Version 1.6 · Last updated: September 2026
1.1 This Privacy Policy explains how מאני פלואו בע"מ, Company No. 517326245 (the "Company" or "Moneyflow"), collects, uses, retains, processes and shares personal information in connection with the website, the application, the system and the related services.
1.2 This Policy applies to private Users, family members, Advisors, professionals, visitors to the website and any person whose information is processed in the course of the Service.
1.3 Use of the Service is also subject to the Terms of Use and to the supplementary documents that apply to the service being used.
2.1 The operator of the Service is מאני פלואו בע"מ, Company No. 517326245. In connection with the open banking services, Moneyflow is in the process of obtaining a license to provide a financial information service under the Financial Information Service Law, 5782-2021 (חוק שירות מידע פיננסי, התשפ"ב-2021).
2.2 Address: Totzeret HaAretz 3, Petah Tikva, Israel.
2.3 Inquiries regarding privacy and rights can be addressed to: support@moneyflow-ai.com.
2.4 Privacy Protection Officer – Ofir Zilbiger (אופיר זילביגר), support@moneyflow-ai.com.
3.1 Moneyflow strives to process information in a manner that is proportionate, transparent and relevant to the purposes of the Service.
3.2 We collect information that is required to operate the Service, to secure it, to improve it, to provide support and to comply with legal and business obligations.
3.3 We do not sell personal information to advertisers.
4.1.1 Name, email address, telephone number, address, login details, language preferences, role, business details, and details required for account verification.
4.1.2 In certain cases, identification documents or additional details may be collected where this is required for a particular service, fraud prevention, identification, regulation or law.
4.2.1 Information that the User, or a person authorized on the User's behalf, enters regarding the household, family members, goals, tasks, documents, habits and preferences.
4.3.1 Information on income, expenses, budgets, assets, liabilities, loans, mortgages, bank accounts, balances and transactions, insurance policies, coverages, premiums, savings, investments, pension, provident funds, study funds, goals, and additional financial information that the User chooses to enter or to connect to the Service. Banking, insurance and pension information may be considered information of special sensitivity and be subject to enhanced controls.
4.4.1 In the case of Advisors and professionals, information may be collected about clients, meetings, tasks, documents, correspondence, marketing funnels, leads, content performance, charges and business activity in the system.
4.5.1 Documents, images, forms, questionnaires, attachments, correspondence, signatures, notes and other content that was uploaded to or created in the Service.
4.6.1 IP address, browser type, operating system, device and session identifiers, access times, pages and actions in the Service, logs, performance data, errors and security events.
4.7.1 We may use cookies and similar technologies for login, security, saving preferences, usage analysis, measurement and improvement of the Service. Full details appear in the Cookies and Tracking Technologies Policy.
4.7.2 Cookies that are not essential will be activated in accordance with the User's choice and applicable law.
5.1 Information may be received:
5.1.1 Directly from the User.
5.1.2 From a family member or an authorized User in a shared account.
5.1.3 From an Advisor or professional who has received authorization to attend to the User.
5.1.4 From external service providers that the User has chosen to connect.
5.1.5 From financial information sources or from open banking providers, where the User has approved such a connection.
5.1.6 From the device, from the browser and from use of the Service.
5.1.7 From business partners or from receiving parties in the framework of a referral program, subject to consent and the law.
6.1 We may use information for the purpose of:
6.1.1 Opening an account, verifying identity and managing the User.
6.1.2 Operating the Service and providing the capabilities the User requested.
6.1.3 Presenting a financial picture, calculations, metrics, alerts and insights.
6.1.4 Sharing information with family members, Advisors or authorized parties in accordance with permissions.
6.1.5 Support, customer service and handling malfunctions.
6.1.6 Information security, fraud prevention, oversight and investigation of unauthorized use.
6.1.7 Analyzing and improving the Service, including on the basis of aggregated or anonymous information.
6.1.8 Operating charges, subscriptions, invoices and settlement of accounts.
6.1.9 Sending service messages and material updates.
6.1.10 Sending marketing content, subject to consent and to the right to unsubscribe.
6.1.11 Managing referrals to professional services, only where the User has chosen to do so and has given the required consents.
6.1.12 Complying with the requirements of law, regulation, a court order or an authorized demand.
7.1 Where several family members use a shared account, each authorized User may view or modify the information in accordance with the permissions granted to that User.
7.2 Where a User connects an Advisor or a professional, the Advisor will receive access only to the information approved for the Advisor, and in accordance with the Advisor's role, the active relationship with the User and the permissions in the system. Information originating from open banking is accessible only to the client who connected the account and will not be disclosed to an Advisor, a family member, a team member, a receiving party or another User, even if a general sharing permission exists. Insurance information, pension information and other information that does not originate from open banking may be shared in accordance with the User's permissions and the law.
7.3 The User is entitled to revoke or limit the access of a family member, Advisor or professional in accordance with the options available in the system. Revoking the permission will stop future access, but does not require the immediate deletion of information that has already been lawfully recorded or that is required to be retained by law, for the protection of rights, or in accordance with the Data Deletion Policy.
7.4 Moneyflow may record the connection and disconnection of permissions, pulls and synchronizations of information, changes to permissions, and access by authorized parties, for purposes of security, support, oversight, fraud prevention and compliance with the law.
8.1 Moneyflow may use artificial intelligence services for the purpose of creating drafts, summaries, insights, analyses, suggestions, automations and other outputs.
8.2 When an AI capability is activated, information required to perform the action may be sent to an external AI provider, such as OpenAI, Anthropic or Google, including through a managed AI gateway. Information originating from open banking will not be sent to an AI provider and will not be processed by means of an external AI capability. We strive to reduce the information sent to the minimum required, to choose business API tracks and settings that limit secondary use of the information, and to prevent the use of Users' personal content for training general models, to the extent this is supported by the agreements and the provider's settings.
8.3 AI services must not be used to enter information that the User is not authorized to process or to transfer.
8.4 Use of AI services is also subject to Moneyflow's Artificial Intelligence Use Policy.
9.1 Advisors who choose to connect a Google or Gmail account do so by means of an OAuth authorization and with their explicit consent.
9.2 The access is used to display and manage correspondence, to send messages on behalf of the User, to manage permitted actions in the mailbox and to link correspondence to client cards, in accordance with the permissions actually approved.
9.3 Information that may be processed includes messages, headers, attachments, thread identifiers, sender and recipient details, OAuth tokens and operational metadata.
9.4 Access tokens are stored using means designed to restrict access to them to the server side only.
9.5 Moneyflow does not use Gmail data for targeted advertising and does not sell it.
9.6 Gmail content is not used to train or to improve general AI models — neither those of Moneyflow nor those of any third party. The only remaining use in which content from the mailbox is processed by a model is the invoice scanning described in Section 9.8, and it is routed exclusively to Google's own Gemini API. In the course of that use, no information is transferred to any other AI provider, nor through a gateway or an intermediary.
9.6.1 This restriction is enforced in code and not by procedure: the list of providers permitted for a call that carries Google data is kept in one place, and any provider that is not on the list is rejected — including the User's private AI keys and including the automatic fallback chain. When the permitted provider is unavailable, the action fails and is not passed on to another provider.
9.7 Humans will not read Gmail content, except with the User's consent for the purpose of support, for the purpose of security and incident investigation, for the purpose of compliance with the law, or on the basis of aggregated or anonymous information.
9.8 A business owner who activates invoice synchronization from the mailbox approves the automatic scanning of attachments of the invoice or receipt type for the purpose of ingesting them, to the limited extent required for that purpose.
9.9 The connection can be disconnected from within the system settings or through the Google account settings. Upon disconnection, we will stop using the token and will delete the integration record in accordance with the Data Deletion Policy. Information that the User created in the system, such as an association with a client file or a standalone note, may be retained as the User's information.
9.10 The use and transfer of information received from Google APIs are subject to the Google API Services User Data Policy, including the Limited Use requirements.
9.11 Moneyflow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9.11.1 Moneyflow does not use, transfer or sell Google Workspace user data — raw, aggregated or derived — to develop, train or improve generalized or foundational artificial intelligence or machine learning models, and does not transfer such data to any third-party AI service that would do so.
9.12 An Advisor is entitled to connect, separately, the Advisor's contacts from Google (Google Contacts) by means of a dedicated OAuth authorization and with the Advisor's explicit consent. This connection is separate from the Gmail connection, and each of them can be maintained without the other.
9.13 Information that may be processed in the framework of this connection includes first name and last name, telephone numbers, email addresses, company name and job title, notes, labels (Labels) defined in Google, the profile photo URL, contact identifiers and version identifiers from Google, and OAuth tokens.
9.14 The access is used to display the contacts to the Advisor, to classify and tag them, to open outreach to them initiated by the Advisor, to edit their details, and to identify whether a person who already exists in the system is the same person. The use is limited to these purposes.
9.15 Contacts imported from Google are not subscribed to a mailing list and do not receive any message from us automatically. Outreach to them is made solely at the Advisor's initiative and under the Advisor's responsibility, in accordance with the law that applies to marketing communications.
9.16 Imported contacts are visible only to the Advisor who connected the account. They are not disclosed to other Advisors, to the organization's manager or to team members, even where an Advisor has permission to view the organization's contacts.
9.17 Edits that the Advisor makes in the system are written back to the Advisor's contacts in Google, and only in the fields the Advisor actually edited. We do not delete contacts in Google and we do not change fields that the Advisor did not edit.
9.18 Moneyflow does not use contacts data from Google for targeted advertising, does not sell it, and does not use it to train a general AI model. Humans will not read it, except with the User's consent for the purpose of support, for the purpose of security and incident investigation, or for the purpose of compliance with the law.
9.19 The contacts connection can be disconnected at any time. Upon disconnection, the authorization is also revoked with Google, and the Advisor is asked whether to delete the imported contacts. Contacts that the Advisor has turned into a client or into a record in the system are retained as the User's information, as set out in Section 9.9.
10.1 Advisors who choose to connect Facebook, Instagram or Threads assets to the publishing module do so by means of an explicit authorization.
10.2 The access is used to publish content that the Advisor created or scheduled, to display the connected assets and to display performance metrics of the User's own content.
10.3 Information that may be processed includes access tokens, asset identifiers, the asset's name and profile picture, and aggregated performance metrics at the post level.
10.4 We do not use Meta data for third-party targeted advertising, we do not sell it, and we do not use it to train general AI models.
10.5 The connection can be disconnected from within the system or through the account settings in Meta's services. The User is also entitled to submit a deletion request in accordance with this Policy and to track the deletion of the data.
11.1.1 Moneyflow is in the process of obtaining a license to provide a financial information service. Feezback is a financial information service provider and an external technological infrastructure, with independent duties and powers under the law and under the agreement with it, and is not merely an ordinary subcontractor of Moneyflow. The connection is made only after an action initiated by the User, identification and the User's explicit authorization, in accordance with the scope of access and the authorization period presented to the User. The identification and OTP process may be carried out through Feezback. The system will display, to the extent the service supports this, the connection status, the date of consent, the expiration date, the last synchronization and a direct link to Feezback's consent management interface. When the authorization expires or when its renewal is required, the User may be asked to re-approve the connection.
11.1.2 The information may include account details, account identifiers, balances, transactions, liabilities, authorization data and additional financial information that Feezback is authorized to transfer in accordance with the User's authorization.
11.1.3 Access through Feezback is for the purposes of receiving information and presenting it only to the client who connected the account. This information will be marked according to its source and will not be transferred to an Advisor, a family member, an AI provider, an external system, an automation, a webhook, a referral or any other third party, and will not be included in a shared report or export. The client who connected the account is entitled to export the information for themselves using the personal export tool in the system, in the format and to the extent that the system supports. Moneyflow does not request or store bank passwords, and cannot, through this connection, transfer funds, withdraw funds, change standing orders, create a charge or perform any other action in the bank account.
11.1.4 Withdrawing consent, stopping future pulls, disconnecting the connection and deleting information are separate actions. The User will be able to manage the User's consent through the tools available in Moneyflow and through a link to Feezback's consent management interface. Information that has already been imported may be retained in accordance with the Data Deletion Policy, documentation obligations and the provisions of the law. Deletion in Moneyflow does not require deletion at Feezback or at the source entity where there is a lawful retention obligation.
11.2.1 Polywizz is an external information and aggregation provider that provides infrastructure for receiving, pulling or importing insurance and pension information from the source entities. When the User chooses to activate this service, Moneyflow may receive the information through Polywizz, after an action initiated by the User, verification, completion of documents, or the granting of authorization and consent, as required for the service and by law.
11.2.2 The information may include details of policies and products, coverages, premiums, insurance, pension, provident fund, study fund and savings data, documents, identifiers and ancillary information that Polywizz is authorized to transfer. By its nature, this information may be of special sensitivity.
11.2.3 Moneyflow uses the information for the purpose of presentation, organization, analysis, internal comparison and generating insights in the Service. Moneyflow is not an insurance company, an insurance agency or an institutional entity, does not issue any product, and does not undertake that the information reflects the full scope of the User's rights, the terms of the product or its current status.
11.2.4 The User is entitled to revoke an authorization or to request that future pulls be stopped. Information that has already been imported may be retained or deleted in accordance with the Data Deletion Policy, the User's request, documentation obligations and the law.
11.3.1 Information received from the external information and aggregation providers Feezback and Polywizz, or from a source entity, may be partial, delayed, duplicated, outdated or different from the official information held by the bank, the insurance company, the institutional entity or the information provider. To the extent possible, the system may display the date of the last pull or synchronization.
11.3.2 In the event of a conflict, the data and records held by the original entity are determinative. Before making a financial, insurance, pension or professional decision, the information must be verified against an official source or with a licensed professional.
12.1 When a User requests a referral to a professional or to a service, Moneyflow may transfer the contact details and the required information to the receiving party, after obtaining appropriate consent.
12.2 Only information required for handling the referral is to be transferred. The receiving party will be responsible for the information it processes in the course of its professional service and in accordance with its privacy policy.
12.3 Moneyflow may receive status updates and information required for managing the referral, oversight and settlement of accounts.
13.1 Except for information originating from open banking, which is not transferred to third parties, as set out in Section 11.1, we may share other information with:
13.1.1 Cloud, storage, backup, security and infrastructure providers.
13.1.2 Payment, mailing, messaging, analytics and support providers.
13.1.3 AI providers and external integrations that the User has chosen to activate.
13.1.4 Advisors, family members or authorized Users, in accordance with permissions.
13.1.5 Receiving parties in the framework of an approved referral.
13.1.6 Authorities, courts or competent bodies, where there is a legal obligation.
13.1.7 An acquirer, an investor or a party in the framework of a merger, acquisition, restructuring or transfer of operations, subject to continued reasonable protection of the information.
13.2 Service providers are required to use the information for the purpose of the service ordered from them and in accordance with the agreements, security instructions and applicable law.
14.1 Some of the service providers may store or process information outside Israel.
14.2 In such cases, we will act in accordance with applicable law and will use appropriate contractual, organizational or technological measures to protect the information.
15.1 Moneyflow operates technological, organizational and operational measures designed to protect the confidentiality, integrity and availability of the information.
15.2 These measures may include encryption in transit and at rest, permission control, access segregation, logs, monitoring, backups, User authentication, secrets management and handling of security incidents.
15.3 No system is absolutely secure. The User is required to safeguard the User's access credentials and to notify us without delay of a suspicion of unauthorized use or of a security incident.
15.4 In the event of a security incident, we will act in accordance with the procedures and with the reporting obligations that apply to us by law.
16.1 We retain information for as long as it is required for the purpose of the Service, for the purposes described in this Policy, for the purpose of legal protection, security, documentation or compliance with the law. Further details regarding account closure, disconnection of integrations, deletion from active systems, backups and retention exceptions appear in Moneyflow's Data Deletion Policy.
16.2 The retention period varies according to the type of information, the nature of the service, the status of the account, and legal or accounting obligations.
16.3 After the account ends, information may be retained for a transition period for the purpose of export, restoration, handling a dispute or compliance with the law, and thereafter be deleted or undergo an anonymization process, subject to backups and archive systems.
16.4 Aggregated or anonymous data that does not reasonably allow identification may be retained without time limitation for purposes of research, measurement and improvement of the Service.
17.1 Subject to applicable law, a User is entitled to request:
17.1.1 To inspect personal information that is held about the User.
17.1.2 To correct information that is incorrect or not up to date.
17.1.3 To delete information in cases in which there is a right to do so.
17.1.4 To withdraw consent or to object to marketing mailings.
17.1.5 To disconnect integrations and external services.
17.1.6 To receive information or to export it, where the Service allows this or where the law requires it. The client who connected the bank account is entitled to export for themselves information originating from open banking using the personal export tool in the system, in the format and to the extent that the system supports. This information will not be included in an export to an Advisor, a family member, a team member, a receiving party or any other third party.
17.2 Requests can be addressed to support@moneyflow-ai.com. We are entitled to request verification of identity before handling a request.
17.3 Certain rights may be limited where there is a legal obligation to retain information, where the information is required for the protection of rights, or where the request infringes the rights of another person.
18.1 The Company is entitled to send service, security, billing and support messages and material updates relating to the account.
18.2 Marketing messages will be sent in accordance with consent and the law. Consent can be withdrawn by means of an unsubscribe link, the account settings or by contacting us.
18.3 Even after unsubscribing from marketing, we may continue to send essential service messages.
19.1 The Service is intended primarily for Users aged 18 and over.
19.2 Information about a minor will be entered only by a parent, a guardian or a person authorized to do so, and only where this is required for the Service.
19.3 If it becomes apparent to us that information about a minor was collected without appropriate authorization, we will act to delete it or to restrict its use in accordance with the law and the circumstances.
20.1 The Service may include links or connections to external websites and services. Their use is subject to their privacy policies and terms.
20.2 Moneyflow is not responsible for the privacy practices of an external service that is not under its control.
21.1 We are entitled to update this Policy due to a change in the Service, in technology, in the law, in regulation or in the business model.
21.2 In the event of a material change, we will publish a notice through the customary means in the Service. The date of the last update will appear at the top of the document.
22.1 Questions, requests or complaints regarding privacy can be addressed to support@moneyflow-ai.com.
22.2 We will review every inquiry in good faith and will respond within a reasonable time and in accordance with the law.
23.1 This Policy is read together with:
23.1.1 Moneyflow's Terms of Use.
23.1.2 Moneyflow Advisor Use Agreement
23.1.3 Artificial Intelligence Use Policy
23.1.4 Acceptable Use Policy
23.1.5 Information Security Policy
23.1.6 Cookies and Tracking Technologies Policy
23.1.7 Data Deletion Policy
23.1.8 Annexes and privacy notices dedicated to specific services.