מדיניות פרטיות — אפליקציית iOS
עודכן לאחרונה: ספטמבר 2026
הדף הזה מתאר את זרימת הנתונים של אפליקציית SubRadar ל-iOS. גרסת הווב היא מוצר נפרד עם ארכיטקטורה שונה — למדיניות שלה ראו מדיניות הפרטיות של גרסת הווב.
בקצרה
- הסריקה מקומית קודם. המנוע שבמכשיר מסווג את הרוב המוחלט של ההודעות בעצמו. רק אימיילים שהמנוע המקומי אינו מצליח לסווג נשלחים הלאה — בדרך כלל כמה עשרות בסריקה מלאה ראשונה, ולרוב אפס בסריקה חוזרת.
- מה נשלח, ולאן. אותם אימיילים נשלחים באופן זמני דרך שרת ה-proxy שלנו ב-Firebase אל Anthropic (Claude API), שמחלץ שם שירות, סכום, מחזור חיוב וסטטוס. לכל היותר 1,200 אימיילי טקסט ו-300 מסמכים חזותיים (PDF או תמונה) בסריקה — תקרת בטיחות, לא יעד.
- אנחנו לא שומרים תוכן אימיילים. לא באפליקציה ולא ב-proxy. לפי מדיניות ה-API הסטנדרטית של Anthropic, קלטים ופלטים עשויים להישמר אצלה עד 30 יום.
- התוצאות נשמרות במכשיר. מנויים, חשבוניות ומצב הסריקה נשמרים ב-SwiftData במכשיר; אסימוני Google נשמרים ב-Keychain.
- אין פרסומות ואין מעקב. ההכנסה מגיעה מרכישות בתוך האפליקציה בלבד.
מידע שאנחנו משתמשים בו
מידע שאתה מספק
- פרטי מנויים וחשבוניות שאתה מזין או מאשר: שירות, תוכנית, סכום, מטבע, מחזור חיוב, תאריכים וסטטוס.
- הגדרות התראות והעדפות באפליקציה.
חשבון Google ומידע מ-Gmail
בחיבור Gmail האפליקציה מבקשת גישת קריאה בלבד (gmail.readonly) יחד עם ההיקפים email ו-profile. היא מקבלת את כתובת המייל, שם התצוגה וכתובת תמונת הפרופיל שלך, ושומרת את פרטי החשבון המחובר ואת אסימוני ה-OAuth ב-Keychain של iOS.
הסריקה מושכת תחילה מזהי הודעות/היסטוריה של Gmail ומטא-דאטה — שולח, נמען, נושא, תאריך, תקציר ומטא-דאטה של קבצים מצורפים. הודעות נבחרות בלבד נטענות עם גוף ההודעה והקבצים המצורפים. הניתוח המקומי עשוי לבחון נושא, תקציר, גוף, טקסט שחולץ מ-PDF, טקסט OCR ובייטים של קבצים מצורפים.
מה בדיוק נשלח ל-Anthropic
ההודעות מסוננות ומנותחות במכשיר תחילה. רק כאשר הניתוח המקומי אינו מצליח להגיע לתוצאה ודאית, ההודעה נשלחת ב-HTTPS דרך פונקציית Firebase שלנו אל Anthropic. הבקשה יכולה לכלול:
- שולח, נושא ותאריך;
- עד 3,000 תווים מגוף ההודעה;
- טקסט שחולץ מקומית מקובץ PDF;
- קובץ PDF או תמונה מצורף אחד לכל היותר — כולל שם הקובץ, סוג ה-MIME והבייטים בקידוד base64.
ה-proxy מקבל בנוסף אימות Firebase App Check ומזהה התקנה יציב. אסימוני OAuth, מזהי הודעות Gmail, מזהי קבצים מצורפים ומפתח חשבון ה-Gmail אינם נכללים בכוונה בבקשה ל-Anthropic — אף שמידע אישי עשוי להופיע בתוך תוכן האימייל עצמו.
מספר הבקשות תחום פעמיים: המנוע המקומי מסווג את רוב ההודעות בעצמו, ומעליו קיימת תקרה קשיחה של 1,200 אימיילי טקסט ו-300 מסמכים חזותיים לסריקה. בפועל סריקה מלאה ראשונה של תיבה בת ~800 הודעות שולחת בערך 20–45 הודעות, וסריקה חוזרת לרוב אפס.
מה ה-proxy שומר
ה-proxy אינו רושם ואינו שומר בכוונה תוכן בקשות או תשובות. הוא רושם מטא-דאטה תפעולית גסה בלבד: שם המודל, קוד סטטוס, גדלים בבייטים, משך ועלות משוערת. Firestore שומר מזהי חלון ומוני קצב לפי התקנה ולפי האפליקציה, חותמות עדכון, ומונה הוצאה יומי מצטבר — כולם נמחקים אוטומטית לפי מדיניות TTL. אין לאף לקוח גישת קריאה או כתיבה ל-Firestore.
שמירה אצל Anthropic
Anthropic מעבדת ועשויה לשמור קלטים ופלטים של ה-API לפי התנאים המסחריים שלה. מדיניות השמירה הסטנדרטית שלה כיום היא עד 30 יום, בכפוף לחריגים שהיא מפרסמת (מדיניות שימוש, דרישות חוק, משוב והסכמים). לפי המדיניות המפורסמת שלה, נתוני API מסחריים אינם משמשים לאימון מודלים אלא אם הלקוח בחר בכך במפורש. ראו מדיניות השמירה ו-מדיניות האימון של Anthropic.
אחסון מקומי ומחזור חיי התוכן
האפליקציה שומרת במכשיר:
- פרטי חשבון Google מחובר ואסימוני OAuth ב-Keychain;
- מזהה התקנה יציב לשירות הבקאנד ב-UserDefaults;
- מנויים, חשבוניות ותוצאות סריקה מובנות ב-SwiftData;
- מצב מטמון סריקה מגורסה — כתובת החשבון הקנונית, מזהי הודעות/היסטוריה של Gmail, חותמות זמן, גרסאות עיבוד, מקור הראיה, קודי דחייה סופיים, שדות מובנים של ספק/תוכנית/סכום/מחזור/סטטוס/מסמך, וזהויות יציבות בגיבוב.
תמונות מצב הסריקה אינן שומרות גוף אימייל גולמי, תקצירים, כותרות שולח/נמען, בייטים של קבצים מצורפים או תשובות מודל גולמיות. מאגרי הגוף והקבצים המצורפים משוחררים וההפניות אליהם מנוקות מיד לאחר הניתוח. Swift אינו מספק ערובה למחיקה פיזית מאובטחת של הזיכרון, ולכן איננו טוענים זאת.
סריקות אוטומטיות אינן שומרות בייטים של קבצי חשבונית במאגר החשבוניות המקומי הראשי. מחיקת האפליקציה מסירה את הנתונים המקומיים שלה.
עמידה במדיניות Google API Services (Limited Use)
השימוש של SubRadar במידע שמתקבל מממשקי Google API, והעברתו, עומדים במדיניות Google API Services User Data Policy, לרבות דרישות ה-Limited Use: אנחנו משתמשים בנתוני Gmail אך ורק כדי לזהות ולהציג לך מנויים; איננו מעבירים אותם לצד שלישי למעט ההעברה הזמנית ל-Anthropic לצורך הניתוח; איננו משתמשים בהם לפרסום; ואיננו מאפשרים לבני אדם לקרוא אותם, אלא בהסכמתך המפורשת, לצורכי אבטחה, או כנדרש בחוק.
שירותי צד שלישי
- Google OAuth ו-Gmail API — חיבור החשבון, פרטי פרופיל וגישת קריאה בלבד לדואר.
- Firebase Cloud Functions, App Check ו-Firestore — העברה מאומתת של בקשות ה-AI, מניעת ניצול לרעה ומונים גסים.
- Anthropic Claude API — ניתוח תוכן האימיילים המתואר למעלה, בכפוף לתנאים ולמדיניות השמירה של Anthropic.
- Firebase Analytics — אנליטיקת מוצר לפי הגדרת האפליקציה ותנאי Google.
- RevenueCat — ניהול רכישות והרשאות. אינו מקבל תוכן הודעות מצינור הסריקה.
האפליקציה אינה כוללת ערכת פרסום ואינה מציגה בקשת מעקב (ATT): אין בה פרסומות, וההכנסה מגיעה מרכישות בתוך האפליקציה בלבד.
קטגוריות הפרטיות ב-App Store
הסריקה מחייבת הצהרה על Emails or Text Messages, Other User Content (קבצי PDF/מסמכים), Photos or Videos (תמונות מצורפות), Purchase History (פעילות קבלות/מנויים) ו-Device ID (מזהה ההתקנה היציב ו-App Check). כולן משמשות לתפקוד האפליקציה או לאבטחה, מקושרות למשתמש או להתקנה, ואינן משמשות למעקב.
אבטחה
- אסימוני OAuth נשמרים ב-Keychain של iOS.
- התעבורה מול Gmail והנתיב אפליקציה → proxy → Anthropic מוצפנים ב-HTTPS.
- סינון מקומי ותקרות קשיחות לסריקה מגבילים אילו הודעות בכלל מגיעות לניתוח מרוחק.
- תוכן אימייל גולמי אינו נכתב בכוונה למאגרים המובנים המקומיים או לאחסון הקבוע של ה-proxy.
- ניתוק חשבון או מחיקת כל הנתונים שולחים בקשת ביטול הרשאה ל-Google לפני ניקוי ה-Keychain, כך שההרשאה עצמה מבוטלת ולא רק העותק המקומי שלה.
שום מערכת העברה או אחסון אינה יכולה להיות מאובטחת לחלוטין.
הזכויות והשליטה שלך
באפשרותך לצפות ולמחוק מנויים וחשבוניות מקומיים, לנתק את Gmail בהגדרות, למחוק את כל הנתונים בלחיצה אחת, ולהסיר את האפליקציה. אפשר גם לבטל את ההרשאה ישירות ב-הרשאות חשבון Google. בהתאם לתחום השיפוט שלך, ייתכן שתוכל לבקש גישה, תיקון, מחיקה, הגבלה, ניוד או התנגדות — פנה אלינו.
עבור משתמשים ב-EEA, עיבוד נתוני Gmail מבוסס על הסכמה שניתנת בעת חיבור החשבון; העיבוד המובנה הליבתי נחוץ לאספקת השירות. אפשר לחזור מההסכמה על ידי ניתוק וביטול ההרשאה.
פרטיות ילדים
SubRadar אינו מיועד לילדים מתחת לגיל 13, ואיננו אוספים ביודעין מידע מילדים.
שינויים במדיניות
אנו עשויים לעדכן מדיניות זו ונעדכן על שינויים מהותיים דרך האפליקציה או חומרי הגרסה.
יצירת קשר
SubRadar for iOS — Privacy Policy (English)
This page describes the data flow of the SubRadar iOS app. The web version is a separate product with a different architecture; see the web privacy policy for that one.
Summary
- The scan is local first. The on-device engine classifies the overwhelming majority of messages by itself. Only the emails it cannot classify are sent onward — typically a few dozen per full first scan, and usually none on a repeat scan.
- What is sent, and where. Those emails are sent transiently through our Firebase proxy to Anthropic (Claude API), which extracts the service name, amount, billing cycle, and status. At most 1,200 text emails and 300 visual documents (PDF or image) per scan — a safety ceiling, not a target.
- We store no email content.Neither the app nor the proxy persists it. Under Anthropic’s standard API policy, inputs and outputs may be retained by Anthropic for up to 30 days.
- Results stay on your device. Subscriptions, invoices, and scan state live in SwiftData on the device; Google tokens live in the iOS Keychain.
- No ads, no tracking. Revenue comes from in-app purchases only.
Google account and Gmail information
Connecting Gmail requests read-only access (gmail.readonly) plus Google’s email and profile scopes. The app receives your email address, display name, and profile-picture URL, and stores connected-account data and OAuth credentials in the iOS Keychain.
The scan first obtains Gmail message/history identifiers and metadata — sender, recipient, subject, date, snippet, and attachment metadata. Only selected messages are hydrated with body and attachment data. Local analysis may inspect subject, snippet, body, extracted PDF text, OCR text, and attachment bytes.
Exactly what reaches Anthropic
Messages are filtered and analyzed on the device first. Only when local analysis cannot reach a confident result is a message sent over HTTPS through our Firebase Cloud Function to Anthropic. That request can contain:
- sender, subject, and date;
- up to 3,000 characters of body text;
- text extracted locally from a PDF;
- at most one PDF or image attachment — including its filename, MIME type, and base64-encoded bytes.
The proxy additionally receives Firebase App Check proof and a stable installation identifier. OAuth tokens, Gmail message IDs, Gmail attachment IDs, and the Gmail account key are not intentionally included in the Anthropic request, although personal information can appear inside the email content itself.
The volume is bounded twice: the local engine resolves most messages itself, and above it a hard per-scan ceiling of 1,200 text emails and 300 visual documents applies. In practice a full first scan of an ~800-message mailbox sends roughly 20–45 messages, and a warm scan usually sends none.
What the proxy keeps
The proxy does not intentionally log or persist raw request or response content. It logs coarse operational metadata only: model name, status code, byte sizes, duration, and estimated cost. Firestore holds per-install and app-wide rate-limit window identifiers and counters, update timestamps, and a rolling daily spend total — all expired automatically by a TTL policy. No client has read or write access to Firestore.
Retention at Anthropic
Anthropic processes and may retain API inputs and outputs under its commercial terms. Its standard API retention is currently up to 30 days, subject to its stated usage-policy, legal, feedback, and contractual exceptions. Under Anthropic’s published policy, commercial API data is not used for model training unless the customer opts in. See Anthropic’s retention and training information.
Local storage and content lifecycle
The app stores on the device:
- connected Google account details and OAuth credentials in the Keychain;
- a stable backend installation identifier in
UserDefaults; - structured subscriptions, invoices, and scan results in
SwiftData; - versioned scan cache state — canonical account email, Gmail message/history identifiers, timestamps, processing versions, evidence origin, terminal-negative reason codes, structured merchant/plan/money/cadence/status/document fields, and hashed stable identities.
Scan snapshots do not persist raw email bodies, snippets, sender/recipient headers, attachment bytes, or raw model responses. Hydrated body and attachment buffers are released and their references cleared immediately after analysis. Swift provides no guarantee of secure physical memory erasure, so this policy makes no such claim.
Automatic scans do not persist invoice attachment bytes in the main local invoice store. Deleting the app removes its local data.
Google API Services Limited Use
SubRadar’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Gmail data is used only to detect and display your subscriptions; it is not transferred to third parties except the transient transfer to Anthropic for that analysis; it is not used for advertising; and humans do not read it except with your explicit consent, for security purposes, or as required by law.
Third-party services
- Google OAuth and Gmail API — account connection, profile information, and read-only mail access.
- Firebase Cloud Functions, App Check, and Firestore — authenticated AI proxying, abuse prevention, and coarse counters.
- Anthropic Claude API — analysis of the email content described above.
- Firebase Analytics— product analytics per the app’s configuration and Google’s terms.
- RevenueCat — purchase and entitlement management. It receives no email content from the scan pipeline.
The app ships no advertising SDK and shows no App Tracking Transparency prompt: there are no ads, and revenue comes from in-app purchases only.
App Store privacy categories
The scan requires declarations for Emails or Text Messages, Other User Content (PDF/document attachments), Photos or Videos (image attachments), Purchase History (receipt/subscription activity), and Device ID (the stable installation identifier and App Check). All are used for App Functionality or Security, are linked to the user or installation, and are not used for tracking.
Security
- OAuth credentials are stored in the iOS Keychain.
- Gmail traffic and the app → proxy → Anthropic path use HTTPS.
- On-device pre-filtering and hard per-scan ceilings limit which messages reach remote analysis at all.
- Raw email content is not intentionally written to the app’s local structured stores or to the proxy’s persistent stores.
- Disconnecting an account or deleting all data sends a revocation request to Google before clearing the Keychain, so the grant itself is revoked rather than merely forgotten.
No transmission or storage system can be guaranteed completely secure.
Your rights and controls
You can view and delete local subscriptions and invoices, disconnect Gmail in Settings, delete all data in one tap, and remove the app. You can also revoke access directly in Google Account Permissions. Depending on your jurisdiction, you may request access, correction, deletion, restriction, portability, or objection by contacting us.
For EEA users, Gmail processing is based on consent given when you connect the account; core structured-data processing is necessary to provide the service. You may withdraw consent by disconnecting and revoking access.
Children’s privacy
SubRadar is not intended for children under 13, and we do not knowingly collect information from children.