מדיניות פרטיות - HomeQuest
עודכן לאחרונה: מאי 2026
מדיניות פרטיות זו מסבירה כיצד Fix Point, בבעלות אסף פרץ ("אנחנו", "המפעיל"), אוסף, משתמש ומגן על המידע שלך באפליקציית HomeQuest ("האפליקציה"). באמצעות השימוש באפליקציה, אתה מסכים לתנאים המפורטים במסמך זה.
1. מי אנחנו ויצירת קשר
המפעיל: Fix Point (אסף פרץ), ישראל.
אימייל לפניות פרטיות: fixpoint.mobile@gmail.com
2. אילו נתונים אנו אוספים
- פרטי הרשמה: כתובת אימייל, שם פרטי, ובאופציה תמונת פרופיל. עבור ילדים: שם פרטי וכינוי בלבד — ללא אימייל או טלפון.
- נתוני שימוש: משימות, פרסים, נקודות, הודעות פנימיות, יומן משפחתי, רשימות קניות, ונתוני לימודים שאתה מזין מרצונך.
- נתונים טכניים: מזהה מכשיר אנונימי, סוג מערכת הפעלה, שפת ממשק, וגרסת אפליקציה — לצורך תמיכה ושיפור.
- הרשאות מכשיר (באפליקציה הנייטיב): התראות Push, מיקרופון (לתכונת הסוכן הקולי בלבד, לא נשמר), גישה לתמונות (להעלאת תמונת פרופיל בלבד).
- נתוני תשלום: מטופלים אך ורק על ידי ספקי הסליקה (PayPal, Bit, PayBox). איננו שומרים פרטי כרטיסי אשראי.
3. למה אנו משתמשים בנתונים
- הפעלת השירות (התחברות, סנכרון נתוני המשפחה).
- שליחת התראות פנימיות (אישור משימות, פרסים, תזכורות).
- שיפור האפליקציה ותיקון תקלות.
- ציות לדרישות חוקיות.
4. שירותי צד שלישי
אנו משתמשים בספקי תשתית הבאים, שלכל אחד מהם מדיניות פרטיות משלו:
- Google Firebase (Authentication, Firestore, Storage, Cloud Functions, Cloud Messaging) — אחסון מאובטח של נתוני המשפחה והעברת הודעות.
- Google Sign-In — להתחברות באמצעות חשבון Google (אופציונלי).
- OpenRouter / OpenAI / Anthropic / Google AI — לעיבוד שאלות אל הסוכן החכם. הטקסט שאתה כותב לסוכן נשלח לעיבוד ולא נשמר אצלם.
- PayPal / Bit / PayBox — לעיבוד תשלומים.
- Monlix (Offerwall, אופציונלי) — תוכן מתאים למשפחות בלבד, אוסף מידע אנונימי על השלמת משימות.
5. הגנה על ילדים (COPPA / GDPR-K)
האפליקציה מיועדת לשימוש משפחתי. חשבונות ילדים נוצרים ומנוהלים אך ורק על ידי הורה או אפוטרופוס. איננו אוספים מילדים כתובות אימייל, מספרי טלפון או מיקום. הורים יכולים לצפות, לערוך ולמחוק את כל נתוני ילדיהם בכל עת מתוך האפליקציה.
6. אחסון ומיקום נתונים
הנתונים מאוחסנים בשרתי Google Cloud (Firebase), בעיקר במרכזי נתונים באירופה ובארה"ב. ההעברה מתבצעת בהצפנה (HTTPS / TLS). הסיסמאות מוצפנות ב-bcrypt ואינן ניתנות לפענוח גם על ידינו.
7. שימור ומחיקה
- נתונים פעילים נשמרים כל עוד החשבון פעיל.
- מחיקת חשבון: ניתן למחוק את החשבון בכל עת מתוך "הגדרות > מחיקת חשבון". לאחר המחיקה, החשבון עובר ל-"מחיקה רכה" למשך 30 יום (להחזרה במקרה של טעות), ולאחר מכן נמחק לצמיתות.
- יומני שרת אנונימיים נשמרים עד 90 יום לצרכי אבטחה.
8. זכויותיך (GDPR / CCPA)
אתה זכאי בכל עת ל:
- עיון בנתונים שלך (זמין מתוך האפליקציה).
- תיקון נתונים שגויים.
- מחיקת חשבונך והנתונים שלך.
- ייצוא הנתונים שלך בפורמט קריא.
- ביטול הסכמתך לעיבוד נתונים (משמעו הפסקת השימוש באפליקציה).
9. עוגיות ואחסון מקומי
האפליקציה משתמשת ב-localStorage לשמירת העדפות (שפה, מצב חיבור). באפליקציה הנייטיב אין עוגיות צד שלישי. באתר הווב יש עוגיות פונקציונליות בלבד.
10. אבטחה
אנו נוקטים אמצעי אבטחה סבירים: הצפנת תקשורת, חוקי גישה ב-Firestore, אימות דו-שלבי לאדמין, מגבלות קצב על קריאות API. למרות זאת, אף מערכת אינה חסינה ב-100%, ושימוש באינטרנט כרוך בסיכון מסוים.
11. שינויים במדיניות
אנו עשויים לעדכן מדיניות זו מעת לעת. שינוי מהותי יפורסם באפליקציה לפחות 14 יום מראש. המשך השימוש לאחר העדכון מהווה הסכמה למדיניות המעודכנת.
12. סמכות שיפוט
על מדיניות זו יחולו דיני מדינת ישראל. כל מחלוקת תתברר בבתי המשפט המוסמכים בתל-אביב יפו.
Privacy Policy - HomeQuest
Last updated: May 2026
This Privacy Policy explains how Fix Point, owned by Asaf Peretz ("we", "the Operator"), collects, uses, and protects your information in the HomeQuest application ("the App"). By using the App, you agree to the terms set forth in this document.
1. Who We Are and Contact
Operator: Fix Point (Asaf Peretz), Israel.
Privacy email: fixpoint.mobile@gmail.com
2. What Data We Collect
- Registration data: email address, first name, and optionally profile picture. For children: first name and nickname only — no email or phone.
- Usage data: tasks, rewards, points, internal messages, family calendar, shopping lists, and study data that you enter voluntarily.
- Technical data: anonymous device identifier, OS type, interface language, and app version — for support and improvement.
- Device permissions (native app): Push notifications, microphone (for the voice assistant feature only, not stored), photo access (for profile picture upload only).
- Payment data: handled exclusively by payment providers (PayPal, Bit, PayBox). We do not store credit card details.
3. Why We Use the Data
- Operating the service (login, family data sync).
- Sending internal notifications (task approvals, rewards, reminders).
- Improving the app and fixing bugs.
- Complying with legal requirements.
4. Third-Party Services
We use the following infrastructure providers, each with its own privacy policy:
- Google Firebase (Authentication, Firestore, Storage, Cloud Functions, Cloud Messaging) — secure storage of family data and message delivery.
- Google Sign-In — for sign-in via Google account (optional).
- OpenRouter / OpenAI / Anthropic / Google AI — for processing questions to the smart agent. Text you write to the agent is sent for processing and not retained by them.
- PayPal / Bit / PayBox — for payment processing.
- Monlix (Offerwall, optional) — family-safe content only, collects anonymous data on task completion.
5. Children's Protection (COPPA / GDPR-K)
The app is intended for family use. Child accounts are created and managed solely by a parent or guardian. We do not collect email addresses, phone numbers, or location from children. Parents can view, edit, and delete all their children's data at any time from within the app.
6. Data Storage and Location
Data is stored on Google Cloud (Firebase) servers, primarily in data centers in Europe and the US. Transfer is encrypted (HTTPS / TLS). Passwords are bcrypt-hashed and cannot be decrypted, even by us.
7. Retention and Deletion
- Active data is retained as long as the account is active.
- Account deletion: you can delete your account at any time from "Settings > Delete Account". After deletion, the account enters a "soft delete" state for 30 days (for restoration in case of mistake), then is permanently deleted.
- Anonymous server logs are retained for up to 90 days for security purposes.
8. Your Rights (GDPR / CCPA)
You are entitled at any time to:
- Access your data (available from within the app).
- Correct inaccurate data.
- Delete your account and data.
- Export your data in a readable format.
- Withdraw consent to data processing (which means stopping use of the app).
9. Cookies and Local Storage
The app uses localStorage to save preferences (language, login state). The native app has no third-party cookies. The web site uses only functional cookies.
10. Security
We take reasonable security measures: encrypted communication, Firestore access rules, two-factor authentication for admin, rate limits on API calls. However, no system is 100% secure, and internet use carries some risk.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be announced in the app at least 14 days in advance. Continued use after the update constitutes agreement to the updated policy.
12. Jurisdiction
This policy is governed by the laws of the State of Israel. Any dispute will be resolved in the competent courts in Tel Aviv-Yafo.