LEGAL

Privacy Policy

1. Who is responsible

Funtika LTD (“Funtika”, “we”, “us”), a company registered in Israel, is the controller of the personal data described in this policy. You can reach us at support@monitor2log.com, or at the address published on the site.

Health information is sensitive, so Monitor2Log is built to hold as little of it as possible: your readings live in your own account, you can edit or delete any row, and you can take the whole diary away as a CSV file at any time.

2. What data we process

Account data — the email address, account identifier and basic profile returned by Google when you sign in, held through Firebase Authentication.

Health records — the readings you confirm (such as systolic and diastolic values, pulse and the measurement time) and any note you write. They are stored in Cloud Firestore under your own account. When you use the diary, Firestore also automatically caches the readings you load in this browser's IndexedDB storage on the device. This makes return visits faster and keeps already-loaded readings available during connection interruptions.

Photos — a photo you choose to scan on the website is sent from your browser for processing. If you opt into WhatsApp and send a photo there, Meta notifies our secured Firebase Function, which checks your scan balance before requesting the image from Meta and passes it to Gemini in memory. Monitor2Log does not retain either kind of photo.

Optional WhatsApp data — if you connect WhatsApp, we keep a protected phone-number lookup, an encrypted copy of the number, its last four digits, your reminder times, language, time zone and delivery state. Extracted draft rows from a WhatsApp photo are kept only until you review them or for up to 24 hours.

Subscription records — the PayPal subscription identifier, selected plan, amount, status and billing-period timestamps, kept in a ledger keyed to your account. Card details and PayPal credentials are handled by PayPal and never reach us.

Technical data — the locale preference cookie (m2l-locale), your Firebase authentication session, interface preferences kept in your browser's local storage and in your account profile, and the data your browser sends when it requests a page, such as an IP address, which our hosting and abuse-protection providers process in their logs.

We do not run advertising trackers and we do not use third-party analytics.

3. Why we process it, and on what legal basis

To provide the Service — creating your account, saving and displaying the readings you confirm, drawing your chart, producing your CSV export, and applying and counting scan-plan allowances. Legal basis: performance of our contract with you. Under the GDPR, health data is processed on the basis of your explicit consent, which you give by choosing to record readings in your diary.

To scan a photo — sending the photo you select for the numbers to be extracted. On WhatsApp, sending MONITOR or NOTEBOOK and then a photo requests that scan. Legal basis: your consent; you can avoid scanning and type the reading by hand.

To provide optional WhatsApp reminders and linking — connecting your signed-in account to your number and sending reminders at the times you choose. Legal bases: performance of the service you request and your consent. You can turn reminders off or disconnect WhatsApp at any time.

To take payment and keep accounts — processing purchases through PayPal and keeping the purchase ledger. Legal bases: performance of our contract and our legal obligations under tax and accounting law.

To keep the Service secure — App Check with reCAPTCHA Enterprise, rate limits and abuse prevention. Legal basis: our legitimate interest in protecting the Service, its users and our providers from abuse.

To communicate with you — support replies and notices about material changes. Legal bases: performance of our contract and our legitimate interest in running the Service properly.

4. Who processes data for us

Google LLC and its affiliates — Firebase Authentication (accounts), Cloud Firestore (your readings and notes), Firebase AI Logic with Gemini models (extracting numbers from a photo you submit) and reCAPTCHA Enterprise (App Check abuse protection). A photo is processed by Google under Google's terms; Monitor2Log does not store it.

PayPal — recurring payment processing and subscription management. PayPal handles your payment details as an independent controller under its own privacy policy; we receive the subscription identifier, plan, amount, status and billing-period timestamps.

Netlify — hosting of the website and of the purchase ledger, on infrastructure in the United States.

Meta Platforms — delivery of WhatsApp linking messages, photos, service replies and reminder templates when you opt into the WhatsApp feature. Meta processes WhatsApp traffic under its own terms and privacy policy.

These providers act on our instructions under data-processing terms, except where they act as controllers in their own right, as PayPal does for payments. We do not sell personal data.

5. International transfers

Monitor2Log is operated from Israel and runs on infrastructure provided by Google and Netlify, located in the United States and other countries. Israel is recognised by the European Commission as offering an adequate level of data protection. Transfers to providers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism offered by that provider.

6. How long we keep it

Readings and notes — until you delete them, or until you ask us to delete your account. You can delete any row yourself at any time.

Local browser cache — until the browser evicts or clears it, or until you clear the site data for monitor2log.com in your browser settings. Signing out does not necessarily remove this device copy.

Purchase ledger records — seven years from the transaction, as tax and accounting law requires.

Account and authentication records, including sign-in logs — for as long as your account exists, and after that according to Firebase's default retention periods.

Photos — not stored by us. A WhatsApp photo is held only in function memory while it is processed. Any retention by Meta or Google for the processing they perform is governed by their terms.

WhatsApp draft rows and linking challenges — deleted after completion or expiry; draft rows expire after 24 hours and linking codes after 10 minutes. Encrypted WhatsApp account and reminder settings remain until you disconnect the feature or delete your account.

7. Your rights

You can see and export your readings at any time from the diary, as a CSV file, and you can correct or delete any row yourself.

You can ask us to correct data we hold, to delete your account and its data, to restrict or object to a processing activity, or to withdraw a consent you have given — write to support@monitor2log.com. Withdrawing consent does not affect processing already carried out.

Where the GDPR applies, you also have the right to access your data, to receive it in a portable form and to object to processing based on our legitimate interests.

If you think we have handled your data wrongly, please tell us first so that we can put it right. You can also complain to the Israeli Privacy Protection Authority or, in the EU or EEA, to the supervisory authority of the country where you live or work.

8. Security

Data travels over encrypted connections and is stored by Google with encryption at rest. Firestore security rules restrict your readings to your own account, and Firebase App Check with reCAPTCHA Enterprise blocks requests that do not come from the genuine application. Health data is never written into the purchase ledger, and billing data is never written into your health records. Because loaded readings are also cached on the device, someone who can access the same unlocked device and browser profile may be able to see them.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority where the law requires it.

9. Cookies and local storage

We use a cookie to remember your language choice (m2l-locale), a session managed by Firebase Authentication to keep you signed in, and browser storage for interface preferences. Firestore automatically keeps a local cache of readings loaded in the diary; there is no separate prompt or switch. You can remove that cache by clearing the site data for monitor2log.com in your browser settings. reCAPTCHA Enterprise sets what it needs in order to tell a person from a bot. There are no advertising or analytics cookies.

10. Children

Monitor2Log is not intended for children. You must be at least 16, or the age of digital consent in your country if it is higher. If you believe a child has created an account, write to us and we will delete it.

11. Changes to this policy

We will update this page whenever our processing changes. The date at the top identifies the current version, and we will give notice of material changes on the site or by email.

12. Contact

Funtika LTD, Israel — support@monitor2log.com, or the address published on the site.

This policy is governed by the laws of the State of Israel, and the competent courts of Tel Aviv-Yafo, Israel have exclusive jurisdiction over disputes arising from it. That does not affect your right to complain to a supervisory authority where you live.