Back to Tovli

Legal

Privacy Policy

What we collect, what we don't, and what we'll do if you ask us to delete it. Written so a person can read it, not so a lawyer can hide in it.

Effective:
27 May 2026
Last updated:
27 May 2026
Version:
1.0
The short version
  • Your receipts and the data on them belong to you. We store them so we can show them back to you — not so we can sell them.
  • No one at Tovli reads your receipts. Routine extraction is done by software. Humans only look at a receipt if you ask us to (e.g. a support ticket) or if the law forces us to.
  • We never sell your data, and we never share it with advertisers.
  • You can export everything and delete your account at any time.

1. Who we are

Tovli (the "service", "we", "us") is operated from Israel. When this policy talks about a "data controller" under the EU General Data Protection Regulation (GDPR) or a "database owner" under Israel's Privacy Protection Law, 1981, that's us.

For any privacy question, you can reach a real person at privacy@tovli.io. We aim to reply within five working days.

2. What we collect

2.1 Receipts you send us

When you forward a photo, PDF or other document to your Tovli WhatsApp number, we receive and store:

  • The original file you sent (photo or document).
  • The text and structured fields our software extracts from it — vendor, total, currency, date, line items, VAT, and similar.
  • Metadata WhatsApp gives us with the message: the sending phone number, message ID, timestamp, and message type.
  • Our processing status for that message — whether OCR succeeded, was retried, or failed — and the reason if it failed.

2.2 Account and contact data

If you sign up for an account, we store the name, business name, email address and WhatsApp number you give us, along with billing details (handled by our payment processor — we never see your card number).

2.3 Operational data

Like any web service, our servers log technical information needed to keep things running: timestamps, request IDs, IP addresses for security purposes, and error traces. Image bytes never appear in our logs.

2.4 Information from cookies on this website

This website uses only strictly necessary cookies (e.g. to remember you've dismissed a banner). We do not use third-party advertising trackers or cross-site analytics. If we ever add privacy-respecting analytics, we will update this policy first.

3. What we don't collect

  • We don't read the conversations you have with other people on WhatsApp. We only ever see messages addressed to your Tovli number.
  • We don't access your phone's contacts, photo library or location.
  • We don't build advertising profiles, and we don't run third-party ad pixels.
  • We don't ask for, store, or process card numbers — that's handled by our payment processor.

4. How we use what we collect

We use the data above to do, and only to do, the following things:

  • Provide the service. Extract data from your receipts, file them in your books, reply to you in WhatsApp, let you search and export.
  • Operate and improve the software. Diagnose failures, retry failed extractions, measure latency and error rates in aggregate.
  • Support you. Look into the specific receipts you point us at when you open a ticket.
  • Bill you. Count documents processed under your plan and produce invoices.
  • Comply with the law. Respond to lawful requests from regulators and tax authorities.

We do not use the contents of your receipts to train general-purpose AI models or to develop products for anyone other than you.

If you're in the EU or UK, we rely on the following legal bases under GDPR / UK GDPR:

  • Contract — to provide the service you've signed up for.
  • Legitimate interests — to keep the service secure, prevent abuse, and run our business (e.g. invoicing, support).
  • Legal obligation — to keep records the law requires (e.g. tax records).
  • Consent — for anything optional we'd ever ask you about. You can withdraw consent at any time without affecting the lawfulness of processing already done.

6. Where your data is stored

Receipt images and extracted data are stored in encrypted storage hosted on Microsoft Azure, in regions chosen to keep latency low for Israeli and European customers. Storage is built to the durability standard typically used by banks and hospitals (roughly eleven nines).

If we ever transfer personal data outside Israel or the European Economic Area, we do so under appropriate safeguards (Standard Contractual Clauses or equivalent).

7. Who else sees the data (sub-processors)

To deliver Tovli, we rely on a small number of vetted vendors who process data on our behalf, under written contracts that bind them to confidentiality and security obligations:

  • Meta Platforms, Inc. (WhatsApp Cloud API) — to deliver and receive WhatsApp messages.
  • Microsoft Azure — hosting, storage, and OCR (Azure Document Intelligence).
  • A payment processor — to handle subscription billing and card data.
  • An email delivery provider — to send account and support emails.

We don't share your receipts or your business data with anyone else — no advertisers, no data brokers, no "partners".

8. How long we keep it

  • Active accounts: we keep your receipts for as long as your account is active, so you can find them when you need them — including at tax time, years later.
  • After you delete your account: we delete receipts and extracted data within 30 days, and remove them from backups within a further 90 days.
  • Legal hold: we may keep limited records longer where the law requires us to (e.g. tax and accounting records, anti-fraud obligations). We keep only what the law requires, and only for as long as the law requires it.
  • Operational logs: kept for up to 90 days for security and debugging, then deleted or anonymised.

9. Your rights

Wherever you are, you can ask us to:

  • See what we have. Get a copy of the personal data we hold about you.
  • Correct it. Fix anything that's wrong or incomplete.
  • Delete it. Remove your account and your data, subject to the retention exceptions above.
  • Export it. Download your receipts and data in a portable format (CSV / JSON / original files).
  • Object or restrict. Ask us to stop or pause certain kinds of processing.
  • Complain. If you're in the EU/UK, lodge a complaint with your local data protection authority. If you're in Israel, with the Privacy Protection Authority (הרשות להגנת הפרטיות).

To exercise any of these, email privacy@tovli.io from the address on your account. We'll verify it's really you and respond within 30 days.

10. How we protect your data

  • Every webhook we receive is cryptographically verified before any business logic runs — payloads that fail verification are rejected.
  • Data is encrypted in transit (TLS 1.2+, no plaintext fallback) and at rest.
  • Production secrets live in a managed key vault with strict access controls. Engineers don't see them.
  • Access to production systems is limited to a small number of staff, logged, and reviewed.

No system is invulnerable, but if we ever discover a breach that affects your personal data, we'll tell you and the relevant regulators in line with applicable law (in practice, within 72 hours of becoming aware of it).

11. Children

Tovli is built for small businesses and is not directed to children under 16. We don't knowingly collect personal data from children. If you believe a child has sent us data, email privacy@tovli.io and we'll delete it.

12. Changes to this policy

If we change anything material about how we handle your data, we'll update this page and email account holders before the change takes effect. The Last updated date at the top tells you when this version went live. Older versions are kept on request.

13. Contact

Anything privacy-related — questions, requests, complaints — goes to privacy@tovli.io. For general support, hello@tovli.io works fine and the team will route it.

A note on language: this policy is written in plain English on purpose. If anything here is unclear, that's our problem, not yours — write to us and we'll rewrite the part you got stuck on.