תאריך תוקף: 26.07.2026
Checksal היא אפליקציה עצמאית לניהול רשימות קניות משפחתיות, השוואת מחירים, וסריקת קבלות. אין רשת פרסום או ספק אנליטיקס מעורב — הגורמים החיצוניים היחידים המעבדים מידע מפורטים למטה.
| מידע | למה | איפה נשמר |
|---|---|---|
| תוכן רשימות הקניות | הרשימות והפריטים שלך | מסד נתונים מקומי מוצפן |
| תמונות קבלות | מקור ל-OCR — נמחק לאחר הסריקה כברירת מחדל | מערכת קבצים מקומית |
| שורות קבלה (מוצר, מחיר, תאריך) | היסטוריית קניות אישית | מסד נתונים מקומי מוצפן |
| מילון כינויי מוצרים | קישור שמות מוצרים לקטלוג | מסד נתונים מקומי מוצפן |
| סטטיסטיקת צריכה | מפעיל הצעות לחידוש מלאי | מסד נתונים מקומי מוצפן |
| צילומי מזווה | רישום פריטים שזוהו בתמונות מקרר/מזווה | מסד נתונים מקומי מוצפן |
אם אתה מצטרף למשק בית, המידע הבא מסונכרן למסד הנתונים שלנו (Supabase) כדי שחברי משק הבית יוכלו לשתף רשימות בזמן אמת:
כל המידע המסונכרן מוגן ב-Row-Level Security: רק חברי משק הבית שלך יכולים לקרוא או לכתוב אותו.
ניתן להתחבר עם קישור חד-פעמי במייל, או עם התחברות Google. אם אתה משתמש בהתחברות Google, גוגל משתפת איתנו את שמך, כתובת המייל ותמונת הפרופיל (דרך Supabase Auth) כדי ליצור את החשבון שלך — אנחנו אף פעם לא רואים או שומרים את הסיסמה שלך בגוגל.
סריקת קבלות (OCR) פועלת כיום לגמרי על המכשיר שלך (מנוע לא מקוון) — תמונת קבלה לעולם לא יוצאת מהטלפון לצורך חילוץ הטקסט.
כדי לאתר ולתקן חלקים איטיים או שבורים באפליקציה (זמן עלייה, מהירות חיפוש מחירים, זמן עיבוד קבלות, קריסות, וכדומה), אנחנו אוספים סט קטן של אירועי ביצועים אנונימיים: כמה זמן פעולה לקחה, האם הצליחה, ותחום גודל גס (למשל "1-5 פריטים") במקום ספירה מדויקת.
בנוסף אנחנו אוספים סט קטן של אירועי שימוש אנונימיים — למשל שסימון מבצע הוצג, שפרטי מבצע נפתחו, או שסכום סל כלל מבצע. אלה מלמדים אותנו אם פיצ'ר באמת מועיל ושווה להשאיר. הם מתעדים רק שאירעה פעולה — לעולם לא מה חיפשת, מה נמצא ברשימה שלך, או באיזה מוצר ספציפי מדובר.
כל אירוע מתויג במזהה התקנה אקראי שנוצר על המכשיר שלך — הוא אינו מזהה החשבון שלך, אינו מזהה פרסום, ואינו מקושר לשם, מייל או נתוני הקניות שלך. המזהה מתאפס בהתקנה מחדש. המידע הזה אינו כולל תוכן רשימות קניות, מיקום, או כל מידע אישי אחר, ולעולם לא משותף עם צד ג'.
| שירות | מתי | מה | למה |
|---|---|---|---|
| Google Sign-In | רק אם בוחרים להתחבר עם Google | שם, מייל, תמונת פרופיל | יצירת חשבון/הזדהות |
| פורטלי מחירים ממשלתיים | יומית, דרך Edge Function שלנו | אין מידע אישי — שולפים XML מחירים פומבי | השוואת מחירים |
| שרתי התמונות של רשתות השיווק | כשמוצגות תמונות מוצרים | איננו שולחים מידע — אבל עצם הבקשה חושפת בפניהם את כתובת ה-IP שלכם | הצגת תמונות מוצרים |
תמונות שמוצגות באפליקציה — תמונות מוצרים ותמונת הפרופיל מגוגל — נטענות ישירות משרתי אותם צדדים שלישיים. אנחנו לעולם לא מעתיקים את קובצי התמונה לשרתים שלנו; הן נשמרות במטמון על המכשיר שלכם בלבד. בקשה ישירה כזו חושפת את כתובת ה-IP שלכם בפני השרת שמארח את התמונה, בדיוק כפי שגלישה רגילה לאתר של אותה חברה הייתה עושה.
| הרשאה | מתי מתבקשת | למה |
|---|---|---|
| מצלמה | פעולת סריקה ראשונה | סריקת ברקוד, OCR לקבלות |
| מיקום (מדויק/משוער) | שימוש ראשון בהשוואת מחירים | דירוג חנויות קרובות לפי מרחק |
| אנשי קשר | רק בלחיצה על "הזמנה מאנשי קשר" | מציג אילו אנשי קשר כבר משתמשים באפליקציה; התאמה לפי hash של טלפון/מייל — הרשימה המלאה לעולם לא מועלית |
| התראות | לאחר אירוע ראשון במשק הבית | נקודת התראה קטנה כשחבר משק בית משנה רשימה משותפת בזמן שאתה לא באפליקציה |
תמונות נבחרות דרך ה-Photo Picker המובנה של אנדרואיד, שלא דורש הרשאת אחסון/מדיה בכלל.
| מידע | שמירה כברירת מחדל | שליטת המשתמש |
|---|---|---|
| תמונות קבלה | נמחקות לאחר OCR מוצלח | הגדרות ← תמונות קבלה |
| מסד נתונים מקומי | נשמר עד מחיקת האפליקציה או "מחיקת חשבון" | מחיקת חשבון מוחקת אותו |
| שורות ב-Supabase | נמחקות כחלק מבקשת "מחיקת חשבון", מעובד אוטומטית בשרת | זהה |
אם מדיניות הפרטיות תשתנה באופן מהותי, מסמך זה יעודכן ותוצג הודעה באפליקציה.
לשאלות או בקשות מחיקת חשבון, פנו אל: checksal.app@gmail.com
Effective date: 2026-07-26
Checksal is an independently developed app for household shopping list management, price comparison, and receipt scanning. There is no advertising network or analytics vendor involved — the only third-party data processors are described below.
| Data | Why | Stored where |
|---|---|---|
| Shopping list contents | Your lists and items | Encrypted local database |
| Receipt images | OCR source — deleted after scan by default | Local filesystem |
| Receipt line items (product, price, date) | Personal purchase history | Encrypted local database |
| Product alias dictionary | Links your product names to catalog SKUs | Encrypted local database |
| Consumption stats | Powers restock suggestions | Encrypted local database |
| Pantry snapshots | Records items seen in fridge/pantry photos | Encrypted local database |
If you join a household, the following is synced to our Supabase database so household members can share lists in real time:
All synced data is protected by Row-Level Security: only members of your household can read or write it.
You can sign in with a one-time email link, or with Google Sign-In. If you use Google Sign-In, Google shares your name, email address, and profile photo with us (via Supabase Auth) to create your account — we never see or store your Google password.
Receipt OCR currently runs entirely on your device (an offline engine) — no receipt photo ever leaves your phone for text extraction.
To find and fix slow or broken parts of the app (startup time, price-lookup speed, receipt-processing time, crashes, and similar), we collect a small set of anonymous performance events: how long an operation took, whether it succeeded, and a coarse size bucket (e.g. "1-5 items") rather than an exact count.
We also collect a small set of anonymous feature-usage events — for example, that a promotion indicator was displayed, that promotion details were opened, or that a basket total included a promotion. These tell us whether a feature is actually useful and worth keeping. They record only that an interaction happened, never what you searched for, what is on your list, or which specific product was involved.
Every event is tagged with a random installation ID generated on your device — it is not your account ID, not an advertising ID, and is not linked to your name, email, or shopping data. It resets if you reinstall the app. This data contains no shopping-list content, no location, and no other personal information, and is never shared with third parties.
| Service | When | What | Why |
|---|---|---|---|
| Google Sign-In | Only if you choose to sign in with Google | Name, email, profile photo | Account creation/authentication |
| Government price portals | Daily, via our Supabase Edge Function | No user data — we fetch public price XML | Price comparison |
| Retailer image servers | When product images are shown | We send no data — but the request itself reveals your IP address to them | Displaying product photos |
Images shown in the app — product photos and your Google profile picture — are loaded directly from those third parties' servers. We never copy the image files to our servers; they are cached on your device only. A direct request like this reveals your IP address to the server hosting the image, exactly as browsing to that company's own website would.
| Permission | When requested | Why |
|---|---|---|
| Camera | First scan action | Barcode scanning, receipt OCR |
| Fine/Coarse Location | First time you use price comparison | Rank nearby stores by distance |
| Read Contacts | Only when you tap "Invite from contacts" | Show which of your contacts already use the app; matched by hashed phone/email — the full list is never uploaded |
| Post Notifications | After the first household event | Small icon badge when a household member changes a shared list while you're away from the app |
Photos are selected via Android's built-in Photo Picker, which does not require a storage/media permission at all.
| Data | Default retention | User control |
|---|---|---|
| Receipt images | Deleted after successful OCR | Settings → Receipt Images |
| Local database | Kept until you delete the app or use "Delete Account" | Delete Account wipes it |
| Supabase rows | Deleted as part of the "Delete Account" request, processed automatically by our server | Same |
If the data practices change materially, this document will be updated and a notice shown in the app.
For questions or account-deletion requests, contact: checksal.app@gmail.com