This Privacy Policy describes how Codebyte Ltd. ("Codebyte", "we", "us") collects, uses, and protects information when you use Asistry ("Service"). We are committed to protecting your personal data in accordance with applicable law, including the Israeli Protection of Privacy Law, 5741-1981 (as amended, including Amendment 13) and, where applicable, the EU General Data Protection Regulation (GDPR). A Hebrew version of this policy is available here; in case of conflict for matters governed by Israeli law, the Hebrew version prevails.
1. Data we collect
Personal data under Israeli law (post Amendment 13) and the GDPR includes online identifiers such as IP addresses and device identifiers.
| Category | Examples | Why |
|---|---|---|
| Account data | Email, name, OAuth identity | Authentication, communication |
| Usage data | Pages visited, features used, timestamps | Analytics, product improvement (with your consent) |
| Task / content data | Task titles, notes, agent outputs | Deliver the Service |
| Integration tokens | OAuth refresh tokens (encrypted) | Connect third-party services |
| Technical data | IP address, browser type, error logs | Security, debugging |
You are not under a statutory obligation to provide us with personal data. Providing account data is necessary to open and operate an account; without it we cannot provide the Service. All other data is provided at your choice.
2. Legal bases and how we use your data
We process personal data on the following legal bases:
- Performance of contract — provide, operate, and secure the Service; authenticate you; execute agent actions on third-party platforms at your direction; send transactional emails (security alerts, billing receipts)
- Consent — analytics cookies and any marketing cookies (see Section 7); you may withdraw consent at any time, as easily as it was given
- Legitimate interests — error monitoring, fraud prevention, and defending legal claims
- Legal obligation — compliance with tax, accounting, and other statutory duties
We do not sell your personal data to third parties. We do not use your data to train AI models without your explicit consent. We do not carry out automated decision-making that produces legal or similarly significant effects on you.
3. Data storage and security
Your data is stored in Supabase (PostgreSQL) hosted in the EU region. Sensitive credentials (API keys, OAuth refresh tokens) are encrypted at rest using AES-256 via pgcrypto. Access is governed by row-level security policies; each user can only access their own rows.
We use industry-standard transport security (TLS 1.2+) for all data in transit. Regular backups are encrypted and stored separately. We maintain security measures consistent with the Israeli Protection of Privacy (Data Security) Regulations, 5777-2017.
4. Third-party processors
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication | EU |
| Vercel | Application hosting | EU / global edge |
| Vercel Analytics | Usage & performance analytics (only with your consent) | EU / global edge |
| Sentry | Error monitoring and diagnostics | EU / US |
We have data processing agreements in place with our processors. See also Section 6 regarding the Google Gemini API (bring-your-own-key).
5. Google user data and Limited Use
Asistry connects to Google services using OAuth. We request only the read-only Google Calendar scope (calendar.readonly) together with your basic profile (name, email address). We access this Google user data solely to display your calendar events within the Service, at your direction.
Asistry's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell, rent, or otherwise disclose your Google user data to third parties. We share, transfer, or disclose Google user data only:
- to the infrastructure sub-processors listed in Section 4 (Supabase, Vercel) that host and operate the Service on our behalf, under contractual confidentiality and data-protection obligations;
- where required to comply with applicable law or a valid legal request; or
- with your explicit consent.
We do not use Google user data for advertising and we do not transfer it to data brokers or information resellers. We do not use Google user data, or any Google Workspace API data, to develop, improve, or train generalized or non-personalized AI and/or machine-learning models.
6. AI and machine learning
Certain optional features (such as task enrichment, prompt enhancement, and suggestions) use a third-party AI integration: the Google Gemini API. These features operate on a bring-your-own-key basis — they call the Google Gemini API using your own Google API key, which you provide and which is stored encrypted at rest (AES-256).
These AI features process only the dashboard content you enter, such as task titles, descriptions, and prompts. They do not process Google user data obtained through the Google OAuth scopes (including your Google Calendar data). We do not use any Google Workspace API data to develop, improve, or train AI or machine-learning models.
7. Cookies and consent
We use the following categories of cookies and similar technologies:
| Category | Examples | Basis |
|---|---|---|
| Strictly necessary | Supabase session token, consent-choice cookie, security | Always active (required to provide the Service) |
| Analytics | Vercel Analytics (page views, performance) | Your opt-in consent |
| Marketing | None currently in use; category reserved for the future | Your opt-in consent |
On your first visit we ask for your consent via a cookie banner. Analytics and marketing technologies are not loaded until you opt in. You can accept all, reject all, or choose per category, and you can change or withdraw your choice at any time via the "Cookie settings" link in the footer — withdrawing consent is as easy as giving it. Your choice is stored for up to 12 months, after which we ask again. Rejecting optional cookies does not limit your use of the Service.
8. Data retention
We retain your data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or audit purposes (up to 7 years for financial records under Israeli law).
9. Your rights
Subject to applicable law, you have the right to:
- Access / inspection — request a copy of your personal data (Section 13 of the Israeli Protection of Privacy Law; Art. 15 GDPR)
- Rectification / correction — correct inaccurate, incomplete, or outdated data (Section 14 of the Israeli Protection of Privacy Law; Art. 16 GDPR)
- Erasure — request deletion of your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Restriction — request restriction of processing in certain circumstances
- Withdrawal of consent — withdraw any consent at any time, as easily as it was given, without affecting processing before withdrawal
To exercise any right, email privacy@asistry.com. We will respond within 30 days. If you are in Israel and we do not respond within 30 days, you may apply to the Magistrate's Court under the Protection of Privacy Law. You also have the right to lodge a complaint with the Israeli Privacy Protection Authority or, if you are in the EEA, with your local supervisory authority.
10. International transfers
If you are in the EEA, your data may be transferred to and processed in countries outside the EEA. We ensure appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions) for all such transfers.
Transfers of personal data from Israel to other countries are made in accordance with the Israeli Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001 — to countries providing an adequate level of protection (including the EEA, which Israel benefits from an EU adequacy decision with), or subject to contractual safeguards or your consent.
11. Data breach notification
In the event of a personal data breach, we will act in accordance with applicable law: we will notify the Israeli Privacy Protection Authority of a reportable breach within 72 hours of discovery (and, where GDPR applies, the competent supervisory authority within 72 hours), and we will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, including the nature of the breach and the steps they can take to protect themselves.
12. Children
The Service is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or in-app notice before they take effect.
14. Contact
Data Controller: Codebyte Ltd., Israel
privacy@asistry.com