Torifon
PricingSign inTry free

Privacy Policy

Last updated: June 20, 2026

Controller: Torifon — a service operated as an individual business based in Israel ("Torifon", "we", "us"). Effective date: 20 June 2026. Privacy contact: [email protected] (a monitored mailbox). No Data Protection Officer is currently appointed; privacy matters are handled via [email protected].

This Policy explains what personal data Torifon processes, why, with whom we share it, how long we keep it, and the rights you have. It applies to our website, the booking pages at torifon.com/[slug], and our web and mobile apps (the "Service"). It is written to meet the Israeli Privacy Protection Law, 5741-1981 and, for users in the EU/EEA, the GDPR.

1. Who we are to you — controller vs processor

Torifon plays two different roles depending on the data:

  • We are the controller for: Professional account data (sign-up, billing), Client/consumer accounts created directly on Torifon, platform-usage and security data, and the operation of the public Discover and booking surfaces.
  • We act as a processor on behalf of the Professional for the Professional's own client records — the contact details, appointment history, and notes a Professional keeps about their customers. For that data the Professional is the controller and decides how it is used; we process it on their instructions to provide the Service. EU Professionals can request a Data Processing Agreement (DPA).

If you are a Client and you have a question about a Professional's records of you, contact that Professional; we will help route requests where we can.

2. Data we collect

From Professionals (account): name, email, phone, password hash or third-party sign-in identifiers, profile photo (optional), preferred language, notification preferences; business details — business name, profession/category, address and geo-coordinates, bio/tagline, logo and gallery photos, social links, opening hours, services and prices, staff names and schedules; billing identifiers from the app store / our subscription manager (App Store or Google Play subscription and customer IDs — we never receive or store your card details).

About Clients (held mostly for the Professional): first name (and optionally last name), phone number (in international E.164 format), optional email, preferred language and contact channel, appointment history and status, booking notes, reviews, and reliability counters (e.g. no-shows). Professionals may keep two kinds of notes: private notes (visible only to the Professional) and AI-shareable notes (which the Professional has marked as safe to use to personalise Tori).

Voice calls (where the Professional enables call handling/recording): call recordings, transcripts, detected language, call outcome, and the caller's phone number. Private notes are never sent to the AI; only AI-shareable notes and a pre-computed personalisation summary are.

Automatically: device and push-notification tokens, session identifiers, language/locale, approximate location you provide for Discover (stored in a cookie/preference so the map remembers it), and basic technical logs needed for security and reliability.

Sensitive data. Booking notes, AI-shareable notes, and (when enabled) call recordings can contain special-category data — for example health information, or details that imply it. Professionals should collect only what they need, and are responsible for obtaining any heightened consent the law requires (e.g. GDPR Art. 9 for EU clients) before recording or storing such data. Private notes are never sent to the AI.

Cookies / similar tech: we use the cookies strictly necessary to sign you in and remember preferences (e.g. session, locale, Discover location). We do not currently run third-party advertising trackers. If we add analytics, we will update this Policy and, where required, ask for consent.

3. Why we use it, and our legal bases (GDPR Art. 6)

PurposeLegal basis
Create and run your account; provide bookings and the booking pagePerformance of a contract
Process subscription purchases (via the app store's In-App Purchase)Performance of a contract / legal obligation (tax)
Operate the Tori voice receptionist and record/transcribe callsConsent (of the caller) and the Professional's legitimate interest in handling their calls
Personalise Tori using AI-shareable notes and historyThe Professional's legitimate interest / their instructions as controller
Send service messages (booking confirmations, reminders, changes)Performance of a contract / consent for marketing-style messages
Security, fraud-prevention, debugging, and cost/usage monitoringLegitimate interest
Comply with law and respond to lawful requestsLegal obligation

Where we rely on consent (e.g. call recording, any future marketing or analytics), you may withdraw it at any time without affecting prior processing.

Israel vs EU. "Legitimate interest" is a lawful basis under the GDPR (for EU/EEA users). Under the Israeli Privacy Protection Law, the same processing rests instead on your consent and on what is necessary to provide the Service you requested. The call-recording basis applies only when the voice receptionist is enabled (see §4).

4. Voice calls, recording and AI

Tori and call recording are off by default and operate only where a Professional turns them on for their business. This section describes how they work when enabled.

Where a Professional turns on call handling, calls may be recorded and transcribed so the Professional can review them and so Tori can book and personalise. The Professional is responsible for informing callers and obtaining the consent the law requires (including under Israeli wiretapping law); Torifon offers a setting to announce recording at the start of a call. Recordings are stored on object storage and accessed through short-lived, signed links — they are not public. Private notes are never injected into AI prompts. Tori is automated and can make mistakes; it is not a substitute for a human and must not be relied on for emergencies.

5. Who we share data with (sub-processors and recipients)

We do not sell your personal data. We share it with service providers ("sub-processors") only to run the Service, and with a Professional and their staff for their own bookings. Below is the current picture; the authoritative, up-to-date list will be maintained at torifon.com/privacy/subprocessors.

Active now:

ProviderPurposeLocation
Apple App Store / Google PlaySubscription billing — In-App Purchase (the store is the merchant of record; we do not receive your card details)US/EU
Google (Sign-in / OAuth)AuthenticationUS/EU
Apple (Sign in with Apple)Authentication (Apple account identifier; name and email or Apple's private relay email)US/EU
ResendTransactional & magic-link emailUS
Google Places / MapsAddress autocomplete, geocoding, map displayUS/EU
Expo (push notifications)Mobile push deliveryUS
HetznerApplication & database hostingGermany (EU)
CloudflareCDN, security, and recording/transcript storage (Cloudflare R2)Global / EU

Engaged when a Professional enables Tori / voice / messaging features:

ProviderPurpose
TwilioTelephony (inbound/outbound calls) & SMS
Google (Gemini + Cloud Speech / Text-to-Speech)Language model powering Tori, and speech-to-text / text-to-speech for voice calls
SonioxSpeech-to-text (call transcription)
Anthropic (Claude)Language model for AI text features (e.g. message auto-replies)
Google CalendarTwo-way calendar sync (the "connect" toggle exists but sync is not yet wired)

We may also disclose data to comply with law, enforce our Terms, or protect rights, safety, and security; and to a successor in a merger or acquisition (you will be notified).

6. International transfers

Torifon is operated from Israel and hosted in the EU (Germany). Some sub-processors are in the United States. Where we transfer personal data internationally, we rely on lawful transfer mechanisms — for EEA data, the European Commission's Standard Contractual Clauses and/or adequacy decisions (Israel benefits from an EU adequacy decision), and equivalent safeguards in our sub-processor agreements.

7. How long we keep data

  • Account & business data: for as long as your account/business is active, then deleted after closure (subject to legal retention).
  • Bookings & client records: while the Professional's business is active; deleted (cascade) when the business is deleted or on a valid erasure request.
  • Call recordings: intended retention 6 months by default, then auto-purged.
  • Transcripts: intended retention 12 months by default.
  • System/security logs: about 90 days.

When you delete a business, deletion is immediate and permanent (hard cascade); we do not keep a backup copy beyond routine, time-limited operational backups.

8. Your rights

Subject to the Israeli Privacy Protection Law and, for EEA users, the GDPR, you may:

  • access the personal data we hold about you, and ask for a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • port your data (receive it in a portable format) — EEA;
  • object to or restrict certain processing, and withdraw consent (e.g. for call recording);
  • not be subject to solely automated decisions with legal/similar effects — Tori books appointments but does not make such decisions about you.

How to exercise them. Email [email protected]. In the mobile app, Account → Privacy & data offers "export my data" and "request deletion" actions. Today these are handled manually (they compose an email to [email protected]); an automated export endpoint and self-service deletion are planned. A Client can ask the relevant Professional, or us, to delete their record; when a Client record is deleted, the linked appointments, calls and recordings are deleted with it, and the Professional is notified. We will respond within the time the law requires (generally 30 days). You may also complain to the Israeli Privacy Protection Authority (PPA) or, in the EEA, your local supervisory authority.

Withdrawing consent does not affect the lawfulness of processing already carried out. We may retain data where the law requires, or to establish, exercise, or defend legal claims. To protect your data, we may need to verify your identity (for example by confirming your email or phone number) before acting on a request.

9. Security

We protect data with measures including encryption in transit (TLS), encryption of the database at rest, short-lived signed links for any recordings, secrets kept out of the database, and an audit log of administrative access. No system is perfectly secure; we cannot guarantee absolute security, and you are responsible for safeguarding your own credentials and devices.

Data breaches. If a breach affecting personal data occurs, we will act without undue delay to contain and assess it; notify the Israeli Privacy Protection Authority (and, for EEA data, the relevant supervisory authority) where the law requires — for high-risk breaches under the GDPR, within 72 hours of becoming aware; and inform affected Professionals and, where required, the individuals concerned. Where a breach affects a Professional's client records, we will notify the Professional so they can meet their own notification duties.

10. Children

The Service is not intended for children under 18 (or under the minimum age in your country). We do not knowingly collect their data; if you believe a child has provided us data, contact [email protected].

11. Israel-specific notes

We process personal data in line with the Privacy Protection Law, 5741-1981 and its regulations, including your right of access and correction and our data-security obligations. Where our databases meet the registration thresholds, we maintain the required registrations and database-management practices.

12. Changes to this Policy

We may update this Policy. If changes are material we will give reasonable notice (in-app or by email). The "last updated" date shows the current version; continued use after that date means you accept the update.

13. Contact

Privacy questions or requests: [email protected].

View the Terms of ServiceBack to home
Torifon

Hire your AI receptionist.

Product

  • Pricing
  • See a demo

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms

© 2026 Torifon