מדיניות פרטיות
בוקר שוקר נבנה כך שכמעט לא יידע עליך כלום. אין הרשמה, אין אימייל, אין סיסמה, ואף תמונה מהמצלמה לא יוצאת מהטלפון. הדף הזה מפרט בדיוק מה כן נשמר, אצל מי, ולמה.
01מי אנחנו ועל מה חלה המדיניות
בוקר שוקר (להלן "האפליקציה", "אנחנו") היא אפליקציית שעון מעורר ל-iPhone, שבה השעון נכבה רק אחרי שהמצלמה מוודאת שביצעת שכיבות סמיכה. מדיניות זו חלה על האפליקציה ועל האתר bokershoker.com.
אנחנו בעלי מאגר המידע והאחראים לעיבוד המידע לפי חוק הגנת הפרטיות, התשמ"א-1981 (לרבות תיקון 13), ולפי תקנת ה-GDPR במקום שהיא חלה.
02בקצרה
- אין הרשמה. לא מבקשים ולא מקבלים שם, אימייל, טלפון או סיסמה.
- המצלמה עובדת רק במכשיר. אין תמונות, אין וידאו, אין העלאה לשום מקום.
- אין פרסום. אין מזהי פרסום, אין מכירת מידע, אין מעקב בין אפליקציות ואתרים.
- מה שנשמר בשרת — השעונים שהגדרת, אירועי קימה, אזור זמן וסטטוס מנוי — מקושר למזהה אקראי בלבד.
03אין חשבון ואין הרשמה
בפתיחה הראשונה האפליקציה יוצרת עבורך משתמש אנונימי אצל ספק התשתית שלנו. מדובר במזהה אקראי (UUID) בלבד. הוא לא מכיל שם, אימייל, טלפון או חשבון רשת חברתית, ואיננו מבקשים אף אחד מהם בשום שלב.
המזהה נשמר על המכשיר. מחיקת האפליקציה מנתקת אותך ממנו, והתקנה מחדש יוצרת מזהה חדש — ולכן ההיסטוריה לא עוברת בין מכשירים. המנוי כן עובר, כי הוא מזוהה מול חשבון ה-Apple ID שלך.
04איזה מידע נאסף ולמה
| מה נאסף | לשם מה | היכן נשמר |
|---|---|---|
| מזהה משתמש אנונימי (UUID) | לשייך שעונים והיסטוריה לאותו משתמש ולזהות מנוי פעיל | שרת + מכשיר |
| הגדרות שעון: שעה, ימים בשבוע, תווית שהקלדת, סוג המשימה, משך ההחזקה, מופעל/כבוי | להפעיל את השעון ולשמור אותו בין הפעלות | שרת + מכשיר |
| אירועי קימה: מתי השעון היה אמור לצלצל, מתי המשימה הושלמה, האם הצליחה, ומשך ההחזקה | לחשב ציון בוקר, רצף ימים והיסטוריה | שרת |
| אזור זמן | לחשב שעות קימה נכון | שרת |
| סטטוס מנוי ותאריך עדכונו | לפתוח את הגישה לפיצ'רים שנרכשו | שרת + Keychain במכשיר |
| העדפות מקומיות: צליל השעון, מספר החזרות וימי המנוחה | להפעיל את השעון בדיוק כפי שהגדרת | המכשיר בלבד |
| תשובות שאלון הפתיחה | להתאים את הצעת המנוי שמוצגת לך (סעיף 06) | מכשיר + RevenueCat |
| נתונים טכניים: כתובת IP, סוג מכשיר, גרסת אפליקציה | אבטחה, מניעת שימוש לרעה ותפעול שוטף | אצל ספקי התשתית, לזמן קצר |
השדה החופשי היחיד באפליקציה הוא תווית השעון. אנא אל תכתבו בה מידע רגיש — היא נשמרת בשרת כפי שהיא.
05המצלמה — הכל קורה במכשיר
המצלמה נדלקת רק במסך המשימה, אחרי שהשעון צלצל, ונכבית ברגע שהמשימה נגמרת.
- הם מנותחים בזמן אמת על ידי מסגרת Vision של Apple, על המכשיר עצמו.
- לא מצולמות תמונות ולא מוקלט וידאו. כל פריים חי בזיכרון לרגע ומוחלף בבא אחריו.
- שום פריים, תמונה או נקודת שלד לא נשלחים אלינו או לצד שלישי, ולא נשמרים בגלריה או בקובץ.
- מה שנשמר בסוף המשימה הוא האם היא הושלמה וכמה זמן היא לקחה. זה הכל.
בפועל, מה שהמכשיר מחשב מהפריים הוא מספרים — זווית מרפק, גובה כתפיים, בהירות התמונה — והם נמחקים מיד. גם אנחנו לא יכולים לראות אותם.
06תשובות שאלון הפתיחה
לפני מסך הרכישה האפליקציה שואלת סדרת שאלות: מגדר, שעת הקימה הנוכחית והרצויה, כמה שעונים אתה מכוון, מה הכי מקשה עליך לקום, איפה שמעת עלינו וכדומה. התשובות:
- נשמרות על המכשיר כדי שתוכל להמשיך מהמקום שעצרת בו;
- נשלחות ל-RevenueCat כמאפייני לקוח (בקידומת
onb_) כדי להחליט איזו הצעת מנוי תוצג לך; - לא נמכרות, לא משמשות לפרסום ולא מקושרות לשמך — אין לנו שם לקשר אליו.
אינך חייב לענות במדויק, וחלק מהשאלות ניתנות לדילוג.
07רכישות ומנוי
התשלום מתבצע דרך ה-App Store של Apple. אנחנו לא רואים ולא שומרים מספר כרטיס אשראי, כתובת חיוב או פרטי Apple ID.
מה שכן מגיע אלינו, דרך RevenueCat: מצב המנוי (פעיל, מתחדש, בוטל, פג), מזהי עסקה ותאריכים. המידע הזה נשמר מול המזהה האנונימי שלך ומשמש רק כדי להחליט אם לפתוח את הגישה.
08הרשאות שהאפליקציה מבקשת
- מצלמה — לאימות תנוחת שכיבת הסמיכה. בלעדיה אי אפשר לסיים את המשימה.
- שעונים (AlarmKit) — כדי לקבוע שעון מערכת שמצלצל גם כשהאפליקציה סגורה.
- אודיו — להשמעת צליל השעון בזמן המשימה. האפליקציה אינה מקליטה קול.
כל הרשאה נשאלת בהקשר שבו היא נחוצה, וניתן לבטל אותה בכל רגע בהגדרות iOS. ביטול הרשאת מצלמה או שעונים ישבית את הפונקציה המרכזית של האפליקציה.
09מה שאנחנו לא עושים
- לא מוכרים, לא משכירים ולא סוחרים במידע.
- אין באפליקציה SDK של פרסום, אין שימוש במזהה הפרסומי (IDFA) ואין מעקב בין אפליקציות ואתרים.
- לא אוספים מיקום, אנשי קשר, לוח שנה, תמונות מהגלריה או נתונים מ-Apple Health.
- לא מקבלים החלטות אוטומטיות בעלות השלכה משפטית עליך.
10עם מי המידע משותף
אנחנו נעזרים בספקים הבאים, וכל אחד מהם מקבל רק את מה שנחוץ לו:
- Supabase — בסיס הנתונים והמשתמש האנונימי. מדיניות הפרטיות שלהם.
- RevenueCat — ניהול המנויים ומאפייני הלקוח. מדיניות הפרטיות שלהם.
- Apple — חנות האפליקציות, מערכת השעונים והתשלום. מדיניות הפרטיות שלהם.
- Cloudflare — אירוח האתר. מדיניות הפרטיות שלהם.
מעבר לאלה נעביר מידע רק אם נידרש לכך בצו שיפוטי או על פי דין.
11היכן המידע נשמר
שרתי הספקים שלעיל עשויים להימצא מחוץ לישראל, בין היתר בארצות הברית ובאיחוד האירופי. ההעברה מתבצעת תחת מנגנוני ההגנה המקובלים של אותם ספקים, לרבות תניות חוזיות סטנדרטיות של האיחוד האירופי.
12שמירה ומחיקה
- מחיקת האפליקציה מוחקת כל מה ששמור על המכשיר: העדפות, תשובות השאלון וההרשאות.
- הרשומות בשרת (שעונים ואירועי קימה) נשמרות כל עוד המזהה פעיל, ולכל היותר 24 חודשים מהפעילות האחרונה, ואז נמחקות.
- למחיקה מוקדמת יותר כתבו לנו. מכיוון שהחשבון אנונימי ואין לנו אימייל שלך, נצטרך פרט שיאפשר לאתר את הרשומה — למשל אישור הרכישה מה-App Store. אם לא נוכל לקשר בין הפנייה לרשומה, נאמר זאת בפירוש ולא נמחק מידע של מישהו אחר.
- נתוני הרכישה מנוהלים אצל Apple ו-RevenueCat וכפופים לתקופות השמירה שלהם.
13אבטחה
כל התעבורה בין האפליקציה לשרת מוצפנת ב-TLS. ההרשאות בבסיס הנתונים מוגדרות ברמת השורה, כך שמזהה אחד אינו יכול לקרוא נתונים של מזהה אחר. סטטוס המנוי נשמר במכשיר ב-Keychain של iOS.
אין שיטת אבטחה מושלמת. הגישה שלנו היא לשמור כמה שפחות מלכתחילה, כדי שיהיה כמה שפחות מה לאבד.
14קטינים
האפליקציה אינה מיועדת למי שטרם מלאו לו 16, ואיננו אוספים ביודעין מידע מקטינים. אם נודע לכם שקטין מסר לנו מידע, פנו אלינו ונמחק אותו.
15הזכויות שלך
לפי חוק הגנת הפרטיות, ולפי ה-GDPR למשתמשים באיחוד האירופי ובבריטניה, עומדות לך זכויות עיון, תיקון, מחיקה, הגבלת עיבוד, התנגדות וניידות.
חלק מהן ממומשות ישירות באפליקציה: אפשר לערוך ולמחוק שעונים ולשנות העדפות בכל רגע. ליתר, פנו אלינו. שימו לב שהאנונימיות עצמה מגבילה — בלי פרט מזהה לא נוכל לאתר את הרשומה שלכם.
אם אתם סבורים שפגענו בפרטיותכם, אתם רשאים להגיש תלונה לרשות להגנת הפרטיות או לרשות המפקחת במדינת מגוריכם.
16שינויים במדיניות
נעדכן את הדף הזה כשמשהו משתנה, ונשנה בהתאם את תאריך העדכון שבראשו. שינוי מהותי יוצג גם באפליקציה לפני שייכנס לתוקף.
17יצירת קשר
לשאלות פרטיות, בקשות עיון או מחיקה: [הוסיפו אימייל ב-config.js]
Privacy Policy
Boker Shoker is built to know almost nothing about you. There is no sign-up, no email, no password, and no camera image ever leaves your phone. This page sets out exactly what is stored, who holds it, and why.
01Who we are and what this covers
Boker Shoker (the "app", "we") is an iPhone alarm app in which the alarm only stops once the camera has confirmed you completed push-ups. This policy covers the app and the bokershoker.com website.
We are the controller of the data described here, under Israel's Privacy Protection Law, 5741-1981 (including Amendment 13), and under the GDPR where it applies.
02The short version
- No sign-up. We never ask for, and never receive, a name, email, phone number or password.
- The camera runs on-device only. No photos, no video, nothing uploaded anywhere.
- No advertising. No ad identifiers, no data sales, no tracking across apps or websites.
- What is stored on our server — your alarms, wake events, time zone and subscription status — is tied to a random identifier and nothing else.
03No account, no sign-up
On first launch the app creates an anonymous user with our infrastructure provider. That is a random identifier (a UUID) and nothing more. It carries no name, email, phone number or social login, and we never ask you for one.
The identifier lives on your device. Deleting the app cuts you loose from it, and reinstalling creates a new one — so your history does not follow you across devices. Your subscription does, because it is tied to your Apple ID rather than to us.
04What we collect and why
| What | Why | Where it lives |
|---|---|---|
| Anonymous user ID (UUID) | Tie alarms and history to one user, and recognise an active subscription | Server + device |
| Alarm settings: time, days of week, the label you type, task type, hold duration, on/off | Run the alarm and keep it between launches | Server + device |
| Wake events: when the alarm was due, when the task was completed, whether it succeeded, and how long you held the position | Calculate your wake score, streak and history | Server |
| Time zone | Compute wake times correctly | Server |
| Subscription status and the date it changed | Unlock what you paid for | Server + iOS Keychain |
| Local preferences: alarm sound, rep count, rest days | Run the alarm exactly as you configured it | Device only |
| Onboarding answers | Choose which subscription offer to show you (section 06) | Device + RevenueCat |
| Technical data: IP address, device type, app version | Security, abuse prevention and day-to-day operation | With our providers, briefly |
The only free-text field in the app is the alarm label. Please don't put anything sensitive in it — it is stored on the server as typed.
05The camera stays on your device
The camera turns on only during the mission screen, after the alarm rings, and off the moment it ends.
- They are analysed in real time by Apple's Vision framework, on the device itself.
- No photo is taken and no video is recorded. Each frame lives in memory for an instant and is replaced by the next one.
- No frame, image or body-joint position is sent to us or to any third party, and nothing is written to your photo library or to a file.
- What is saved at the end is whether the mission was completed and how long it took. That is all.
What the device actually derives from a frame is numbers — elbow angle, shoulder height, scene brightness — and they are discarded immediately. We cannot see them either.
06Your onboarding answers
Before the purchase screen the app asks a series of questions: gender, your current and target wake time, how many alarms you set, what makes getting up hardest, where you heard about us, and so on. Those answers are:
- kept on your device so you can pick up where you left off;
- sent to RevenueCat as customer attributes (prefixed
onb_) to decide which subscription offer you are shown; - never sold, never used for advertising, and never tied to your name — we have no name to tie them to.
You are not required to answer precisely, and some questions can be skipped.
07Purchases and subscriptions
Payment is handled by Apple's App Store. We never see or store your card number, billing address or Apple ID credentials.
What does reach us, via RevenueCat: subscription state (active, renewing, cancelled, expired), transaction identifiers and dates. That is stored against your anonymous ID and used only to decide whether to unlock access.
08Permissions we ask for
- Camera — to verify your push-up position. Without it the mission cannot be completed.
- Alarms (AlarmKit) — to schedule a system alarm that rings even when the app is closed.
- Audio — to play the alarm sound during the mission. The app does not record audio.
Each permission is requested in the context where it is needed, and you can revoke any of them at any time in iOS Settings. Revoking camera or alarm access disables the core of the app.
09What we never do
- We do not sell, rent or trade your data.
- The app contains no advertising SDK, does not use the advertising identifier (IDFA), and does not track you across apps or websites.
- We do not collect location, contacts, calendar, photo library or Apple Health data.
- We do not make automated decisions that produce legal effects for you.
10Who we share data with
We rely on the following providers, each receiving only what it needs:
- Supabase — database and anonymous authentication. Their privacy policy.
- RevenueCat — subscription management and customer attributes. Their privacy policy.
- Apple — the App Store, the alarm system and payment. Their privacy policy.
- Cloudflare — website hosting. Their privacy policy.
Beyond these, we disclose data only where required by a court order or by law.
11Where data is stored
The providers above may hold data on servers outside Israel, including in the United States and the European Union. Such transfers rely on those providers' standard safeguards, including the EU Standard Contractual Clauses.
12Retention and deletion
- Deleting the app removes everything held on the device: preferences, onboarding answers and permissions.
- Server records (alarms and wake events) are kept while the identifier is in use, and at most 24 months after the last activity, then deleted.
- To delete sooner, write to us. Because the account is anonymous and we hold no email for you, we will need something that lets us locate the record — an App Store purchase receipt, for example. If we cannot link your request to a record, we will say so plainly rather than delete somebody else's data.
- Purchase records are held by Apple and RevenueCat under their own retention periods.
13Security
All traffic between the app and our server is encrypted with TLS. Database permissions are enforced at the row level, so one identifier cannot read another's data. Subscription status is stored on the device in the iOS Keychain.
No security is perfect. Our approach is to hold as little as possible in the first place, so there is as little as possible to lose.
14Children
The app is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has provided us with data, contact us and we will delete it.
15Your rights
Under Israel's Privacy Protection Law, and under the GDPR for users in the EU and the UK, you have rights of access, rectification, erasure, restriction of processing, objection and portability.
Some of these you can exercise directly in the app: alarms can be edited and deleted and preferences changed at any time. For the rest, contact us. Note that anonymity itself is a limit — without an identifying detail we cannot locate your record.
If you believe we have infringed your privacy, you may complain to the Israeli Privacy Protection Authority or to the supervisory authority where you live.
16Changes to this policy
We will update this page when something changes, and update the date at the top accordingly. A material change will also be surfaced in the app before it takes effect.
17Contact
For privacy questions, access requests or deletion requests: [add an email in config.js]