Privacy Policy

CREMEDYX LTD · Israeli company no. 517292207 · Last updated 21 August 2026

Every category below was written by reading our actual database schema, not from a template. If something is not listed here, we do not store it.

1. Who we are

Cremedyx is operated by CREMEDYX LTD, a company registered in Israel under number 517292207, at Hai El-Madares 141, Jerusalem 9709201, Israel. Contact: admin@cremedyx.com.

Cremedyx is a tool for merchants. It reads a merchant's own business data and helps them publish, reply to their customers, and understand what worked.

2. Two kinds of people, two different roles

This distinction decides everything else in this policy, so we state it first.

3. What we store about merchants

4. What we store about a merchant's customers

Only what the merchant's own channels give us, and only so the merchant can serve them.

We do not sell this data. We do not use it to build advertising profiles. We do not use one merchant's data to answer another merchant's customers.

5. Artificial intelligence, stated plainly

Some replies to customers are generated by AI, and some analysis shown to merchants is AI-produced.

When a customer is answered by AI, we tell them so. The first automated reply in a conversation identifies itself as an assistant and states that a person will follow up when needed.

When a reply is generated, the message text, recent thread history, and a bounded snapshot of the merchant's own catalogue and business description are sent to our AI provider for the sole purpose of producing that reply. When the assistant is not confident it does not guess: it stops, hands the thread to the merchant, and sends nothing.

We do not use customers' messages to train any model. Our AI provider is Anthropic. Under their commercial terms, data submitted through the API is not used to train their models, and we have additionally disabled model-improvement and feedback sharing at the organisation level. We do not send customer messages to any other AI provider.

Inputs and outputs may be retained by our AI provider for up to 30 days for safety and abuse monitoring, after which they are deleted. They are not used for training.

6. Improving our own models

We may use merchants' own business data — business descriptions, product catalogues, and a merchant's own conversations with the in-app assistant — to develop and improve Cremedyx's own models and features.

We never use a merchant's customers' messages for this. Customer conversations are processed only to produce a reply for that merchant.

Before any such use, data is stripped of direct identifiers. Merchants can opt out at any time in Settings; opting out applies going forward.

7. Where the data lives, and who else processes it

Our database and server functions run on Supabase infrastructure in the Singapore (ap-southeast-1) region. We say this plainly because it matters: for users in the European Economic Area this is a transfer to a third country, made under the European Commission's Standard Contractual Clauses as incorporated in our providers' data processing terms.

Data in transit is encrypted with TLS. Data at rest is encrypted by the hosting provider. Provider access tokens are further restricted so that only server-side functions can reach them: no client application can read a token, and no client application can write one.

Our processors:

ProcessorPurpose
SupabaseDatabase, authentication, file storage, server functions
AnthropicAI reply and analysis generation
Meta PlatformsInstagram, Messenger and Facebook, for channels a merchant connects themselves
Google (Firebase)Push delivery, crash reporting, performance monitoring, product analytics
ApplePush notification delivery
Resend / Amazon SESTransactional email such as sign-in and password reset
A foreign-exchange rate providerPublic reference rates for currency display. No personal data is sent

Each is used for the stated purpose only.

We do not embed advertising SDKs, we do not sell or share data for advertising, and we do not collect an advertising identifier. We use Firebase for crash reporting, performance monitoring and product analytics on both iOS and Android, governed by the consent switches in the app. Firebase receives technical and usage signals only — never message content, never customer contact details, and never catalogue data.

8. How long we keep it

Account and business data are kept while the account is open. Conversations and orders are kept while the account is open, because the merchant needs their own history.

When an account is deleted, deletion is immediate and cascading, not a flag. What survives is narrow and named: invoice and subscription records required for accounting are retained under a one-way cryptographic digest, so the figures remain auditable while the person is no longer identifiable from them. Uploaded files are queued and removed through the storage provider's API.

9. Your rights, and how to actually use them

Under Israeli privacy law and, where it applies to you, the GDPR, you may request access, correction, deletion, restriction and portability, and you may object to processing.

10. Children

Cremedyx is a business tool and is not directed at children. Accounts require the user to be at least 18, or the age of majority where they live.

11. Security incidents

If a breach affects your data and creates a real risk to you, we will notify you and the competent authority within the time limits the applicable law sets, and we will tell you what happened rather than what is comfortable.

12. Changes

If we change this policy materially we will notify merchants by email or in the app at least 30 days before it takes effect, and the date at the top of this page will change.

13. Contact

CREMEDYX LTD
Hai El-Madares 141, Jerusalem 9709201, Israel
admin@cremedyx.com
+972 52-220-5143