מדיניות פרטיות
עדכון אחרון: 8 באוקטובר 2026
מי אחראי על המידע
השירות UseTimer (https://usetimer.app) מופעל על ידי אבי עזרא, ישראל. לכל שאלה או בקשה בנושא פרטיות: [email protected].
איזה מידע נאסף
- פרטי חשבון: כתובת דואר, שם לתצוגה, אזור זמן, שפה והעדפות. הסיסמה נשמרת רק כגיבוב (hash) ואינה ניתנת לשחזור.
- נתוני עבודה שאתם מזינים: רשומות זמן, תיאורים, לקוחות, פרויקטים, משימות, תגיות, תעריפים, דוחות, הגדרות צוות וקבצים שאתם מייבאים.
- חיבורים ואבטחה: עוגיית חיבור, שם המכשיר שבחרתם, כתובת IP, סוג הדפדפן, מועדי כניסה ורישומי ביקורת של פעולות רגישות.
- קישור זהות ורכישות ב־Fiduso: מזהה משתמש UseTimer, מזהה החשבון (subject) ב־Fiduso ופרופיל הכולל שם לתצוגה וכתובת דואר ראשית; אישור הקישור, מזהי רכישה, מסלול, כמות משתמשים, תקופת הזכאות ומצב הרכישה והזכאות. UseTimer אינו מקבל או שומר פרטי כרטיס אשראי.
- דואר מערכת: מצב שליחה של הודעות אימות, שחזור והזמנה.
אין באתר פרסומות, אין מכירת מידע ואין עוגיות מעקב של צד שלישי.
הכתבה קולית באמצעות הדפדפן
אם אפשרות ההכתבה זמינה בדפדפן שלכם, היא מופעלת רק לפי פעולה שלכם ולאחר גילוי בממשק והרשאת המיקרופון של הדפדפן. הקול עשוי להישלח לשירות הזיהוי של ספק הדפדפן, ולעיבוד זה חלים התנאים ומדיניות הפרטיות של ספק הזיהוי. זיהוי הדיבור עשוי לדרוש חיבור לאינטרנט; UseTimer אינו מבטיח זיהוי מקומי או פעולה ללא רשת.
UseTimer אינו שומר קובץ שמע. הטקסט המזוהה עשוי להישמר כתיאור רשומת זמן, בטיוטה המקומית או בתור הסנכרון, בהתאם לפעולה שלכם ולמצב המערכת. לאחר שהטקסט נשמר כנתון עבודה, חלים עליו כללי השמירה, השיתוף והמחיקה של נתוני העבודה המתוארים במדיניות זו. ניתן לבטל את ההכתבה או לא להשתמש בה ולהקליד תיאור במקום.
למה המידע משמש
להפעלת השירות עבורכם: כניסה לחשבון, שמירה וסנכרון של נתוני העבודה, הפקת דוחות, שיתוף עם חברי צוות שהזמנתם, שליחת הודעות מערכת, קישור הזהות בין החשבונות, שיוך רכישות והפעלת זכאות Pro או Team, בירור חיובים ובקשות ביטול והחזר, מניעת שימוש לרעה ואבטחת החשבון. איננו משתמשים בתוכן העבודה שלכם לשום מטרה אחרת.
עוגיות ואחסון בדפדפן
עוגייה אחת הכרחית, timer_session, שומרת את החיבור שלכם (HttpOnly, Secure, SameSite=Strict). הדפדפן שומר גם עותק מקומי של הנתונים ופעולות שממתינות לסנכרון, כדי שהמערכת תעבוד בלי חיבור. יציאה מהחשבון מאפשרת למחוק את העותק המקומי.
ספקים שמעבדים מידע עבורנו
- Cloudflare: DNS, הצפנת התעבורה והגנה מפני התקפות. התעבורה לאתר עוברת דרכם.
- Brevo: שליחת הודעות דואר של המערכת (אימות כתובת, שחזור סיסמה, הזמנות). הם מקבלים את כתובת הנמען ואת תוכן ההודעה.
- Fiduso: קישור חשבונות, תשלום, חיוב, חשבוניות וניהול רכישות וביטולים והחזרים. בעת קישור החשבונות UseTimer מעביר את מזהה המשתמש שלו ל־Fiduso ומקבל את מזהה ופרופיל חשבון Fiduso ואת אישור הקישור. Fiduso מעביר ל־UseTimer את פרטי הרכישה והזכאות הנדרשים להפעלת המסלול ולעדכונו. פרטי הכרטיס נמסרים בתהליך התשלום של Fiduso ולא ל־UseTimer; מידע שנמסר בתהליך התשלום מעובד גם בידי Fiduso. במועד עדכון מסמך זה אין בידינו קישור למדיניות פרטיות ציבורית שלה; ניתן לפנות אלינו לבירור לפני קישור חשבון או רכישה.
- שרת ייעודי (VPS) שעליו פועלים השירות ומסד הנתונים, והגיבויים שלו.
חלק מהספקים עשויים לעבד מידע מחוץ לישראל, בהתאם להגנות המקובלות אצלם.
שיתוף עם אחרים
בנוסף לעיבוד בידי הספקים המתוארים לעיל, מידע משותף לפי פעולה שלכם: חברי צוות בסביבת עבודה שאתם חברים בה, או מי שקיבל מכם קישור לדוח משותף. נמסור מידע לרשויות רק כשהחוק מחייב זאת.
חיבורים למערכות אחרות
חיבור לשירות חיצוני, כגון Zync, נעשה באישורכם עבור סביבת עבודה והרשאות מוגדרות. השירות המחובר עשוי לקבל מזהי משתמש וסביבה, פרטי קטלוג ורשומות זמן בהתאם להרשאות שאישרתם. Webhook מוסר הודעת שינוי ומזהה סביבה; התוכן עצמו נמשך רק באמצעות הרשאה. ניתן לבטל את מפתח החיבור בהגדרות החשבון. ביטול עוצר גישה נוספת אך אינו מוחק אוטומטית מידע שהועתק כבר לשירות המחובר; מחיקתו כפופה גם למדיניות אותו שירות.
כמה זמן המידע נשמר
- נתוני החשבון והעבודה נשמרים לצורך הפעלת החשבון והשירות. מחיקה במערכת עשויה להיות מחיקה לוגית: הרשומה מסומנת כמחוקה, אך נשארת באחסון עד להסרה בפועל. סימון כמחוק או בקשת מחיקת חשבון אינם מבטיחים מחיקה מיידית מכל עותק. בקשת מחיקה תיבחן לפי סוג המידע, הצורך בו להפעלת השירות וחובות השמירה לפי דין.
- פרטי קישור, אישורי קישור, רכישות וזכאות נשמרים לצורך ניהול הקישור והמנוי, בירור חיובים, ביטולים והחזרים, מניעת הונאה ועמידה בחובות דין ככל שחלות. ביטול מנוי אינו מוחק רישומים אלה אוטומטית. בקשת מחיקה נבחנת מול הצורך לשמור רישומים למטרות אלה; אין כאן הבטחה למחיקת רישומים שחובה לשמור. מידע שכבר נמסר ל־Fiduso מנוהל אצלה; ניתן לפנות אלינו לבירור בקשת מחיקה הנוגעת לקישור.
- קישורי דוח משותפים פוקעים לפי ההגדרה שבחרתם.
- רישומים טכניים ורישומי ביקורת נשמרים לצורכי אבטחה, מניעת שימוש לרעה ובירור תקלות; רישומי חיוב וחשבונאות נשמרים ככל שנדרש לבירור עסקאות ולעמידה בחובות דין. הצורך בשמירה תלוי במטרה, באירועים שדורשים בירור ובחובות הדין החלות, ולא בתקופה אחידה לכל המידע.
- גיבויים עשויים לכלול מידע שנמחק מהמערכת הפעילה עד להחלפתם או להסרתם במחזור הגיבוי. מחיקה מהמערכת הפעילה אינה מחיקה מיידית מהגיבויים.
הזכויות שלכם
אתם רשאים לעיין במידע, לתקן אותו, לייצא את נתוני העבודה (דוחות וייצוא מתוך המערכת) ולבקש את מחיקת החשבון והנתונים שלו, בכפוף לשמירת רישומים הנדרשים למטרות המתוארות לעיל או לפי דין. בקשות נשלחות ל־[email protected] מהכתובת הרשומה בחשבון ככל שאפשר, כדי לסייע באימות הבקשה. נאשר קבלת בקשה ונבחן אותה, לרבות הצורך באימות זהות ובהמשך שמירת רישומים, בכפוף למועדים המחייבים לפי הדין החל. אם אינכם מרוצים מהטיפול, ניתן לפנות לרשות להגנת הפרטיות.
אבטחה
התעבורה מוצפנת (HTTPS), סיסמאות נשמרות כגיבוב, הגישה לנתונים נבדקת לפי חשבון והרשאה, והגיבויים נשמרים בגישה מוגבלת. אף מערכת אינה חסינה לחלוטין; אם תתגלה פגיעה שנוגעת לכם, נודיע לכם.
ילדים
השירות מיועד לשימוש מקצועי ואינו מיועד לילדים מתחת לגיל 16.
שינויים
נעדכן את המדיניות בעמוד זה. על שינוי מהותי נודיע בדואר או בתוך המערכת לפני שייכנס לתוקף.
Privacy policy
Last updated: 8 October 2026
Who we are
UseTimer (https://usetimer.app) is operated by Avi Ezra, Israel. Privacy questions and requests: [email protected].
What we collect
- Account details: email address, display name, time zone, language and preferences. Passwords are stored only as a one-way hash.
- Work data you enter: time entries, descriptions, clients, projects, tasks, tags, rates, reports, team settings and files you import.
- Sessions and security: a session cookie, the device name you choose, IP address, browser type, sign-in times and audit records of sensitive actions.
- Fiduso identity links and purchases: UseTimer user identifier, Fiduso account identifier (subject) and profile including display name and primary email; link confirmation, purchase identifiers, plan, member quantity, entitlement period, and purchase and entitlement status. UseTimer does not receive or store credit-card details.
- System email: delivery status of verification, recovery and invitation messages.
There are no ads, no sale of data and no third-party tracking cookies.
Browser speech dictation
Where supported by your browser, dictation starts only at your direction, after an in-product disclosure and the browser's microphone permission. Audio may be sent to the browser provider's recognition service; that processing is subject to the recognition provider's terms and privacy policy. Recognition may require an internet connection. UseTimer does not promise local processing or offline recognition.
UseTimer does not save an audio file. The recognized text may be stored as a time-entry description, in a local draft or in the synchronization queue, depending on your action and the system state. Once saved as work data, it follows the work-data retention, sharing and deletion rules in this policy. You can cancel dictation or choose to type a description instead.
How we use it
Only to provide the service: sign-in, storing and syncing your work, reports, sharing with team members you invite, system email, linking account identities, assigning purchases and enabling Pro or Team entitlements, resolving billing and cancellation/refund requests, abuse prevention and account security.
Cookies and browser storage
One essential cookie, timer_session (HttpOnly, Secure, SameSite=Strict). The browser also keeps a local copy of your data and pending changes so the app works offline; signing out lets you clear it.
Service providers and recipients
Cloudflare (DNS, TLS and attack protection; site traffic passes through it), Brevo (system email: recipient address and message content) and the virtual server that hosts the service, its database and backups. Some providers may handle data outside Israel.
Fiduso: account linking, checkout, billing, invoices, purchase management, cancellations and refunds. When you link accounts, UseTimer sends its user identifier to Fiduso and receives the Fiduso account identifier, profile and link confirmation. Fiduso sends UseTimer purchase and entitlement information needed to activate and update your plan. Card details are supplied in Fiduso’s checkout, not to UseTimer. Information provided at checkout is also processed by Fiduso. At this update we have no link to a public Fiduso privacy policy; contact us for clarification before linking accounts or purchasing.
Sharing
In addition to processing by the providers described above, sharing at your direction includes members of workspaces you belong to, or anyone you send a shared report link. We disclose data to authorities only when legally required.
Connections to other systems
A connection to an external service, such as Zync, requires your approval for a specific workspace and permissions. The connected service may receive user and workspace identifiers, catalog details and time entries within those permissions. A webhook sends change metadata and the workspace identifier; content is fetched only with authorization. Revoke the connection token in account settings to stop further access. Revocation does not automatically delete information already copied by the connected service; deletion is also subject to that service’s policy.
Retention
Account and work data are retained to operate your account and the service. Deletion in the app may be logical (soft) deletion: the record is marked deleted but remains in storage until actual removal. Marking a record deleted or requesting account deletion does not guarantee immediate removal from every copy. Deletion requests are assessed according to the type of information, the need to operate the service and applicable legal retention obligations. Identity-link details and confirmations, purchases and entitlements are retained to manage the link and subscription, resolve billing, cancellations and refunds, prevent fraud and meet applicable legal obligations. Cancelling a subscription does not automatically delete these records. Deletion requests are assessed against the need to retain records for those purposes; we do not promise deletion of records that must legally be kept. Information already provided to Fiduso is managed there; contact us to clarify a deletion request concerning the link. Shared links expire as you set them. Technical logs and audit records are retained for security, abuse prevention and troubleshooting; billing and accounting records are retained as needed to resolve transactions and meet legal obligations. Retention depends on the purpose, incidents requiring investigation and applicable legal obligations, rather than a single period for all information. Backups may retain data deleted from the active system until they are replaced or removed through backup rotation. Deletion from the active system does not immediately remove data from backups.
Your rights
You may access, correct and export your data and ask for your account and data to be deleted, subject to retaining records required for the purposes above or by law. Email [email protected] from your account address where possible to help verify the request. We will acknowledge and review the request, including any need for identity verification and continued record retention, subject to mandatory deadlines under applicable law. You may also contact the Israeli Privacy Protection Authority.
Security
Traffic is encrypted (HTTPS), passwords are hashed, access is checked per account and permission, and backups are access-restricted. If a breach affects you, we will tell you.
Children
The service is for professional use and not intended for children under 16.
Changes
Updates are published on this page; material changes are announced by email or in the app before they take effect.