Every category below was written by reading our actual database schema, not from a template. If something is not listed here, we do not store it.
Cremedyx is operated by CREMEDYX LTD, a company registered in Israel under number 517292207, at Hai El-Madares 141, Jerusalem 9709201, Israel. Contact: admin@cremedyx.com.
Cremedyx is a tool for merchants. It reads a merchant's own business data and helps them publish, reply to their customers, and understand what worked.
This distinction decides everything else in this policy, so we state it first.
Only what the merchant's own channels give us, and only so the merchant can serve them.
We do not sell this data. We do not use it to build advertising profiles. We do not use one merchant's data to answer another merchant's customers.
Some replies to customers are generated by AI, and some analysis shown to merchants is AI-produced.
When a customer is answered by AI, we tell them so. The first automated reply in a conversation identifies itself as an assistant and states that a person will follow up when needed.
When a reply is generated, the message text, recent thread history, and a bounded snapshot of the merchant's own catalogue and business description are sent to our AI provider for the sole purpose of producing that reply. When the assistant is not confident it does not guess: it stops, hands the thread to the merchant, and sends nothing.
We do not use customers' messages to train any model. Our AI provider is Anthropic. Under their commercial terms, data submitted through the API is not used to train their models, and we have additionally disabled model-improvement and feedback sharing at the organisation level. We do not send customer messages to any other AI provider.
Inputs and outputs may be retained by our AI provider for up to 30 days for safety and abuse monitoring, after which they are deleted. They are not used for training.
We may use merchants' own business data — business descriptions, product catalogues, and a merchant's own conversations with the in-app assistant — to develop and improve Cremedyx's own models and features.
We never use a merchant's customers' messages for this. Customer conversations are processed only to produce a reply for that merchant.
Before any such use, data is stripped of direct identifiers. Merchants can opt out at any time in Settings; opting out applies going forward.
Our database and server functions run on Supabase infrastructure in the
Singapore (ap-southeast-1) region. We say this plainly because it matters: for
users in the European Economic Area this is a transfer to a third country, made under the European
Commission's Standard Contractual Clauses as incorporated in our providers' data processing terms.
Data in transit is encrypted with TLS. Data at rest is encrypted by the hosting provider. Provider access tokens are further restricted so that only server-side functions can reach them: no client application can read a token, and no client application can write one.
Our processors:
| Processor | Purpose |
|---|---|
| Supabase | Database, authentication, file storage, server functions |
| Anthropic | AI reply and analysis generation |
| Meta Platforms | Instagram, Messenger and Facebook, for channels a merchant connects themselves |
| Google (Firebase) | Push delivery, crash reporting, performance monitoring, product analytics |
| Apple | Push notification delivery |
| Resend / Amazon SES | Transactional email such as sign-in and password reset |
| A foreign-exchange rate provider | Public reference rates for currency display. No personal data is sent |
Each is used for the stated purpose only.
We do not embed advertising SDKs, we do not sell or share data for advertising, and we do not collect an advertising identifier. We use Firebase for crash reporting, performance monitoring and product analytics on both iOS and Android, governed by the consent switches in the app. Firebase receives technical and usage signals only — never message content, never customer contact details, and never catalogue data.
Account and business data are kept while the account is open. Conversations and orders are kept while the account is open, because the merchant needs their own history.
When an account is deleted, deletion is immediate and cascading, not a flag. What survives is narrow and named: invoice and subscription records required for accounting are retained under a one-way cryptographic digest, so the figures remain auditable while the person is no longer identifiable from them. Uploaded files are queued and removed through the storage provider's API.
Under Israeli privacy law and, where it applies to you, the GDPR, you may request access, correction, deletion, restriction and portability, and you may object to processing.
Cremedyx is a business tool and is not directed at children. Accounts require the user to be at least 18, or the age of majority where they live.
If a breach affects your data and creates a real risk to you, we will notify you and the competent authority within the time limits the applicable law sets, and we will tell you what happened rather than what is comfortable.
If we change this policy materially we will notify merchants by email or in the app at least 30 days before it takes effect, and the date at the top of this page will change.
CREMEDYX LTD
Hai El-Madares 141, Jerusalem 9709201, Israel
admin@cremedyx.com
+972 52-220-5143