Privacy policy
In effect from 30.08.2026
This document explains, in plain language, what information OPEN collects, why, and who else sees it. We wrote it to be read to the end - so that afterwards you actually know what happens to your data.
1.Who we are and what this covers
OPEN is a service that shows which businesses are open right now, and until when. It is operated by Shimon Yehuda Cohen, a registered sole proprietor (dealer number 317735439), of 12/3 HaRav Eliyahu Lopian St., Jerusalem
This policy covers the three places OPEN runs: the mobile app, the openow.app website, and the MCP server that lets you ask OPEN questions from inside a chat assistant.
It does not cover other businesses, websites or apps you reach through OPEN.
2.The short version
- Account
- An email address, a password and a name. Optionally a phone number and a profile picture.
- Location
- Your coordinates are sent only as part of the "what is near me" query, and are never stored by us.
- Contributions
- Favourites, status confirmations and reports are stored by us and linked to your account.
- What there isn’t
- No identifying analytics - only aggregate demand counts (coarse area, category, hour, plus the operating system and app version). No advertising, no tracking across apps or sites, and we do not sell data.
Every line here is expanded below. Where the summary and a detailed section disagree, the detailed section governs.
3.Account details
To create an account you give an email address and a password. Authentication runs through Supabase Auth and your password is managed there - we do not store it and we cannot read it.
Your account holds a name and an email address, and optionally a phone number and a profile picture. Those are all the profile details that exist; there are no extra ones we are not telling you about.
4.What you contribute
OPEN works because people keep it current. These three actions are stored by us and linked to your account:
- Favourites - which businesses you saved.
- Status confirmations - your answer to “is this open right now?”.
- Reports - the kind of problem you reported about a business, plus any free text you wrote.
The app does not show your name next to a confirmation or a report. What it shows is the kind of source - business owner, user, or admin - not who you are.
If you claim ownership of a business, the claim is stored with your account and with the phone number you entered, so that a person on our team can verify the business is yours. A successfully claimed business is linked to your account, and the statuses you publish for it are shown publicly as the owner’s status.
Content a business owner uploads for their business - a logo and photos - is public content: it is shown to anyone who sees the business in the app, on the website and in search results. An uploaded photo is re-encoded before it is stored, so EXIF data - including where the picture was taken - is neither kept nor published.
A business owner who asks for a verification mark can choose one of several routes, all of them voluntary: a code by SMS, a business or company number, and a photo from inside the business. None of them is a condition for creating a business or for using the service.
For the SMS route, the number we send to is not a number the owner types here: we find the number already published for the business - on Google, on the business website, or on a business page the owner points us to - and send the code there. To do that we query Google Places with the business name and location, and we pass the business phone number to an Israeli SMS provider so the message can be sent. That is business contact data, already published, not the personal data of a user. The code itself is stored only as a hash, expires within ten minutes, and is never returned to anyone.
A photo from inside the business is stored in fully private storage and is used solely as evidence for the OPEN team. It is never shown to customers, never shown back to the owner after it is sent, and never published anywhere. It is re-encoded before storage too, so EXIF data is not kept.
5.Location
The app asks for foreground location only - that is, only while the app is open in front of you. There is no background location tracking.
When you search for what is open near you, your coordinates are sent to our server as part of the query - that is how the database sorts businesses by distance and returns the ones that are genuinely closest. The precise coordinates are used for that query alone: we do not store them anywhere, which also means we have no location history to hand to anybody. Alongside it, an aggregate count of the search itself is kept - see “Aggregate analytics” below.
Declining the permission does not break the app: the list and search still work, just without distances.
One nuance worth stating plainly: to display a city name, the app asks the operating system to turn your coordinates into a place name. That request is handled by Apple or Google depending on your device, not by OPEN, and it is subject to their privacy policies.
6.Notifications for businesses you favourited
Push notifications are entirely opt-in: they are off until you approve the operating system’s own permission dialog yourself.
If you turn notifications on, the app stores a push token linked to your account. The token is used solely to notify you when a business you favourited publishes a new note or changes its opening hours - for no other purpose.
The token is deleted when you sign out of the account on that device, and when you delete the account.
A business owner sees how many customers follow them, and how many were sent a notification about a given update - counts only. The owner never sees who the followers are.
7.What we do not collect
The following is true as of this document, and we are stating it without “may” and without “might”:
- There is no identifying analytics and no third-party analytics tool. What is counted - aggregate tallies only - is described precisely in “Aggregate analytics”.
- Owner reminders, if you turn them on, are scheduled locally on your device only and use no push token at all - they are entirely separate from the favourites notifications described above, where their push token is detailed.
- There is no advertising, no ad-network SDK, and no tracking of you across other apps or websites.
- We do not sell, rent or trade your information.
If any of that changes, we will update this document before the change takes effect - not after.
8.Aggregate analytics - exactly what is counted
When a “what is open near me” search runs, the app records that the search happened - so we can tell business owners things like “dozens of people searched for open cafés in your area tonight”. That record is aggregate in the narrowest sense, and this is everything it contains:
- A coarse area cell of roughly one kilometre - never your precise location.
- The category filter, if one was applied (for example “cafés”).
- The hour of day.
- The operating system (iPhone or Android) and the app version.
The last two items on that list, the operating system and the app version, were added on 19.08.2026 and are attached to every record in this section. They describe the BUILD, not you: everyone using a given version sends exactly the same value, and no two people can be told apart by them. They exist for one reason only - when a new version crashes the moment it opens, it stops sending records, and that absence is the only way we can find out quickly. In August 2026 that is precisely what happened to an iPhone version, and it took hours to notice.
Interactions around a specific business are counted in exactly the same way: opening a business page, tapping "Directions" and tapping "Call". Each such record contains the business in question, the hour of day and those two version items - nothing more. That is how we can one day show an owner how many people were interested in their business, without knowing who they were.
A search that found nothing is recorded too: the search text itself (in its normalized form), the hour of day and those two version items - no location at all, not even the coarse area square, and nothing about you. That is how we learn which words people search for and which businesses OPEN is still missing.
Since 20.08.2026 a failed sign-in with Apple or Google is recorded too: which provider, at which stage it failed (inside the provider’s own sheet, or at the point where our server checks the credential), the short error code the provider returned, the hour of day and those two version items. The code alone is kept - never the provider’s written message, because a written auth message is exactly where an email address tends to appear. The record is created when a sign-in FAILED, meaning there is no signed-in user at all, and it does not include the email address you tried to sign in with or any other identifying detail. Why it exists: Apple sign-in failed for real people in August 2026, and because the failure happened inside Apple’s own sheet it never reached our servers - without this record we have no way of knowing it is happening.
What these records do not contain: no user id (even when you are signed in), no device id, no location of yours, and nothing that links one action to another. These are counts, not a history. The raw rows are readable only by OPEN administrators, and they are used in their aggregate form only.
9.The sign-up form on this website
The openow.app website has an early sign-up form for business owners. It collects a business name, a contact name, a phone number, an email address and a city, and stores them with us so we can contact you before launch. That is the only use.
The form does not require an account and is not linked to your app account. If you want your enquiry deleted, write to us.
10.OPEN inside chat assistants
You can connect OPEN to Claude or ChatGPT and ask in chat what is open. That server is read-only: it serves public business data, writes nothing, and requires no account.
Two things do go to a third party there, and you should know about them:
- If you type a place name, that text is sent to OpenStreetMap’s geocoding service - Nominatim - to turn it into coordinates.
- The interactive map in the chat loads map tiles from openstreetmap.org. OpenStreetMap therefore sees the IP address of whoever is viewing the map.
The conversation itself also takes place at the assistant’s provider - Anthropic or OpenAI - under their privacy policy, not ours.
11.Service providers
These are all the third parties involved in running OPEN:
- Supabase
- Database, authentication and storage.
- Vercel
- Hosting for the website and the MCP server.
- OpenStreetMap
- Turning a place name into coordinates, and map tiles.
- Expo
- Building and delivering the mobile app and its updates.
- Apple and Google
- The app stores, and turning coordinates into a city name on the device.
These providers process information on our behalf and on our instructions. The exceptions are Apple, Google and OpenStreetMap in the operations described above: there they act independently, under their own policies.
12.Why we use the information
- To run your account and recognise you when you sign in.
- To keep your favourites and show them to you.
- To check and correct the information about a business - status confirmations and reports reach our team for review.
- To handle business ownership claims and prevent abuse.
- To reply when you write to us.
The basis for this use is your consent and the provision of the service you asked for, in line with the Israeli Protection of Privacy Law, 5741-1981.
13.Retention, deletion and your rights
We keep your account details and your contributions for as long as the account exists.
You can delete your account at any time, directly inside the app: Profile → Delete account. You can also send a request to hello@openow.app from the account’s email address and we will delete the account and the information tied to it.
When an account is deleted, its profile, favourites and status confirmations are deleted with it. Contributions that form part of a business’s history - reports, and status updates that were published - remain as a record with no link to the account, so that the business’s history does not break.
Under Israeli law you are entitled to inspect the information held about you, to ask for incorrect information to be corrected, and to ask for it to be deleted. One email to the address above is enough.
14.Security
Access to data is enforced in the data layer itself, not only in the app: every query passes through rules that decide what your account may read and write. Traffic is encrypted with HTTPS.
No service is completely immune. If we learn of a security incident affecting your information, we will notify you and the authorities as the law requires.
15.Age
OPEN is not directed at children under 13, and we do not knowingly collect information from anyone younger. If it turns out that we have, write to us and we will delete it.
16.Where the information is stored
Information is stored on Supabase servers in the European Union (Frankfurt, Germany), and the website is served from Vercel’s network. Some providers operate infrastructure outside Israel, so information may cross borders as part of delivering the service.
17.Changes to this policy
If we change this policy we will update the effective date at the top of the page. A material change - for example, starting to collect a new kind of data not described here - will be brought to your attention in the app or by email before it takes effect.
18.Contact
Questions, access or deletion requests, and anything else: hello@openow.app. Our registered address is 12/3 HaRav Eliyahu Lopian St., Jerusalem