (תקינות השירות)אצל הספק עד 90 יום
14מדידת קמפיינים (Meta, AppsFlyer, TikTok)אירועי AppsFlyer SDK (התקנה, סשנים, השלמת הרשמה) עם פרטי מכשיר ואפליקציה, IP ומזהי הפלטפורמה (IDFV/SKAdNetwork ב-iOS, GAID באנדרואיד); מזהים מגובבים, IP, UA (אירוע שרת); אירועי אתראינטרס לגיטימי עם זכות התנגדות; באיחוד האירופי/בריטניה: הסכמה, משיופעל מנגנון ההסכמה (3.13)אצלנו: מועד שליחת אירוע השרת ודוחות קמפיין מצרפיים; מידע גולמי נשמר אצל AppsFlyer לפי תקופת השמירה שלה במסגרת ההסכם איתנו
15תמיכה ומענה לפניותתוכן פניותביצוע חוזה; אינטרס לגיטימיעד 3 שנים מסיום הטיפול, אלא אם נדרש להגנה מפני תביעה
16עמידה בחובות חוקיות, מענה לרשויות, הגנה משפטיתלפי הצורךחובה חוקית; אינטרס לגיטימילפי הדין ותקופת ההתיישנות
17פדיון קלפים (ישראל; רק אם תבקשו)צילום מסמך זיהוי, סלפי, פרטי בנק, רשומות בקשה ותשלוםחובה חוקית (מס, איסור הלבנת הון); ביצוע חוזהכנדרש לפי דיני המס ואיסור הלבנת הון בישראל, בדרך כלל 7 שנים
18הודעות מערכת תפעוליות למפעילמזהים פנימיים ומונים מצטברים בלבדאינטרס לגיטימי (תפעול)זמני

5.2 כשהבסיס הוא אינטרס לגיטימי, ערכנו איזון מול זכויותיכם, ותוכלו להתנגד (סעיף 11.5). כשהבסיס הוא הסכמה, ניתן לבטלה בכל עת מבלי שהדבר ישפיע על חוקיות העיבוד שקדם לביטול.


6. קבלת החלטות אוטומטית ופרופיילינג

6.1 דירוג החפיסה (Deck) וחשיפה: סדר הצגת התוכניות והפרופילים נקבע אוטומטית לפי העדפות התוכנית שלכם, פעילות באפליקציה, קרבה גיאוגרפית (ברמת עיר), עדכניות ומידת השלמת הפרופיל. בנוסף: Boost בתשלום מעלה לזמן מוגבל את בולטות התוכנית; תג אימות והגבלות אכיפה (לרבות הגבלת חשיפה של חשבון שהפר את הכללים) משפיעים על הסדר ועל ההכללה; חסימות הדדיות מסתירות את הצדדים זה מזה; והעדפות גיל ומגדר שמארח הגדיר לתוכנית קובעות למי היא תוצג (6.2).

6.2 העדפות מארח: מארח יכול להגדיר טווח גילאים ומגדר מועדף לתוכנית שלו. האפליקציה משתמשת בכך כדי לקבוע למי תוצג התוכנית ומי יוכל לבקש להצטרף. ההחלטה הסופית על אישור משתתף היא של המארח (אדם).

6.3 בדיקות תמונה אוטומטיות: תמונה ללא פנים גלויות או תמונה כפולה נדחית אוטומטית, ואתם מתבקשים להעלות תמונה אחרת. ניתן לערער ולבקש בדיקה אנושית דרך support@afterup.co.il.

6.4 הגבלות קצב ומניעת ספאם: מגבלות אוטומטיות על תדירות פעולות (למשל הודעות, בקשות, סופר-לייקים יומיים) כדי למנוע הטרדה וספאם.

6.5 אכיפה: החלטות על אזהרה, הסתרה, הגבלה, הקפאה או חסימה של חשבון מתקבלות בידי בני אדם בצוות שלנו, בסיוע דיווחים ובדיקות אוטומטיות. שלושה סוגי פעולות מתבצעים אוטומטית: חסימה זמנית לצורכי אבטחה (למשל ניסיונות התחברות חריגים), דחיית תמונה שאינה עומדת בכללים (6.3), ודחיית הרשמה או סגירת חשבון כשתאריך הלידה שהוצהר מעיד על גיל מתחת ל-18. על כל אחת מהן ניתן לערער ולקבל בדיקה אנושית (6.6).

6.6 זכותכם: לבקש הסבר על החלטה שנוגעת לכם, להביע עמדה, ולבקש בדיקה אנושית, דרך support@afterup.co.il או ערוצי הערעור המתוארים בתנאי השימוש (https://afterup.io/terms).


7. עם מי אנחנו משתפים מידע

7.1 ספקים ומקבלי מידע

הספקים הבאים מקבלים מידע כמתואר. "מעבד" מעבד מידע עבורנו לפי הסכם עיבוד מידע ורק למטרה המצוינת; "בעל שליטה עצמאי" או "משותף" מעבד את המידע גם לפי תנאיו שלו. לספקים בארה"ב אנו מסתמכים על הסמכת הספק ל-Data Privacy Framework (DPF) כשהיא בתוקף, ואחרת על סעיפים חוזיים סטנדרטיים (SCCs), ובבריטניה עם ה-Addendum או IDTA (סעיף 8.2).

ספק תפקיד מטרה מידע מדינה/אזור אמצעי הגנה בהעברה
Supabaseמעבדאחסון, מסד נתונים, הזדהות (OTP, Apple, Google), קבצים, פונקציות שרתכל נתוני החשבון והשירותאחסון באיחוד האירופי (גרמניה)אחסון באיחוד האירופי; ספק אמריקאי - SCCs/DPF; הסכם עיבוד
ספק שליחת SMS דרך Supabase Auth (למשל Twilio)מעבדשליחת קוד OTPמספר טלפון, קודארה"בSCCs/DPF
Cloudinaryמעבדאחסון והגשת מדיה (תמונות פרופיל, מדיה בצ'אט, סטוריז, שערי תוכניות, קליפים)קובצי תמונה/וידאוארה"ב (רשת הגשה גלובלית)SCCs/DPF
AWS Rekognition (Amazon Web Services)מעבדבדיקה אוטומטית שרואים פנים בתמונות פרופיל (איתור פנים בלבד, ללא זיהוי)תמונות פרופיל; אלינו חוזרת תוצאת הבדיקהאחסון ועיבוד באיחוד האירופי (גרמניה, פרנקפורט)אחסון באיחוד האירופי; ספק אמריקאי - SCCs/DPF; הסכם עיבוד
Sentryמעבדניטור שגיאות וקריסותדוחות שגיאה, גרסה, מזהה משתמש פנימיאחסון באיחוד האירופיאחסון באיחוד האירופי; ספק אמריקאי - SCCs/DPF; הסכם עיבוד
Mixpanelמעבדאנליטיקס מוצראירועי שימוש ופרופיל אנליטיקס (3.12)אחסון באיחוד האירופיאחסון באיחוד האירופי; ספק אמריקאי - SCCs/DPF; הסכם עיבוד
Google (Firebase Cloud Messaging) ו-Apple (שירות ההתראות ב-iOS)מעבדשליחת התראותאסימון התראות (FCM), כותרת ותוכן ההתראה (עשויים לכלול שם תצוגה ותצוגה מקדימה של הודעה)ארה"בSCCs/DPF
RevenueCatמעבדניהול רכישות ACמזהה משתמש, מוצר, עסקה, מחיר, מטבעארה"בSCCs/DPF
Apple App Store / Google Playבעלי שליטה עצמאייםתשלום בחנות, החזרים, התחברות (Sign in with Apple / Google Sign-In)לפי תנאי החנות; מזהה OAuth ואימיילארה"ב / אירלנדלפי תנאי הפרטיות של Apple ו-Google
Mapboxמעבדהצגת מפותכתובת IP, אזור המפה הנצפה; טלמטריית שימוש ומיקום של ה-SDK לפי מדיניות הפרטיות של Mapbox (3.3)ארה"בSCCs/DPF
Google Maps Platform (Places, Geocoding)מעבדהשלמת שמות מקומות, תמונות מקום, המרת שם עיר לקואורדינטותשאילתות חיפוש, שם עירארה"בSCCs/DPF
Google Fontsספק עצמאיטעינת גופנים באפליקציהכתובת IPארה"בלפי מדיניות הפרטיות של Google
Meta Platforms Ireland / Meta Platforms, Inc.בעלת שליטה משותפת (איסוף והעברה) ועצמאית (עיבוד לאחר מכן)מדידת פרסום (אירוע שרת ב-Conversions API, Pixel באתר, דיווחי ייחוס המתקבלים מ-AppsFlyer)מזהים מגובבים, IP, UA, עוגיות Meta, אירועי אתר; דיווחי התקנה ואירועים מ-AppsFlyer (מצרפיים דרך SKAdNetwork ב-iOS; עם מזהה הפרסום באנדרואיד)אירלנד / ארה"בSCCs/DPF; ראו 3.13
AppsFlyer Ltd.מעבדתייחוס התקנות ומדידת קמפיינים (שותף מדידה למובייל)אירועי SDK (התקנה, סשנים, השלמת הרשמה), IDFV ונתוני SKAdNetwork (iOS), מזהה הפרסום של Google ומזהי מכשיר (אנדרואיד), IP, דגם מכשיר, מערכת הפעלה, שפה, גרסת אפליקציה, מועד התקנהישראל; אחסון בארה"ב (האזור הגלובלי של AppsFlyer); מעבדת שהיא חברה ישראלית; הסכם עיבוד מידע + SCCsישראל מוכרת כנאותה להעברות מהאיחוד האירופי/בריטניה; אחסון בארה"ב - SCCs; הסכם עיבוד מידע; ראו 3.13
TikTok (TikTok Technology Limited, אירלנד / TikTok Inc., ארה"ב)בעלת שליטה עצמאית (עיבוד למטרותיה)פלטפורמת פרסום לקמפיינים שלנו; מקבלת דיווחי ייחוס דרך AppsFlyer בלבד (אין SDK של TikTok באפליקציה)דיווחי התקנה ואירועים (מצרפיים דרך SKAdNetwork ב-iOS; עם מזהה הפרסום באנדרואיד)אירלנד / ארה"בלפי תנאי העסקים של TikTok; SCCs/DPF; ראו 3.13
Vercelמעבדאירוח האתר ופאנל הניהוליומני שרת, IPארה"ב (רשת גלובלית)SCCs/DPF
Resend ו-Google (Gmail)מעבדיםשליחה וקבלה של מיילים מטפסי האתרפרטי הטופסארה"בSCCs/DPF
Telegramמעבדהתראות תפעוליות פנימיות למפעיל (למשל "הרשמה חדשה", "דיווח חדש")מזהים פנימיים ומונים מצטברים בלבד - ללא שם, טלפון, תמונה או תוכןמחוץ לישראל ולאיחוד האירופיצמצום למזהים פנימיים שאינם מזהים אתכם ללא גישה למערכותינו
הבנק שלנו (ישראל)בעל שליטה עצמאיביצוע העברות בנקאיות לתשלומי פדיון קלפים (3.17)שם בעל החשבון, פרטי בנק, סכוםישראללפי דיני הבנקאות בישראל

אנו בודקים שכל מעבד מתחייב לרמת הגנה שאינה פחותה מזו שבמדיניות זו.

7.2 משתמשים אחרים

  • פרופיל ציבורי: שם התצוגה, גיל, מגדר, תמונות, ביו, תשובות לשאלות, העדפות תוכנית, רשימת משאלות, קליפ מוזיקה, עיר, תג אימות, קישורים לרשתות חברתיות ושדות וולונטריים שמילאתם (גובה, עיסוק, שפות) גלויים למשתמשים רשומים.
  • פרופיל פרטי: אם הפעלתם פרופיל פרטי, הפרופיל שלכם אינו מוצג בגילוי הכללי ובהצעות; הוא נשאר גלוי למשתמשים שאתם מקיימים איתם קשר באפליקציה (למשל עוקבים שאישרתם, מארחים של תוכניות שביקשתם להצטרף אליהן, משתתפים בתוכניות משותפות ושיחות קיימות). ההגדרה נשמרת גם אם ביטלתם בקשת מחיקה ושחזרתם את החשבון.
  • תוכניות: תוכנית שיצרתם מוצגת למשתמשים העונים להעדפות שהגדרתם, עם מיקום מטושטש. מארח רואה את הפרופיל של מי שביקש להצטרף. משתתפים מאושרים רואים את הכתובת המדויקת, את שאר המשתתפים בצ'אט הקבוצתי, ואת הטלפון ליצירת קשר של המארח אם המארח מילא אותו.
  • צ'אט וסטוריז: הודעות גלויות לנמעניהן; סטוריז גלויים למשתמשים רשומים שיכולים לראות את הפרופיל שלכם (בכפוף להגדרת פרופיל פרטי ולחסימות); בעל הסטורי רואה מי צפה והגיב.
  • פעולות: "פינג", מעקב, לייקים ובקשות נראים לצד השני. חסימה אינה נמסרת לנחסם.
  • מה לא מוצג: מספר הטלפון של החשבון, האימייל, כתובת ה-IP, אסימון ההתראות, סלפי האימות ונתוני האימות, הערות פנימיות ורשומות אכיפה שלכם אינם מוצגים למשתמשים אחרים. אם מילאתם "טלפון ליצירת קשר" בפרופיל, הוא מוצג רק למשתתפים שאישרתם לתוכנית שלכם, כדי שיוכלו ליצור איתכם קשר (למשל בוואטסאפ או בשיחה); ניתן למחוק אותו מהפרופיל בכל עת.

7.3 מארחים ומקומות

מארח אינו סוכן שלנו. מה שאתם מוסרים למארח בצ'אט או במפגש נמצא באחריותו. איננו מעבירים פרטים שלכם למקומות בילוי.

7.4 רשויות ודרישות חוק

נמסור מידע לרשויות אכיפה, בתי משפט או רגולטורים כאשר הדין מחייב זאת (צו, דרישה חוקית תקפה), וכן במצבי חירום שבהם קיים סיכון ממשי לחיים או לבטיחות. נדווח על חשד לניצול מיני של ילדים לגופים המוסמכים (כגון NCMEC) במקום שהדין מחייב, ונשמור את התוכן הרלוונטי לתקופה שהדין מחייב.

7.5 שינוי מבני

במיזוג, רכישה, מכירת נכסים או הליך דומה, מידע עשוי לעבור לישות הקולטת בכפוף למדיניות זו; נודיע לכם מראש על שינוי בזהות בעלת השליטה במאגר.

7.6 בהסכמתכם

בכל מקרה אחר נשתף מידע רק אם ביקשתם או הסכמתם לכך.

7.7 איננו מוכרים מידע אישי

איננו מוכרים מידע אישי תמורת כסף, ואיננו מעבירים אותו לצדדים שלישיים לשיווק עצמאי שלהם. שליחת אירועי המדידה ל-Meta, ונתוני ייחוס דרך AppsFlyer ל-Meta ול-TikTok (3.13), עשויה להיחשב "שיתוף" או "מכירה" לפי ההגדרות הרחבות של חוקי מדינות מסוימות בארה"ב; ראו סעיף 15.2 לזכות ההימנעות.


8. העברת מידע בין מדינות

8.1 אנחנו חברה ישראלית והצוות שלנו ניגש למידע מישראל. מסד הנתונים המרכזי ובדיקות התמונה האוטומטיות מאוחסנים באיחוד האירופי (גרמניה), וחלק מהספקים פועלים בארה"ב או ברשתות גלובליות. צוותי תמיכה של הספקים עשויים לגשת למידע ממדינות נוספות לפי הסכמי העיבוד. המידע שלכם עשוי לכן להיות מעובד מחוץ למדינת מגוריכם. שותף המדידה שלנו AppsFlyer (סעיף 3.13) הוא חברה ישראלית ושומר את נתוני המדידה בארה"ב (ראו סעיף 7.1); שותפי הפרסום שלנו Meta ו-TikTok מקבלים את דיווחי הייחוס באירלנד ובארה"ב.

8.2 משתמשים באיחוד האירופי/האזור הכלכלי האירופי ובבריטניה: ישראל מוכרת בהחלטת נאותות של הנציבות האירופית (שאושרה מחדש ב-2024) ובתקנות הנאותות של בריטניה, כך שהעברה אלינו אינה דורשת אמצעים נוספים. העברות לספקים בארה"ב מבוססות על Data Privacy Framework (כולל ההרחבה לבריטניה) כשהספק מוסמך לו, או על סעיפים חוזיים סטנדרטיים של הנציבות (ובבריטניה IDTA/Addendum), וככל שנדרש - הערכת העברה. ניתן לבקש עותק מהאמצעים דרך support@afterup.co.il.

8.3 משתמשים בישראל: העברות לחו"ל מבוצעות לפי תקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001, בין היתר למדינות בעלות רמת הגנה נאותה (האיחוד האירופי) ולספקים שהתחייבו בכתב לעמוד בתנאי החזקת מידע לפי הדין הישראלי ובאבטחה נאותה.

8.4 משתמשים במדינות אחרות: העברות מבוצעות בהתאם לדין המקומי (למשל LGPD סעיף 33, APP 8, PIPEDA), עם אמצעי הגנה חוזיים.


9. תקופות שמירה

9.1 טבלת שמירה:

מידע תקופה
חשבון ופרופיל (כולל תמונות, העדפות, רשימת משאלות, קליפ)עד בקשת מחיקה; אנונימיזציה והסתרה מיידיות, 30 ימי חסד, ואז מחיקה לצמיתות (9.2)
הודעות צ'אט ומדיהעד מחיקת החשבון לצמיתות (עותק מקומי מוסר עם הסרת האפליקציה; במכשיר של המשתמש השני עשוי להישמר עותק לא-מקוון); הודעות בצ'אט קבוצתי עשויות להישאר ללא שמכם
סטוריזמוצג למשך 24 שעות, ואז בארכיון עד מחיקה לצמיתות על ידכם או מחיקת החשבון; צפיות ותגובות עם הסטורי; סטוריז פעילים נמחקים עם בקשת מחיקת חשבון
תוכניות, בקשות, מעקבים, פינגים, לייקיםעד מחיקת החשבון לצמיתות
סלפי אימות והחלטהסלפי: באחסון פרטי רק עד ההחלטה, נמחק עם סיום הבדיקה, ובכל מקרה בתוך 30 יום; רשומת ההחלטה (3.9) עד ביטול התג או מחיקת החשבון
תוצאות בדיקת תמונה (פנים/כפילות)עם התמונה, עד הסרתה או מחיקת החשבון
רשומות רכישה ויומן ACעד מחיקת החשבון לצמיתות; החנויות וספק ניהול הרכישות שומרים רשומות לפי כלליהם; רשומות חשבונאיות מצטברות שאינן מזהות אתכם לפי דין
קלפים שהתקבלועד מחיקת החשבון
דיווחים, חסימות ורשומות אכיפהעד מחיקת החשבון לצמיתות, בכפוף לשמירה לפי דין (למטה)
יומן ביקורת של הצוותכשהצוות שלנו מבצע מחיקת חשבון (במסגרת אכיפה או לבקשתכם דרך התמיכה), יומן הביקורת שומר רשומה מינימלית (שם התצוגה ומספר הטלפון שנמחקו, מועד ופעולה) כדי לתעד את הפעולה ולמנוע עקיפת חסימה; הגישה מוגבלת לצוות מורשה; תקופה: 7 שנים
רשומות הסכמהעד מחיקת החשבון לצמיתות; יומן אישור מינימלי (מזהה משתמש מגובב (SHA-256), סוג אירוע, גרסה, מועד, מקור) נשמר לתקופת ההתיישנות (בישראל 7 שנים)
IP ומועד התחברות אחרונהבפרופיל, מוחלף בכל התחברות, עד מחיקת החשבון
רישומי אבטחה (אירועי התחברות/התנתקות, מכשירים)עד מחיקת החשבון; יומני שרת של ספקי האירוח - לפי ברירת המחדל של הספק, לכל היותר 90 יום
אנליטיקס (Mixpanel)אצל הספק לפי הגדרת השמירה בחשבוננו, לכל היותר 5 שנים; נמחק לבקשתכם
שגיאות (Sentry)אצל הספק עד 90 יום
גיבוייםגיבויי מסד הנתונים מתחלפים במחזוריות; מידע שנמחק נעלם גם מהגיבויים בדרך כלל בתוך 90 יום; גיבוי משמש רק לשחזור כלל-מערכתי, ואם חשבון שנמחק ישוחזר כך - נמחק אותו שוב
פניות תמיכהעד 3 שנים מסיום הטיפול, אלא אם נדרש להגנה מפני תביעה
טפסי אתר (רשימת המתנה)עד 12 חודשים מקבלת הטופס או עד בקשת מחיקה, המוקדם מביניהם
מסמכי זהות, פרטי בנק ורשומות תשלום (רק אם תבקשו פדיון בישראל)כנדרש לפי דיני המס ואיסור הלבנת הון בישראל, בדרך כלל 7 שנים; בקשה שנזנחה/נדחתה נמחקת תוך זמן סביר

גרסה 3.1 (2 בספטמבר 2026): הבהרה שהתראות פוש על פעילות בחשבון, חידושים באפליקציה ופעילות סביבכם הן חלק מהשירות וניתנות לכיבוי בהגדרות המכשיר;; וסעיפי המיקום (0.1, 3.3, 4.1, 5) עודכנו: מיקום המכשיר נשלח לשרת בזמן שימוש ועשוי להישמר כמיקום אחרון ידוע להצגת תוכניות, אנשים ומרחק משוער; ביצירת תוכנית חופשה נשמר מיקום המוצא.

שמירה לפי דין: בכל המקרים שבטבלה, אנו רשאים לשמור מידע מעבר לתקופה המצוינת כשהדין מחייב זאת, כשמתנהל הליך משפטי או בירור תלוי, כשנדרש לשמר ראיות (למשל דיווחים על ניצול מיני של ילדים, לתקופה שהדין קובע), או כשנדרש להגנה מפני תביעות - ואז לתקופה הנדרשת בלבד ובגישה מוגבלת. איננו מוחקים חשבונות אוטומטית בשל חוסר פעילות.

9.2 מחיקת חשבון - מה קורה בפועל:

  • עם הבקשה: הפרופיל מוסתר ועובר אנונימיזציה מיידית - שם התצוגה מוחלף בכיתוב "Deleted User" (משתמש שנמחק); תמונות, ביו, תאריך לידה, עיר ומדינה, העדפות מוזיקה, קישורים לרשתות חברתיות וטלפון ליצירת קשר מוסרים; החשבון מסומן כמחוק ואינו מופיע לאחרים. הסטוריז הפעילים נמחקים מיד. שיחות עם משתמשים אחרים נשארות אצלם עם הסימון "Deleted User" למשך 30 הימים. יתרת ה-AC נשמרת בשלב זה.
  • 30 ימי חסד: התחברות בתוך 30 יום מבטלת את המחיקה ומשחזרת את החשבון, הפרופיל (כולל הגדרת פרופיל ציבורי/פרטי) ויתרת ה-AC; סטוריז שנמחקו עם הבקשה אינם משוחזרים.
  • מחיקה לצמיתות: לאחר 30 הימים המחיקה מתוזמנת ומבוצעת בסמוך לאחר מכן: הודעות, שיחות, סטוריז וארכיון, תוכניות, מעקבים, חסימות, דיווחים (כמדווח וכמדווח עליו), רשומות רכישה, רשומות הסכמה, נתוני אימות ופרטי החשבון נמחקים, ומספר הטלפון משתחרר. קובצי המדיה נמחקים מספק המדיה. הודעות ושיחות אישיות נמחקות מהשרתים שלנו; במכשיר של המשתמש השני עשוי להישמר עותק לא-מקוון. הודעות ששלחתם בצ'אט קבוצתי של תוכנית עשויות להישאר ללא שמכם.
  • מה נשאר: רשומת ביקורת מינימלית של הצוות (9.1), יומן אישור מינימלי של ההסכמה (3.14), רשומות חשבונאיות מצטברות שאינן מזהות אתכם, רשומות אימות זהות ותשלום אם פדיתם קלפים (3.17, למשך תקופת השמירה שבדין), ומידע שעלינו לשמור לפי דין או להליך תלוי (9.1).
  • AC: יתרת ה-AC אובדת עם המחיקה לצמיתות. לפני המחיקה הסופית ניתן לבקש במייל support@afterup.co.il החזר על AC שנרכשו בכסף ולא נוצלו; ההחזר ניתן מקום שבו הדין החל או כללי החנות מזכים אתכם בו, ואחרת לפי שיקול דעתנו הסביר, כמפורט בתנאי השימוש.

10. אבטחת מידע

10.1 אנו מיישמים אמצעים טכניים וארגוניים בהתאם לתקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017, ול-GDPR סעיף 32, בהם: הצפנה בתעבורה (TLS) ובאחסון; בקרת גישה ברמת השורה במסד הנתונים (RLS) שמגבילה כל משתמש למידע שהוא רשאי לראות; הרשאות מינימליות לצוות; הזדהות דו-שלבית חובה לפאנל הניהול; יומני ביקורת על פעולות צוות; גיבויים; אחסון מסמכים רגישים (סלפי אימות, מסמכי זהות לפדיון קלפים) במאגרי אחסון פרטיים (private buckets); הגשת מדיה של משתמשים דרך ספק המדיה בכתובות ייחודיות; ובדיקות אבטחה.

10.2 שום שיטה אינה מאובטחת במאה אחוז. שמרו על קוד ה-OTP שלכם, אל תשתפו אותו, והתנתקו ממכשירים שאינם שלכם.

10.3 אירוע אבטחה: במקרה של אירוע אבטחה נעריך את היקפו ואת הסיכון, ונודיע לרשות המוסמכת (בישראל - הרשות להגנת הפרטיות; באיחוד האירופי - רשות הפיקוח הרלוונטית, בתוך 72 שעות מרגע המודעות כשהדין מחייב; בבריטניה ICO; בקנדה OPC; באוסטרליה OAIC; בברזיל ANPD; בארה"ב רשויות מדינתיות) ולמשתמשים שנפגעו, בתוך המועד ובהתאם לסף שקובע הדין החל.


11. הזכויות שלכם ואיך לממש אותן

11.1 עיון וגישה: לדעת אם אנו מחזיקים מידע עליכם, ולקבל אותו (חוק הגנת הפרטיות סעיף 13; GDPR סעיף 15).

11.2 העתק וניידות: כיום אין כלי ייצוא אוטומטי באפליקציה. ניתן לבקש עותק של המידע שלכם בפורמט נפוץ וקריא במייל support@afterup.co.il, ונספק אותו בתוך המועדים הקבועים בדין.

11.3 תיקון: את רוב פרטי הפרופיל ניתן לערוך ישירות באפליקציה. לתיקון מידע אחר פנו אלינו.

11.4 מחיקה: באפליקציה (הגדרות > מחיקת חשבון, באישור כפול), בדף https://afterup.io/delete-account, או במייל support@afterup.co.il. ראו סעיף 9.2 לתהליך ולתקופת החסד של 30 יום. באפליקציה ניתן למחוק בעצמכם תמונות, סטוריז (כולל מהארכיון), תוכניות והודעות; מחיקה של פריטי מידע אחרים בלי למחוק את החשבון ניתן לבקש דרך התמיכה, כשהדין מקנה זאת וככל שהדבר ישים טכנית.

11.5 הגבלה והתנגדות: לבקש להגביל עיבוד, ולהתנגד לעיבוד המבוסס על אינטרס לגיטימי (למשל אנליטיקס ומדידת קמפיינים) ולדיוור ישיר בכל עת.

11.6 ביטול הסכמה: תג אימות - בקשו מאיתנו בכל עת לבטל את התג ולמחוק את סלפי האימות ונתוני האימות שלכם; דיוור שיווקי - סעיף 12; הרשאת מיקום - בהגדרות המכשיר; התראות - בהגדרות המכשיר; מדידת Meta ואנליטיקס - סעיפים 3.13 ו-13.1.

11.7 מידע על החלטות אוטומטיות: סעיף 6.

11.8 תלונה אלינו: כתבו ל-support@afterup.co.il עם "תלונת פרטיות" בנושא. נאשר קבלה בתוך 30 יום (ובבריטניה, כנדרש ב-Data (Use and Access) Act 2025) ונשיב בלי עיכוב מיותר.

11.9 תלונה לרשות: בישראל - הרשות להגנת הפרטיות (www.gov.il/he/departments/the_privacy_protection_authority); באיחוד האירופי - רשות הפיקוח במדינת מגוריכם; בבריטניה - ICO; בקנדה - OPC (ובקוויבק CAI); באוסטרליה - OAIC; בברזיל - ANPD; בארה"ב - התובע הכללי של מדינתכם או הרשות המוסמכת (בקליפורניה CPPA).

11.10 איך פונים ומה קורה אחר כך: שלחו מייל מכתובת הקשורה לחשבון או פנו דרך האפליקציה. כדי להגן עליכם נאמת את זהותכם (למשל אישור דרך מספר הטלפון של החשבון) לפני שנמסור או נמחק מידע. נשיב בתוך המועד הקבוע בדין החל (בישראל בדרך כלל בתוך 30 יום; לוחות זמנים אזוריים בסעיף 15); אם נדרש זמן נוסף, כפי שהדין מתיר, נודיע לכם ונסביר. המימוש חינם, אלא אם הבקשות חוזרות ובלתי סבירות באופן מובהק. לא נפלה אתכם לרעה בשל מימוש זכויות.

11.11 מיופה כוח: ניתן לפנות באמצעות מיופה כוח, בצירוף הרשאה בכתב; נאמת גם את זהות המשתמש עצמו.


12. דיוור ותקשורת

12.1 הודעות שירות (קוד התחברות, אישור הצטרפות, הודעה חדשה, עדכון תוכנית, אבטחה, שינויים במסמכים המשפטיים) נשלחות כחלק מהשירות ואינן דורשות הסכמה. כך גם התראות פוש על פעילות בחשבונכם, על תכונות וחידושים באפליקציה ועל פעילות ומשתמשים חדשים באזורכם: הן חלק מהשירות. ניתן לכבות התראות פוש בהגדרות המכשיר בלבד; אין כרגע אפשרות לבחור סוגי התראות בתוך האפליקציה. הודעות אבטחה וחובה יישלחו בערוץ זמין.

12.2 דיוור שיווקי ב-SMS ובדוא"ל (מבצעים, שיתופי פעולה, קמפיינים) נשלח רק אם סימנתם בעת ההרשמה או לאחר מכן את תיבת ההסכמה הנפרדת, שאינה מסומנת מראש ואינה תנאי לשימוש. כל הודעה שיווקית מסומנת כנדרש בדין החל עליה (בישראל: "פרסומת", באנגלית: "Advertisement") וכוללת את פרטינו ודרך פשוטה וחינמית להסרה באותו ערוץ, כנדרש בסעיף 30א לחוק התקשורת (בזק ושידורים), התשמ"ב-1982, ב-CAN-SPAM, ב-CASL ובדינים דומים.

12.3 הסרה: כתבו ל-support@afterup.co.il; ב-SMS שיווקי - השיבו "הסר"; במייל שיווקי - לחצו על קישור ההסרה. התראות פוש ניתן לכבות בהגדרות המכשיר. ההסרה נכנסת לתוקף בהקדם ולא יאוחר מהמועד הקבוע בדין.

12.4 דיוור ישיר (חוק הגנת הפרטיות סעיפים 17ג-17ו): אם נפנה אליכם על בסיס אפיון (למשל לפי עיר או העדפות), הפנייה תציין שהיא דיוור ישיר, שמקור המידע הוא הפרטים שמסרתם לנו בהרשמה ובשימוש, ואת זכותכם להימחק מרשימת הדיוור בכל עת במייל support@afterup.co.il.

12.5 איננו מוסרים את פרטי הקשר שלכם למפרסמים אחרים.


13. עוגיות, ערכות פיתוח (SDK) ומעקב

13.1 באפליקציה

רכיב מטרה שליטה
Supabaseהפעלת השירות (חיוני)אין, חיוני
RevenueCatרכישות AC (חיוני לרכישה)אין, חיוני
Firebase Cloud Messagingהתראותהגדרות המכשיר
Sentryדיווחי קריסה (עם מזהה משתמש פנימי בלבד)חיוני לתקינות; ניתן להתנגד דרך התמיכה
Mixpanelאנליטיקס מוצר (פועל כיום לכל המשתמשים)בקשה להפסקה דרך support@afterup.co.il; אין כיום מתג באפליקציה
Mapbox, Google Places/Geocodingמפה וחיפוש מקומותהרשאת מיקום; הגדרת הטלמטריה של Mapbox נמצאת בתפריט הייחוס (ⓘ) במפה; חיפוש לפי בחירתכם
Cloudinaryהצגת מדיהחיוני
Google Fontsגופניםחיוני לתצוגה
Sign in with Apple / Google Sign-Inהתחברותרק אם בחרתם להתחבר כך
AWS Rekognitionבדיקה אוטומטית שרואים פנים בתמונות פרופיל (איתור פנים בלבד)חיוני לכללי הפרופיל
AppsFlyer SDK (ייחוס)ייחוס התקנות ומדידת קמפיינים (iOS ואנדרואיד): אירועי התקנה, פתיחה ראשונה וסשנים ואירוע השלמת הרשמה, עם דגם מכשיר, גרסת מערכת הפעלה ואפליקציה, שפה, מועד התקנה ו-IP; ב-iOS מזהה הספק (IDFV) ו-SKAdNetwork, ללא IDFA, ללא בקשת מעקב; באנדרואיד מזהה הפרסום של Google; דיווחים ל-Meta ול-TikTok (3.13)בקשה להפסקה דרך support@afterup.co.il, תכובד לגבי אירועים עתידיים; באנדרואיד ניתן לאפס או להגביל את מזהה הפרסום בהגדרות Google במכשיר; אין כיום מתג באפליקציה; שכבת הסכמה לאיחוד האירופי/בריטניה ממתינה (להלן)
  • ה-SDK של AppsFlyer באפליקציה: האפליקציה מטמיעה את ה-SDK של AppsFlyer ב-iOS ובאנדרואיד, כמתואר בסעיף 3.13; הוא מאותחל עם פתיחת האפליקציה. אין באפליקציה SDK של Meta ואין SDK של TikTok; Meta ו-TikTok מקבלות דיווחי ייחוס מ-AppsFlyer בלבד. איננו מעבירים ל-SDK את מזהה המשתמש שלנו, שם, טלפון או אימייל, איננו קוראים את ה-IDFA ואיננו מציגים בקשת מעקב (App Tracking Transparency); ב-iOS הייחוס נעשה באמצעות מזהה הספק (IDFV) ו-Apple SKAdNetwork (דיווחים מצרפיים), ובאנדרואיד באמצעות מזהה הפרסום של Google, שניתן לאפס או להגביל בהגדרות Google במכשיר. ה-SDK שומר מזהים על המכשיר. בנוסף, אירוע מדידה נשלח מהשרת שלנו ל-Meta (Conversions API), ו-Meta Pixel פועל באתר בלבד.
  • איחוד אירופי ובריטניה: נכון למועד זה האנליטיקס (Mixpanel) ואירועי המדידה (ה-SDK של AppsFlyer מאותחל עם פתיחת האפליקציה, וכן אירוע השרת ל-Meta) פועלים לכל המשתמשים, ללא שכבת הסכמה מקדימה באפליקציה. שכבת הסכמה למשתמשים באיחוד האירופי ובבריטניה, שתגביל אנליטיקס ומדידה עד להסכמה, תופעל לפני שהשירות ישווק למשתמשים באיחוד האירופי, באזור הכלכלי האירופי (EEA) או בבריטניה. עד אז ניתן לבקש הפסקה דרך support@afterup.co.il, ונכבד את הבקשה לגבי עיבוד עתידי.

13.2 באתר afterup.io

  • עוגיות חיוניות: תפעול האתר, זכירת בחירתכם בבאנר העוגיות (נשמר מקומית בדפדפן), והעדפת גרסה מקומית של האתר לפי מדינה.
  • Meta Pixel (שיווק): דפי נחיתה של קמפיינים וקישורי קמפיין טוענים את Meta Pixel עם פתיחת הדף. בדפי האתר הראשיים מוצג באנר עוגיות; נכון למועד זה הבאנר אינו מונע את טעינת הפיקסל בדפי הקמפיין. התניית טעינת הפיקסל בהסכמה מראש למבקרים מהאיחוד האירופי ומבריטניה תושלם לפני שהאתר ישווק למבקרים מהאיחוד האירופי, מהאזור הכלכלי האירופי (EEA) או מבריטניה. בינתיים ניתן למנוע את הפיקסל בהגדרות הדפדפן, בחוסם מעקב, או בהגדרות הפרסום בחשבון Meta שלכם.
  • אין Google Analytics או כלי מעקב נוספים באתר נכון למועד זה.
  • Global Privacy Control (GPC): האתר אינו מזהה כיום אות GPC באופן אוטומטי. אנו פועלים לכבד אותות GPC; עד אז, בקשות הימנעות משיתוף/מכירה מתקבלות במייל (13.3) ומכובדות.

13.3 "אל תמכור או תשתף" (ארה"ב)

ניתן לבקש שלא נשתף את המידע שלכם לצורכי מדידה או פרסום ממוקד במייל support@afterup.co.il (נושא: "Do Not Sell or Share"). ראו סעיף 15.2.


14. ילדים וקטינים

14.1 השירות מיועד לבני 18 ומעלה בלבד, בכל מדינה. אנו אוכפים זאת בהצהרת תאריך לידה ובחסימה אוטומטית של גיל מתחת ל-18, משתמשים בדירוג הגיל 18+ בחנויות האפליקציות, ועשויים להשתמש באותות גיל של מערכת ההפעלה או החנות כשהם זמינים - לצורכי עמידה בדרישות הגיל בלבד.

14.2 איננו אוספים ביודעין מידע מקטינים. אם נגלה שמשתמש מתחת לגיל 18 פתח חשבון, נסגור את החשבון ונמחק את המידע בהתאם לסעיף 9.2, והחשבון לא ישוחזר.

14.3 דיווח על קטין: support@afterup.co.il עם הנושא "בטיחות ילדים", או דרך כפתור הדיווח באפליקציה. מדיניות בטיחות הילדים המלאה: https://afterup.io/child-safety.


15. נספחים אזוריים

15.1 האיחוד האירופי / האזור הכלכלי האירופי ובריטניה

  • בסיסים חוקיים: ראו טבלת סעיף 5. לקטגוריות מיוחדות: תוכן פרופיל שבחרתם להציג לאחרים - סעיף 9(2)(ה), ככל שסעיף 9 חל (סעיף 4.4).
  • חובה או רשות למסור מידע ותוצאות הסירוב: סעיף 0.2.
  • זכויות: גישה, תיקון, מחיקה, הגבלה, ניידות, התנגדות (לרבות לדיוור ישיר בכל עת), ביטול הסכמה, ואי-כפיפות להחלטה אוטומטית בלבד (סעיפים 15-22). מימוש לפי סעיף 11, חינם, מענה בתוך חודש (ניתן להאריך בחודשיים במקרים מורכבים, בהודעה).
  • נציגים: סעיף 1.4. ממונה הגנת מידע: סעיף 1.3.
  • תלונה: לכל רשות פיקוח באיחוד, בפרט במדינת מגוריכם או עבודתכם; בבריטניה ל-ICO (ico.org.uk). בבריטניה נאשר תלונה אלינו בתוך 30 יום ונשיב ללא עיכוב.
  • העברות: סעיף 8.2.
  • ePrivacy: סעיף 13.1 (מצב נוכחי ומועד הפעלת שכבת ההסכמה).
  • ילדים: סעיף 14 (18+).
  • שינוי והודעה: שינויים מהותיים יימסרו לפחות 30 יום מראש (סעיף 16).

15.2 ארצות הברית (זכויות פרטיות מדינתיות)

הסעיף חל על תושבי מדינות עם חוקי פרטיות מקיפים (למשל קליפורניה, קולורדו, קונטיקט, וירג'יניה, טקסס, אורגון ואחרות). ייתכן שאיננו עומדים בספי התחולה של חלק מהחוקים; אנו מכבדים את הזכויות הבאות כמדיניות לכל משתמש בארה"ב.

  • קטגוריות מידע אישי שנאספו ב-12 החודשים האחרונים (במונחי CCPA), המקור, הנמסרים למטרה עסקית, והאם "נמכר"/"שותף":
קטגוריה דוגמאות מקור נמסר למטרה עסקית ל "נמכר"/"שותף"
מזהיםטלפון, אימייל מ-OAuth, מזהה משתמש, IP, אסימון התראות (FCM)אתם; המכשירהמעבדים בסעיף 7.1מזהים מגובבים, IP ו-UA ל-Meta (3.13); IP, מזהה הספק (IDFV, iOS) או מזהה הפרסום של Google (אנדרואיד) ל-AppsFlyer, ומזהה הפרסום הלאה ל-Meta ול-TikTok בדיווחי ייחוס באנדרואיד
רשומות אישיותשם, תאריך לידהאתםמעבדיםלא
מאפיינים מוגניםגיל, מגדראתםמעבדיםלא
מידע מסחרירכישות ACהחנויות, ספק הרכישותמעבדיםלא
פעילות באינטרנט/באפליקציהאירועי שימוש, צפיות, אירועי אפליקציה (התקנה, סשנים, השלמת הרשמה), עוגיות קמפייןהמכשיר; Meta (עוגיות קמפיין)Mixpanel, Sentry, Vercel, AppsFlyerאירועי אפליקציה דרך AppsFlyer ל-Meta ול-TikTok כשותפות ייחוס, ואירועי Pixel באתר ל-Meta, למדידת פרסום
גיאולוקציהמיקום המכשיר - נשלח לשרת בזמן שימוש ונשמר לכל היותר כמיקום אחרון ידוע; עיר - בשרת; מיקום מדויק של מקום התוכנית - למארחים, נחשף למשתתפים מאושרים; מיקום מטושטש - לכולםאתם; המכשירSupabase, Mapbox, Google Mapsלא
מידע חזותי/שמעתמונות, סרטוני סטורי, בחירת קליפ, סלפי אימותאתםCloudinary, Supabase (אחסון פרטי), AWS (איתור פנים)לא
מידע מקצועיעיסוק (אם מולא)אתםמעבדיםלא
הסקותדירוג החפיסהנוצר אצלנולא נמסרלא
מידע אישי רגישמיקום המכשיר (מיקום אחרון ידוע), פרטי התחברות (OTP), תוכן הודעותאתםמעבדים הנדרשים לשירותלא
  • מטרות: סעיף 5. גילוי למטרה עסקית: למעבדים בסעיף 7.1.
  • "מכירה"/"שיתוף" ופרסום ממוקד: שליחת פעילות באפליקציה ומזהה הפרסום (אנדרואיד) או מזהה הספק (iOS) ל-AppsFlyer ודיווחי הייחוס הנובעים מכך ל-Meta ול-TikTok, שליחת מזהים מגובבים, IP ו-UA ל-Meta (3.13) ו-Pixel באתר עשויים להיחשב "שיתוף" לפרסום התנהגותי חוצה-הקשרים (ולפי חלק מחוקי המדינות, "מכירה"). איננו מוכרים מידע תמורת כסף, ואיננו מוכרים או משתפים מידע רגיש או מידע של מי שידוע לנו שהוא מתחת לגיל 16.
  • הימנעות: מייל ל-support@afterup.co.il בנושא "Do Not Sell or Share". נכבד בקשה תוך 15 ימי עסקים, נפסיק שליחת אירועים עתידיים ונבקש מ-AppsFlyer, מ-Meta ומ-TikTok למחוק. ב-AppsFlyer הפעלנו את ההגדרה "הגבלת השימוש במידע אישי" עבור Meta והשבתנו את שיתוף המידע המתקדם ואת ההתאמה המתקדמת עבור Meta ו-TikTok. באנדרואיד ניתן גם לאפס או להגביל את מזהה הפרסום בהגדרות Google במכשיר, מה שמפסיק ייחוס ברמת המכשיר; ב-iOS לעולם לא נעשה שימוש ב-IDFA ולא מוצגת בקשת מעקב. האתר אינו מזהה כיום אות GPC באופן אוטומטי; אנו פועלים לכבד אותות GPC (13.2).
  • מידע רגיש: חלקו נחוץ לאספקת השירות שביקשתם (פרטי התחברות, תוכן ההודעות שאתם שולחים, מיקום מקום התוכנית שבחרתם) ומעובד למטרה זו בלבד; מיקום המכשיר נשמר לכל היותר כמיקום אחרון ידוע (סעיף 3.3). איננו משתמשים במידע רגיש להסקת מאפיינים או לפרסום, וניתן לבקש להגביל את השימוש בו למה שנחוץ לשירות.
  • זכויות: לדעת/לגשת, לקבל עותק (ניידות), לתקן, למחוק, להימנע ממכירה/שיתוף/פרסום ממוקד/פרופיילינג עם השפעה משמעותית, ואי-אפליה בגין מימוש זכויות (לא נמנע שירות, לא נשנה מחיר או איכות).
  • אימות: נאמת בקשות באמצעות מספר הטלפון של החשבון ומידע נוסף אם נדרש. מיופה כוח: מותר עם הרשאה חתומה; נאמת גם אתכם.
  • זמן מענה: בתוך 45 יום (ניתן להאריך ב-45 יום נוספים בהודעה). ערעור: אם דחינו בקשה, ניתן לערער במייל עם "Appeal" בנושא; נשיב בתוך 45 יום, וניידע אתכם על האפשרות לפנות לתובע הכללי של מדינתכם.
  • הודעה במועד האיסוף: סעיפים 3, 5 ו-9 מהווים את ההודעה. תמריצים כספיים: איננו מציעים תמריץ כספי תמורת מידע אישי; בונוסים ותגמולי הפניה ניתנים על פעולות באפליקציה ולא תמורת מסירת מידע או הסכמה למכירה/שיתוף. "Shine the Light" (קליפורניה): איננו מוסרים מידע לצדדים שלישיים לשיווק ישיר שלהם, ולכן אינו רלוונטי.
  • אין בוררות במדיניות פרטיות זו. הסדרי יישוב סכסוכים מופיעים בתנאי השימוש.

15.3 קנדה (PIPEDA וחוקים מחוזיים, לרבות קוויבק)

  • אנו אוספים, משתמשים ומגלים מידע אישי בהסכמה משמעותית ולמטרות שאדם סביר יראה כראויות, כמפורט בסעיפים 3 ו-5. ארבעת המרכיבים: מה נאסף (סעיף 3), עם מי משותף (סעיף 7), למה (סעיף 5), וסיכונים (העברה למדינות אחרות, סעיף 8; אין הצפנה מקצה לקצה, סעיף 3.5).
  • מידע מעובד ומאוחסן מחוץ לקנדה (גישה מישראל; אחסון באיחוד האירופי ובארה"ב) וכפוף לדיני אותן מדינות.
  • זכויות: גישה, תיקון, ביטול הסכמה (בכפוף להשלכות חוזיות: למשל בלי מספר טלפון לא ניתן להחזיק חשבון, ובלי הרשאת מיקום לא תוצג המפה), תלונה אלינו ול-OPC (priv.gc.ca). נשיב לבקשת גישה או תיקון בתוך 30 יום; אם נסרב, ננמק בכתב ונציין את זכות התלונה, ואם תיקון שנוי במחלוקת - נצרף לרשומה הערה על התיקון המבוקש. תלונות אלינו נבדקות בידי אדם ונשיב בכתב.
  • אירועי אבטחה: נתעד אירועים ונודיע ל-OPC ולנפגעים כשיש סיכון ממשי לנזק משמעותי.
  • CASL: דיוור מסחרי אלקטרוני רק בהסכמה מפורשת, עם זיהוי השולח ומנגנון הסרה (סעיף 12).
  • קוויבק (חוק 25): האחראי על הגנת המידע האישי: צוות הפרטיות של החברה, support@afterup.co.il. המידע מועבר אל מחוץ לקוויבק (סעיף 8). זמינות המדיניות בצרפתית: השירות אינו מוצע כיום בקוויבק; גרסה בצרפתית תסופק לפני שיוצע שם.

15.4 אוסטרליה (Privacy Act 1988, APPs)

  • סוגי המידע, דרכי האיסוף וההחזקה: סעיפים 3, 9 ו-10. מטרות: סעיף 5.
  • גילוי לחו"ל (APP 8): המידע מאוחסן ומעובד באיחוד האירופי (גרמניה) ובארה"ב על ידי הספקים בסעיף 7.1, והצוות שלנו ניגש אליו מישראל. ספקים מסוימים מפעילים רשתות הגשה גלובליות (למשל Vercel, Cloudinary), והתראות תפעוליות פנימיות (מזהים ומונים בלבד) עוברות דרך Telegram, ששרתיה מחוץ לישראל ולאיחוד האירופי.
  • גישה ותיקון (APP 12-13): סעיף 11; מענה בתוך 30 יום. אם נסרב, ננמק בכתב, נציין את זכות התלונה, ולבקשתכם נצרף לרשומה הצהרה על התיקון המבוקש.
  • תלונות: תחילה אלינו (support@afterup.co.il); נאשר קבלה, נבדוק ונשיב בכתב בתוך 30 יום. אם אינכם מרוצים, ניתן לפנות ל-OAIC (oaic.gov.au). ניתן גם לפנות ל-eSafety Commissioner בעניין פגיעה מקוונת.
  • אירועי אבטחה: נפעל לפי מנגנון ה-Notifiable Data Breaches.
  • מזהים ממשלתיים: איננו אוספים (למעט מסמכי זהות לפדיון קלפים בישראל, סעיף 3.17).

15.5 ברזיל (LGPD)

  • בסיסים חוקיים (סעיף 7): ביצוע חוזה (שורות 1-7, 10, 15 בטבלת סעיף 5), הסכמה (שורה 11), אינטרס לגיטימי (שורות 7-9, 12-15, 18), עמידה בחובה חוקית (שורות 16-17), ומימוש זכויות בהליכים. מידע רגיש (סעיף 11): מיקום אינו מידע רגיש לפי LGPD; תוכן שאתם בוחרים לשתף העשוי לחשוף את צנעת חייכם מטופל כמתואר בסעיף 4.
  • בעלי שליטה נוספים: Meta ו-TikTok (סעיף 3.13) וחנויות האפליקציות (סעיף 7.1) פועלים גם לפי תנאיהם.
  • זכויות (סעיף 18): אישור קיום עיבוד, גישה, תיקון, אנונימיזציה/חסימה/מחיקה של מידע מיותר, ניידות, מחיקת מידע שעובד בהסכמה, מידע על שיתוף, מידע על האפשרות לא להסכים והשלכותיה, ביטול הסכמה, עיון בהחלטות אוטומטיות (סעיף 6).
  • אחראי (encarregado): support@afterup.co.il.
  • העברה בינלאומית (סעיף 33): לפי סעיף 8, באמצעות סעיפים חוזיים סטנדרטיים של ANPD או מנגנון מוכר אחר, ככל שחל.
  • תלונה: ל-ANPD (gov.br/anpd).

16. שינויים במדיניות

16.1 נעדכן מדיניות זו כשהשירות או הדין משתנים. על שינוי מהותי (למשל מטרות חדשות, סוגי מידע חדשים, מעבדים מקטגוריה חדשה, שינוי בזכויות) נודיע לפחות 30 יום מראש במייל או בהודעה באפליקציה, ונבקש אישור מחדש של הגרסה החדשה באפליקציה. אנו רושמים את הגרסה שאישרתם, מועד האישור ושפת התצוגה.

16.2 בראש המסמך מופיעים מספר הגרסה ותאריך התחילה. גרסאות קודמות נשמרות אצלנו, וניתן לקבל עותק שלהן במייל support@afterup.co.il.

16.3 שינויים אינם פועלים למפרע ואינם גורעים מזכויות שהדין מקנה.


17. יצירת קשר

מונולוקו בע"מ (Monoloco Ltd.), ח.פ. 516332269

מנחם מדמון 45, תל אביב-יפו 6767634, ישראל

מייל: support@afterup.co.il (פרטיות, זכויות, תלונות, "Do Not Sell or Share", בטיחות ילדים)

ממונה על הגנת הפרטיות: צוות הפרטיות, support@afterup.co.il (ממונה על הגנת הפרטיות ימונה ויפורסם)

נציג באיחוד האירופי: טרם מונה (השירות טרם מוצע באיחוד האירופי או באזור הכלכלי האירופי (EEA); נציג לפי סעיף 27 ל-GDPR וסעיף 13 לתקנת השירותים הדיגיטליים ימונה ויפורסם כאן לפני שיוצע שם) | נציג בבריטניה: טרם מונה (השירות טרם מוצע בבריטניה; נציג לפי סעיף 27 ל-UK GDPR ימונה ויפורסם כאן לפני שיוצע שם)

אחראי LGPD (ברזיל): support@afterup.co.il

תנאי שימוש: https://afterup.io/terms | מחיקת חשבון: https://afterup.io/delete-account

© 2026 מונולוקו בע"מ. כל הזכויות שמורות.

Operator and controller of the database: Monoloco Ltd. (מונולוקו בע"מ), Israeli company no. 516332269, 45 Menachem Madmon St., Tel Aviv-Jaffa 6767634, Israel

Privacy contact: support@afterup.co.il

Languages: This document is published in Hebrew, English and Russian. For users in Israel the Hebrew version is binding. Outside Israel the English version prevails over any other translation.

Related documents: Terms of Service (https://afterup.io/terms), Account deletion (https://afterup.io/delete-account), Child safety standards (https://afterup.io/child-safety), Accessibility statement (https://afterup.io/accessibility).

0. Key points (non-binding summary) and notice under section 11 of the Israeli Privacy Protection Law

0.1 Key points

  • AfterUp is a social app for adults (18+) where you create a "Plan", get matched with participants and chat. To make that work we process account details, profile, photos, your city, Plans you created or joined, and messages.
  • Location: when location permission is on, the app sends your device location to the server only while you use the app (never in the background) and only for actions that need it: setting your city, creating a vacation Plan (your starting location is stored) and fixing a place that was not found on the map. We may keep your last known location to show you Plans and people nearby and an approximate distance; other users never see your location, only a city or a rounded distance. A Plan's location is shown to everyone blurred (about 500 m); the exact address is revealed only to participants the host approved.
  • The verification badge is optional. You submit a selfie inside the app, following the on-screen instruction, and a member of our team reviews it manually against your profile photos and against a social account linked on your profile (Instagram/Facebook, if you added one; optional, but it helps the review). The selfie is kept in private storage only until the decision and is deleted when the review is completed, and in any case within 30 days. No automated face matching is used for the badge.
  • Chat is not end-to-end encrypted. Messages are kept until account deletion. Our team's access to messages is limited to safety and report handling, security, support at your request, operations and legal requirements, and is logged. A notification about a new message may include a preview of it, which passes through the push provider (Google / Apple).
  • We do not sell personal data. We use providers (hosting, media, error monitoring, analytics, push, purchases, maps) and measure our ad campaigns: the app embeds the AppsFlyer SDK (a mobile measurement partner) on iOS and Android, which records the install, sessions and a registration completed event with device and app details (on iOS the vendor identifier IDFV and Apple SKAdNetwork; on Android the Google Advertising ID) and reports attribution postbacks to our ad partners Meta and TikTok; our server sends Meta one event when registration is completed, with hashed identifiers; and the website loads the Meta Pixel. The app does not embed a Meta or TikTok SDK, AppsFlyer does not receive your name, phone or email, we do not read the IDFA and do not show a tracking prompt. As of today the events are sent for every user, without a prior consent layer (for the EU and UK a consent layer is pending); you can object, ask us to stop future uses and ask that the data be deleted, and on Android reset or limit your advertising ID.
  • Users in Israel who received cards can redeem their value for a bank transfer. For that we collect, once, an image of an identity document, a selfie and bank details; our team reviews them manually, they are kept in private storage, and they are retained as Israeli tax and anti-money-laundering law requires (typically 7 years). Details in section 3.17.
  • Account deletion is available in the app, on the website (https://afterup.io/delete-account) and by email. On request the profile is hidden and anonymised and stories are deleted; logging in within 30 days cancels the deletion and restores the account, the profile and the coin balance (stories deleted with the request are not restored); after that the data is permanently deleted, except data we must keep by law.
  • You have the right to access, correct, delete, obtain a copy of your data, object, restrict and withdraw consent. Write to support@afterup.co.il and we answer within the period set by applicable law (in Israel usually within 30 days).
  • Push notifications about activity on your account, new features in the app and what is happening around you are part of the Service; you can turn them off in your device settings only (there is currently no notification-management screen inside the app). Marketing SMS and email are sent only with separate, unticked opt-in consent and are labelled "Advertisement"; you can opt out at any time by email or by replying "STOP" to an SMS.

0.2 Notice under section 11 of the Israeli Privacy Protection Law, 5741-1981

  • Legal duty or voluntary: You are not legally required to give us information. Providing basic account and profile details (phone number, date of birth, gender, display name, at least two photos, city, Plan preferences, wishlist places) is a condition for opening an account and using the Service, because without them we cannot match you with Plans and users. Other information (answers to profile prompts, social links, height, occupation, languages, music clip, contact phone, verification badge, marketing consent) is voluntary and not a condition of use.
  • Purposes: operating the Service (account, profile, Plans, matching, chat, stories, AfterCoins), safety and fraud prevention, support, product improvement and marketing measurement, and compliance with legal duties. Details in section 5.
  • Recipients and purposes of transfer: other users according to your privacy settings (section 7.2); providers that process data on our behalf (hosting, media, analytics, error monitoring, push, purchases, maps, photo checks) and providers acting as independent controllers (the app stores), table in section 7.1; Meta, AppsFlyer and TikTok for advertising measurement (section 3.13); our bank for executing card redemption payouts (section 3.17); authorities where the law requires.
  • Consequences of refusal: without the basic information an account cannot be opened or some capabilities cannot be used (for example, without location permission the map around you will not be shown). Refusing voluntary information does not prevent use of the Service.
  • Controller of the database and contact details: Monoloco Ltd., company no. 516332269, 45 Menachem Madmon St., Tel Aviv-Jaffa 6767634; support@afterup.co.il.
  • Right of access and correction: under sections 13 and 14 of the Law you may inspect the information about you held in the database and ask to correct or delete it if it is not accurate, complete, clear or up to date. How to do so: section 11.
  • Data of special sensitivity: we process location data and content you choose to share that may reveal your intimate life. Location requires a dedicated device permission; intimate content is your choice of what to write and upload. We do not use this data for advertising. Details in section 4.
  • Data transferred from the European Economic Area (EEA): data of EEA users is stored together with all other data, so we apply to the whole database the Privacy Protection Regulations (Instructions for Data that was Transferred to Israel from the European Economic Area), 5783-2023: minimisation, deletion when no longer needed, accuracy, and rights of access, correction and deletion for all users. We do not automatically delete accounts for inactivity; if we decide to do so we will give advance notice.

1. Who we are

1.1 Controller of the database (the "Company", "AfterUp", "we"): Monoloco Ltd., an Israeli company, company no. 516332269, 45 Menachem Madmon St., Tel Aviv-Jaffa 6767634, Israel.

1.2 Privacy contact: support@afterup.co.il (put "Privacy" in the subject line). You may also contact us through the chat with the AfterUp support account in the app.

1.3 Privacy Protection Officer / DPO: privacy matters are handled by the Company's privacy team; a Privacy Protection Officer will be appointed as required by law and published here. Contact: support@afterup.co.il (subject: Privacy).

1.4 EU representative (GDPR Article 27): not yet appointed. The Service is not yet offered to users in the EU/EEA; a representative under Article 27 GDPR and Article 13 of the Digital Services Act will be appointed and published here before the Service is offered there.

UK representative (UK GDPR Article 27): not yet appointed. The Service is not yet offered to users in the UK; a representative under Article 27 UK GDPR will be appointed and published here before the Service is offered there.

1.5 Brazil (LGPD): the contact channel for the person in charge (encarregado) is support@afterup.co.il.

1.6 Canada / Quebec: details of the "person in charge of the protection of personal information" are in section 15.3.


2. Scope and definitions

2.1 This Policy applies to the AfterUp app for iOS and Android, to the website afterup.io (including campaign links under go.afterup.io and landing pages), and to your communications with us (support, email). It does not apply to processing by independent third parties: the app stores (Apple, Google), venues or hosts you meet, or other users regarding what they do outside the app.

2.2 Short definitions:

  • "Personal data" - any information that identifies you or can identify you, directly or indirectly.
  • "Plan" - a meet-up or activity that a user (the "host") creates in the app and that other users ask to join. A person the host approved is an "approved participant". A "match" is created when a join request is approved.
  • "Story" - content (photo or video) a user shares for a limited time.
  • "AfterCoins" ("AC") - an internal virtual currency bought through the app stores or received as a bonus. Referred to below as "AC".
  • "Cards" - virtual items that can be received from other users (sending cards is currently disabled; see section 3.8).
  • "Verification badge" - a profile mark showing that a verification selfie you submitted was reviewed manually by our team and found to match your profile photos (and a linked social account, if provided) at the time of the review. It is not identity or age verification.
  • "Provider" - a third party that provides us a service. A "processor" is a provider that processes data for us and only on our instructions; other providers (for example the app stores) act as independent controllers under their own terms. The classification appears in the table in section 7.1.
  • "Terms" - the AfterUp Terms of Service at https://afterup.io/terms.

3. Data we collect - by feature

3.1 Account and sign-in

  • Phone number - the primary account identifier. Verified with a one-time code (OTP) by SMS sent through our authentication system (Supabase Auth) and an SMS delivery provider (for example Twilio).
  • Sign in with Apple / Google - if you choose this, we receive from the provider a user identifier and an email address (Apple may provide a relay address). Phone verification is still required.
  • Account security data - IP address and time of last login, login count, logout events and security logs.
  • Version of the Terms and Policy you accepted, time of acceptance, display language and additional consents (see 3.14).

3.2 Profile

What you fill in, part of which is shown to other users (see 7.2):

  • Basics: display name, gender, date of birth (used to enforce 18+, to show your age and to filter by the age range a host set for a Plan), bio, home city (city centre point, not an address), country.
  • Photos: between 2 and 9 profile photos. For each photo we keep the storage address, position in the gallery, a digital fingerprint (hash) for duplicate detection, face-detection status and review status.
  • Plan preferences: the Plan types you are interested in (at least two, for example after-party, food, club, vacation).
  • Profile prompts: short answers to prompts you selected (optional, up to five).
  • Wishlist: places you want to visit, by category (at least two categories with two places each). For each place we store its name and the place's coordinates (not your location).
  • Music clip: a clip from our in-house music library you chose for your profile, and music preferences.
  • Voluntary fields: height, occupation, languages, Instagram/Facebook links, interface language, and a contact phone with a preferred contact method. Note: a contact phone you entered is shown to participants you approved for your Plan (section 7.2); the account's own phone number is shown to no one.
  • Settings: public/private profile, direct-invite policy, display order of categories.
  • Data we generate about the profile: account status, verification status, internal activity points (XP), karma score, warning count, follower and following counts, last active time, your app build number and platform, profile completeness.

3.3 Location

  • Device location (GPS): collected only while the app is in the foreground and only for actions that need it; there is no background location collection. To set your city, the location is converted on the device to a city, and the server receives the city (city name, country, region and city centre point). When you create a vacation Plan, your starting location (the GPS fix at creation time) is sent to the server and stored to calculate the distance to the destination; when you fix a place that was not found on the map, the device location is sent to locate the place. We may store the device's last known location (no location history) to show you Plans and people nearby and an approximate distance to them. Other users never see your location: at most a city or a rounded distance. The last known location is deleted with the account.
  • Plan location: when you create a Plan you choose a venue. We store on the server the venue's exact coordinates (not your location) and a blurred version (about 500 m). The blurred version is shown on the map to everyone; the exact address is shown only to approved participants.
  • In summary, the location levels: device location - sent to the server only while you use the app, for the actions above, and kept at most as a last known location; city - on the server and shown on the profile; exact location of the Plan venue - on the server, revealed to approved participants; blurred Plan location - shown to everyone; rounded distance - shown to other users, if the feature is active.
  • Place search and map: when you type a venue name, the text you typed is sent to Google Places for autocomplete, and city names are sent to Google's Geocoding service (converting a city name to coordinates). Map tiles load from Mapbox servers, which receive your IP address and the map area viewed. The Mapbox SDK may collect usage and location telemetry under Mapbox's privacy policy; the Mapbox attribution menu (the ⓘ symbol) on the map includes Mapbox's telemetry setting.
  • You can revoke location permission in your device settings at any time; some capabilities (map, nearby Plans) will not work without it.

3.4 Plans and participation

  • Plans you created: title, cover image, venue, exact and blurred location, country, duration, age range, and preferred gender for participants. The age range and preferred gender are host settings for the Plan, and the app uses them to decide to whom the Plan is shown (section 6.2).
  • Participation: join requests, approvals and rejections, participant list, direct invites.
  • Social actions: follows and followers (and unfollow history), "pings" you sent or received, profile views, ratings, photo likes, super-likes (with a daily cap), and blocks.
  • Scoring: XP log and actions that earn points.

3.5 Chat and media

  • Messages: message content, sender, recipient, timestamps, read status. A one-to-one chat opens after a Plan match (without a match you can send one message until the other side replies). Each Plan has a group chat for its participants.
  • Chat media: photos and videos are stored with our media provider (Cloudinary). "View-once" media can be opened once by the recipient and cannot be reopened after viewing or after 4 hours; the file itself is retained as part of the message until the message or the account is deleted; screenshots are not technically prevented, and the media is not end-to-end encrypted.
  • Message notifications: a notification about a new message may include the sender's display name and a preview of the beginning of the message. This content passes through the push provider (Google Firebase Cloud Messaging, and on iOS also Apple's notification service) to reach your device, and may appear on a locked screen. You can turn notifications off in device settings.
  • Local copy: the app keeps a local copy of conversations on your device to allow offline viewing. The copy lives on your device and is removed when you uninstall the app.
  • Encryption and access: messages are encrypted in transit (TLS) and at rest, but not end-to-end. AfterUp is technically able to access messages. Such access is limited to authorised staff, is logged, and is made only for these purposes: safety and the handling of reports and moderation, security and fraud prevention, support at your request, technical operations and maintenance, and compliance with legal requirements or an order.
  • Retention and deletion: messages are kept until permanent account deletion. A message you deleted is marked as deleted and disappears for both sides, and the record is permanently deleted from our servers with the account; the other user's device may keep an offline copy. In a Plan's group chat, messages you sent may remain in the group after your account is deleted, without your name (the sender is shown as "Deleted User").

3.6 Stories

  • A story you upload (photo/video, upload time) is shown for 24 hours and then moves automatically to your private Archive in the app, where you can view it, restore it or delete it permanently.
  • We store who viewed and who reacted to your story and show this to you as the story owner.
  • Media files are deleted from the media provider when you permanently delete a story or when the account is permanently deleted. Live stories are deleted immediately when you request account deletion and are not restored even if you cancel the deletion.

3.7 AC and purchases

  • AC purchases are made through the Apple App Store or Google Play. We do not receive or store credit card numbers or payment instrument details.
  • From our purchase management system (RevenueCat) and the stores we receive: our user identifier, the product purchased, transaction identifier, price and currency, the store and the purchase time.
  • We keep an internal ledger of your AC balance: purchases, bonuses (for example a welcome bonus) and uses (Boost, super-likes). This ledger is needed for fraud prevention and dispute resolution.
  • We do not currently offer a subscription. Legacy internal status fields relating to a subscription or "premium" are not in use. If we offer a subscription in the future, we will update this section before launch.

3.8 Cards received

  • Sending cards is currently disabled. Cards you received in the past are still displayed: the card type and value, who sent it and when.
  • Cards are virtual items. Users in Israel who received cards can ask to redeem their value for a bank transfer (Terms, section 13); the data collected for that purpose is described in section 3.17. Redemption outside Israel is not offered today; if and when it is offered, it will be governed by separate Redemption Terms and executed through a licensed payout provider.

3.9 Verification badge (manual selfie review)

  • The verification badge is optional. Without it all other capabilities of the Service are available.
  • The process: you take a selfie inside the app, following the on-screen instruction (for example holding a note with the text shown). A member of our team reviews the selfie manually against your profile photos and against a social account linked on your profile (an Instagram/Facebook URL, if you provided one; a social link is optional, but it helps the review), and approves or rejects the request. We do not use facial recognition, biometric identification, automated face comparison or automated face detection for verification: no face template is created, and no software compares the selfie to your photos.
  • What we store: the selfie in a private storage bucket (it is never shown on your profile and does not enter your gallery), the request status, the time of submission and of the review decision, and the staff member who reviewed it.
  • Retention: the selfie is kept only until the decision and is deleted when the review is completed, and in any case within 30 days; the decision record (status and time, without the selfie) is kept as proof of the badge until the badge is revoked or the account is deleted.
  • The verification badge is not verification of identity, age or criminal background, and may be revoked.
  • Automated photo checks for all users: every profile photo uploaded goes through an automated check that a face is visible (AWS Rekognition DetectFaces, Frankfurt region, European Union) and a duplicate check against existing photos. The face check is face detection only - it does not identify anyone and does not compare faces. These checks store no face template, only a result (face detected / not detected) and a digital fingerprint of the file.
  • You can ask us at any time to delete your verification selfie and revoke the badge by emailing support@afterup.co.il.

3.10 Reports, blocks and enforcement records

  • Reports you filed or that were filed about you: the category (for example inappropriate content, scam/fake, spam, safety, harassment, intimate image shared without consent, other), free text, the reported content or profile, and time. A report button exists on profiles, Plans and messages; a story is reported through the profile of the person who uploaded it or by email.
  • Blocks: who blocked whom and when (blocking is mutual and not disclosed to the other side).
  • Enforcement records: decisions of our enforcement team, warnings, hides, freezes, bans, ban reason, internal notes, account status history and an audit log of enforcement team actions.
  • Reports in the "intimate image without consent" category are automatically flagged for priority handling with a removal target of up to 48 hours.

3.11 Device and technical data

  • Push token (FCM), platform (iOS/Android), app version and build number, language.
  • IP address and time at login, login count, logout events.
  • Notifications: the push provider (Google Firebase Cloud Messaging, and on iOS also Apple) receives the push token and the notification title and body, which may include a display name and a message preview (section 3.5).
  • Crash and error reports (Sentry, servers in the European Union): stack trace, release, environment and our internal user identifier (no name, email or IP).
  • Font loading: the app loads fonts from Google Fonts servers, which receive your IP address in the request.

3.12 Analytics events (Mixpanel)

We use Mixpanel (servers in the European Union) to understand how the app is used. As of today analytics runs for all users (see 13.1 for your choices).

  • Events: sign-up, app opened, app backgrounded, screen view and screen duration, login and logout, profile viewed, card sent, AC purchased, AC spent, Boost activated, Plan created, message sent (chat type and whether it included media - not the message content), story created, story viewed (including the story owner's identifier), days since registration, and submitting a report about a user who has a DJ profile (we record the DJ profile's city, genres and whether it has external links - not the report content).
  • Analytics profile: our user identifier, name, gender, email and phone (if present), user type, internal "premium" status (not in use), platform and app version.
  • What the SDK adds automatically: device and operating-system data (model, OS version, carrier, language, screen resolution) and an approximate city/region-level location derived from your IP address.
  • What is not sent: precise GPS location, message content, photos or verification selfies.

3.13 Marketing measurement (Meta, AppsFlyer, TikTok)

  • On the website: certain landing pages and campaign links load the Meta Pixel, which reports page views, content views and leads to Meta, together with Meta cookies and your IP address. See section 13.2.
  • In the app (AppsFlyer SDK, iOS and Android): the app embeds the SDK of AppsFlyer Ltd. (Israel), a mobile measurement partner, on iOS and Android, for install attribution and measurement of our Meta and TikTok ad campaigns. The SDK initialises when the app starts and automatically records the install, first open and sessions; in addition we send through it one explicit event today: "registration completed" (with the registration method "phone"); we may add events such as profile completed, Plan created and invite accepted. We do not send purchase or revenue events, and we do not pass your name, phone, email or our customer identifier to AppsFlyer. With these events AppsFlyer receives: on iOS the vendor identifier (IDFV) and Apple SKAdNetwork data (aggregated, without IDFA; the app does not show a tracking prompt, App Tracking Transparency); on Android the Google Advertising ID (GAID) and Android device identifiers; and on both platforms your IP address, device model, operating system and language, app version, install time and first-open and session events. AppsFlyer reports install and event postbacks to our ad partners Meta and TikTok for attribution: on iOS through SKAdNetwork (aggregated, without a device identifier), and on Android at device level using the advertising ID. Partner sharing scope: only install and in-app event postbacks are shared with Meta and TikTok for attribution; we have disabled AppsFlyer's advanced data sharing and advanced matching, so no hashed personal details (such as email or phone) are sent to them through AppsFlyer. On iOS these postbacks are aggregated SKAdNetwork data without a device identifier; on Android they are sent with the device advertising ID. For Meta we have also enabled the 'limit use of personal information' (CCPA) setting in AppsFlyer. AppsFlyer stores the data in the United States (AppsFlyer's global region); AppsFlyer Ltd. is an Israeli company acting as our processor under a data processing agreement, with standard contractual clauses for the US storage where required. There is no TikTok SDK in the app; TikTok receives attribution postbacks through AppsFlyer only. The SDK stores identifiers on the device.
  • From our server (Conversions API): when you complete profile registration, our server sends Meta a single event - "CompleteRegistration" - containing your email, phone and user identifier after one-way hashing (SHA-256), your IP address, a device/software identification string (User Agent), and Meta cookie identifiers if you arrived from a campaign. We store only the time of sending. As of today the event is sent once for every user who completes registration, without a prior consent mechanism.
  • Purpose: to measure which campaigns bring installs and registrations, to optimise our Meta and TikTok app-install campaigns, and to let Meta avoid showing our ads to people who already registered (audience exclusion). We do not pass data to Meta, TikTok or AppsFlyer for their own independent marketing. Meta does not receive a clear-text phone or email from us, but hashed data and advertising identifiers are still personal data.
  • Roles of Meta, AppsFlyer and TikTok: AppsFlyer processes the data on our behalf as a processor. Under Meta's business tools terms, Meta Platforms Ireland Ltd. (and in the US Meta Platforms, Inc.) is a joint controller with us for the collection and transmission of the events, and an independent controller for the subsequent processing in its services; the essence of the arrangement is available in Meta's business tools terms. TikTok (TikTok Technology Limited in Ireland, and in the US TikTok Inc.) receives the attribution postbacks under its business products terms and processes them as a controller for its own purposes.
  • Choice: you can object at any time by emailing support@afterup.co.il - we will stop sending future measurement events about you, instruct AppsFlyer to delete the data and ask Meta and TikTok to delete what was sent to them (US state residents see also section 15.2 regarding "Do Not Sell or Share"). On Android you can also reset or limit your advertising ID in the Google settings on the device; on iOS no IDFA is used, so there is nothing to switch off. For users in the EU and UK a prior consent mechanism will be introduced before the Service is marketed to users in the EU/EEA or the UK; until then the events (SDK and server) are sent as described above, and you can object as stated.

3.14 Consent records

  • We keep: the version of the Terms and Privacy Policy you accepted, the time of acceptance and display language, marketing consent and its time, terms region, and a non-editable log of consent events (source: consent window, login screen, OTP verification, settings, consent gate).
  • When we change the documents materially, the app asks you to accept the new version again.
  • The records are deleted when the account is permanently deleted, except a minimal acceptance log, written automatically by the database when a consent event is deleted (SHA-256 hashed user identifier, event type, version accepted, timestamp and source), kept for the limitation period as proof of acceptance and for the defence of claims (section 9).

3.15 Support and enquiries

When you contact us (email, chat with the support account in the app, website forms) we keep the content of the enquiry, the contact details you gave and the correspondence, to handle the enquiry and improve the Service.

3.16 Referrals

If you joined through a referral code or link, we store the referral source on your profile. A click on a campaign or referral link on the website may be logged (time, IP address, browser type) for campaign measurement; automatic attribution of such a click to an account opened later is not active today. Referral rewards are points, AC or cards only, never money.

3.17 Identity verification and bank details - only if you apply to redeem cards (Israel)

If you are in Israel and apply to redeem received cards (Settings > Wallet > Redeem), we collect, in order to execute the payout and as required by Israeli tax and anti-money-laundering law: an image of an identity document (front/back), a selfie, the account holder's name and bank account details (bank, branch, account number), and the request records (amount, status, decision and payment time). Identity verification is completed once; later requests reuse it unless your details change. Purpose and legal basis: performance of the contract (executing the redemption you requested) and compliance with legal obligations (tax, anti-money-laundering). Storage and access: the documents are kept in a private storage bucket, access is restricted to authorised staff, the application is reviewed manually by our team, and the documents are not shown to other users; bank details are passed to our bank only to execute the transfer. Retention: identity documents, bank details and payout records are kept as required by Israeli tax and anti-money-laundering law, typically 7 years, and then deleted; an abandoned or rejected application is deleted within a reasonable time. Redemption outside Israel is not offered today; if and when it is offered, it will run through a licensed payout provider under separate terms, and this section will be updated before launch.

3.18 Website forms

The waitlist and contact forms on the website collect email and/or phone, IP address and campaign parameters (UTM). The details are emailed to us through the Resend service and received in a team mailbox hosted by Google (Gmail), and are used to contact you about the launch and to respond. The website is hosted on Vercel and uses country-level location derived from your IP address to show a localised version of the site (a preference cookie).

3.19 Data about you coming from other users

Other users may generate data about you: reports, blocks, ratings, likes, profile views, join requests, messages to you. We process this data to operate the Service and for safety, and we do not disclose to the reporter or the reported person the other side's identity beyond what is already visible.


4. Sensitive data and special categories

4.1 Whether data counts as "sensitive" depends on the law. This is how we treat the relevant types:

  • Location: "data of special sensitivity" under the Israeli Privacy Protection Law and "sensitive data" under US state laws; it is not a "special category" under GDPR Article 9 and not sensitive data under the LGPD. The device location is sent to the server only while you use the app and for the actions listed in section 3.3, and is kept at most as a last known location; the server also receives the city; the location of a Plan you host is stored precisely and displayed blurred. Basis: a dedicated device location permission, which you can revoke at any time, and performance of the Service you requested.
  • Content revealing your intimate life: what you choose to write or upload in your profile, chat and stories may reveal intimate information. That is your choice; we do not ask for such information and do not infer characteristics from it. We process this content only to provide the Service and enforce the rules.

4.2 We do not ask about sexual orientation and the profile has no such field. A Plan host may set a preferred gender for participants in their Plan; that is a setting of the Plan that decides to whom it is shown, not data about anyone's orientation.

4.3 We do not use sensitive data for advertising and we do not sell it. We do not pass location, verification selfies, message content, photos, bio, prompt answers, wishlist places or Plan preferences to analytics or advertising providers. The analytics profile at Mixpanel receives only the attributes listed in section 3.12: display name, gender, email and phone (if present), user type and the internal "premium" flag (not in use), plus platform and app version. Meta receives only the data listed in section 3.13, and we do not use Meta's tools to build segments based on sensitive characteristics.

4.4 Legal basis: for profile content you chose to display to other users - data you yourself made manifestly public (GDPR Article 9(2)(e)), to the extent Article 9 applies to it. For chat and story content - provision of the Service you requested, and in safety or legal-defence situations, the law that permits it (including GDPR Article 9(2)(f)). You can withdraw consent at any time (section 11.6).


5. Purposes, legal bases and retention

5.1 Purposes and bases table:

# Purpose Data Legal basis (GDPR / UK GDPR / LGPD; in Israel: informed consent and the provisions of the Law) Retention
1Opening an account, sign-in and account securityphone, OTP, OAuth identifiers, login IP and timeperformance of a contract (the Terms); legitimate interest (security)until account deletion
2Displaying the profile and matching with Plans and usersprofile, photos, preferences, prompts, wishlist, city, age, genderperformance of a contractuntil account deletion
3Showing the map, nearby Plans and people, and an approximate distancecity, location permission, last known device location, vacation Plan starting location, blurred Plan locationperformance of a contract; device permissioncity and last known location: until updated/account deleted; starting location: with the Plan
4Creating Plans, requests, approvals, revealing the address to approved participantsPlan data, participationperformance of a contractuntil Plan/account deletion
5One-to-one and group chat, media, storiesmessages, media, stories, viewsperformance of a contractmessages: until account deletion; stories: 24 hours then archive until deleted
6Buying and using AC, Boost, super-likespurchase records, AC ledgerperformance of a contract; legal obligation (accounting evidence)until account deletion; aggregate, anonymised accounting records as required by law
7Verification badge (manual review of a selfie, profile photos and a linked social account)verification selfie, linked social account (if provided), request status, review decisionperformance of a contract (a feature you requested); legitimate interest (profile authenticity)selfie: deleted when the review is completed, and in any case within 30 days; decision record: until badge revoked/deletion
8Automated photo checks (visible face, duplicates)profile photos, check status, hashlegitimate interest (profile authenticity, preventing impersonation); performance of a contractwith the photo
9Safety, fraud prevention and enforcement of the rulesreports, blocks, enforcement records, messages (after a report), counters and rate limitslegitimate interest (user safety); legal obligationuntil account deletion, subject to retention required by law (section 9)
10Notifications and service messages (matches, messages, Plan updates)push token (FCM), identifiers, message previewperformance of a contractuntil logout/deletion
11Marketing communicationsphone/email, consentconsent (Israeli Communications Law s.30A; GDPR 6(1)(a))until consent withdrawn/deletion
12Analytics and product improvementusage events (3.12), device datalegitimate interest (service improvement) with a right to object; in the EU/UK: consent, once the consent mechanism is live (13.1)at the provider per the retention setting in our account, at most 5 years; deleted on your request
13Error monitoring and stabilitycrash reports, internal user identifierlegitimate interest (service integrity)at the provider up to 90 days
14Campaign measurement (Meta, AppsFlyer, TikTok)AppsFlyer SDK events (install, sessions, registration completed) with device and app details, IP and the platform identifiers (IDFV/SKAdNetwork on iOS, GAID on Android); hashed identifiers, IP, UA (server event); website eventslegitimate interest with a right to object; in the EU/UK: consent, once the consent mechanism is live (3.13)at our end: time of sending of the server event and aggregated campaign reports; raw data is kept by AppsFlyer for its retention period under our agreement
15Support and responding to enquiriesenquiry contentperformance of a contract; legitimate interestup to 3 years after the enquiry is closed, unless needed for the defence of a claim
16Compliance with legal duties, responding to authorities, legal defenceas neededlegal obligation; legitimate interestas required by law and the limitation period
17Card redemption (Israel; only if you apply)identity document image, selfie, bank details, request and payout recordslegal obligation (tax, anti-money-laundering); performance of a contractas required by Israeli tax and anti-money-laundering law, typically 7 years
18Operational system alerts to the operatorinternal identifiers and aggregate counts onlylegitimate interest (operations)transient

5.2 Where the basis is legitimate interest, we have balanced it against your rights, and you may object (section 11.5). Where the basis is consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.


6. Automated decision-making and profiling

6.1 Deck ranking and visibility: the order in which Plans and profiles are shown is set automatically based on your Plan preferences, app activity, geographic proximity (city level), freshness and profile completeness. In addition: paid Boost temporarily raises a Plan's prominence; the verification badge and enforcement restrictions (including reduced visibility of an account that broke the rules) affect ordering and inclusion; mutual blocks hide the parties from each other; and the age and gender preferences a host set for a Plan decide to whom it is shown (6.2).

6.2 Host preferences: a host may set an age range and preferred gender for their Plan. The app uses this to decide to whom the Plan is shown and who can ask to join. The final decision on approving a participant is the host's (a human).

6.3 Automated photo checks: a photo without a visible face or a duplicate photo is rejected automatically and you are asked to upload another one. You can appeal and request human review via support@afterup.co.il.

6.4 Rate limits and anti-spam: automatic limits on how often actions can be performed (for example messages, requests, daily super-likes) to prevent harassment and spam.

6.5 Enforcement: decisions to warn, hide, restrict, freeze or ban an account are made by humans on our team, assisted by reports and automated checks. Three kinds of actions happen automatically: a temporary block for security reasons (for example unusual sign-in attempts), rejection of a photo that does not meet the rules (6.3), and rejection of a sign-up or closure of an account when the declared date of birth shows an age under 18. Each of these can be appealed and reviewed by a human (6.6).

6.6 Your right: to ask for an explanation of a decision concerning you, to express your point of view and to request human review, via support@afterup.co.il or the appeal channels described in the Terms (https://afterup.io/terms).


7. Who we share data with

7.1 Providers and recipients

The following providers receive data as described. A "processor" processes data for us under a data processing agreement and only for the stated purpose; an "independent" or "joint" controller also processes the data under its own terms. For US providers we rely on the provider's Data Privacy Framework (DPF) certification where it is in force, and otherwise on Standard Contractual Clauses (SCCs), in the UK with the Addendum or IDTA (section 8.2).

Provider Role Purpose Data Country/region Transfer safeguard
Supabaseprocessorhosting, database, authentication (OTP, Apple, Google), file storage, server functionsall account and Service datahosted in the European Union (Germany)EU hosting; US provider - SCCs/DPF; processing agreement
SMS delivery provider via Supabase Auth (for example Twilio)processorsending the OTP codephone number, codeUSASCCs/DPF
Cloudinaryprocessorstoring and serving media (profile photos, chat media, stories, Plan covers, clips)image/video filesUSA (global delivery network)SCCs/DPF
AWS Rekognition (Amazon Web Services)processorautomated check that a face is visible in profile photos (face detection only, no identification)profile photos; a detection result returns to ushosted and processed in the European Union (Germany, Frankfurt)EU hosting; US provider - SCCs/DPF; processing agreement
Sentryprocessorerror and crash monitoringerror reports, release, internal user identifierhosted in the European UnionEU hosting; US provider - SCCs/DPF; processing agreement
Mixpanelprocessorproduct analyticsusage events and analytics profile (3.12)hosted in the European UnionEU hosting; US provider - SCCs/DPF; processing agreement
Google (Firebase Cloud Messaging) and Apple (notification service on iOS)processorpush notification deliverypush token (FCM), notification title and body (may include a display name and a message preview)USASCCs/DPF
RevenueCatprocessorAC purchase managementuser identifier, product, transaction, price, currencyUSASCCs/DPF
Apple App Store / Google Playindependent controllersstore payment, refunds, sign-in (Sign in with Apple / Google Sign-In)per store terms; OAuth identifier and emailUSA / Irelandper Apple's and Google's privacy terms
Mapboxprocessormap displayIP address, map area viewed; SDK usage and location telemetry under Mapbox's privacy policy (3.3)USASCCs/DPF
Google Maps Platform (Places, Geocoding)processorvenue autocomplete, place photos, converting a city name to coordinatessearch queries, city nameUSASCCs/DPF
Google Fontsindependent providerfont loading in the appIP addressUSAper Google's privacy policy
Meta Platforms Ireland / Meta Platforms, Inc.joint controller (collection and transmission) and independent controller (subsequent processing)advertising measurement (Conversions API server event, website Pixel, attribution postbacks received from AppsFlyer)hashed identifiers, IP, UA, Meta cookies, website events; install and event postbacks from AppsFlyer (aggregated via SKAdNetwork on iOS; with the advertising ID on Android)Ireland / USASCCs/DPF; see 3.13
AppsFlyer Ltd.processorinstall attribution and campaign measurement (mobile measurement partner)SDK events (install, sessions, registration completed), IDFV and SKAdNetwork data (iOS), Google Advertising ID and device identifiers (Android), IP, device model, OS, language, app version, install timeIsrael; storage in the USA (AppsFlyer global region); processor of an Israeli company; DPA + SCCsIsrael is recognised as adequate for EU/UK transfers; US storage - SCCs; data processing agreement; see 3.13
TikTok (TikTok Technology Limited, Ireland / TikTok Inc., USA)independent controller (processing for its own purposes)ads platform for our campaigns; receives attribution postbacks via AppsFlyer only (no TikTok SDK in the app)install and event postbacks (aggregated via SKAdNetwork on iOS; with the advertising ID on Android)Ireland / USAper TikTok's business terms; SCCs/DPF; see 3.13
Vercelprocessorwebsite and admin panel hostingserver logs, IPUSA (global network)SCCs/DPF
Resend and Google (Gmail)processorssending and receiving emails from website formsform detailsUSASCCs/DPF
Telegramprocessorinternal operational alerts to the operator (for example "new sign-up", "new report")internal identifiers and aggregate counts only - no name, phone, photo or contentoutside Israel and the EUreduced to internal identifiers that do not identify you without access to our systems
Our bank (Israel)independent controllerexecuting bank transfers for card redemption payouts (3.17)account holder name, bank details, amountIsraelper Israeli banking law

We check that every processor commits to a level of protection not lower than this Policy.

7.2 Other users

  • Public profile: your display name, age, gender, photos, bio, prompt answers, Plan preferences, wishlist, music clip, city, verification badge, social links and voluntary fields you filled in (height, occupation, languages) are visible to registered users.
  • Private profile: if you enabled a private profile, your profile is not shown in general discovery and suggestions; it remains visible to users you interact with in the app (for example followers you approved, hosts of Plans you asked to join, participants in shared Plans and existing conversations). The setting is preserved if you cancel a deletion request and restore the account.
  • Plans: a Plan you created is shown to users who match the preferences you set, with a blurred location. A host sees the profile of anyone who asked to join. Approved participants see the exact address, the other participants in the group chat, and the host's contact phone if the host entered one.
  • Chat and stories: messages are visible to their recipients; stories are visible to registered users who can see your profile (subject to the private-profile setting and blocks); the story owner sees who viewed and reacted.
  • Actions: pings, follows, likes and requests are visible to the other side. A block is not disclosed to the blocked person.
  • What is not shown: your account phone number, email, IP address, push token, verification selfie and data, internal notes and enforcement records are not shown to other users. If you entered a "contact phone" in your profile, it is shown only to participants you approved for your Plan, so they can reach you (for example on WhatsApp or by call); you can remove it from your profile at any time.

7.3 Hosts and venues

A host is not our agent. What you give a host in chat or at a meet-up is the host's responsibility. We do not pass your details to venues.

7.4 Authorities and legal demands

We will disclose data to law enforcement, courts or regulators where the law requires it (a valid order or legal demand), and in emergencies involving a real risk to life or safety. We report suspected child sexual exploitation to the competent bodies (such as NCMEC) where the law requires, and preserve the relevant content for the period the law requires.

7.5 Corporate transactions

In a merger, acquisition, sale of assets or similar process, data may pass to the acquiring entity subject to this Policy; we will notify you in advance of a change in the identity of the controller of the database.

7.6 With your consent

In any other case we share data only if you asked for it or agreed to it.

7.7 We do not sell personal data

We do not sell personal data for money and we do not pass it to third parties for their own independent marketing. Sending measurement events to Meta, and attribution data through AppsFlyer to Meta and TikTok (3.13), may count as "sharing" or a "sale" under the broad definitions of certain US state laws; see section 15.2 for the right to opt out.


8. International transfers

8.1 We are an Israeli company and our team accesses data from Israel. The main database and the automated photo checks are hosted in the European Union (Germany), and some providers operate in the USA or on global networks. Providers' support teams may access data from other countries under the processing agreements. Your data may therefore be processed outside your country of residence. Our measurement partner AppsFlyer (section 3.13) is an Israeli company and stores the measurement data in the USA (see section 7.1); our ad partners Meta and TikTok receive the attribution postbacks in Ireland and the USA.

8.2 Users in the EU/EEA and the UK: Israel is recognised by an adequacy decision of the European Commission (reconfirmed in 2024) and by the UK adequacy regulations, so transfer to us requires no additional measures. Transfers to US providers rely on the Data Privacy Framework (including the UK Extension) where the provider is certified, or on the Commission's Standard Contractual Clauses (and in the UK the IDTA/Addendum), and where required, a transfer assessment. You can request a copy of the safeguards via support@afterup.co.il.

8.3 Users in Israel: transfers abroad are made under the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001, including to countries with an adequate level of protection (the European Union) and to providers that undertook in writing to comply with the Israeli data-holding conditions and adequate security.

8.4 Users in other countries: transfers are made in accordance with local law (for example LGPD Article 33, APP 8, PIPEDA), with contractual safeguards.


9. Retention periods

9.1 Retention table:

Data Period
Account and profile (including photos, preferences, wishlist, clip)until deletion request; immediate anonymisation and hiding, 30-day grace period, then permanent deletion (9.2)
Chat messages and mediauntil permanent account deletion (local copy removed when you uninstall the app; the other user's device may keep an offline copy); group-chat messages may remain without your name
Storiesshown for 24 hours, then in the Archive until you permanently delete them or the account is deleted; views and reactions with the story; live stories are deleted on an account deletion request
Plans, requests, follows, pings, likesuntil permanent account deletion
Verification selfie and decisionselfie: in private storage only until the decision, deleted when the review is completed, and in any case within 30 days; decision record (3.9) until badge revoked or account deleted
Photo check results (face/duplicate)with the photo, until it is removed or the account deleted
Purchase records and AC ledgeruntil permanent account deletion; the stores and the purchase management provider keep records under their rules; aggregate accounting records that do not identify you as required by law
Cards receiveduntil account deletion
Reports, blocks and enforcement recordsuntil permanent account deletion, subject to retention required by law (below)
Staff audit logwhen our team performs an account deletion (as an enforcement measure or at your request through support), the audit log keeps a minimal record (the deleted display name and phone number, time and action) to document the action and prevent ban evasion; access is limited to authorised staff; period: 7 years
Consent recordsuntil permanent account deletion; a minimal acceptance log (SHA-256 hashed user identifier, event type, version, timestamp, source) is kept for the limitation period (7 years in Israel)
Last login IP and timeon the profile, overwritten at each login, until account deletion
Security logs (login/logout events, devices)until account deletion; hosting providers' server logs - per the provider's default, at most 90 days
Analytics (Mixpanel)at the provider per the retention setting in our account, at most 5 years; deleted on your request
Errors (Sentry)at the provider up to 90 days
Backupsdatabase backups rotate on a cycle; deleted data disappears from backups as well, typically within 90 days; a backup is used only for system-wide recovery, and if a deleted account were restored that way we would delete it again
Support enquiriesup to 3 years after the enquiry is closed, unless needed for the defence of a claim
Website forms (waitlist)up to 12 months from receipt of the form or until you ask us to delete, whichever is earlier
Identity documents, bank details and payout records (only if you apply for redemption in Israel)as required by Israeli tax and anti-money-laundering law, typically 7 years; an abandoned/rejected application is deleted within a reasonable time

Version 3.1 (2 September 2026): clarifies that push notifications about account activity, app news and activity around you are part of the Service and can be turned off in device settings;; and the location sections (0.1, 3.3, 4.1, 5) were updated: the device location is sent to the server while you use the app and may be kept as a last known location to show Plans, people and an approximate distance; creating a vacation Plan stores your starting location.

Retention required by law: in every case in the table, we may keep data beyond the stated period where the law requires it, where legal proceedings or a pending enquiry are ongoing, where evidence must be preserved (for example reports of child sexual exploitation, for the period the law sets), or where needed for the defence of claims - and then only for the necessary period and with restricted access. We do not automatically delete accounts for inactivity.

9.2 Account deletion - what actually happens:

  • On request: the profile is hidden and anonymised immediately - the display name is replaced with "Deleted User"; photos, bio, date of birth, city and country, music preferences, social links and contact phone are removed; the account is marked deleted and no longer appears to others. Live stories are deleted immediately. Conversations with other users remain on their side marked "Deleted User" for the 30 days. The AC balance is preserved at this stage.
  • 30-day grace period: logging in within 30 days cancels the deletion and restores the account, the profile (including the public/private setting) and the AC balance; stories deleted with the request are not restored.
  • Permanent deletion: after the 30 days the deletion is scheduled and completed promptly thereafter: messages, conversations, stories and archive, Plans, follows, blocks, reports (as reporter and as reported), purchase records, consent records, verification data and account details are deleted, and the phone number is released. Media files are deleted from the media provider. One-to-one messages and conversations are deleted from our servers; the other user's device may keep an offline copy. Messages you sent in a Plan's group chat may remain without your name.
  • What remains: a minimal staff audit record (9.1), a minimal acceptance log of consent (3.14), aggregate accounting records that do not identify you, identity-verification and payout records if you redeemed cards (3.17, for the legal retention period), and data we must keep by law or for pending proceedings (9.1).
  • AC: the AC balance is forfeited on permanent deletion. Before final deletion you may ask by emailing support@afterup.co.il for a refund of AC bought with money and not used; it is granted where applicable law or the store's rules entitle you to it, and otherwise at our reasonable discretion, as set out in the Terms.

10. Security

10.1 We implement technical and organisational measures in line with the Israeli Privacy Protection (Data Security) Regulations, 5777-2017, and GDPR Article 32, including: encryption in transit (TLS) and at rest; row-level security (RLS) in the database restricting each user to the data they are allowed to see; least-privilege access for staff; mandatory two-factor authentication for the admin panel; audit logs of staff actions; backups; storage of sensitive documents (verification selfies, identity documents for card redemption) in private buckets; serving of user media through the media provider at unique addresses; and security testing.

10.2 No method is 100% secure. Keep your OTP code to yourself, never share it, and log out of devices that are not yours.

10.3 Security incident: in the event of a security incident we will assess its scope and risk and notify the competent authority (in Israel - the Privacy Protection Authority; in the EU - the relevant supervisory authority, within 72 hours of becoming aware where the law requires; in the UK the ICO; in Canada the OPC; in Australia the OAIC; in Brazil the ANPD; in the US state authorities) and affected users, within the time and at the threshold set by applicable law.


11. Your rights and how to use them

11.1 Access: to know whether we hold data about you and to receive it (Israeli Privacy Protection Law s.13; GDPR Article 15).

11.2 Copy and portability: there is currently no automated export tool in the app. You may request a copy of your data in a common, readable format by emailing support@afterup.co.il, and we will provide it within the legal time limits.

11.3 Correction: most profile details can be edited directly in the app. To correct other data, contact us.

11.4 Deletion: in the app (Settings > Delete account, with double confirmation), on https://afterup.io/delete-account, or by email to support@afterup.co.il. See section 9.2 for the process and the 30-day grace period. In the app you can delete photos, stories (including from the Archive), Plans and messages yourself; deletion of other data items without deleting the account can be requested through support, where the law grants it and as far as technically feasible.

11.5 Restriction and objection: to ask us to restrict processing, and to object to processing based on legitimate interest (for example analytics and campaign measurement) and to direct marketing at any time.

11.6 Withdrawing consent: verification badge - ask us at any time to revoke the badge and delete your verification selfie and data; marketing - section 12; location permission - device settings; notifications - device settings; Meta measurement and analytics - sections 3.13 and 13.1.

11.7 Information about automated decisions: section 6.

11.8 Complaint to us: write to support@afterup.co.il with "Privacy complaint" in the subject. We acknowledge within 30 days (and in the UK, as required by the Data (Use and Access) Act 2025) and respond without undue delay.

11.9 Complaint to an authority: in Israel - the Privacy Protection Authority (www.gov.il/he/departments/the_privacy_protection_authority); in the EU - the supervisory authority in your country of residence; in the UK - the ICO; in Canada - the OPC (and in Quebec the CAI); in Australia - the OAIC; in Brazil - the ANPD; in the US - your state Attorney General or the competent agency (in California the CPPA).

11.10 How to ask and what happens next: email from an address linked to your account or contact us through the app. To protect you we will verify your identity (for example confirmation via the account's phone number) before disclosing or deleting data. We respond within the period set by applicable law (in Israel usually within 30 days; regional timelines in section 15); if more time is needed, as the law permits, we will tell you and explain. Exercising rights is free unless requests are manifestly repetitive and unreasonable. We will not discriminate against you for exercising rights.

11.11 Authorised agent: you may act through an authorised agent with written authorisation; we will also verify the user's own identity.


12. Marketing and communications

12.1 Service messages (login code, join approval, new message, Plan update, security, changes to the legal documents) are sent as part of the Service and do not require consent. The same applies to push notifications about activity on your account, about features and news in the app, and about activity and new users in your area: they are part of the Service. Push notifications can be turned off in your device settings only; there is currently no option to choose notification types inside the app. Security and mandatory notices will still be sent through an available channel.

12.2 Marketing SMS and email (promotions, partnerships, campaigns) are sent only if you ticked, at sign-up or later, the separate consent box, which is unticked by default and is not a condition of use. Every marketing message is labelled as required by the law that applies to it (in Israel: "פרסומת", meaning "Advertisement") and includes our details and a simple, free way to opt out in the same channel, as required by section 30A of the Israeli Communications (Telecommunications and Broadcasting) Law, 5742-1982, CAN-SPAM, CASL and similar laws.

12.3 Opting out: write to support@afterup.co.il; for a marketing SMS - reply "STOP" (in Hebrew "הסר"); for a marketing email - click the unsubscribe link. Push notifications can be turned off in your device settings. Opt-out takes effect promptly and no later than the time set by law.

12.4 Direct mailing (Israeli Privacy Protection Law ss.17C-17F): if we contact you based on characterisation (for example by city or preferences), the message will state that it is direct mailing, that the source of the data is the details you gave us at sign-up and in use, and your right to be removed from the mailing list at any time by emailing support@afterup.co.il.

12.5 We do not give your contact details to other advertisers.


13. Cookies, SDKs and tracking

13.1 In the app

Component Purpose Control
Supabaseoperating the Service (essential)none, essential
RevenueCatAC purchases (essential for purchasing)none, essential
Firebase Cloud Messagingnotificationsdevice settings
Sentrycrash reports (with an internal user identifier only)essential for stability; you may object via support
Mixpanelproduct analytics (currently runs for all users)request to stop via support@afterup.co.il; there is currently no in-app switch
Mapbox, Google Places/Geocodingmap and venue searchlocation permission; Mapbox's telemetry setting is in the map's attribution menu (ⓘ); search used at your choice
Cloudinarymedia displayessential
Google Fontsfontsessential for display
Sign in with Apple / Google Sign-Insign-inonly if you chose to sign in this way
AWS Rekognitionautomated check that a face is visible in profile photos (face detection only)essential for profile rules
AppsFlyer SDK (attribution)install attribution and campaign measurement (iOS and Android): install, first open and session events and a registration completed event, with device model, OS and app version, language, install time and IP; on iOS the vendor identifier (IDFV) and SKAdNetwork, no IDFA, no tracking prompt; on Android the Google Advertising ID; postbacks to Meta and TikTok (3.13)request to stop via support@afterup.co.il, honoured for future events; on Android reset or limit the advertising ID in the device's Google settings; there is currently no in-app switch; EU/UK consent layer pending (below)
  • AppsFlyer SDK in the app: the app embeds the AppsFlyer SDK on iOS and Android, as described in section 3.13; it initialises when the app starts. There is no Meta SDK in the app and no TikTok SDK; Meta and TikTok receive attribution postbacks from AppsFlyer only. We do not pass our user identifier, name, phone or email to the SDK, we do not read the IDFA and we do not show a tracking prompt (App Tracking Transparency); on iOS attribution uses the vendor identifier (IDFV) and Apple SKAdNetwork (aggregated postbacks), and on Android the Google Advertising ID, which you can reset or limit in the device's Google settings. The SDK stores identifiers on the device. In addition, a measurement event is sent from our server to Meta (Conversions API), and the Meta Pixel runs on the website only.
  • EU and UK: as of today analytics (Mixpanel) and the measurement events (the AppsFlyer SDK initialises at app start, and the Meta server event) run for all users, without a prior in-app consent layer. A consent layer for users in the EU and UK, which will hold analytics and measurement until consent, will be introduced before the Service is marketed to users in the EU/EEA or the UK. Until then you can ask us to stop via support@afterup.co.il, and we will honour the request for future processing.

13.2 On the website afterup.io

  • Essential cookies: operating the site, remembering your choice in the cookie banner (stored locally in the browser), and the preference for a country-localised version of the site.
  • Meta Pixel (marketing): campaign landing pages and campaign links load the Meta Pixel when the page opens. The main site pages show a cookie banner; as of today the banner does not prevent the Pixel from loading on campaign pages. Making the Pixel load only after prior consent for visitors from the EU and UK will be completed before the website is marketed to users in the EU/EEA or the UK. In the meantime you can prevent the Pixel in browser settings, with a tracking blocker, or in the advertising settings of your Meta account.
  • No Google Analytics or other tracking tools on the site as of this date.
  • Global Privacy Control (GPC): the site does not currently detect a GPC signal automatically. We are working to honour GPC signals; until then, opt-out requests for sharing/sale are received by email (13.3) and honoured.

13.3 "Do Not Sell or Share" (USA)

You may ask us not to share your data for measurement or targeted advertising by emailing support@afterup.co.il (subject: "Do Not Sell or Share"). See section 15.2.


14. Children and minors

14.1 The Service is for people aged 18 and over only, in every country. We enforce this with a date-of-birth declaration and automatic blocking under 18, we use the 18+ age rating in the app stores, and we may use operating-system or store age signals where available - for age compliance only.

14.2 We do not knowingly collect data from minors. If we discover that a user under 18 opened an account, we close the account and delete the data in accordance with section 9.2, and the account will not be restored.

14.3 Reporting a minor: support@afterup.co.il with the subject "Child safety", or via the report button in the app. Full child safety policy: https://afterup.io/child-safety.


15. Regional annexes

15.1 European Union / EEA and United Kingdom

  • Legal bases: see the table in section 5. For special categories: profile content you chose to display to others - Article 9(2)(e), to the extent Article 9 applies (section 4.4).
  • Whether providing data is required and the consequences of refusal: section 0.2.
  • Rights: access, rectification, erasure, restriction, portability, objection (including to direct marketing at any time), withdrawal of consent, and not to be subject to a solely automated decision (Articles 15-22). Exercised under section 11, free of charge, response within one month (extendable by two months in complex cases, with notice).
  • Representatives: section 1.4. Data protection officer: section 1.3.
  • Complaint: to any supervisory authority in the EU, in particular in your country of residence or work; in the UK to the ICO (ico.org.uk). In the UK we acknowledge a complaint to us within 30 days and respond without undue delay.
  • Transfers: section 8.2.
  • ePrivacy: section 13.1 (current state and the date the consent layer goes live).
  • Children: section 14 (18+).
  • Changes and notice: material changes are notified at least 30 days in advance (section 16).

15.2 United States (state privacy rights)

This section applies to residents of states with comprehensive privacy laws (for example California, Colorado, Connecticut, Virginia, Texas, Oregon and others). We may not meet the applicability thresholds of some of these laws; we honour the following rights as a matter of policy for every US user.

  • Categories of personal information collected in the last 12 months (in CCPA terms), their source, recipients for a business purpose, and whether "sold"/"shared":
Category Examples Source Disclosed for a business purpose to "Sold"/"shared"
Identifiersphone, email from OAuth, user identifier, IP, push token (FCM)you; your devicethe processors in section 7.1hashed identifiers, IP and UA to Meta (3.13); IP, the vendor identifier (IDFV, iOS) or the Google Advertising ID (Android) to AppsFlyer, and the advertising ID onward to Meta and TikTok in Android attribution postbacks
Personal recordsname, date of birthyouprocessorsno
Protected classificationsage, genderyouprocessorsno
Commercial informationAC purchasesthe stores, the purchase providerprocessorsno
Internet/app activityusage events, views, app events (install, sessions, registration completed), campaign cookiesyour device; Meta (campaign cookies)Mixpanel, Sentry, Vercel, AppsFlyerapp events via AppsFlyer to Meta and TikTok as attribution partners, and website Pixel events to Meta, for advertising measurement
Geolocationdevice location - sent to the server while you use the app, kept at most as a last known location; city - on the server; exact Plan venue location - for hosts, revealed to approved participants; blurred location - to everyoneyou; your deviceSupabase, Mapbox, Google Mapsno
Audio/visual informationphotos, story videos, clip choice, verification selfieyouCloudinary, Supabase (private storage), AWS (face detection)no
Professional informationoccupation (if filled in)youprocessorsno
Inferencesdeck rankinggenerated by usnot disclosedno
Sensitive personal informationdevice location (last known location), login credentials (OTP), message contentyouprocessors needed for the Serviceno
  • Purposes: section 5. Disclosure for a business purpose: to the processors in section 7.1.
  • "Sale"/"sharing" and targeted advertising: sending app activity and the advertising ID (Android) or vendor identifier (iOS) to AppsFlyer and the resulting attribution postbacks to Meta and TikTok, sending hashed identifiers, IP and UA to Meta (3.13) and the website Pixel may count as "sharing" for cross-context behavioural advertising (and under some state laws a "sale"). We do not sell data for money, and we do not sell or share sensitive data or data of anyone we know to be under 16.
  • Opt-out: email support@afterup.co.il with the subject "Do Not Sell or Share". We honour a request within 15 business days, stop sending future events and ask AppsFlyer, Meta and TikTok to delete. In AppsFlyer we have enabled the 'limit use of personal information' setting for Meta and disabled advanced data sharing and advanced matching for Meta and TikTok. On Android you can also reset or limit the advertising ID in the device's Google settings, which stops device-level attribution; on iOS no IDFA is ever used and no tracking prompt is shown. The site does not currently detect a GPC signal automatically; we are working to honour GPC signals (13.2).
  • Sensitive data: part of it is necessary to provide the Service you requested (login credentials, the content of messages you send, the location of the Plan venue you chose) and is processed for that purpose only; the device location is kept at most as a last known location (section 3.3). We do not use sensitive data to infer characteristics or for advertising, and you may ask us to limit its use to what is necessary for the Service.
  • Rights: to know/access, to obtain a copy (portability), to correct, to delete, to opt out of sale/sharing/targeted advertising/profiling with significant effects, and non-discrimination for exercising rights (we will not deny service or change price or quality).
  • Verification: we verify requests using the account's phone number and additional information if needed. Authorised agent: permitted with signed authorisation; we will also verify you.
  • Response time: within 45 days (extendable by a further 45 days with notice). Appeal: if we denied a request, you may appeal by email with "Appeal" in the subject; we respond within 45 days and inform you of the option to contact your state Attorney General.
  • Notice at collection: sections 3, 5 and 9 constitute the notice. Financial incentives: we do not offer a financial incentive in exchange for personal information; bonuses and referral rewards are given for actions in the app and not for providing data or consenting to sale/sharing. "Shine the Light" (California): we do not disclose data to third parties for their direct marketing, so it does not apply.
  • No arbitration in this Privacy Policy. Dispute resolution arrangements appear in the Terms.

15.3 Canada (PIPEDA and provincial laws, including Quebec)

  • We collect, use and disclose personal information with meaningful consent and for purposes a reasonable person would consider appropriate, as set out in sections 3 and 5. The four key elements: what is collected (section 3), with whom it is shared (section 7), why (section 5), and risks (transfer to other countries, section 8; no end-to-end encryption, section 3.5).
  • Information is processed and stored outside Canada (access from Israel; storage in the European Union and the USA) and is subject to the laws of those countries.
  • Rights: access, correction, withdrawal of consent (subject to contractual consequences: for example, without a phone number an account cannot be held, and without location permission the map is not shown), complaint to us and to the OPC (priv.gc.ca). We respond to an access or correction request within 30 days; if we refuse, we give written reasons and note the right to complain, and if a correction is disputed we attach a note of the requested correction to the record. Complaints to us are reviewed by a human and answered in writing.
  • Breaches: we keep records of incidents and notify the OPC and affected individuals where there is a real risk of significant harm.
  • CASL: commercial electronic messages only with express consent, with sender identification and an unsubscribe mechanism (section 12).
  • Quebec (Law 25): person in charge of the protection of personal information: the Company's privacy team, support@afterup.co.il. Information is communicated outside Quebec (section 8). Availability of this Policy in French: the Service is not currently offered in Quebec; a French version will be provided before it is.

15.4 Australia (Privacy Act 1988, APPs)

  • Kinds of information, how collected and held: sections 3, 9 and 10. Purposes: section 5.
  • Overseas disclosure (APP 8): information is stored and processed in the European Union (Germany) and the USA by the providers in section 7.1, and our team accesses it from Israel. Some providers operate global delivery networks (for example Vercel, Cloudinary), and internal operational alerts (identifiers and counts only) pass through Telegram, whose servers are outside Israel and the EU.
  • Access and correction (APP 12-13): section 11; response within 30 days. If we refuse, we give written reasons, note the right to complain, and on your request attach a statement of the requested correction to the record.
  • Complaints: first to us (support@afterup.co.il); we acknowledge, investigate and respond in writing within 30 days. If you are not satisfied, you may contact the OAIC (oaic.gov.au). You may also contact the eSafety Commissioner regarding online harm.
  • Breaches: we follow the Notifiable Data Breaches scheme.
  • Government identifiers: we do not collect them (except identity documents for card redemption in Israel, section 3.17).

15.5 Brazil (LGPD)

  • Legal bases (Article 7): performance of a contract (rows 1-7, 10, 15 of the section 5 table), consent (row 11), legitimate interest (rows 7-9, 12-15, 18), compliance with a legal obligation (rows 16-17), and exercise of rights in proceedings. Sensitive data (Article 11): location is not sensitive data under the LGPD; content you choose to share that may reveal your intimate life is treated as described in section 4.
  • Other controllers: Meta and TikTok (section 3.13) and the app stores (section 7.1) also act under their own terms.
  • Rights (Article 18): confirmation of processing, access, correction, anonymisation/blocking/deletion of unnecessary data, portability, deletion of data processed with consent, information about sharing, information about the option not to consent and its consequences, withdrawal of consent, review of automated decisions (section 6).
  • Person in charge (encarregado): support@afterup.co.il.
  • International transfer (Article 33): per section 8, through ANPD standard contractual clauses or another recognised mechanism, where applicable.
  • Complaint: to the ANPD (gov.br/anpd).

16. Changes to this Policy

16.1 We will update this Policy when the Service or the law changes. For a material change (for example new purposes, new data types, processors of a new category, a change in rights) we will give at least 30 days' notice by email or in-app message and ask you to accept the new version again in the app. We record the version you accepted, the time of acceptance and the display language.

16.2 The version number and effective date appear at the top of the document. Previous versions are kept by us, and a copy can be obtained by emailing support@afterup.co.il.

16.3 Changes do not operate retroactively and do not reduce rights granted by law.


17. Contact

Monoloco Ltd. (מונולוקו בע"מ), company no. 516332269

45 Menachem Madmon St., Tel Aviv-Jaffa 6767634, Israel

Email: support@afterup.co.il (privacy, rights, complaints, "Do Not Sell or Share", child safety)

Privacy Protection Officer: privacy team, support@afterup.co.il (Privacy Protection Officer to be appointed)

EU representative: not yet appointed (the Service is not yet offered in the EU/EEA; a representative under Article 27 GDPR and Article 13 of the Digital Services Act will be appointed and published here before it is) | UK representative: not yet appointed (the Service is not yet offered in the UK; a representative under Article 27 UK GDPR will be appointed and published here before it is)

LGPD person in charge (Brazil): support@afterup.co.il

Terms of Service: https://afterup.io/terms | Account deletion: https://afterup.io/delete-account

© 2026 Monoloco Ltd. All rights reserved.

© 2026 מונולוקו בע"מ. כל הזכויות שמורות.

דף הבית פרטיות תנאים הסרת תמונות אינטימיות בטיחות ילדים נגישות תמיכה מחיקת חשבון