מדיניות פרטיות
עודכן לאחרונה: 29 בספטמבר 2026
בקצרה
- אנחנו אוספים רק את מה שצריך כדי שהשירותים יעבדו: בעיקר מייל, שם, וסיסמה מוצפנת.
- אנחנו לא מוכרים מידע אישי לאף אחד.
- אפשר לבקש לראות, לתקן או למחוק את המידע שלך בכל רגע — במייל [email protected].
1.מי אנחנו ועל מה המדיניות חלה
reem.bi הוא אוסף של אתרים ופרויקטים שמפתח ומפעיל רעם, מפתח עצמאי (להלן: "אנחנו"). המדיניות הזו חלה על:
- האתר הראשי reembir.com, כולל אזור החברים ("Members terminal") וטופס יצירת הקשר;
- מערכת ההתחברות המרכזית — חשבון reem.bi בכתובת login.reembir.com, שבאמצעותה מתחברים לכל הפרויקטים;
- הפרויקטים שמשתמשים בחשבון reem.bi, כמו NeverLost (reembir.com/neverlost).
לחלק מהפרויקטים יש מדיניות פרטיות משלימה משלהם (למשל אפליקציות מסוימות). במקרה כזה, המדיניות הספציפית גוברת לגבי אותו פרויקט.
2.אילו נתונים אנחנו אוספים
חשבון reem.bi
- מייל ושם — כשנרשמים או נכנסים עם קישור במייל.
- סיסמה — נשמרת רק בצורה מוצפנת חד-כיוונית (hash). אנחנו לא יכולים לראות אותה.
- סטטוס החשבון — האם המייל אומת, תאריך הצטרפות וכניסה אחרונה, לאילו אתרים יש לך גישה, והתוכנית שלך בכל אתר (למשל Free / Pro) ותוקפה.
- חיבורים פעילים — לכל חיבור נשמר מזהה מוצפן, תאריך תפוגה וסוג הדפדפן/המכשיר (User-Agent), כדי שתוכל/י להתנתק מכל המכשירים.
- נתונים טכניים לאבטחה — כתובת IP משמשת זמנית להגבלת ניסיונות התחברות ושליחת מיילים, כדי למנוע ניצול לרעה.
NeverLost
- המידע שמוזן לכל תג: שם החפץ, הודעה למוצא, מספר טלפון ומייל ליצירת קשר (אופציונלי).
- שימו לב: דף התג ציבורי. כל מי שסורק את קוד ה-QR יכול ליצור איתך קשר דרך כפתורי וואטסאפ, שיחה או מייל — ולכן פרטי הקשר שהזנת לתג נגישים למי שמחזיק בקישור. אל תכניסו לתג מידע שאתם לא רוצים שמוצא יראה.
האתר הראשי
- טופס יצירת קשר — שם, מייל ותוכן ההודעה. אם את/ה מחובר/ת, נשלח גם מזהה החשבון שלך.
- קיר ההודעות באזור החברים — ההודעה שכתבת, השם שלך ומועד הכתיבה גלויים לכל החברים המחוברים.
נתוני שימוש, סטטיסטיקה ופרסום
באתר הראשי פועלים כלי סטטיסטיקה (Google Analytics / Google Tag Manager, וכלי סטטיסטיקה של open-domains) שאוספים נתוני שימוש כלליים כמו עמודים שנצפו, סוג מכשיר ומדינה משוערת. בחלק מהעמודים עשויות להופיע מודעות של Google AdSense, ובאתר יש גם כפתור תרומה של Ko-fi. השירותים האלה עשויים להשתמש בעוגיות ובמזהים משלהם, בהתאם למדיניות הפרטיות שלהם.
3.איך אנחנו משתמשים במידע
- לאפשר התחברות, לאמת את המייל ולשחזר גישה (איפוס סיסמה);
- להפעיל את השירותים — למשל להציג את התגים שלך ב-NeverLost ולאכוף את מכסת התוכנית;
- לנהל גישה ותוכניות (כולל Pro) לכל אתר;
- לשלוח מיילים הקשורים לשירות, ולענות לפניות;
- לשמור על אבטחה ולמנוע ספאם וניצול לרעה;
- להבין איך משתמשים באתרים ולשפר אותם (בנתונים סטטיסטיים כלליים).
אנחנו לא מוכרים, משכירים או סוחרים במידע אישי, ולא משתמשים בו לקבלת החלטות אוטומטיות עם השפעה משמעותית עליך.
4.שיתוף מידע וספקי שירות
המידע נשמר ומעובד אצל ספקי תשתית שעוזרים לנו להפעיל את השירותים, ורק במידה הדרושה לכך:
| ספק | למה |
| Cloudflare | אירוח מערכת ההתחברות ומסד הנתונים של החשבונות, והגנה על האתר |
| GitHub Pages | אירוח האתר הראשי והפרויקטים |
| Google Firebase | אחסון התגים של NeverLost |
| Resend | שליחת מיילים (קישורי התחברות, איפוס סיסמה, עדכונים) |
| FormSubmit | העברת הודעות מטופס יצירת הקשר למייל שלנו |
| Google Analytics / Tag Manager / AdSense, open-domains, Ko-fi | סטטיסטיקה, פרסום ותרומות באתר הראשי |
חלק מהספקים שומרים מידע בשרתים מחוץ לישראל (למשל בארה"ב ובאירופה). מלבד זאת, נמסור מידע רק אם נידרש לכך על פי דין, או כדי להגן על זכויות, ביטחון או רכוש שלנו או של משתמשים.
5.עוגיות ואחסון בדפדפן
- עוגיית התחברות (
sso_session) ב-login.reembir.com — חיונית כדי שתישאר/י מחובר/ת. היא מאובטחת (HttpOnly) ובתוקף עד 30 יום.
- אחסון מקומי (localStorage) באתרים שמתחברים דרך חשבון reem.bi — שומר את טוקן ההתחברות לאותו אתר והעדפות קטנות (כמו צבע רקע שבחרת).
- עוגיות של צד שלישי — של כלי הסטטיסטיקה והפרסום שהוזכרו למעלה. אפשר לחסום אותן בהגדרות הדפדפן, והאתר ימשיך לעבוד.
6.מיילים
המיילים נשלחים מכתובות בדומיין reembir.com (למשל [email protected]). נשלח אליך מיילים הכרחיים לשירות (התחברות, אימות, איפוס סיסמה), ומדי פעם עדכונים הנוגעים לחשבון או לשירותים שבהם את/ה משתמש/ת. אם אינך רוצה לקבל עדכונים שאינם הכרחיים — כתבו ל-[email protected] ונפסיק.
7.כמה זמן נשמר המידע
- פרטי החשבון נשמרים כל עוד החשבון קיים. אחרי מחיקת החשבון הם נמחקים, יחד עם הגישות והודעות הקיר שלך.
- חיבורים פגים אחרי 30 יום; קישורים שנשלחים במייל פגים אחרי 15 דקות עד 3 ימים וניתנים לשימוש פעם אחת.
- תגי NeverLost נשמרים עד שתמחק/י אותם.
- יומן מיילים שנשלחו ונתוני אבטחה נשמרים לתקופה הדרושה לתפעול ולמניעת ניצול לרעה.
8.אבטחת מידע
אנחנו נוקטים אמצעים סבירים להגנה על המידע: חיבור מוצפן (HTTPS), סיסמאות מוצפנות ב-PBKDF2, שמירת טוקנים רק כ-hash, קישורי מייל חד-פעמיים עם תוקף מוגבל, הגבלת ניסיונות והגנות מפני CSRF. עם זאת, אף מערכת אינה חסינה לחלוטין, ואיננו יכולים להבטיח אבטחה מוחלטת. שמרו על הסיסמה שלכם ואל תשתפו אותה.
9.הזכויות שלך
בהתאם לחוק הגנת הפרטיות, התשמ"א-1981, ובמידה שחל עליך — גם לפי ה-GDPR, את/ה רשאי/ת:
- לעיין במידע שנשמר עליך;
- לבקש לתקן מידע שגוי (את השם אפשר לשנות לבד בדף החשבון login.reembir.com);
- לבקש למחוק את החשבון ואת המידע שלך;
- לבקש לקבל עותק של המידע, ולהתנגד לשימושים מסוימים בו.
לכל בקשה בנוגע למידע שלך (עיון, תיקון, מחיקה או קבלת עותק): [email protected]. נשתדל לענות תוך 30 יום. בדף החשבון אפשר גם להתנתק מכל המכשירים בלחיצה.
10.ילדים
השירותים אינם מיועדים לילדים מתחת לגיל 13 (או הגיל המינימלי הקבוע בדין במדינה שלך). אם נודע לנו שנאסף מידע על ילד מתחת לגיל זה ללא הסכמת הורה, נמחק אותו.
11.שינויים במדיניות
ייתכן שנעדכן את המדיניות מעת לעת. התאריך בראש העמוד יתעדכן, ובשינויים מהותיים נודיע גם במייל או באתר.
12.יצירת קשר
שאלות על פרטיות ובקשות בנוגע למידע שלך: [email protected].
לכל נושא אחר: [email protected].
ראו גם: תנאי השימוש.
Privacy Policy
Last updated: September 29, 2026
The short version
- We only collect what the services need to work — mainly your email, name and a hashed password.
- We never sell personal information.
- You can ask to see, correct or delete your data at any time: [email protected].
1.Who we are and what this covers
reem.bi is a collection of websites and projects built and run by Re'em, an independent developer ("we", "us"). This policy covers:
- the main website reembir.com, including the Members terminal and the contact form;
- the central sign-in system — your reem.bi account at login.reembir.com, used to sign in to every project;
- projects that use the reem.bi account, such as NeverLost (reembir.com/neverlost).
Some projects have their own supplementary privacy policy (for example, certain apps). Where they do, that policy takes precedence for that project.
2.What we collect
reem.bi account
- Email and name — when you sign up or sign in with an email link.
- Password — stored only as a one-way hash. We can't see it.
- Account status — whether your email is verified, when you joined and last signed in, which sites you can access, and your plan on each site (e.g. Free / Pro) and its expiry.
- Active sessions — for each session we keep a hashed identifier, an expiry date and your browser/device type (User-Agent), so you can sign out everywhere.
- Security data — your IP address is used briefly to rate-limit sign-in attempts and emails and prevent abuse.
NeverLost
- What you enter for each tag: item name, a message for the finder, and a phone number and email for contact (optional).
- Please note: tag pages are public. Anyone who scans the QR code can contact you via WhatsApp, a call or email — so the contact details on a tag are available to whoever has its link. Don't put anything on a tag you wouldn't want a finder to see.
Main website
- Contact form — your name, email and message. If you're signed in, your account ID is included.
- Members wall — the message you post, your name and the time are visible to all signed-in members.
Usage data, analytics and advertising
The main website uses analytics tools (Google Analytics / Google Tag Manager and open-domains analytics) that collect general usage data such as pages viewed, device type and approximate country. Some pages may show Google AdSense ads, and the site includes a Ko-fi tip button. These services may use their own cookies and identifiers under their own privacy policies.
3.How we use information
- to let you sign in, verify your email and recover access (password reset);
- to run the services — for example, showing your NeverLost tags and applying your plan's limits;
- to manage access and plans (including Pro) for each site;
- to send service-related emails and reply to you;
- to keep things secure and prevent spam and abuse;
- to understand how the sites are used and improve them (using aggregate statistics).
We don't sell, rent or trade personal information, and we don't use it for automated decisions that significantly affect you.
4.Sharing and service providers
Your data is stored and processed by infrastructure providers that help us run the services, only as needed:
| Provider | Purpose |
| Cloudflare | Hosting the sign-in system and account database; site protection |
| GitHub Pages | Hosting the main website and projects |
| Google Firebase | Storing NeverLost tags |
| Resend | Sending email (sign-in links, password resets, updates) |
| FormSubmit | Forwarding contact-form messages to our inbox |
| Google Analytics / Tag Manager / AdSense, open-domains, Ko-fi | Analytics, ads and tips on the main website |
Some providers store data on servers outside Israel (for example in the US and EU). Otherwise we only disclose information when required by law, or to protect the rights, safety or property of us or our users.
5.Cookies and browser storage
- Sign-in cookie (
sso_session) on login.reembir.com — essential to keep you signed in. It is HttpOnly and lasts up to 30 days.
- Local storage on sites that use the reem.bi account — keeps that site's sign-in token and small preferences (like a background color you picked).
- Third-party cookies — from the analytics and ad tools mentioned above. You can block them in your browser settings and the site will keep working.
6.Emails
Emails are sent from addresses on the reembir.com domain (such as [email protected]). We send emails the service needs (sign-in, verification, password reset) and occasionally updates about your account or the services you use. If you'd rather not receive non-essential updates, email [email protected] and we'll stop.
7.How long we keep data
- Account details are kept while your account exists. When the account is deleted, they are removed along with your access records and wall messages.
- Sessions expire after 30 days; email links expire after 15 minutes to 3 days and work only once.
- NeverLost tags are kept until you delete them.
- The sent-email log and security data are kept as long as needed to operate the service and prevent abuse.
8.Security
We take reasonable measures to protect your data: encrypted connections (HTTPS), passwords hashed with PBKDF2, tokens stored only as hashes, single-use time-limited email links, rate limiting and CSRF protection. Still, no system is completely secure and we can't guarantee absolute security. Keep your password safe and don't share it.
9.Your rights
Under Israel's Protection of Privacy Law, 5741-1981, and — where it applies to you — the GDPR, you may:
- access the data we hold about you;
- ask us to correct inaccurate data (you can change your name yourself at login.reembir.com);
- ask us to delete your account and data;
- request a copy of your data, and object to certain uses of it.
For any request about your data (access, correction, deletion or a copy): [email protected]. We aim to reply within 30 days. You can also sign out of all devices from your account page.
10.Children
The services are not intended for children under 13 (or the minimum age required by law in your country). If we learn we've collected data from a child below that age without parental consent, we'll delete it.
11.Changes to this policy
We may update this policy from time to time. The date at the top will change, and for significant changes we'll also let you know by email or on the site.
12.Contact
Privacy questions and requests about your data: [email protected].
Anything else: [email protected].
See also: Terms of Service.