מדיניות פרטיות
עודכן לאחרונה: 2 בספטמבר 2026
Kolav היא אפליקציית ארון בגדים חכם. כדי לעבוד היא צריכה לראות את הבגדים שלך, ובחלק מהפיצ'רים גם את הפנים שלך. העמוד הזה מסביר בשפה פשוטה איזה מידע נאסף, למי הוא נשלח, כמה זמן הוא נשמר ואיך מוחקים אותו.
מי אחראי למידע
האחראי על המידע הוא מפעיל האפליקציה Kolav (להלן "אנחנו"). כתובת ליצירת קשר בכל נושא פרטיות: support@kolav.app.
איזה מידע אנחנו אוספים
1. חשבון והתחברות
ההתחברות מתבצעת דרך Apple, דרך Google או באמצעות קוד חד פעמי לטלפון. שירות ההתחברות (Firebase Authentication של Google) מחזיק מזהה משתמש, ואת כתובת המייל או מספר הטלפון שאיתם התחברת. אנחנו שומרים אצלנו את מזהה המשתמש, ואת כתובת המייל אם היא נמסרה.
2. פרופיל והעדפות שמסרת לנו
- שם פרטי, שם תצוגה ושם משתמש.
- מגדר, טווח גיל, ותאריך לידה אם בחרת למסור אותו.
- שפת ממשק ואזור זמן של המכשיר.
- גובה, משקל בקילוגרמים (אופציונלי), מבנה גוף וגוון עור.
- מידות בגדים (עליון, תחתון, נעליים).
- סגנון מועדף, צבעים אהובים ומותגים מועדפים.
- העדפות לבוש וצניעות: אורך שרוול, מחשוף, אורך חצאית, כיסוי ראש ושכבות.
- מטרות, איך הגעת אלינו, והתשובות לשאלות ההיכרות על תהליך ההתלבשות.
3. תמונות
- תמונות של פריטי לבוש שאת מוסיפה לארון, וגרסאות מוקטנות או מנוקות רקע שנוצרות מהן.
- סלפי שהעלית כדי לבנות אווטאר, והאווטאר שנוצר ממנו.
- תמונת פנים שהעלית עבור "מדידה על עצמך".
- תמונות המדידה שנוצרות מהשילוב של הפריטים עם האווטאר או עם הפנים שלך.
- תמונות שצילמת עבור מודעה במרקט.
4. מרקט (רק אם בחרת להשתמש בו)
עיר, מספר טלפון בפורמט בינלאומי, והמודעות שפרסמת (תמונה, מידה, מצב הפריט, מחיר והערה). כמו כן דיווחים שהגשת ומשתמשים שחסמת. מספר הטלפון שלך לא מוחזר בשום מסך של המרקט. הוא עוזב את השרת רק ברגע שקונה לוחץ על יצירת קשר במודעה שלך, ורק כדי לפתוח שיחת ווטסאפ מולך.
5. מנוי ותשלום
סוג המנוי, הסטטוס ותאריך החידוש. הרכישה עצמה מתבצעת מול חשבון ה-App Store שלך, ומנוהלת עבורנו על ידי RevenueCat. אנחנו לא רואים ולא שומרים פרטי כרטיס אשראי.
6. מכשיר ואפליקציה
מזהה התראות של Expo, האם התראות מופעלות, שעת הלוק היומי, שפת האפליקציה ואזור הזמן שנשלח בכל בקשה כדי שהתאריכים יוצגו נכון.
7. דוחות קריסה וניתוח שימוש
- דוחות קריסה נשלחים ל-Sentry. לפני השליחה, עוד על המכשיר, מוסרים מהדוח אסימוני הזדהות, עוגיות ותוכן של בקשות שכוללות תמונות.
- ניתוח שימוש נשלח ל-Mixpanel ומקושר למזהה אקראי שנוצר בהתקנה, לא לשם ולא לחשבון. שם, שם פרטי, שם מלא, כתובת מייל ומספר טלפון חסומים בקוד ולא נשלחים לניתוח שימוש.
- ב-iOS נשאלת שאלת המעקב של Apple. אם לא אישרת, מזהה הפרסום לא בשימוש.
למה אנחנו משתמשים במידע
- לזהות את הפריטים שצילמת ולתייג אותם לפי קטגוריה, צבע, עונה וסגנון.
- להרכיב לוקים שמתאימים למידות, להעדפות ולמזג האוויר.
- לייצר תמונות מדידה על אווטאר או על הפנים שלך.
- לתפעל את המרקט, כולל טיפול בדיווחים ומניעת שימוש לרעה.
- לנהל את המנוי ואת מגבלות התוכנית החינמית.
- לשלוח התראות שביקשת, כמו הלוק היומי או סיום מדידה.
- לתקן תקלות ולשפר את המוצר.
מי עוד מעבד את המידע
אלה ספקי המשנה שלנו. כל אחד מהם מקבל רק את מה שנחוץ לו כדי לבצע את התפקיד שלו.
| ספק | לשם מה | מה נשלח |
|---|---|---|
| Firebase Authentication (Google) | התחברות וזיהוי | מזהה משתמש, מייל או טלפון |
| MongoDB | מסד הנתונים של הפרופיל, הארון, הלוקים והמודעות | המידע שבסעיפים 1, 2, 4, 5, 6 |
| Amazon S3 (AWS), אירלנד | אחסון תמונות | כל התמונות שבסעיף 3 |
| Google Gemini דרך Vertex AI, הולנד | זיהוי פריטי לבוש ויצירת תמונת מדידה על עצמך | תמונת הפריט, ותמונת הפנים במדידה על עצמך |
| Replicate | יצירת אווטאר, מדידה על אווטאר, והסרת רקע כגיבוי | הסלפי לאווטאר, תמונות הפריטים |
| Fashn.ai | מדידה על אווטאר כגיבוי | תמונת האווטאר ותמונות הפריטים |
| remove.bg | הסרת רקע מתמונות פריטים | תמונת הפריט |
| RevenueCat | ניהול מנוי ורכישות | מזהה משתמש וסטטוס המנוי |
| Sentry | דוחות קריסה | נתוני שגיאה אחרי ניקוי מזהים |
| Mixpanel | ניתוח שימוש | אירועים עם מזהה אקראי, בלי פרטים מזהים |
| שירות ההתראות של Expo | שליחת התראות | מזהה ההתראות של המכשיר וטקסט ההתראה |
| Microlink | קריאת עמוד מוצר שהדבקת מקישור | הכתובת בלבד, בלי מידע אישי |
איננו מוכרים מידע אישי ואיננו מעבירים אותו למפרסמים. הספקים ברשימה מורשים להשתמש במידע רק כדי לספק לנו את השירות, ואיננו מתירים להם להשתמש בתמונות שלך כדי לאמן מודלים שלהם. גם אנחנו לא מאמנים מודלים על התמונות שלך.
איפה המידע נשמר
התמונות נשמרות ב-Amazon S3 באירלנד. יצירת תמונות המדידה רצה מול Vertex AI של Google בהולנד. חלק מהספקים ברשימה למעלה מפעילים תשתית גם מחוץ לאיחוד האירופי, ולכן ייתכן שמידע יעובד גם במדינות אחרות, בהתאם להסכמי עיבוד המידע מולם.
כמה זמן שומרים
- תמונת הפנים למדידה על עצמך: נמחקת אוטומטית 90 יום אחרי המדידה האחרונה שלך. כל מדידה מוצלחת מאריכה את התאריך ב-90 יום נוספים. תהליך יומי בשלוש לפנות בוקר מוחק את התמונות שפג תוקפן, גם מהאחסון וגם מהרשומה.
- ייצוג מתמטי של הפנים: לא נשמר בכלל. הוא מחושב בזיכרון בזמן המדידה, משמש רק כדי לוודא שהתוצאה דומה לך, ונמחק מיד.
- פריטי הארון, הלוקים, המדידות והמודעות: נשמרים כל עוד החשבון פעיל, או עד שתמחקי אותם.
- דוחות קריסה וניתוח שימוש: נשמרים אצל הספקים לפי תקופת השמירה שלהם.
מחיקת חשבון
בתוך האפליקציה: הגדרות, פרטיות, מחיקת החשבון שלי. הפעולה מיידית ואינה הפיכה, ומוחקת:
- את כל פריטי הארון, כולל התמונות והגרסאות המוקטנות שלהם באחסון.
- את כל תוצאות המדידה, כולל התמונות שנוצרו.
- את האווטארים ואת הסלפי שהועלה כדי לבנות אותם.
- את הלוקים השמורים.
- את כל המודעות שלך במרקט.
- את רשומת הפרופיל שלך, כולל המידות, ההעדפות ומספר הטלפון של המרקט.
- את החסימות שמשתמשים אחרים הגדירו עלייך.
רשומת ההתחברות שמוחזקת אצל ספק ההזדהות (Firebase Authentication) מטופלת בנפרד. אם ברצונך שגם היא תימחק מיד, כתבי לנו ל- support@kolav.app ונמחק אותה.
למחיקת תמונת הפנים בלבד, בלי למחוק את החשבון: הגדרות, פרטיות, מידע ביומטרי, מחיקת כל נתוני הפנים שלי.
הזכויות שלך
יש לך זכות לדעת איזה מידע מוחזק עלייך, לקבל עותק ממנו, לתקן אותו, למחוק אותו, ולחזור בך מהסכמה שנתת. לבקשת עותק או תיקון, כתבי לנו ל- support@kolav.app מהכתובת שאיתה נרשמת, ואנחנו נטפל בבקשה תוך 30 יום.
שימוש בתמונת הפנים למדידה על עצמך מבוסס על הסכמה נפרדת שאת מאשרת במסך ייעודי לפני המדידה הראשונה. אפשר לבטל אותה בכל רגע דרך מסך המידע הביומטרי, וביטול מוחק את התמונה השמורה.
גיל
Kolav מיועדת לגיל 13 ומעלה. מי שמסמן בהרשמה שהוא מתחת לגיל 13 אינו יכול להמשיך. המרקט פתוח לגיל 18 ומעלה בלבד, גם לפרסום מודעה וגם ליצירת קשר עם מוכר. אם נודע לנו שנפתח חשבון על ידי ילד מתחת לגיל 13, נמחק אותו.
אילינוי
הפיצ'ר "מדידה על עצמך" אינו מוצע למשתמשים במדינת אילינוי שבארצות הברית, בשל חוק הפרטיות הביומטרית שלה.
אבטחה
כל התקשורת מוצפנת. גישה לתמונות נעשית רק דרך כתובות חתומות עם תוקף קצר, כך שאין קישור ציבורי קבוע לתמונות שלך. הגישה למידע מוגבלת לצוות שזקוק לה לצורך תפעול ותמיכה.
שינויים במדיניות
אם נשנה את המדיניות נעדכן את התאריך בראש העמוד. שינוי מהותי בדרך שבה מטופלת תמונת הפנים ידרוש ממך לאשר מחדש את ההסכמה בתוך האפליקציה.
יצירת קשר
Privacy Policy
Last updated: 2 September 2026
Kolav is a smart wardrobe app. To work, it has to see your clothes, and for some features your face. This page explains in plain language what is collected, who it is sent to, how long it is kept and how to delete it.
Who is responsible
The controller of your data is the operator of the Kolav app ("we"). For any privacy matter, write to support@kolav.app.
What we collect
1. Account and sign-in
You sign in with Apple, with Google, or with a one-time code sent to your phone. The sign-in service (Google's Firebase Authentication) holds a user identifier and the email address or phone number you signed in with. We store that identifier, and the email address if one was provided.
2. Profile and preferences you give us
- First name, display name and username.
- Gender, age band, and date of birth if you chose to give one.
- App language and your device timezone.
- Height, weight in kilograms (optional), body type and skin tone.
- Clothing sizes (top, bottom, shoes).
- Preferred style, favourite colours and preferred brands.
- Dress and modesty preferences: sleeve length, neckline, skirt length, head covering and layering.
- Goals, how you found us, and your answers to the getting-dressed questions during onboarding.
3. Photos
- Photos of clothing items you add, plus thumbnails and background-removed versions generated from them.
- A selfie you upload to build an avatar, and the avatar generated from it.
- A face photo you upload for Try On Yourself.
- Try-on images generated by combining your items with an avatar or with your face.
- Photos you take for a marketplace listing.
4. Marketplace (only if you use it)
City, phone number in international format, and the listings you publish (photo, size, condition, price and note). Also reports you file and users you block. Your phone number is never returned on any marketplace screen. It leaves the server only when a buyer taps to contact you on a listing, and only to open a WhatsApp conversation with you.
5. Subscription and payment
Plan type, status and renewal date. The purchase itself happens against your App Store account and is managed for us by RevenueCat. We never see or store card details.
6. Device and app
An Expo push notification token, whether notifications are on, your daily look time, the app language, and the timezone sent with each request so dates display correctly.
7. Crash reports and product analytics
- Crash reports go to Sentry. Before they are sent, on the device, auth tokens, cookies and the bodies of requests that carry images are stripped from the report.
- Product analytics go to Mixpanel and are tied to a random identifier created at install, not to your name or account. Name, first name, full name, email address and phone number are blocked in code and are never sent to analytics.
- On iOS you are shown Apple's tracking prompt. If you decline, the advertising identifier is not used.
Why we use it
- To recognise the items you photograph and tag them by category, colour, season and style.
- To build outfits that fit your sizes, preferences and the weather.
- To generate try-on images on an avatar or on your face.
- To run the marketplace, including handling reports and preventing abuse.
- To manage your subscription and the free plan limits.
- To send the notifications you asked for, such as the daily look or a finished try-on.
- To fix problems and improve the product.
Who else processes it
Our sub-processors. Each receives only what it needs to do its job.
| Provider | Purpose | What is sent |
|---|---|---|
| Firebase Authentication (Google) | Sign-in and identity | User identifier, email or phone |
| MongoDB | Database for profile, wardrobe, looks and listings | The data in sections 1, 2, 4, 5, 6 |
| Amazon S3 (AWS), Ireland | Image storage | All photos in section 3 |
| Google Gemini via Vertex AI, Netherlands | Garment recognition and Try On Yourself image generation | The item photo, and your face photo for Try On Yourself |
| Replicate | Avatar generation, avatar try-on, and background removal fallback | The avatar selfie, item photos |
| Fashn.ai | Avatar try-on fallback | The avatar image and item photos |
| remove.bg | Background removal for item photos | The item photo |
| RevenueCat | Subscription and purchase state | User identifier and subscription status |
| Sentry | Crash reports | Error data after identifiers are stripped |
| Mixpanel | Product analytics | Events with a random identifier, no identifying details |
| Expo push service | Sending notifications | The device push token and the notification text |
| Microlink | Reading a product page from a link you paste | The address only, no personal data |
We do not sell personal data and we do not pass it to advertisers. The providers listed above may use the data only to provide the service to us, and we do not permit them to use your photos to train their own models. We do not train models on your photos either.
Where data is stored
Photos are stored in Amazon S3 in Ireland. Try-on generation runs on Google's Vertex AI in the Netherlands. Some of the providers above operate infrastructure outside the European Union, so data may also be processed in other countries under our data processing agreements with them.
How long we keep it
- The Try On Yourself face photo: deleted automatically 90 days after your last try-on. Every successful try-on extends that by another 90 days. A daily job at 03:00 deletes expired photos from both storage and the database record.
- The mathematical representation of your face: never stored. It is computed in memory during a try-on, used only to check the result still looks like you, and discarded immediately.
- Wardrobe items, looks, try-ons and listings: kept while your account is open, or until you delete them.
- Crash reports and analytics: kept by those providers under their own retention periods.
Deleting your account
In the app: Settings, Privacy, Delete my account. It is immediate and cannot be undone, and it deletes:
- All wardrobe items, including their photos and thumbnails in storage.
- All try-on results, including the generated images.
- Your avatars and the selfie uploaded to build them.
- Your saved looks.
- All of your marketplace listings.
- Your profile record, including sizes, preferences and your marketplace phone number.
- Blocks other users placed on you.
The sign-in record held by the identity provider (Firebase Authentication) is handled separately. If you want that removed immediately as well, write to support@kolav.app and we will remove it.
To delete only the face photo, without deleting your account: Settings, Privacy, Biometric Data, Delete all my face data.
Your rights
You have the right to know what data is held about you, to receive a copy, to correct it, to delete it, and to withdraw a consent you gave. For a copy or a correction, write to support@kolav.app from the address you registered with, and we will handle the request within 30 days.
Use of your face photo for Try On Yourself is based on a separate consent you give on a dedicated screen before your first try-on. You can withdraw it at any time from the Biometric Data screen, and withdrawing deletes the stored photo.
Age
Kolav is for ages 13 and over. Anyone who selects an age under 13 during onboarding cannot continue. The marketplace is for ages 18 and over only, both to publish a listing and to contact a seller. If we learn that an account was created by a child under 13, we will delete it.
Security
All traffic is encrypted. Images are served only through signed, short-lived addresses, so there is no permanent public link to your photos. Access to data is limited to the staff who need it to operate the service and answer support requests.
Changes to this policy
If we change this policy we will update the date at the top of the page. A material change to how the face photo is handled will require you to re-confirm your consent inside the app.