Al-Tahmitsu

Al-Tahmitsu

Privacy Policy

Effective All versions

At a glance

  • Most of the app works without an account, and your baking data stays only on your device.
  • An account is optional and only needed for the community. If you create one, we store your email, a display name and what you post.
  • No ads, no tracking, no selling data. The app has no advertising or analytics SDKs.
  • The app runs on Supabase, with servers in the EU. Apple handles sign-in and payments.
  • You can delete your account at any time in the app (Profile → Delete account) or by email.
Contents

Al-Tahmitsu ("the app") is a sourdough baking app with a community of bakers. This policy explains what data we collect, why, who we share it with, how long we keep it and what your rights are. It is our notice under section 11 of the Israeli Protection of Privacy Law, 5741-1981, and under any other privacy law that applies to you.

1. Who is responsible for your data

The app is built and operated by Oz Yahav, Israel, under the AbraCodeAbra studio. He is the controller of your data (the "database owner" under Israeli law).

2. What we collect

Without an account (guest mode)

Most of the app works without an account, and in guest mode nothing that identifies you is stored on our servers. That includes baking tracking, your starter, timers, recipes, the guide and read-only access to the community. Your baking data (doughs, starter, history and timers) is stored only on your device.

Account details (only if you choose to sign in)

You need an account to post, comment, like, follow, publish recipes or send a tip. With an account we store:

  • Your email address. It comes either from Sign in with Apple, which may give us an anonymous Apple relay address, or from signing in with a one-time code sent to your email.
  • A display name. If you choose to add them, also a profile photo, a short bio, a general location and how long you've been baking.
  • An internal user ID that links your content to your account.

Content you create

Posts, comments, reactions, recipes you publish and photos you upload to the community or your profile. We also store reports and blocks you make.

"Firgun" tips

If you send a "Firgun" tip, we store a running count of your tips so we can show a supporter badge. We never receive any payment details (see section 9).

Camera, photos and notifications

  • Camera and photos: access is requested only when you choose to take or attach a photo, and used only for that. The app never browses your photo library.
  • Notifications: off by default. If you turn them on, baking reminders are scheduled on your device.

What we don't collect

  • Advertising identifiers (IDFA).
  • Your precise location.
  • Any tracking of you across other apps or websites.
  • Data for advertising, analytics or behavioral-profiling SDKs, because the app has none.

3. Do you have to give us this data?

No law requires you to give us any data. Everything you provide is voluntary:

  • If you don't create an account, you can still use everything except posting, commenting and other community actions.
  • Extra profile details and photos are entirely optional.
  • An email and a display name are needed for an account to work, so you can't create one without them.

4. How we use your data

  • To run the app and its community features: posting, comments, likes, follows and recipe sharing.
  • To show the community feed, including basic personalization such as posts from people you follow.
  • To manage and secure your account and prevent abuse.
  • To enforce the community guidelines, filter abusive content and handle reports.
  • To provide support and answer your messages.

We do not use your data for targeted advertising or marketing profiles, and we never sell it.

If the GDPR or a similar law applies to you, we process your data on one of these bases:

  • Performance of a contract: to provide the service you asked for.
  • Consent: for example, turning on notifications or uploading photos. You can withdraw consent at any time.
  • Legitimate interests: keeping the service secure and preventing abuse.
  • Legal obligation: where the law requires it.

6. Who receives your data, and why

We never sell or rent your data. It is shared only with the parties below, and only for the purposes described:

  • Supabase, our infrastructure provider, runs the database, photo storage and authentication, and sends one-time sign-in codes by email. It acts as a processor on our behalf and follows our instructions. Its servers are in the EU region, and all traffic is encrypted with TLS.
  • Apple handles Sign in with Apple and in-app purchases. Apple's privacy policy also applies to your use of these services.
  • Other users see what you post publicly (see section 7).
  • Authorities, if we are legally required to share data, or to protect safety, rights or property.

Equal protection: every provider that receives data from us must protect it at a level equal to, or equivalent to, the one described in this policy, and use it only for the purpose it was shared for.

We never share data with ad networks or data brokers.

7. Public community content

Everything you post in the community can be seen by every user of the app, including guests without an account. That includes posts, comments, public recipes, your display name, your profile photo and your supporter badge. Don't share anything you don't want to be public. You can delete anything you've created at any time.

8. Content filtering, reports and blocking

Because the app has user-generated content, it has a few safeguards:

  • Automatic filtering: before anything is published, all text is checked against a list of banned terms, both on your device and on the server. Text that contains a banned term isn't published. This is the only automated decision in the app, and it does not use AI.
  • Reports: we review every report within 24 hours, remove content that breaks the rules and block repeat offenders.
  • What we process: only what's needed to handle it, meaning the reported content, the report and the user ID.

9. In-app purchases ("Firgun" tips)

A "Firgun" is a voluntary one-time tip that supports the developer and adds a cosmetic badge. It unlocks nothing. Apple processes the payment, and we never receive, see or store your card or payment details.

10. How long we keep data, and how to delete it

  • Account data and content are kept as long as your account is active.
  • Deleting your account: do it in the app (Profile → Delete account) or ask us by email. Full instructions are on the Delete your account and data page.
    • Deletion permanently removes from our servers your profile, posts, comments, reactions, recipes, follows, blocks and tip count.
    • Anything you posted disappears from the community immediately.
  • Local data (doughs, starter and baking history) exists only on your device and is removed when you delete the app.
  • Backups: backup copies held by our infrastructure provider are erased in its normal backup cycle. Records we are legally required to keep are kept only for as long as that requirement lasts.
  • Support emails are kept only as long as we need them to handle your request.

11. Your rights

  • Access: under section 13 of the Israeli Protection of Privacy Law, you can find out what data we hold about you.
  • Correction and deletion: under section 14, you can ask us to correct or delete data that is inaccurate, incomplete, unclear or out of date.
  • Further rights, if the GDPR or a similar law applies to you:
    • restrict or object to processing;
    • receive a copy of your data in a portable format;
    • withdraw your consent.

How to use your rights: email privacy@abracodeabra.org from the address linked to your account. We'll reply within 30 days at most. If you're not satisfied with our answer, you can complain to the Israeli Privacy Protection Authority or to the data protection authority in your country.

12. International transfers

Account and community data is stored on servers in the EU. The EU recognizes Israel as providing an adequate level of data protection, and Israeli law allows transfers to EU countries. If you use the app from another country, your data may be processed outside your country, always with the protections described here.

13. Security

  • Traffic between the app and our servers is encrypted with TLS.
  • Access to data is limited by row-level security, so each user can reach only what they're allowed to.
  • Administrative access is limited to the operator.

No service is 100% secure. If a serious security incident affects your data, we will notify you as the law requires.

14. Children

  • The community is for users aged 13 and over, and you'll be asked to confirm your age before entering it.
  • Without the community, anyone can use the rest of the app without giving us any data.
  • Data from children under 13: we don't knowingly collect it. If we find that we have, we'll delete it. If you're a parent or guardian and think your child has given us data, please contact privacy@abracodeabra.org.

15. Do Not Track

We don't track users across apps or websites, and we don't let third parties do so. The app therefore behaves the same whether or not a Do Not Track signal is turned on.

16. Changes to this policy

  • Every version is published at this address with its effective date.
  • Previous versions are kept in the version archive.
  • Material changes: we'll tell you about them actively and in advance, with an in-app notice or an email to account holders.

17. Contact

This policy is governed by the laws of the State of Israel. For any privacy question or request: privacy@abracodeabra.org

Questions?

You can write to us about anything related to this document.

privacy@abracodeabra.org