Privacy Policy — Novoli
English courtesy translation. The Hebrew text is authoritative; this translation carries no independent legal force.
1. Who we are, and what this document is
Novoli is a household-management application for families. The service is operated by Ronny Or, as a private individual, and is intended for users in Israel.
This policy explains what personal information the service collects, what for, who it is shared with, and how to exercise the rights the law gives you. It is written under the Privacy Protection Law, 5741-1981, as amended by Amendment 13, which came into force on 14 August 2025.
For anything in this policy you can reach us at privacy@novoliapp.com.
This document does not address the GDPR. The service is intended for Israel only at this stage, and we do not want to give the impression of complying with a regulatory regime we have not examined.
2. What is collected
Account details: email address, encrypted password, display name, and a profile picture if you upload one.
Household content: shopping lists, products, stores, recipes, meal plans, meal votes, pantry, freezer and fridge inventory, and items on the Needed list.
Images you upload: recipe photographs, product images and profile pictures. An image may contain people, including children — what to upload is your decision.
Activity log: who created, updated or deleted what within the family. It exists for transparency between family members and for security.
Usage data: product usage events, so we can understand what works and what does not.
Notifications: if you enable push notifications, the subscription identifier and browser or device details are stored.
Enquiries through the interest form: name, email, phone number and a free-text message. That form is open to the public.
Essential cookies: for managing your session and remembering your language preference only.
What we do not collect: the service has no dedicated field for allergies, diet or medical information, and we do not ask for any. If you write such information into a free-text field — a note on a product, or a recipe's instructions — it is stored like any other text. We recommend that you do not.
3. Why it is collected
To operate the service, so that members of the same family see the same lists, inventory and recipes.
Authentication and identification: signing in, resetting a password, and inviting family members.
Operational messages: email and notifications arising from your use of the service.
Improving the product, on the basis of aggregate usage data.
Security and accountability: the activity log, and the recording of security incidents as the regulations require.
Answering enquiries received through the interest form or the privacy address.
We do not sell personal information, we do not pass it to advertisers, and we do not build profiles for marketing.
4. Children and minor family members
The service is built for a household: the family account is opened and managed by an adult, and members of the household — including children — take part as family members. Opening a family account is intended for those aged 18 and over, and joining an existing family account as a member is intended for those aged 14 and over — both as stated in the Terms. The inviting adult declares the invitee's age at the time of the invitation; we do not verify that declaration, and we do not store a date of birth.
A family member is added to the account by the family's manager. Responsibility for a minor's participation in the service, and for the information they enter, rests with the adult who added them.
We do not ask a minor for information beyond what their participation requires — a display name, and a profile picture if one is chosen.
Full disclosure: at this stage the service has no dedicated screen on which a parent or guardian separately confirms a minor's participation. We are building one. We write this explicitly so as not to describe a mechanism that does not exist.
5. Who the information is shared with
We do not sell information. We rely on providers to operate the service, and each receives only what its role requires.
Supabase — user authentication and the database. Frankfurt, Germany.
Vercel — hosting and running the service. Frankfurt, Germany; the delivery network is global.
Vercel Blob — image storage. Frankfurt, Germany.
Vercel Analytics — page-view measurement on the marketing pages only, not inside the application.
Resend and AWS SES — sending operational email. Ireland.
Sentry — error reporting. Germany.
Forward Email — receiving inbound mail to the service's addresses. United States.
OpenAI — extracting a recipe from a web page, extracting a recipe from a photograph, suggesting an ingredient substitute, and generating generic product images for the catalog. United States.
Apple and Google — delivering push notifications to the device. United States.
Google — signing in with a Google account, if you choose it. Your email address, your account identity and the fact of signing in are passed to it. This is a separate role from the push notifications above. United States.
6. Transfer outside Israel
Some of the providers above operate outside Israel. These are the transfers that go to the United States, and it is worth knowing exactly what is sent in each.
Extracting a recipe from a web page: the page's text is sent.
Suggesting an ingredient substitute: only the recipe name and the ingredient name are sent. No name, email, user identifier or family identifier is sent.
Extracting a recipe from a photograph: the photograph itself is sent, and a photograph may contain a person.
Generic product images for the catalog: only the product name is sent — to phrase a generic name from it, match it against names already in the catalog, and generate an image from it. The image is generated from text: no photograph of yours is sent. No name, email, user identifier or family identifier is sent.
The matching step also sends the list of generic names already in the catalog. These are product names only, with no family attached — and it is the only operation that sends anything not belonging solely to your household.
Push notifications: the device identifier and delivery data are sent. The notification's content is encrypted.
Free-text fields are your responsibility: if you write an identifying detail into a recipe name or a note, it may be sent along with the request. This is a built-in limitation and we cannot filter it for you.
7. Information security
The service is classified at the basic security level under the Privacy Protection Regulations (Information Security), 5777-2017. A security procedure, a database definitions document and a security incident register exist, as that level requires.
How information is separated between families: every server-side query is filtered by the user's family identifier. The database has no direct access surface from the browser, and all access goes through our server code. Traffic is encrypted.
What we deliberately do not claim: we do not assert that separation between families is enforced at the database layer itself. It is enforced at the application layer. In July 2026 a real cross-family access defect found in testing was fixed. No security is perfect and we cannot guarantee absolute protection.
8. How long information is kept
Information is kept for as long as the family account exists.
At this stage we do not run automated deletion of old data. We have set retention periods and are building the mechanism that will enforce them; we will publish the exact periods here in the same update that brings that mechanism into operation, and not before.
We put it this way deliberately. It is better to say what actually happens than to name a period the system does not yet enforce.
9. Your rights
The Privacy Protection Law gives you two rights, and we describe them as they are rather than more broadly.
The right of inspection under section 13: to ask to see the personal information held about you in the service.
The right of correction under section 14: to ask for correction of information that is incorrect, incomplete, unclear or not up to date.
The timings the law sets: inspection is to take place within 30 days of the request being received. A refusal of an inspection request is to be given within 21 days, and a refusal of a correction request within 30 days. Only the Registrar may extend the inspection period, by a further 15 days and only for a specific matter — it is not an extension we can take.
What Israeli law does not provide, and which we therefore do not promise: the Privacy Protection Law contains no general right to erasure, no right to restrict processing, and no right to data portability. Section 14 permits deletion only of information that is incorrect, incomplete, unclear or not up to date. We preferred to say this plainly rather than promise rights that do not exist.
To exercise these rights, write to us at privacy@novoliapp.com. You may also approach the Privacy Protection Authority. Today these requests are handled manually by us; the service has no dedicated screen for them.
10. Cookies
Only essential cookies are used — managing your session and remembering your language preference. There are no advertising cookies, no third-party tracking cookies, and the page-view measurement on the marketing pages does not use cookies.
11. Privacy protection officer
No privacy protection officer has been appointed, and there is no duty to appoint one. The duty in section 17B1(a) applies to bodies whose principal occupation is the processing of personal information, and to further categories that do not apply here. This service's occupation is household management, not the processing of information as such.
We do not claim an exemption arising from the number of users. The law sets no single clear numerical threshold for this.
12. Changes to this policy
We will update this policy from time to time. The date of the last update appears at the foot of the page, and a material change will be brought to users' attention.
13. Contact
For any question, request or complaint regarding personal information: privacy@novoliapp.com.
27.08.2026