מדיניות פרטיות
עודכן לאחרונה: 2026-07-12
דיבור היא אפליקציה לתרגול היגוי (הגייה נכונה) לילדים בעברית, בשימוש הורי ולרוב בליווי קלינאי/ת תקשורת. אנחנו מתייחסים לפרטיות הילד שלכם ברצינות רבה ובונים את האפליקציה לפי הסטנדרטים הקפדניים ביותר לאפליקציות לילדים: PPL תיקון 13 (ישראל), GDPR-K (האיחוד האירופי), ו-COPPA (ארה״ב). המסמך הזה מסביר בשפה פשוטה איזה מידע אנחנו אוספים, למה, וכיצד אתם — ההורים — שולטים בו.
מי אנחנו
דיבור מופעלת על-ידי צוות דיבור. ניתן ליצור איתנו קשר בנושאי פרטיות בכתובת dor362@gmail.com.
מה זה דיבור ומי יכול להירשם
דיבור עוזרת לילדים לתרגל הגייה נכונה של צלילי השפה העברית באמצעות תרגול קולי — הילד מבטא צלילים ומילים, והאפליקציה מלווה אותו במסלול תרגול. במסלול הקליני, קלינאי/ת תקשורת מזמין/ה את ההורה ומלווה את ההתקדמות.
קיימים שני סוגי חשבון, לפי הפלטפורמה, ושניהם לבגירים בלבד. הורים נרשמים באפליקציה לנייד ויוצרים פרופיל עבור הילד — הילד עצמו אינו יוצר חשבון ואינו מזין פרטי התקשרות. קלינאי/ת תקשורת נרשמ/ת באתר האינטרנט ופותח/ת חשבון מקצועי לניהול המטופלים.
איזה מידע אנחנו אוספים
מההורה: כתובת אימייל לצורך אימות, וחותמת זמן + גרסה של ההסכמות שאישרתם.
על הילד (יוצר על-ידכם): שם פרטי או כינוי שאתם בוחרים (לא שם משפחה), חודש ושנת לידה לצורך התאמת רמת התרגול (לא היום המדויק של הלידה), ובחירת דמות מתוך אסט מוכן.
הקלטות קוליות של ניסיונות ההגייה של הילד — נאספות ונשמרות רק עם הסכמתכם המפורשת, כדי שקלינאי/ת התקשורת תוכל לבחון את ההגייה. מוסבר בנפרד בסעיף "הקלטות קוליות של הילד" למטה.
אם הילד שולח בקשה למשחק חדש — טקסט מסונן של הבקשה בלבד (ללא אודיו). מוסבר בנפרד בסעיף "בקשות למשחקים חדשים" למטה.
במהלך התרגול: התקדמות, רמות, השלמות ופרקי זמן של שימוש.
הקלטות קוליות של הילד
התרגול מבקש מהילד לבטא צלילים ומילים, ולשם כך האפליקציה מקליטה קטעי אודיו קצרים של ההגייה.
עם הסכמתכם — הניתנת בעת אישור ההזמנה של קלינאי/ת התקשורת, וניתנת לניהול ולביטול בכל עת ב"אזור הורים" שבאפליקציה — אנו שומרים את ההקלטות כדי שקלינאי/ת התקשורת המלווה את הילד תוכל להאזין ולהעריך את ההגייה.
ההקלטות מוצפנות (AES-256-GCM) לפני שמירה ונשמרות במאגר פרטי ומוגן-גישה הממוקם באיחוד האירופי. רק אתם וקלינאי/ת התקשורת המשויך/ת לילד יכולים לגשת אליהן — דרך השרת שלנו, אף פעם לא דרך קישור ציבורי.
ההקלטות נשמרות עד 180 יום ואז נמחקות אוטומטית. תוכלו למחוק אותן מוקדם יותר, או לבטל את ההסכמה להקלטה, בכל רגע ב"אזור הורים".
בנפרד ובאופן אופציונלי (כבוי כברירת מחדל), תוכלו לאשר שימוש בהקלטות לשיפור מנוע זיהוי הדיבור שלנו. הקלטות שאישרתם לשימוש זה נשמרות מעבר ל-180 יום — למשך הזמן הדרוש לפיתוח ולשיפור המנוע — ואינן נמחקות אוטומטית בתום 180 יום. הן נשארות בשליטתכם המלאה: ניתן לחזור מההסכמה בכל עת (הביטול חל גם על הקלטות שכבר נשמרו ומסיר אותן משימוש עתידי), ולמחוק הקלטה בודדת או את החשבון כולו — ואז הן נמחקות לחלוטין.
חשוב: קול הילד מעובד אך ורק על-ידי שירות ניקוד הדיבור שלנו (המתארח באיחוד האירופי) ונשמר אך ורק במאגר שלנו באיחוד האירופי. הוא אינו נשלח לעולם ל-OpenAI, ל-ElevenLabs, ל-Anthropic, לספקי אנליטיקה או לכל צד שלישי אחר. הפקת ההקראות הקוליות של האפליקציה מתבצעת באמצעות ספקי TTS בענן (OpenAI / ElevenLabs, הפועלים באיחוד האירופי/ארה״ב) — רק טקסט ההנחיה נשלח אליהם, לעולם לא קול הילד.
בקשות למשחקים חדשים
באפליקציה הילד יכול (בעזרת ההורה) לבקש משחק חדש על-ידי הקלטת תיאור קצר. אנו ממירים את ההקלטה לטקסט מיד, מסננים ממנו פרטים אישיים (שמות, אימיילים וכדומה), ומוחקים את האודיו — לא נשמר שום קובץ קול. הטקסט המסונן נשמר מוצפן (AES-256-GCM) במאגר שלנו באיחוד האירופי ומשמש אך ורק כדי שנשקול לבנות את המשחק. הוא נשמר עד מחיקת החשבון, וניתן לבטל את התכונה ולמחוק את הבקשות בכל עת ב"אזור הורים".
המסלול הקליני — מידע על הקלינאי/ת
אם את/ה קלינאי/ת תקשורת שנרשמ/ת לדיבור באתר, אנו אוספים ממך: שם מלא, מספר טלפון, מקום עבודה או קליניקה, כתובת אימייל לאימות, וחותמת זמן + גרסה של ההסכמה לתנאים ולמדיניות. פרטים אלה נדרשים לניהול החשבון המקצועי ולתקשורת איתך. הם מתייחסים אליך כבגיר/ה מקצועי/ת — לא לילד — ולכן אינם כפופים למגבלות איסוף המידע על ילדים שבמסמך זה.
ביחס למטופלים שלך: את/ה מזמין/ה את ההורה, וההורה הוא הנותן את ההסכמה לאיסוף ולשמירת הקלטות הילד. אנחנו מעבדים את נתוני המטופל בהתאם להסכמה זו וכדי לספק לך את השירות; נתוני הילד וההקלטות מוגנים בכל האמצעים המתוארים בסעיפים שלמעלה. את/ה מתחייב/ת להשתמש בגישה למטופלים אך ורק למטרות קליניות ולשמור על סודיות מקצועית.
המסלול הקליני פועל באתר אינטרנט, ולכן אנו מפעילים בו הקלטת סשן ואנליטיקת מוצר (PostHog, באיחוד האירופי) לשיפור הממשק. שדות קלט ופרטים מזהים של מטופלים מוסתרים (masked) בהקלטה, והסשן מזוהה עם האימייל המקצועי שלך לצורך תמיכה וניתוח שימוש. זוהי אנליטיקה של שימוש מקצועי בלבד — קול הילד, ההקלטות והתמלילים לעולם אינם נשלחים אליה.
מה אנחנו לא אוספים על הילד ועל ההורה — לעולם
על הילד: שם משפחה, כתובת, מספר טלפון, אימייל, או היום המדויק של תאריך הלידה (אנחנו אוספים רק חודש ושנה).
אנחנו לא מציגים פרסומות, לא משדרים אף נתון לרשתות פרסום, ולא מוכרים מידע לאף גורם.
עם מי אנחנו חולקים את המידע
אנחנו לא מוכרים ולא משדרים את המידע לאף אחד. כדי להפעיל את השירות אנחנו נעזרים בספקי תשתית מוסמכים שמעבדים נתונים בשמנו, תחת הסכמי עיבוד נתונים (DPA):
• Supabase (בסיס נתונים ואחסון, באיחוד האירופי) — שומר את נתוני החשבון, פרופילי הילדים, ואת ההקלטות המוצפנות.
• Render (אירוח, באיחוד האירופי) — מארח את השרת שלנו ואת שירות ניקוד הדיבור הפנימי שלנו.
• Anthropic (Claude) — מעבד טקסט בלבד (למשל יצירה והערכה של תוכן תרגול וסינון פרטים אישיים מטקסט). אינו מקבל את ההקלטות הקוליות של הילד, ואינו משמש לאימון המודלים שלו.
• OpenAI ו-ElevenLabs (הקראה קולית, באיחוד האירופי/ארה״ב) — מקבלים אך ורק את טקסט ההנחיה כדי להפיק את ההקראות הקוליות של האפליקציה. אינם מקבלים את קול הילד או את ההקלטות שלו.
אנליטיקת מוצר (PostHog, באיחוד האירופי) פועלת באתר האינטרנט בלבד ומקבלת רק מזהים אנונימיים ומטא-דאטה של שימוש — לעולם לא את שם הילד, אימייל של הורה או ילד, תמלילים, או אודיו. סשן של קלינאי/ת מזוהה עם האימייל המקצועי שלו (ראו "המסלול הקליני" למעלה). אפליקציית ה-iOS אינה כוללת כל ערכת אנליטיקה של צד שלישי.
כל הספקים ממוקמים בארה״ב או באיחוד האירופי ופועלים תחת SCC (Standard Contractual Clauses) להעברת מידע בינלאומית.
כמה זמן אנחנו שומרים מידע
נתוני חשבון ופרופיל ילד: עד שתמחקו את החשבון.
נתוני חשבון קלינאי/ת (שם, טלפון, מקום עבודה, אימייל): עד מחיקת החשבון.
הקלטות קוליות: עד 180 יום, ואז נמחקות אוטומטית (או מוקדם יותר לפי בקשתכם / ביטול הסכמה).
הקלטות שאישרתם לשימוש לשיפור המודל: נשמרות מעבר ל-180 יום, למשך הזמן הדרוש לפיתוח המנוע, עד שתחזרו מההסכמה או תמחקו אותן / את החשבון.
בקשות למשחקים חדשים (אם הסכמתם): עד מחיקת החשבון.
נתוני תרגול והתקדמות: עד מחיקת החשבון.
אנליטיקת מוצר (באתר בלבד): עד שנה אחת לפי מדיניות PostHog, או עד מחיקת החשבון — המוקדם מביניהם.
בעת מחיקת החשבון, כל הנתונים נמחקים יחד — הילדים, ההתקדמות, ההקלטות וההיסטוריה — בקסקדה אחת.
הזכויות שלכם
לעיון: ניתן להוריד את כל מה שאנחנו יודעים על החשבון כקובץ JSON מההגדרות.
למחיקה: ניתן למחוק הקלטה בודדת, בקשת משחק, את כל ההקלטות, או את כל החשבון, מ"אזור הורים" / ההגדרות.
לביטול הסכמה להקלטה: כפתור ייעודי ב"אזור הורים"; מאותו רגע לא נשמרות הקלטות חדשות.
לביטול השימוש בהקלטות לשיפור המודל: ניתן לחזור בכם בכל עת, והביטול חל גם על הקלטות קיימות.
לתיקון: עריכת שם הילד, חודש ושנת הלידה, או הדמות — בהגדרות.
לשאלות נוספות: dor362@gmail.com.
אבטחה
אנחנו מצפינים את כל החיבורים (HTTPS/TLS). בסיס הנתונים מצפין נתונים ב-rest, וההקלטות מוצפנות בנוסף ברמת היישום (AES-256-GCM) לפני העלאתן — כך שאפילו דליפת מאגר ללא מפתח ההצפנה לא תחשוף את האודיו. הגישה ל"אזור הורים" מוגנת ב"שער הורים" (חידת מתמטיקה) כדי שילדים לא ייכנסו בטעות.
אף מערכת אינה מאובטחת ב-100%. במקרה של דליפה, ניצור אתכם קשר במייל ונדווח לרשויות כנדרש (תוך 72 שעות תחת GDPR; באופן דומה תחת PPL תיקון 13).
עוגיות ומזהים מתמשכים
אנחנו משתמשים רק במזהי אימות הכרחיים (טוקן הסשן של Supabase) ובאחסון מקומי לזכירת העדפות. אין עוגיות מעקב, אין פיקסלים של פרסום, ואפליקציית ה-iOS אינה כוללת ערכת אנליטיקה של צד שלישי.
פרטיות ילדים
דיבור נבנתה לילדים. אנחנו אוספים את המינימום ההכרחי, מבקשים הסכמת הורה מאומתת לפני איסוף מידע מהילד (כולל הקלטות), ומאפשרים לכם לעיין, למחוק ולבטל הסכמה בכל עת — בהתאם ל-COPPA, GDPR-K ו-PPL תיקון 13.
שינויים במדיניות
אם נשנה את המדיניות בצורה שמשפיעה על איזה מידע אנחנו אוספים או איך אנחנו משתמשים בו — נבקש מההורים הסכמה מחודשת לפני שהשינוי יחול. שינויים פחות מהותיים יפורסמו כאן עם תאריך עדכון חדש.
Privacy Policy
Last updated: 2026-07-12
Dibur is a Hebrew articulation (pronunciation) practice app for children, used by parents and usually alongside a speech-language clinician. We take your child's privacy seriously and build the app to the strictest standards for children's apps: PPL Amendment 13 (Israel), GDPR-K (EU), and COPPA (US). This notice explains in plain language what we collect, why, and how you — the parent — control it.
Who we are
Dibur is operated by the Dibur team. For privacy questions, contact us at dor362@gmail.com.
What Dibur is and who can sign up
Dibur helps children practice correct pronunciation of Hebrew speech sounds through spoken practice — the child says sounds and words, and the app guides them through a practice path. In the clinical track, a speech-language clinician invites the parent and follows the child's progress.
There are two account types, by platform, both for adults only. Parents sign up in the mobile app and create a profile for the child — the child does not create an account or enter any contact details. Speech-language clinicians sign up on the website and open a professional account to manage their patients.
What we collect
From the parent: an email address for authentication, and a timestamp + version of the consents you accepted.
About the child (created by you): a first name or nickname you choose (not a last name), a birth month and year to match the practice level (not the exact day of birth), and an avatar from a preset palette.
Voice recordings of your child's pronunciation attempts — collected and stored only with your explicit consent, so the speech-language clinician can review pronunciation. See the dedicated "Your child's voice recordings" section below.
If the child submits a new-game request — scrubbed text of the request only (no audio). See the dedicated "New-game requests" section below.
During practice: progress, levels, completions, and usage timestamps.
Your child's voice recordings
Practice asks the child to pronounce sounds and words, so the app records short audio clips of their attempts.
With your consent — given when you accept the speech clinician's invitation, and manageable and revocable anytime in the in-app "Parent Area" — we store these recordings so the clinician supporting your child can listen and assess pronunciation.
Recordings are encrypted (AES-256-GCM) before storage and held in a private, access-controlled database located in the EU. Only you and your child's assigned clinician can access them — via our server, never through a public link.
Recordings are kept for up to 180 days, then automatically deleted. You can delete them sooner, or revoke recording consent, anytime in the Parent Area.
Separately and optionally (off by default), you may allow recordings to be used to improve our speech-recognition model. Recordings you allow for this purpose are kept beyond 180 days — for as long as needed to develop and improve the model — and are not auto-deleted at 180 days. They stay fully under your control: you can withdraw anytime (withdrawal also applies to recordings already stored and removes them from future use), and you can delete a single recording or your whole account, which erases them entirely.
Important: your child's voice is processed only by our own speech-scoring service (hosted in the EU) and stored only in our own EU database. It is never sent to OpenAI, ElevenLabs, Anthropic, analytics providers, or any other third party. The app's spoken prompts are generated by cloud TTS providers (OpenAI / ElevenLabs, operating in the EU/US) — only the prompt text is sent to them, never the child's voice.
New-game requests
In the app, your child (with your help) can request a new game by recording a short description. We convert the recording to text immediately, scrub personal details from it (names, emails, etc.), and discard the audio — no voice file is kept. The scrubbed text is stored encrypted (AES-256-GCM) in our EU database and used only so we can consider building the game. It is kept until you delete your account, and you can disable the feature and delete the requests anytime in the Parent Area.
Clinical track — clinician account data
If you are a speech-language clinician who signs up on the website, we collect from you: full name, phone number, workplace or clinic, an email address for authentication, and a timestamp + version of your acceptance of the Terms and this Policy. These are needed to run your professional account and to contact you. They concern you as a professional adult — not a child — and so are not subject to the children's-data collection limits described in this document.
Regarding your patients: you invite the parent, and it is the parent who consents to collecting and storing the child's recordings. We process patient data under that consent and to provide you the service; the child's data and recordings are protected by all the measures described in the sections above. You undertake to use patient access solely for clinical purposes and to maintain professional confidentiality.
The clinical track runs on a website, so we operate session recording and product analytics (PostHog, EU) there to improve the interface. Patient input fields and identifying details are masked in the recording, and the session is identified by your professional email for support and usage analysis. This is professional-usage analytics only — the child's voice, recordings, and transcripts are never sent to it.
What we never collect about the child or parent
About the child: last name, address, phone number, email, or the exact day of birth (we collect only birth month and year).
We do not show ads, do not transmit data to any ad network, and do not sell information to anyone.
Who we share data with
We do not sell or transmit your data to anyone. To run the service we use certified infrastructure providers that process data on our behalf under data-processing agreements (DPAs):
• Supabase (database + storage, EU) — stores account data, kid profiles, and the encrypted recordings.
• Render (hosting, EU) — hosts our server and our in-house speech-scoring service.
• Anthropic (Claude) — processes text only (e.g. generating/evaluating practice content and scrubbing personal details from text). It never receives your child's voice recordings and is not used to train its models.
• OpenAI and ElevenLabs (text-to-speech, EU/US) — receive only the prompt text in order to generate the app's spoken prompts. They never receive your child's voice or recordings.
Product analytics (PostHog, EU) runs on the website only and receives only anonymous identifiers and usage metadata — never a child's name, a parent's or child's email, transcripts, or audio. A clinician's session is identified by their professional email (see "Clinical track" above). The iOS app contains no third-party analytics SDK.
All providers are located in the US or EU and operate under Standard Contractual Clauses (SCC) for international data transfer.
How long we keep data
Account and kid-profile data: until you delete the account.
Clinician account data (name, phone, workplace, email): until account deletion.
Voice recordings: up to 180 days, then auto-deleted (or sooner on your request / consent revocation).
Recordings you allowed for model improvement: kept beyond 180 days, for as long as needed to develop the model, until you withdraw consent or delete them / your account.
New-game requests (if you consented): until account deletion.
Practice and progress data: until account deletion.
Product analytics (website only): up to one year per PostHog's policy, or until you delete your account — whichever is sooner.
When you delete the account, all data is wiped together — kids, progress, recordings, and history — in a single cascade.
Your rights
Access: download everything we know about your account as a JSON file from Settings.
Delete: delete a single recording, a new-game request, all recordings, or the whole account, from the Parent Area / Settings.
Revoke recording consent: a dedicated control in the Parent Area; from that moment, no new recordings are stored.
Withdraw model-improvement use: you can withdraw anytime, and it also applies to existing recordings.
Correct: edit your child's name, birth month/year, or avatar in Settings.
Other questions: dor362@gmail.com.
Security
All connections are encrypted (HTTPS/TLS). The database encrypts data at rest, and recordings are additionally encrypted at the application level (AES-256-GCM) before upload — so even a database leak without the encryption key would not expose the audio. Access to the Parent Area is protected by a "parent gate" (a math puzzle) so kids don't enter by accident.
No system is 100% secure. In the event of a breach, we will contact you by email and report to authorities as required (within 72 hours under GDPR; similarly under PPL Amendment 13).
Cookies and persistent identifiers
We only use essential auth identifiers (the Supabase session token) and local storage to remember preferences. No tracking cookies, no advertising pixels, and the iOS app includes no third-party analytics SDK.
Children's privacy
Dibur is built for children. We collect the minimum necessary, obtain verifiable parental consent before collecting any information from the child (including recordings), and let you access, delete, and revoke consent anytime — in line with COPPA, GDPR-K, and PPL Amendment 13.
Changes to this policy
If we change the policy in a way that affects what we collect or how we use it, we'll re-request parental consent before the change applies. Less material changes will be published here with a new updated date.