Skip to content
Back to Home

Privacy Policy

Last updated: October 2, 2026

1. Introduction

This Privacy Policy explains how Huzim ("we", "our", "us") handles personal information when you use our public-beta legal document platform. It describes the beta as currently deployed; features that are disabled are identified below and do not receive your data through Huzim.

2. Data We Collect

We collect account information such as your name, email address, a password hash when you create a password, preferred language, and verification and policy-acceptance records. If you choose Google sign-in, Google provides your name, verified email address, and stable Google account identifier; Huzim stores the provider account link and those identity data for your Huzim account. We also collect identity and contact details you choose to save; answers and document content entered in the contract wizard; generated private documents and PDFs; contract-deadline labels, dates, status and reminder schedules; authentication and administrative MFA data; and limited technical, security, reminder-delivery, and audit records such as request identifiers, IP or proxy information, browser details, timestamps, and actions taken. We do not collect card details in the initial beta.

3. How We Use Your Data

We use this information to create and privately deliver documents, save your progress, operate the contract-lifecycle workspace and deliver deadline reminders, operate and secure accounts, enforce limits, diagnose failures, send verification, recovery, and service emails, respond to support or privacy requests, and meet applicable legal obligations. We use Google identity data only to create or link, authenticate, secure, and recover your Huzim account. We do not use Google identity data for advertising, selling or brokering data, credit decisions, or training AI models. In the initial beta we do not use your documents for payment processing, AI contract analysis, e-signatures, or public sharing because those features are disabled.

Sensitive Information in Document Answers

Some templates ask for information that may be sensitive. Preparation notes for an enduring power of attorney may include your health, medical-treatment, and personal-care wishes; a will may include family relationships, heirs, and details of your property and estate; an employment contract may include salary and other pay terms. Answers can also include personal details of other people named in the document, such as relatives, an employee, an agent, or witnesses. Enter only what your document needs. Huzim uses these answers only for your document: to save your progress, show your answers for review, generate the document text and PDF, deliver the document privately to you, and send any deadline reminders for dates in it. Administrator access to a document’s content is recorded in an audit log. These answers are excluded from the optional beta research events, and because payments, AI analysis, e-signatures, and public sharing are disabled, they are not sent to providers for those features. The protections in this policy apply to them in full: wizard answers and rendered documents are protected with the versioned AES-256-GCM field encryption described in section 4, generated files are kept in private storage behind authorization checks, and the answers are retained and deleted as described in section 9, including through the account-deletion workflow.

4. Data Storage and Security

Huzim runs on Vercel and stores application records in Neon PostgreSQL; private generated files may be stored in private object storage used by the application. For Google sign-in, Huzim retains the name, verified email address, and stable Google account identifier needed to maintain the account link, but discards and does not retain the Google profile image or Google access, refresh, or ID tokens after linking. Selected identity fields, wizard answers, rendered contracts, manual deadline labels, and MFA secrets are protected with versioned AES-256-GCM field encryption, while passwords are one-way hashed. Deadline dates, status, reminder schedules, and delivery state are stored as operational records. Network traffic is protected with HTTPS/TLS. No system is risk-free, and we continue to test and improve these controls.

5. Cookies and Tracking

We use essential cookies or similar local storage for authentication, security, language, and consent preferences. We also measure aggregate traffic with a random identifier that lasts only for the current browser tab session; we do not attach IP addresses, account details, document identifiers, query strings, or contract content to these traffic metrics. Sentry may receive limited error and performance diagnostics in accordance with your available consent choices and our configuration. We do not use advertising cookies or sell information for targeted advertising.

CarApp Used-Car Agreement Handoff

When you choose a CarApp link to Huzim that carries the displayed 7- or 8-digit licence plate, that plate is the only vehicle or user-supplied value that CarApp passes to Huzim to help you start a used-car sale agreement; a CarApp link to Huzim without a plate passes no such value. The protocol version and launch locale are routing metadata; CarApp does not send the vehicle report, VIN, price, notes, or site or user identifiers. The link is untrusted convenience input: Huzim does not verify that CarApp created it or that the plate is accurate. The plate travels only in the link's URL fragment, which browsers do not send to servers; it may briefly appear in local browser history. On Huzim's entry page, a small inline script copies a correctly formatted plate into this browser's local storage and removes the fragment from the address bar before analytics, error reporting, or any other page code loads, and the page then opens the used-car sale template. Huzim creates no cookie, database record, or other server-side state for the link. The stored plate stays only in this browser and can be used for at most 30 minutes; it is deleted when you use it, when you choose "Enter another plate", or when you sign out, and an expired entry is deleted as soon as it expires if a Huzim page is open in this browser, or otherwise the next time you open one. The plate is applied only when you click "Use this plate" in the agreement form; from then on it is handled exactly as if you had typed it, and your draft follows Huzim's ordinary agreement retention and deletion policy. Huzim independently processes the plate under this policy, performs its own vehicle lookup through a body-only POST request, and asks you to review the result; the CarApp report is not lookup input, and an unavailable or incomplete lookup may be completed manually. The plate is excluded from URLs after the entry page, callback URLs, emails, analytics, logs, metrics, and error reporting.

Optional Public-Beta Research

With your explicit consent, Huzim records a limited, first-party event stream covering template views, wizard starts and resumes, completed step numbers, allowlisted validation codes, document finalization, PDF downloads, lifecycle workspace views, and deadline create or complete actions during the current consent period and within the 90-day retention window. Documents finalized before the current consent period are not linked retroactively. Current event rows exclude contract answers, deadline labels and dates, document titles and identifiers, names, email addresses, account IDs, and generated text. During a 90-day transition, older analytics rows may still contain an account ID; they are deleted when consent is withdrawn or the account is deleted, or automatically under the retention policy. Current events use a random identifier for each consent period; a separate, narrow account link is used to associate and enforce the current consent period, produce aggregate reports, and support deletion. You can withdraw consent in Account Settings, which deletes your behavioral events and journey bindings. Events and inactive journey bindings are automatically deleted after 90 days. Feedback you submit voluntarily is stored separately, and optional comments are encrypted.

6. Third-Party Services

We disclose only the data needed to operate the beta to Vercel (hosting and application infrastructure), Neon (PostgreSQL database hosting), Resend (account verification, recovery, and other service email delivery), Sentry (error monitoring and limited diagnostics), and Google (authentication when you select Google sign-in). Google processes the authentication request under its own terms and privacy notice and returns the basic identity data described above. Huzim does not send your document content to Google for sign-in. Payments, AI analysis, e-signatures, and public sharing are disabled, so Huzim does not send beta document content to providers for those features. We do not sell personal information.

7. Your Rights

Subject to applicable law, you may ask to inspect information about you, correct inaccurate information, or delete your account and personal data. You may also change optional consent choices where offered. Some records may need to be retained for security, dispute, or legal reasons. To make a request, contact privacy@huzim.co.il; we may need to verify your identity before acting.

8. Israeli Privacy Law Compliance

We intend to operate the beta in accordance with Israel's Privacy Protection Law, 5741-1981, its applicable regulations, and other applicable requirements. This statement is not a claim that a database-registration requirement applies or has been completed. Independent legal review of the policies, translations, generated PDFs, and each published template edition remains a full-launch readiness condition. A template edition approved by the service operator only, with its approval basis explained in the beta terms, may be published during the limited beta without satisfying that full-launch condition; it has no independent legal review, and users should seek advice from a qualified Israeli lawyer. Availability of Huzim is not government or bar-association approval.

9. Data Retention

We retain information while your account is active and only as long as reasonably needed for the purposes described here, security, dispute handling, or applicable law. We do not state a fixed retention period for all records. The account-deletion workflow revokes sessions, removes private files and personal data, and pseudonymizes retained audit records; completion may be retried if a provider is temporarily unavailable. Backups and records subject to a legal hold may expire on their applicable operational or legal schedule.

10. Security Measures

Controls used for the beta include versioned field encryption for selected identity and document data, one-way password hashing, HTTPS/TLS, private-file authorization checks, request and account rate limits, origin checks for cookie-authenticated changes, Content Security Policy headers, security logging designed to avoid document content and credentials, and administrator access through verified Google SSO or password sign-in protected by TOTP MFA. These safeguards reduce risk but cannot guarantee absolute security.

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this policy when the Service, our providers, or applicable requirements change. Where appropriate, we will give notice through the Service or by email and request renewed acceptance when required. The date shown above identifies the current version.

13. Contact Us

For privacy questions, account-deletion support, or a request concerning your information, contact: privacy@huzim.co.il

© 2026 Huzim

  • About
  • Terms of Service
  • Privacy Policy
  • Accessibility Statement

Disclaimer: Huzim provides tools for document generation and does not provide legal advice. Using this service does not create an attorney-client relationship.

HomeTemplates
Huzim
Log in
Choose a template