Privacy Policy — Flowli-App
This is a convenience translation. The Hebrew version is the legally binding one. Hebrew version
Version 3.9 · September 2026
Full transparency: when you use Flowli-App, it is important that you know what happens to your information, who sees it, where it is stored, and when it is deleted. This document explains all of that in full. It was written following the Privacy Protection Law (Amendment 13), which took effect in August 2025 and implements expanded transparency obligations.
1. Who We Are
Flowli-App is operated by Ran Moshe, a registered sole proprietor in Israel (business no. 021661715), 55 Vardia St., Haifa, Israel ("we"). "Flowli-App" is a trade name of that business, not a separate company. Flowli-App is not an AISP, not a financial intermediary and not an insurer, and it is an independent product — not part of ManoMix and sharing no data with it. Contact for any matter, including requests under the Israeli Consumer Protection Law and the Privacy Protection Law: user@flowliapp.co.il.
2. Information We Collect
- Account details: name, email address, financial profile (private / salaried / Exempt Dealer / Licensed Dealer).
- Budget data you enter: expenses, income, savings goals, and the bank-account or credit-card details you enter — name, nickname, the last four digits (never a full number), and a balance, debt or credit limit.
- Chat history with the bot.
- Voice (Boti mode): if you choose to speak to the bot instead of typing — the transcript of what you said. The recording itself is neither sent to us nor stored by us; speech-to-text is performed by your device's operating-system speech-recognition service (see Section 4). The transcript is sent to the bot and kept in your chat history exactly like a typed message, and the reply is read aloud by the device itself. The microphone is activated only after you tap the speak button, and turns off at the end of the sentence or on a second tap.
- Answers and figures you entered in the tax and tax-refund screens (see §5d).
- Technical information: device type, app version, anonymous error logs.
- How you found us: the option you chose in a question asked once during onboarding — Instagram, Facebook, TikTok, YouTube, Google, the app store, a friend, WhatsApp, "Something else" or "I don't remember". Stored on your account. One option must be chosen to finish onboarding, and "I don't remember" is a fully valid answer. Only the choice from that list is stored — there is no free-text field here, and any other value is rejected rather than saved.
- Notifications: if you allowed notifications on your device — the device's notification identifier, a random installation identifier, and the interface language you chose. The identifiers are randomly generated, are not derived from your hardware, and do not identify you outside the App.
3. Use of Information
The information is used solely to:
- Display your data back to you.
- Perform financial calculations (taxes, savings, trends).
- Operate the AI Bot when you ask it questions — typed or spoken.
- Improve the App (aggregate statistics only, with no personal identification).
- Send you service notifications in the language you chose — for example a seasonal reminder to check a possible tax refund. A notification never contains amounts, names or financial details.
- To know which channels are worth telling people about Flowli-App on — from aggregate counts of the answers to "How you found us" only, never linking an answer to a person.
4. Sub-processors
To operate the service we rely on the following providers — all under signed DPA agreements:
- Cloudflare (Ireland / EU + USA) — data storage (D1) and file storage (R2). The platform is based in an EU region with standard security mechanisms.
- Anthropic (USA) — the Claude model that powers the AI Bot and the categorization of PDF files (see Section 5b). What is sent to it: the content of your conversation with the bot, the budget context attached to it, and the contents of files you approved for processing. Anthropic contractually undertakes not to use our input to train models, and automatically deletes inputs and outputs within 30 days — this is its default policy for API customers, and it is the one that applies to us. We do not have a zero-retention agreement with it, so within a window of up to 30 days the content exists on its servers.
- Expo (USA) — the notification delivery service. Receives the device's notification identifier, the notification title and body, and a short technical field telling the app which screen to open on tap and which campaign the notification belongs to (for example "tax_refund_2025") — and passes them to Apple or Google. Receives no financial data and does not receive your account contents.
- Firebase Authentication (Google, USA) — authentication service (sign-in via Google and Apple only). It receives only your email address as provided by the provider (Google/Apple), not files and not financial data. Flowli-App does not collect or store passwords — authentication is performed entirely by Google and Apple.
- Resend (Ireland / EU) — operational email service (feedback to the developer, consent confirmations). It does not receive file contents or financial records.
Speech recognition in Boti mode is not a sub-processor of ours: it is a built-in service of your device's operating system — Apple on iOS, Google on Android — operating between you and that company under its terms of use and privacy policy, and depending on the device settings the audio may be processed on its servers for conversion to text. We receive only the transcript. The bot's reply is read aloud on the device and is not sent to any provider.
5. Importing Bank and Credit Card Statements
5a. CSV / TSV / Excel files — read on the device only.
When you import a bank or credit statement in CSV, TSV, or Excel format via "Data Import and Export," the file is read and parsed exclusively on your device. The bytes are not uploaded to our server, are not sent to Anthropic, and are not exposed to any third party. The automatic category suggestion for each line (food / car / insurance, etc.) is computed on your device according to an open Hebrew keyword list. Only the records you explicitly approved on the review screen (date, description, amount, category) are saved in Cloudflare D1 as items in your monthly budget — the same place and with the same encryption as records you entered manually. The original file, the account numbers and balances that appear in it, and lines you did not choose to import — all remain on the device and are not transferred to any third party.
5b. PDF files and receipt images — Track B (AI processing in the cloud).
PDF files (from bank statements that do not provide CSV, and your accountant's ledger) and receipt images require advanced text recognition (OCR) that cannot be performed locally on an iPhone/Android. For a PDF/image file:
- A bank or card statement, and your accountant's ledger: before uploading, we request your explicit consent for each specific file. The consent is recorded in Cloudflare D1, and without it the server refuses to process the file.
- A receipt, and any image you attach in the chat: before the first one, we request your explicit consent once, on a screen that sets out what is sent, where and for how long. The consent is recorded in Cloudflare D1 and covers every receipt and image you send after it from the same device; another device asks again. No receipt is sent without an action of yours — taking a photo or choosing a file — and never in the background.
- The file will be uploaded to secure private storage (Cloudflare R2, private, inaccessible without authentication).
- A bank or card statement and a ledger are deleted from storage as soon as their reading ends — also when it fails — and within 24 hours at the latest (for instance when a file was uploaded but its reading never started). Nothing needs them after the reading: only the records you approved go into your budget.
- A receipt, and any image from the chat, stay in storage for up to 24 hours, so you can see the document before you approve the receipt. An automatic sweep running every hour deletes them after 23 hours — so such a file is always deleted within 24 hours of upload. An image you attached in the chat is sent to the AI again with your next messages in the same conversation while it is stored, so the bot can keep working on it.
- A scanned receipt waits for your approval in the "Receipts to approve" screen, and that queue has no deadline. The file itself is deleted at the time above regardless, even if you have not approved it yet. The details extracted from the receipt (supplier, date, total, VAT) are kept and you can still approve it later — only the original document is no longer available. The app shows you how long is left before the file is deleted.
- The file's contents — including any PII (account numbers, IBAN, ID numbers) to the extent they appear in it — will be sent to Anthropic Claude (USA) for OCR. Anthropic is contractually obligated not to train models on your input, and automatically deletes inputs and outputs within 30 days. We do not have a zero-retention agreement with it, so within that window the file contents exist on its servers.
- As of May 23, 2026: automatic filtering is applied to the processing results — sensitive identifiers (ID number, IBAN, credit card, bank account number) are removed before the derived records are saved in D1.
- Only the records you approved on the review screen will be saved in your budget — exactly as with CSV.
- You may withdraw your consent at any time: for a statement or a ledger, simply do not approve the next file; for receipts and images, under Settings → Privacy → "Sending files to AI". The withdrawal applies to the device you make it on, and after it we will ask again before the next one.
- Alternative: export CSV/Excel from the bank and upload it instead — the file will be read only on your device (Track A).
5c. Track distinction — Track A (local) and Track B (AI):
Track A (CSV / Excel / TSV): the file is read only on your device. Anthropic is not involved. Only the records you approved are sent to the server.
Track B (PDF / images): the file's contents — including possible PII — pass through Anthropic's servers for OCR. After processing, PII is automatically filtered from the derived records. The original file is deleted from our storage — a statement or ledger as soon as it has been read (within 24 hours at the latest), a receipt or image within 24 hours (see §5b); at Anthropic, inputs and outputs are deleted within 30 days (see Section 4).
5d. Form 106 — salaried tax-refund check.
In the "tax refund check" screen you can type two figures from your form 106 by hand, or scan the form instead. The scan is the only path in this feature that involves cloud processing, and it is subject to a stricter contract than §5b:
- Before any upload we ask for your explicit consent for that specific file; the consent is recorded in Cloudflare D1, and without it the server refuses to process the file.
- The file is uploaded to secure private storage (Cloudflare R2) and deleted the moment it has been read — not after 24 hours. The hourly cleanup cron remains only as a safety net.
- The form's content is sent to Anthropic Claude (USA) to be read, like any document under §5b. Anthropic is contractually bound not to train models on your input, and deletes inputs and outputs within 30 days. The immediate deletion described above applies to our storage only — we have no zero-retention agreement with Anthropic.
- The server returns to the app numbers and yes/no flags only — taxable salary, tax withheld, the year on the form, and three technical flags: whether the form carries payments for a previous year, whether it shows employer contributions, and whether the file holds forms for more than one person. No text from the document comes back: your name, ID number, employer file number, employer name and address are not returned, are not stored in D1, and do not appear in logs — not even when the reading fails.
- Scanning is available to everyone and counts against a separate monthly quota — 3 scans a month free, 10 on the Flowli-App Plus plan (§7). Typing the same two figures by hand is unlimited and reaches the same result, with no file leaving your device.
- Consent is asked again for every file: if you do not accept the dialog, the file does not leave your device. There is no automatic upload and no standing consent.
- The result of the check is stored in your account in Cloudflare D1 — the two figures you typed or scanned, the answers you selected in the questionnaire (months worked, children's birth years, donations, locality, year of aliyah) and the computed result — so we can show it to you again and remind you before the filing window closes. It contains no name, ID number or employer name, and it is deleted when you delete your account.
6. Legal Notice — Flowli-App Is Not an AISP
Flowli-App is not a financial information service provider under the Financial Information Service Law, 5782-2021. We do not have automatic read access to banks, an API connection, open-banking authorization, or any mechanism for continuous consumption of financial data. Every import is a one-time act that you initiate. Flowli-App acts as a data processor on your behalf — exactly like a spreadsheet program you use to organize your own files.
7. Security — Protective Measures We Implement
- TLS 1.3 for all communications.
- Domain pinning on the client side (the server address is hardened).
- Encryption at rest in Cloudflare D1 and R2.
- Local biometric PIN (salted SHA-256, 100 rounds) — optional and enabled by you.
- Tokens and User cache in SecureStore (iOS Keychain / Android Keystore).
- Session timeout: 20 minutes, with a check every 60 seconds while in the foreground.
- Lockout: 5 incorrect PIN attempts → temporary lock.
- Rate limiting: 5 login attempts / 30 seconds.
- Monthly usage limits: enforced server-side. On the free plan — up to 30 chat/voice conversations, 10 bank/credit statement imports, 40 receipt scans and 3 Form 106 scans (§5d) per month. On Plus — 60 / 15 / 60 / 10 respectively. In addition there is a daily ceiling on AI requests (including scans and imports) shared by all users; once it is spent the action is declined until midnight and a message is shown. All adjustable remotely without an app update.
- Tenant isolation: every query over personal data in D1 is filtered by user; there is no leakage between users. The single exception is the deletion of a notification identifier reported to us as dead — such an identifier describes a device rather than a person, and is removed everywhere it appears.
8. Sharing of Information
We do not sell, share, or use your data for any purpose beyond operating the service. Your data is yours alone.
9. Your Rights Under the Law
Under the Privacy Protection Law (Amendment 13), you have the following rights:
- Access: Settings → Export Data (CSV/JSON).
- Correction: direct editing of any record on the budget screen. One exception — the "How you found us" answer is stored once and cannot be edited in the app; it is also not part of the data export; to see, change or delete it, write to user@flowliapp.co.il.
- Deletion: Settings → Delete Account (deletes the account and all data associated with it).
- Portability: export in standard CSV/JSON.
- Objection to processing: deleting the account = ceasing processing.
- Withdrawal of consent: the consent to send receipts and images to AI can be withdrawn at any time under Settings → Privacy → "Sending files to AI" (the withdrawal applies to the device you make it on). For a statement, a ledger and Form 106, consent is asked before every file, and you can simply not approve the next one.
- Complaint: user@flowliapp.co.il + the Privacy Protection Authority.
10. Account Deletion
Deleting your account via Settings → Delete Account erases all data associated with it: transactions, savings goals, files you uploaded, chat history with the bot, and personal settings. The deletion is irreversible. Only an anonymous log is retained for internal statistical purposes (with no personal identification). So that deleting and signing up again cannot reset usage limits or grant a second free trial, for up to 40 days after deletion we keep a one-way code derived from your email address (a keyed cryptographic hash that cannot be turned back into the address) together with the date of deletion and the usage counters of the current month and day. It contains no name or address, and after 40 days it is erased.
11. Smart Savings Coach — Optional
This feature is activated only if the user chose to enable it under Settings → Privacy and Personalization. The default: off.
What is shared with third parties:
- Only the category (food / mobile / internet, etc.) and an estimated monthly amount — not a specific transaction description, not an account number, not your name, not your email address, not a phone number.
- Amounts are passed in coarse rounding (for example, "₪200-300 for internet"), not precisely.
- No unique identifier of yours is passed to the providers. The request is anonymous from their side.
Who are these providers?
- Anthropic Claude (USA) — for analyzing the category and suggesting initial alternatives.
- Israeli price-comparison services (when the feature is fully integrated) — for returning alternatives and prices. A full list will be published here upon final launch.
What does not happen:
- Flowli-App does not receive any payment, affiliate, or commission from any provider for a suggestion. The suggestions are pure AI analysis.
- Should this change in the future — we will disclose it explicitly in this document and in every suggestion.
- We do not share your identity with the providers that make suggestions.
Your consent:
- Will be recorded in consent_logs in Cloudflare D1 with consent_type='smart_savings_v1' and a precise date.
- Can be withdrawn at any time under Settings → Privacy and Personalization.
- Withdrawing consent immediately stops the external sharing of categories + amounts.
Suggestions:
- Are clearly marked "Automatic AI suggestion — not advice."
- Are not financial advice, tax advice, insurance advice, or a formal recommendation.
- Always verify terms with the provider before switching.
12. Children
The App is not intended for children under 13, and we do not knowingly collect information from children. If we learn that a user under 13 has registered, we will delete the account. A parent or guardian who believes their child has used the App is welcome to contact us: user@flowliapp.co.il
13. Changes to the Policy
This policy may be updated as new features are added or in response to regulatory changes. Material changes will be displayed with a notice in the App. The last revision date is shown at the top of the document.
14. Contact
For questions regarding privacy, exercising your rights, or reporting an incident: user@flowliapp.co.il
Last updated: September 2026 · Version 3.9
About this website
The policy above is the privacy policy of the Flowli-App mobile app. This marketing website, flowliapp.co.il, may set a consent cookie and, only if you accept the "marketing" category in the cookie banner, load the Meta Pixel; marketing data is deleted after 90 days. The details are in the website appendix of the Hebrew privacy policy. To ask us anything about your data, or to request deletion, write to user@flowliapp.co.il.