We use a pseudonymous per-install identifier (a UUID stored in your iOS keychain) so the app works without forcing you to create an account. This is pseudonymous personal data, not anonymous — see below.
When you chat with Faben, your messages are forwarded to Anthropic (Claude). We ask you in-app, the first time, before any message is sent. Anthropic does not train on API content.
We do not store the text of your Faben Chat messages on our backend. Our server logs token-count metadata and content-free quality/safety metrics (for example model, input tokens, output tokens, cost, latency, tool-use counts, hashed user key, and safety flags) for billing, abuse protection, reliability, and AI quality monitoring.
We collect trip plans, preferences, and (with permission) location only to make the app work. Faben only requests "When in use" location — never background tracking.
We use PostHog (US Cloud) for pseudonymous product analytics, crash reports, and masked session replay (text inputs and images are masked on-device; recordings kept 30 days), plus standard server logs (kept 90 days). We do not use any third-party advertising or cross-app tracking SDK.
You can delete your account and all associated data inside the app: Profile → Delete Account. We do not sell your data, run ads, use third-party trackers, or train AI on what you put in the app.
Faben is built by FABEN, an unincorporated partnership between Ohad Nissim and Or Leon, both based in Israel.
We are the joint controllers of your personal data under
GDPR Article 26 and the Israeli Privacy Protection Law, 5741-1981.
We publish the Faben iOS app and operate the faben.co.il website and the
api.faben.co.il backend that powers the app.
EU representative (GDPR Article 27). Faben does not currently target users in the
European Economic Area or the United Kingdom. We have not appointed an EU representative under
GDPR Article 27 because we believe our processing falls under the exemption in Article 27(2)(a) —
it is occasional, not on a large scale, does not involve Article 9 or Article 10 categories of data
on a large scale, and is unlikely to result in a risk to the rights and freedoms of data subjects.
We will reassess this if our processing or audience changes, and we will update this notice when
an appointment is made. If you are an EU or UK resident and would like to exercise your data
rights, please contact hello@faben.co.il and we will
respond within the statutory timelines.
Contact: hello@faben.co.il — we read all mail at this address (privacy, legal, safety, general).
2. What this policy covers
This policy applies to:
The Faben iOS app (bundle il.faben.app, Apple ID 6775216680).
The backend at api.faben.co.il that the app talks to.
It does not cover other apps or services that happen to link to ours.
3. Your pseudonymous identifier
We use a pseudonymous per-install identifier — a random UUID generated on first launch and stored in your
iOS keychain. This identifier is pseudonymous personal data under GDPR, CCPA, and the Israeli Privacy
Protection Law, because it is consistently tied to your trips, chats, and crash logs even though it is not your
name or email.
Calling it "anonymous" would be misleading: the identifier persists across app launches, lets us tie your activity together
across sessions, and is also used as the user-identifier tag on crash reports. We treat it the way the law requires — as
personal data — and you have the same access, correction, deletion, and export rights over it that you would have over an
account tied to your email.
If you choose to use Sign in with Apple, we additionally receive your name (if you choose to share it) and
either your real email or Apple's private relay email. Apple sign-in is optional. Without it, your pseudonymous identifier
is the only key we have for your data.
4. Data we collect
For each kind of data, we say what it is, why we have it,
where it goes, and how long we keep it.
a. Pseudonymous device identifier Required
What
A random UUID created on first launch and stored in the iOS keychain on your device. It is not linked to your Apple ID, your email address, your phone number, or any advertising identifier (we do not request IDFA).
Why
So the app works without forcing you to create an account. Every request to api.faben.co.il carries this identifier so we can return your trips and preferences and apply per-user rate limits.
Where
Stored in your device keychain and on our backend (Israel).
Kept
Until you delete your account inside the app (Profile → Delete Account) or uninstall and reset the device keychain.
b. Sign in with Apple Optional
What
If you choose to sign in, we receive your name (only if you choose to share it) and either your real email or Apple's private relay email. We do not see your Apple password.
Why
To let you use Faben across more than one device with the same data, and to recover your account if you change phones.
Where
Our backend (Israel). The Apple authentication step itself happens with Apple.
Kept
Until you delete your account (Profile → Delete Account) or email hello@faben.co.il.
c. Faben Chat — messages and replies Functional
What
The text you type into Faben Chat and the model's replies.
Why
So Faben can answer your travel questions in real time.
Where
The app sends your message to our backend, which immediately forwards the message — together with any conversation context the model needs — to Anthropic (Claude). Anthropic returns a reply that is passed back to your device.
Stored on our backend
We do not store the text of your messages or the model's replies on our backend. Once a reply has been delivered, we log only token-usage and content-free quality metadata: the model name, the count of input tokens, the count of output tokens, estimated cost, latency, tool-use counts, content-free safety/quality flags, a hashed or pseudonymous user key, and a timestamp. We use this metadata for billing reconciliation, per-user daily budget enforcement, abuse protection, reliability monitoring, and AI quality monitoring. We do not log the content.
Stored at Anthropic
Per Anthropic's API terms, Anthropic does not train its models on API content. Anthropic may retain inputs and outputs for up to 30 days for trust-and-safety review and then deletes them. See Anthropic's privacy and usage policies for details.
Stored on your device
Your recent chat history is kept on your device so the conversation has memory across screens. You can clear chat history from inside the app.
d. Trips and itineraries Functional
What
The trips you build in the app: destinations, dates, day-by-day plans, places you saved, and notes you wrote.
Why
So your saved trips show up in your Journal and in Trip Mode while you're traveling.
Where
Our backend (Israel). Tied to your pseudonymous device identifier (and Apple account if you signed in).
Kept
Until you delete the trip from inside the app, or delete your account.
e. My Info preferences Functional
What
Diet (e.g. vegetarian), allergies (e.g. peanuts), and accessibility needs (e.g. step-free) — only what you choose to enter.
Why
So Faben can suggest places and trips that fit. We don't infer any of these — we use only what you tell us.
Where
Our backend (Israel).
Kept
Until you change or clear them, or delete your account.
f. Product analytics, crash reports & session replay (PostHog) Diagnostics
What
We use PostHog for three things, all tied to your pseudonymous device identifier (never your name):
Pseudonymous usage events — which screens you open and which features you tap, so we can understand how the app is used and what to improve.
Crash reports — if the app crashes, a report with your device model, iOS version, your pseudonymous device identifier, and the technical stack trace at the moment of the crash, so we can fix the bug.
Session replay — a reconstructed recording of your interactions with the app's screens (taps and navigation) so we can diagnose confusing or broken flows. All text inputs and all images are masked before anything leaves your device, so the recording never captures what you typed, your photos, or any sensitive on-screen content — only the structure of the screen and where you interacted.
Why
So we can find and fix bugs, see where people get stuck, and improve the app's usability — never to advertise to you.
Where
PostHog Cloud (United States). We do not link any of this to advertising profiles, and PostHog does not train AI models on it. We do not bundle any third-party marketing or ad-attribution SDK.
Kept
Session recordings are retained for 30 days, then deleted. Usage events and crash reports are kept only as long as needed to diagnose and fix issues, and are deleted when you delete your account.
g. Standard server logs Operational
What
Standard web/server logs: the IP address the request came from, the user-agent string, the path requested, the response status, and a timestamp.
Why
To run the service, debug problems, and protect against abuse (e.g. rate-limiting brute-force attempts).
Where
Our backend hosting (Israel).
Kept
90 days, then deleted.
5. AI consent
Before your first Faben Chat message is sent to Anthropic, the app asks for your consent.
The consent dialog explains, in plain English, that your message will leave Faben and be forwarded to Anthropic
(Claude) to generate a reply, and that Anthropic does not train its models on that content.
You can revoke consent at any time from Profile → Settings → Faben Chat. After
revocation:
Faben Chat is disabled on your account — no new messages can be sent to Anthropic.
Your existing chat history is deleted from your device, and any in-flight token-usage metadata referencing your account is purged from our backend within 30 days.
Consent is required only for Faben Chat. Refusing or revoking it does not affect any other Faben feature
(trip planning, journal, map, profile, etc.).
6. Location
Faben only requests "When in Use" location authorization. We never request "Always" authorization,
and the iOS background-location entitlement has been removed from the app. That means iOS will not give Faben
location updates while the app is closed or in the background — only while you are actively using the app.
How the data flows:
You grant the "When in Use" permission in iOS, the first time a feature needs it.
Your device asks Apple's location services for the current coordinates.
The app passes rough coordinates to our backend as a query parameter on requests that need them — for example, the "near me" places query.
Our backend uses the coordinates to look up places near you and returns the results.
Our backend logs the fact that a "near me" query happened (timestamp, user, response status) but does not retain the precise latitude / longitude beyond the active request.
We do not build a continuous location history of you. We do not sell location data, and we do not share it with advertising networks.
You can revoke the location permission at any time in iOS Settings → Faben → Location. Faben features that
need location (such as "what's near me") will then ask again, or fall back to a manual search.
7. Third parties we share data with
We share the minimum data each third party needs to do its job. We do not give any of them permission to use your data for their own marketing.
Anthropic
Receives the text of your Faben Chat messages so Claude can generate a reply. Does not train on API content.
Hosted on PostHog Cloud (United States). Receives pseudonymous usage events, crash reports (device model, iOS version, pseudonymous device identifier, stack trace), and masked session recordings (text inputs and images are masked on-device before sending). Not used for advertising, and PostHog does not train AI models on it.
Google Places API
Receives place-search queries from our backend (not your identity) so we can show real venues.
Apple
Handles Sign in with Apple if you choose it, and runs the App Store, push notifications, and iOS itself.
8. What we do not do
We do not sell, rent, or trade your personal data — ever.
We do not run ads, and there are no ad networks in the app.
We do use PostHog for first-party product analytics, crash reporting, and masked session replay — to understand and improve the app, never for advertising. We do not bundle Facebook Pixel, AppsFlyer, ad networks, or any cross-app advertising-tracking SDK.
We do not request the iOS background-location entitlement, and we never ask for "Always" location authorization.
We do not share your data with data brokers.
We do not train any AI model on your chats, trips, or preferences. Anthropic does not train its models on Faben Chat content.
We do not track you across other apps or websites for advertising.
9. Your rights
No matter where you live, you can:
Delete your account and all associated data from within the Faben app: Profile → Delete Account. This is the fastest path — it removes your trips, preferences, chat usage records, and pseudonymous identifier from our backend.
Access a copy of the data we hold about you.
Correct data that is wrong.
Export (port) your data in a machine-readable format.
Withdraw consent for any optional processing — for example, revoke Faben Chat consent from Profile → Settings → Faben Chat, revoke the iOS location permission, or unlink Sign in with Apple.
To exercise any of these without using the in-app flow, email hello@faben.co.il
from the email tied to your Apple sign-in, or include your pseudonymous device identifier
(Profile → About → Device ID inside the app) so we can find your data. We aim to respond within 30 days.
Regional notes. Where applicable, we align our practices with the EU
GDPR (including the right to lodge a complaint with your local supervisory authority), the
California CCPA / CPRA (we do not sell or share personal information as defined in the CCPA),
and the Israeli Privacy Protection Law, 5741-1981.
10. Children
Faben is not directed at children. To use the app you must be at least 13
(the Apple minimum). If you are in the European Economic Area, GDPR Article 8 sets the digital-
consent age between 13 and 16 depending on your member state; you must meet
whichever age applies where you live, or have parental consent. We do not knowingly collect data
from anyone below those ages. If you believe a child has used the app, email
hello@faben.co.il and we will delete the data.
11. International data transfers
We are based in Israel and our backend runs in Israel. Some of our third-party processors — notably
Anthropic, PostHog, Google Places, and Apple — operate in the United States and other regions.
As a result, your data may be processed in Israel and the United States (and other regions
where those processors operate).
Where required by law (for example, transfers from the EEA or the UK), we rely on the relevant
legal transfer mechanism for the destination — for example, the European Commission's adequacy
decision for Israel for data we process on our own backend, and Standard Contractual Clauses (or
an equivalent mechanism made available by the processor) for transfers to processors in the
United States and other regions.
12. Changes to this policy
We will update this page if our practices change. The "Last updated" date at the top will
always reflect the most recent change. If a change is material (for example, a new category
of data or a new third party), we will also notify you inside the app before it takes effect.
13. Contact
Privacy questions, requests, or complaints — write to
hello@faben.co.il (we read all mail at this address).
FABEN
an unincorporated partnership of Ohad Nissim and Or Leon
Israel
Postal address available on request faben.co.il