Privacy Policy

Last updated: July 28, 2026

This English-language Privacy Policy is the governing legal document. A Hebrew translation is provided for convenience at /privacy/he. In the event of any conflict or inconsistency between the two versions, this English version shall prevail.

TaxFlow ("we", "us", the "Service") operates a platform that centralizes and manages invoices for businesses (עוסקים) and accounting firms (מייצגים). This document explains what data we collect, how we use it, and who it may be shared with as part of providing the Service.

1. Information We Collect

Account details: name, email address, and account type (business owner / accountant) at signup.

Invoice content: PDF/image files of invoices received via Gmail or WhatsApp, and fields extracted from them by our recognition engine (supplier, amount, date, invoice number, allocation number).

Gmail access (OAuth): when a business owner connects their Gmail account, we request read-only access (`gmail.readonly`) solely to locate messages containing invoice attachments. We do not read, store, or share email content unrelated to invoices, and we do not use this data for advertising. Access tokens are encrypted at rest and can be revoked at any time from account settings.

WhatsApp: the sending phone number and message content (text/image) when an invoice is sent to the Service's dedicated WhatsApp channel.

Usage and system data: sensitive activity logs (login, invoice approval, export, settings changes) for security, support, and fraud prevention.

2. How We Use Information

  • Automatically recognizing and extracting fields from invoice documents.
  • Displaying invoices and reporting periods to the user and their linked accounting firm.
  • Detecting anomalies (unknown supplier, duplicates, missing fields) to raise alerts.
  • Exporting data to an accounting-software format (Hashavshevet) at the user's request.
  • Securing the account, preventing fraud, and maintaining the Service.

3. Sharing Information with Third Parties

We use the following infrastructure providers to operate the Service, subject to data processing agreements:

  • Google — for Gmail connectivity (OAuth) and locating invoice attachments only.
  • Meta / WhatsApp Business Platform — for receiving invoices sent via WhatsApp.
  • Anthropic (Claude) — for processing invoice images/documents and extracting fields (Vision).
  • Supabase — database hosting, user authentication, and invoice file storage (private storage, accessible only via time-limited links).
  • Resend — sending operational emails (signup confirmation, password reset).
  • Vercel — application hosting and operation.

We do not sell personal information to third parties, and we do not share invoices with any party other than the business owner themselves or the accounting firm they have explicitly linked to.

4. Google API Services User Data Policy

TaxFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Specifically regarding data accessed via Gmail OAuth (gmail.readonly):

  • Purpose limitation: we access your Gmail account solely to locate and retrieve emails containing invoice attachments or billing notifications.
  • No advertising: information obtained through Google APIs is never used, sold, or shared for advertising, market research, or user profiling.
  • Human access restrictions: no TaxFlow employee reads your email content, except (1) with your explicit permission for support/troubleshooting, (2) where necessary to investigate suspected abuse or fraud, or (3) where required by applicable law.
  • AI sub-processing: invoice attachments retrieved via Gmail are transmitted to our sub-processor, Anthropic, solely for automated field extraction (OCR/Vision). This data is processed transiently and is never used to train machine-learning models.

5. Data Security

Every database table is protected by Row Level Security so that each user can only see data belonging to them or to clients linked to them. Sensitive OAuth tokens are encrypted at rest. Invoice documents are stored in private storage and are only accessible via time-limited signed URLs.

6. Data Retention and Deletion

We retain account and invoice data for as long as the account is active. You may request deletion of your account and associated data by contacting the address below, subject to legally required retention obligations (for example, audit-log records).

7. Your Rights

You may at any time request access to, correction of, or deletion of your personal information, and disconnect your Gmail/WhatsApp connections from account settings.

8. Cookies

We use essential cookies only, for managing login sessions and verifying identity when viewing share links.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be posted on this page with a new update date.

10. Contact Us

For questions about this policy or requests regarding personal information, contact us at hello@taxflow.co.il.