Back to home

Privacy Policy

Last updated: August 18, 2026

Prosperiu holds personal financial information, so this document tries to be specific rather than general: exactly what is collected, what is explicitly not, and who sees it along the way. The most important point: the app has no bank connection, so bank credentials are never held here and never will be.

And these are the four answers most people are looking for straight away. The data is kept at Supabase, on servers in Germany (sections 8 and 16). A message to Sapir, the assistant inside the app, is handled by the language model provider, and its content is visible to it on the way (section 5). There is no such thing as absolute security in any system, here included (section 14). And the account and all of its data can be deleted entirely from the settings screen in the app, immediately and with no restore (section 12).

1.Who is responsible

The party responsible for the data in Prosperiu is AfikCraft, a business owned by Afik Ben Bocher, Israeli sole trader (עוסק פטור), business ID 324159268. Full contact details are in section 19.

This policy describes what is actually collected, what for, who sees it, and how to exercise the rights the law gives you. It covers the application, Sapir, the assistant inside it, and what remains of the WhatsApp channel during the transition, as sections 4 and 5 set out.

2.What we collect

The data in the system comes from one source only: what you hand over or record.

  • Account details: email address, first and last name, a default currency, and the form of address you chose, masculine, feminine or unspecified, so Sapir addresses you correctly. The form of address is chosen in settings; if none was chosen yet and Sapir asked in the chat, your answer is saved as the account's default, and a choice made in settings is never overridden from a chat. The password is stored hashed by the authentication service, and we keep no copy of it, neither in the database nor on your device. The detail is in section 11 and in section 14.
  • Phone numbers: no longer collected. Registration used to require at least one, and accounts that linked numbers in that period keep them until they are removed. What those numbers still do, and how they are removed, is set out in section 4.
  • The financial data you record: accounts and balances, transactions with amount, date, description and category, budgets, savings goals, subscriptions and recurring payments, loans and mortgages with their terms, property, portfolio holdings, watchlists and alerts, and any free notes you write.
  • The conversation with Sapir: the messages you write to her in the app and her replies are stored in the account's database. The detail is in section 5.
  • Report preferences: whether Sapir sends a report, how often, and at what hour.
  • Shares: the email address of whoever you invited, the permission level given, and the status of the invitation.
  • Phone change requests: records left over from the period when numbers were managed in the app: the requested action, the number, the expiry time, the number of wrong attempts, and a hash of the verification code. The code itself was never stored, and new requests are no longer created.
  • Display preferences: language, dark or light mode, brightness and accessibility menu settings. These live in your browser, not with us.
  • Operational logs: our infrastructure providers record, as is standard, request details such as IP address, timestamp and browser type, for security and fault finding.

3.What we do not collect

  • Bank credentials. The app has no connection to a bank or a card issuer, so there is no field for a bank username, password or code, and there never will be. We will never ask for them, on any channel.
  • Card numbers. A credit card account is stored under the name you gave it and the limit you entered, with no card number and no security code.
  • National id numbers or identity documents.
  • Device location.
  • Advertising cookies, pixels or third party analytics. There is no advertising or tracking code anywhere in the app.

4.Phone numbers: what changed

Registration used to require a phone number, because the assistant worked over WhatsApp: a message arriving there carries a phone number and not much else, so the number was the only identifier, and the report was sent to it. Both of those jobs have ended. Sapir works inside the app and recognises you by the signed in session itself, and the report arrives in the app's reports conversation. So the product no longer collects phone numbers, and the number management screens were removed.

  • Accounts that linked numbers in the past keep them, for one job only: continued delivery of the WhatsApp report, until the move to the in app report is complete. We do not delete them on our own initiative, so nobody's report disappears mid transition.
  • You can ask for a number to be removed at any time, writing from the account's own email address to the address in section 19, and all numbers are deleted together with the account.
  • The numbers are not used for marketing, are not passed to advertisers, and are not sold to anyone.

5.Talking to Sapir

Sapir sits inside the app, and on a phone she is also installed as a separate app on the home screen. It is the same system, the same account and the same database, and everything in this section applies to both forms equally. A message to her is written in the signed in account, stored in the account's database, and handled by a server function of the system. It does not travel through WhatsApp and does not travel through GREEN-API. One outside party is involved on the way, and that should be plain:

  • Anthropic: the content of the messages and the results of the actions, amounts included, are sent to it so the request can be understood and a reply composed.

So the content of your message, including amounts and descriptions you wrote in it, is exposed to the language model provider while the request is handled. The result, the entry itself, is stored in your account's database, and the conversation is stored there too, behind the same separation between users as the rest of the data. Another user does not see it, not even somebody you share a cashflow with.

We do not use the content of messages as training material for models. That is an undertaking about what we do, not a promise made on behalf of the provider that handles the message: what it does with what passed through it, and how long it keeps it, is governed by its own policy and is not in our control. Do not write to Sapir anything you would not want travelling that way, including bank details, passwords or sensitive documents.

What remains of the WhatsApp channel is the report alone, for accounts that linked a phone number while the product still collected them, until the move to the in app report is complete. That report passes through GREEN-API and through WhatsApp, from Meta, under each one's own policy, and is sent from the business number of AfikCraft, which Afik holds himself. Conversations held with the WhatsApp assistant in the earlier period still exist where they were kept then. The full detail, for both routes, is in section 10.

6.How the data is used

  • To run the service: display the cashflow, calculate totals and manage the account.
  • To identify you to Sapir by the signed in session, and carry out what you asked for.
  • To send the report and the alerts you chose to receive.
  • To confirm sensitive changes, such as a password reset, through the account's email.
  • To secure the system, detect abuse and fix faults.
  • To improve the product. A user's financial data is not used to serve advertising, is not sold, is not handed to advertisers, and is not used by us as training material for models.

7.Providers who process data

Running the service relies on providers. These are the categories and what each one actually does:

  • Database, authentication and server functions: Supabase. The account and the financial data live there. The project's servers are in the eu-central-1 region, that is Frankfurt in Germany, inside the European Union. The detail is in section 16.
  • Website and application hosting: Vercel.
  • Email delivery: Resend, for signup confirmation, password reset, share invitations, and sending the daily backup file.
  • WhatsApp gateway: GREEN-API, carrying, during the transition, the WhatsApp report to accounts that linked a number in the past.
  • Push notification services: Apple, Google or Microsoft, depending on the browser and the device, carrying notifications to devices where they were turned on. The content of a notification is encrypted on its way to the device. The detail is in section 17.
  • Language model provider: Anthropic, for interpreting messages sent to Sapir and composing the reply. It also produces securities summaries.
  • Voice message transcription: Groq, on the WhatsApp channel only. The conversation with Sapir in the app has no voice messages.
  • Market data sources: public services for prices and exchange rates. What is sent to them is the instrument symbol, or the search string you typed, with no name and no email address. The currency calculator calls the rates service directly from the browser, so the visitor's browsing address is exposed to it. The detail is in section 10.

We do not sell data and do not pass it to a third party for advertising. Beyond the use described here, data is handed over only where the law or an order from a competent authority requires it. Each provider has its own privacy policy; we do not make undertakings on their behalf, and we do not state contract terms here that we cannot verify. The full list, and what each party actually sees, is in section 10.

8.Storage and separation

  • Data is stored in a managed PostgreSQL database at Supabase, on servers in the eu-central-1 region, in Frankfurt, Germany. Processing outside Israel is set out in section 16.
  • Every table holding user data is protected by Row Level Security: a request arriving from the app carries the user's identity, and the database itself returns only rows that belong to them, or rows explicitly shared with them. The separation does not rest on display code.
  • On Sapir's route too the separation is enforced by the database: actions on the money data run under the signed in user's own identity, not under a service key. On the earlier WhatsApp channel the separation was enforced by the system's code, and that remains true for the transition period's report. The full explanation is in section 10.
  • Traffic between browser and server is encrypted in transit.
  • Besides the database provider's own backups, we produce a full encrypted backup daily and send it to the business mailbox. The detail is in section 10.

9.Sharing a cashflow

  • Your data reaches another user only if you chose to share it with them by email address, and only after they accepted the invitation. For the access held by the person who runs the service and by the infrastructure providers, see section 10.
  • Under view only the invited person sees and cannot change. Under full access they can change and delete too. Sapir honours the same permission.
  • A share can be revoked at any time. Revoking stops access, but does not erase what the invited person has already seen or copied.
  • Sharing means exposing the financial data in that cashflow. It is worth weighing the permission level before inviting.

10.Operator access to data

Prosperiu is run by one person. Afik Ben Bocher, the owner of AfikCraft, builds the service, maintains it and answers requests. No other person works on the service and sees the data. The infrastructure companies the service runs on are listed further down this section.

Sapir works inside the app, and the conversation with her is stored in the system's database. Afik's access to it is therefore the same access he has to the rest of the data, described below, and it does not sit on a WhatsApp handset. AfikCraft's business number, printed at the end of this document, remains the support line for the service, and during the transition the WhatsApp report is also sent from it to accounts that linked a number in the past. That is an ordinary WhatsApp on a handset Afik holds, so whatever is sent on that channel, and the conversations held with the WhatsApp assistant in the earlier period, sit with him too.

You can use the app without ever talking to Sapir. The report is sent only to whoever chose to receive it, turning it off in settings stops it, and the rest of the app stays fully open.

Why the access exists

Running a service, finding a fault and answering a request all need access to the data stored in the system. It is also why someone who writes that an entry was not recorded properly can be helped. In practice the access exists through several routes, and each one is enough on its own:

  • Ownership of the database, and therefore the ability to open anything stored in it.
  • Service keys, meaning passwords the system itself uses for automated processes. They are not subject to the separation enforced inside the database.
  • The daily backup file that arrives in the business mailbox, together with the password that opens it.
  • The handset that runs the business WhatsApp number, where the transition period's reports and the WhatsApp era's conversations sit.
  • The hosting account, which holds the system's operational logs and the conversation history from the WhatsApp channel.

What the access is used for

  • To run the service, to find and fix faults, to handle a user's request, and to meet a requirement under the law.
  • Financial data is not sold, is not handed to advertisers, is not used for advertising, and is not used by us as training material for models.
  • The app has no access log that shows a user when Afik looked at an entry of theirs, and there is no technical block that stops him from looking. What limits the access is the undertaking written here and the applicable law. At any moment you can ask for a copy of your data, delete the account, or use the app without ever talking to Sapir.
  • If another person with access to the data is ever added, this policy will be updated before that access is granted.

Other users

Another Prosperiu user cannot see your data. That does not rest on a promise but on the database itself. Every request leaving the app carries the identity of whoever signed in, and the database returns only records belonging to them. Someone else's records come back only if they invited you to share a cashflow and you accepted.

Sapir works to the same rules, and in fact leans on them directly: she runs under the identity of whoever signed in, so everything she does with the money data is enforced by the database itself, as in the rest of the app. On the earlier WhatsApp channel identification was by phone number and the separation was enforced by the system's code, because that route worked with a service key. That remains the case for the report sent there during the transition.

The daily backup

Once a day a full backup of the database is produced, meaning the data of all users together. The file also holds the account details themselves: email address, the last sign in time, and phone numbers on accounts that linked them in the past. Passwords are not included, because the database provider does not allow them to be exported.

The file is encrypted and sent as an attachment to the business mailbox, info@afikcraft.com, which is hosted at Google. The password that opens it is held by Afik alone and is not sent with the file, so anyone who obtains the file without the password cannot read it. It does not limit Afik, because he holds both the file and the password.

There is currently no automated process that deletes old backups, and they stay in the mailbox. So a user who deletes their account is removed from the database, but their data remains inside backup files sent before the deletion. You can ask for those files to be deleted as well. There is no automated process for it, and each backup file contains all users together, so such a request is reviewed and handled by hand and is not immediate.

Who else is exposed

These are the outside parties involved in running the service, each with its role:

  • Supabase: stores the account, the financial data and the conversation with Sapir, performs the authentication, and runs the server function Sapir answers through.
  • Vercel: runs the site. During the transition the WhatsApp channel runs there too, and its operational logs record phone numbers and short opening excerpts of messages, for fault finding.
  • Vercel KV: a fast store holding the conversation history from the WhatsApp channel. The conversation with Sapir is not kept there but in the database.
  • GREEN-API: an outside company connecting WhatsApp to the system. Whatever is still sent on that channel, chiefly the transition period's report, passes through it.
  • WhatsApp, by Meta: the messaging network the transition period's report travels over, under its own privacy policy.
  • Anthropic: receives the content of messages to Sapir and the results of her actions, amounts included, in order to understand the request and compose a reply. It also writes securities summaries, and for those only public market data is sent to it, with no identifying detail.
  • Groq: transcribes voice messages on the WhatsApp channel. The conversation with Sapir has no voice messages.
  • Resend: sends the service's email, including the daily backup file.
  • The browser makers' push services: Apple, Google or Microsoft, depending on the device, carry notifications to devices where they were turned on. The content of a notification is encrypted on its way to the device, so they see that a notification was sent and to which delivery address, not what it says. The detail is in section 17.
  • Google: hosts the mailbox the backups arrive in. The site also loads fonts from Google servers, so a visitor's browsing address (IP) is exposed to them.
  • Make.com: triggers scheduled processes, the daily backup among them. It receives a confirmation of execution and not the data itself.
  • Market data sources: price and exchange rate services. What is sent to them is the instrument symbol, or the search text typed when looking one up, with nothing that identifies a user. The currency calculator calls a rates service directly from the browser, so the browsing address is exposed to it.

The conversation with Sapir is stored in the account's database, alongside the rest of the data, and is deleted together with the account. Conversation history from the WhatsApp channel is kept in the fast store while the conversation is active and is deleted automatically after 120 days with no message in it; the last sixty turns are what is stored, and the assistant on that channel also kept up to twenty short notes for one year. You can ask for all of these to be deleted.

For a question about this, a copy of your data or a deletion request, the contact details are in the last section. Account deletion is also available from the settings screen in the app.

11.Cookies and local storage

The app stores in your browser what it needs to work, plus a record that makes the next sign in instant. There are no advertising cookies, no third party analytics and no tracking pixel. That said, the site loads fonts from Google servers, and the currency calculator calls a rates service directly from the browser, so your browsing address is exposed to those services.

  • A session token saved in the browser by the authentication service, so you do not have to type your password on every visit.
  • Display preferences: language, dark or light mode, and brightness.
  • Accessibility menu preferences: font size, contrast and the rest.
  • Card open or closed state on the overview screen, and the order the cards are arranged in.
  • The active cashflow: if a shared cashflow was selected for viewing, its id is kept so the screen opens on the same one next time. It is a display preference and grants nothing: the permission itself is checked in the database on every request, as described in section 14.
  • Markers for budget alerts already dismissed or acknowledged, so they do not come back.
  • The id of the app version loaded last, used to notice an update and clear an old cache.
  • The last activity time: the timestamp of the last occasion the app was opened or came back to the foreground, whose only use is the automatic sign out in section 14.
  • The last user record: your email address, name and profile picture, so the sign in screen can greet you by name and you need not type your address again. No password is kept there. The record expires after seven days without use, and you can erase it at once on the sign in screen with "Use a different account". The detail is in section 14.

Clearing your browser storage erases those preferences and requires signing in again. The financial data itself is not held in the browser as its source, it lives in the database.

12.Retention and deletion

  • Data is kept for as long as the account exists.
  • The settings screen can reset the financial data while keeping the account itself. That action cannot be undone.
  • Full deletion of the account and all of its data is done from the settings screen, after typing the account's own email address as confirmation. It happens immediately and cannot be undone. It applies to the database. Encrypted backup files sent beforehand are not removed automatically, and you can ask for them to be deleted, as described in section 10.
  • The record kept in your browser so the sign in screen can greet you by name expires after seven days without use. You can erase it at once on the sign in screen, with "Use a different account".
  • Phone numbers linked in the past are kept until removed on request, or until the account is deleted. Phone change records, from the period when numbers were managed in the app, hold a hash of the verification code, not the code.
  • Operational logs at infrastructure providers are kept under their own policies.
  • The conversation with Sapir is kept in the database for as long as the account exists, and is deleted together with it. Conversation history from the WhatsApp channel is deleted automatically after 120 days with no message in it, the short notes kept there are kept for up to a year, and you can ask for them to be deleted.
  • Data we are legally obliged to retain is kept as the law requires and no further.

13.Your rights

Under the Israeli Privacy Protection Law, 5741 1981, and the regulations made under it, you have the following rights:

  • Access: to receive a copy of the data held about you. There is no export button in the app at present, so the copy is sent in reply to a request.
  • Correction: to correct data that is wrong. Most of it can be corrected directly in the app, at any moment.
  • Deletion: you can delete the account and all of its data yourself, from the settings screen in the app under "Danger Zone", after typing the account's email address as confirmation. It is immediate and cannot be undone. You can also ask us to do it, and ask separately for backup files sent earlier to be deleted. The detail is in section 12 and in section 10.

To exercise them, write to info@afikcraft.com from the account's own email address, so we can confirm the request really comes from the account holder. We reply within 30 days.

14.Security

What follows is what is actually in place today, not a list of intentions. There is no standard we passed, no certificate and no external audit, because none was carried out.

What is protected, and how

  • The password: stored hashed by Supabase's authentication service. We have no access to it and cannot recover it as readable text, and the daily backup file does not contain it either. A password reset is done with a code sent to the account's email address.
  • Staying signed in: we do not keep your password in the browser. Until now an obscured copy was kept there, and it has been removed: obscuring was not encryption, and anyone with access to the device could recover the password from it. What is kept instead is a secure session that renews itself, so coming back to the app stays automatic without the password sitting on your device. Anyone who already had such a copy had it erased from the browser the first time this version loaded. After seven days without use the session closes and the password has to be typed again.
  • Separation between users: enforced by the database itself on every request arriving from the app, not only by display code. Sharing permissions are enforced there too, not on the screen. Sapir runs under the signed in user's identity and is bound by the same enforcement; on the earlier WhatsApp channel it was enforced by the system's code, as described in section 10.
  • Traffic: the connection between the browser and the servers is encrypted.
  • The phone numbers left from the past: the app no longer accepts new numbers, and the management screens were removed. Direct writing to the phone number table remains blocked from the browser, so taking over an open session does not allow attaching a number to an account.
  • The number mechanism's confirmation codes: the mechanism is no longer reachable from the screens, and its protections remain in force in the database: the code is stored only as a hash, under a key that lives on the server, valid for 30 minutes, works once, and is blocked after five wrong attempts.
  • The daily backup: compressed and encrypted with AES-256, under a key derived from a passphrase over 600,000 rounds, before it is sent. The system decrypts the file it produced and compares it with the source before sending, and refuses to send at all if the passphrase is too weak, rather than sending a readable file. The detail is in section 10.
  • Account deletion: identified from the sign in token alone, and requires typing the account's email address as confirmation.
  • Automatic sign out after a period without use: the system records in your browser the last time the app was opened or came back to the foreground. If more than seven days have passed since, it closes the session at the next opening and asks you to sign in again. The check runs when the app opens and whenever it returns to the foreground, not in the background, so a device that is never opened stays signed in until it is. A token renewal the browser performs on its own does not count as use.

What is still missing

  • There is no two factor authentication. The password is currently the only barrier to entering an account.
  • No penetration test and no external security audit have been carried out.
  • There is no access log showing a user who looked at their records, as described in section 10.

There is no such thing as absolute security

This has to be said plainly, uncomfortable as it is. No system is immune. A third party can break into any service, including services far larger and better secured than this one, and including the infrastructure providers this service rests on. We do what can be done to prevent it, and there is no way to guarantee it will not happen. Anyone promising absolute security is saying something untrue, and we do not promise it.

So a risk remains even after everything described here, and registering for the service is done in the knowledge of it. None of this limits a liability that cannot be waived under applicable law.

What you can do on your side

  • A long, unique password, used on no other service.
  • Never hand the password to anyone. We will never ask for it on a call, on WhatsApp or by email, and a request like that in Prosperiu's name is an impersonation attempt.
  • On a shared device, erase the saved record with "Use a different account".
  • Do not write to Sapir, or send over WhatsApp, documents or details you would not want reaching the parties described in section 5 and section 10.
  • Revoke a cashflow share that is no longer needed.
  • Tell us at once about any suspicion of unauthorised use of the account.

If a security incident is discovered

  • We will establish what happened, stop what can be stopped, and close the hole.
  • We will notify by email whoever the incident concerns, as early as possible, and say what data was involved and what we recommend doing.
  • We will report it to the competent authority where the law requires that.
  • And for accuracy: there is at present no written incident procedure that has been tested in a drill. What is written here is the undertaking, not a description of a mechanism that has already run.

To report a suspected breach or unauthorised use: info@afikcraft.com. Full details are in section 19.

15.Minors

The service is not intended for children under 18, and we do not knowingly collect information about minors. If you learn that a minor opened an account without permission, tell us and we will delete the account and its data.

16.Processing outside Israel

Data in the system is processed and stored outside Israel. That is not a technical footnote, so it is set out here rather than hinted at.

  • The account and the financial data are kept at Supabase, in a project that sits in the eu-central-1 region, that is Frankfurt in Germany, inside the European Union.
  • The other providers described in section 7, among them Vercel, Resend, GREEN-API, Anthropic and Groq, are international companies. Data passing through them may also be processed in the United States and in other countries, under each one's own policy.
  • The daily backup file is sent to a mailbox hosted at Google, as described in section 10.

The basis for the transfer: the Israeli Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761 2001, list the grounds on which data may be transferred out of Israel. The ground this service relies on is the data subject's consent: whoever registers accepts this policy, including this section, and thereby agrees that the data is processed and stored outside Israel as well.

Each provider has its own privacy policy, and that is what governs what happens to the data there. We do not state contract terms here that we cannot verify. Anyone who does not agree to the data leaving Israel cannot use the service, because there is no way to run it without these providers.

17.Push notifications

You can choose to receive notifications from the app even while it is closed, through the browser's own notification mechanism (Web Push). On a device where notifications were never turned on, nothing described here happens.

  • Turning notifications on makes the browser issue a delivery address (an endpoint) and encryption keys for that device, and we store them, tied to the account. That is all that is stored, and no further detail about the device is collected.
  • The address serves one purpose: delivering your own notifications to you, meaning the report you scheduled with Sapir, Sapir's replies, and a test notification you trigger yourself. It is not used for marketing.
  • The content of a notification is encrypted on its way to the device, so whoever carries it sees that a message was sent and to which delivery address, not what it says.
  • The carrying is done by the browser makers' push services, Apple, Google or Microsoft, depending on the device. They are one more party on the way, so they also appear in the provider list in section 7.
  • A subscription that is no longer valid, for example after notifications were blocked in the browser, is deleted on our side automatically.
  • Turning them on is done per device, and on some devices, the iPhone in particular, notifications work only while the app is installed to the home screen.
  • You can stop the notifications at any moment from the browser or device settings, and deleting the account deletes these subscriptions too.

18.Changes to this policy

This policy may be updated. The current version is published on this page with its revision date at the top, and a material change will be brought to users' attention by email or by a notice inside the app.

19.Contact

For a privacy question, a request to access, correct or delete data, or to report a suspected security incident: