Privacy Policy

← Back

Last updated: September 16, 2026

Safety & Crisis Resources

This Privacy Policy explains what information IsraelGPT ("the Service," "we," or "us") collects when you visit or use israelgpt.site, why we collect it, who it may be shared with, and the choices available to you. It should be read together with our Terms of Service and our Safety & Crisis Resources page. IsraelGPT is operated privately, under an alias, from the United States. It is a satirical entertainment product and is not affiliated with, endorsed by, or operated on behalf of the government of Israel, any political party, or any religious organization.

1. Information We Collect

We collect information in three ways: what you give us directly, what our systems collect automatically, and what we receive from third parties you interact with through the Service.

1.1 Information You Provide Directly

  • Chat messages, prompts, uploaded images and files, and other content you submit to the Service.
  • Account information such as your email address, and, if you sign in with a third-party identity provider, the name and profile picture that provider makes available to us.
  • Whether you opted in to marketing emails when signing up.
  • An optional "about me" note and any memories you choose to save to personalize responses, and the content and settings of chats you save to your account.
  • If you use the GoyBeam Telepathic Trading feature, the stock or cryptocurrency symbol and timeframe you select, so that live market data can be fetched and displayed.
  • If you use the in-app Contact Support form, the email address and message you enter. This form is processed by a third-party form service — see Sections 6 and 16.
  • If a message appears to reference child sexual abuse material (CSAM) — by any term or euphemism, including "CP" — the IP address it was sent from, the full text of the message, and any email address you voluntarily enter in the resulting verification step, together with account or session identifiers when available. See Section 3.

1.2 Information Collected Automatically

  • Technical information such as your IP address, browser type, operating system, and device information.
  • Approximate location information, but only if you grant permission when the Service's own optional browser location prompt appears.
  • Interaction data such as which features you use and general timestamps of activity, used for security and service improvement.
  • Identifiers and preferences stored in your browser's local storage, described in Section 8.

1.3 Information We Receive From Third Parties

  • If you sign in with a third-party identity provider, it shares your email address, name, and profile picture with us as part of the standard sign-in flow.
  • Our infrastructure providers (Section 6) may provide us with technical metadata about requests, such as an approximate geographic region inferred from IP address, for security and abuse-prevention purposes.

1.4 Sensitive Content You Submit

Messages associated with suicide or self-harm risk, and messages that appear to reference CSAM, are handled under dedicated protocols described in Section 2 and Section 3, which explain exactly what is and is not recorded in each case.

1.5 What We Do Not Collect

The Service is currently free to use and does not process payments, so we do not collect payment card or billing information. Our Terms of Service ask you not to submit passwords, confidential information, trade secrets, or other sensitive personal information in chat messages, and we do not want or need that information to operate the Service.

1.6 Public API Usage Data

If you create a public API key from the API Dashboard, we collect the name you give the key, a cryptographic hash of the key itself (we never store the key in readable form after it is first issued to you), and per-request usage metadata for each call made with it — the endpoint called, response status, which model and persona were used, message length and estimated token counts, and response time. We do not store a separate copy of your API request message content beyond this metadata; the same handling and retention rules described elsewhere in this Policy (Section 1.1, Section 9) apply to messages sent through the API as they do to the web chat, including the crisis and CSAM protocols in Sections 2 and 3, which run on API requests the same way they run on messages sent through the Service's own interface. See the Terms of Service for API key issuance, acceptable use, and revocation terms.

1.7 Voice Calling Feature

If you use the optional voice calling feature, we collect the caller display name and, if you are signed in and choose to add one, the custom picture shown to whoever you call; the time a call is placed and the anonymous, short usernames (Section 8) of the caller and callee; and, only while placing or accepting a call and only after your browser's own microphone permission prompt, access to your microphone. We do not record, store, or review the audio content of your calls. Section 19 explains this in full, including our TURN/STUN relay provider.

2. Crisis Detection

Messages you write are automatically screened on your own device, before being sent, for language associated with suicide and self-harm. This screening runs locally in your browser. The text of your message is not transmitted anywhere for the purpose of this check.

When a message matches, it is not sent to the AI, and we record a minimal event so that referral counts can be reported as required by law. That record contains only:

  • The date and time of the detection.
  • An anonymous session identifier, or your account identifier if you are signed in.
  • The general category of the match, such as "self_harm".
  • Whether the crisis notification was displayed.

This record does not contain the text of your message. Full details are published on our Safety & Crisis Resources page.

Messages that instead appear to reference child sexual abuse material (CSAM) are handled under a completely separate, zero-tolerance protocol and are not sent to the AI either — see Section 3.

3. Child Sexual Abuse Material (CSAM) Detection & Reporting

IsraelGPT has a zero-tolerance policy for child sexual abuse material (CSAM). This section explains, in full, how messages that appear to reference it are handled — separately from every other category of content described in this Policy.

Detection and interception. Messages are automatically screened for language that references CSAM by any term or euphemism, including "CP." A message that matches is intercepted before it reaches the AI model — the chatbot never sees it and never generates a reply to it. This applies regardless of which model, persona, or content setting you have selected, including Uncensored Mode.

What we record. When a message is intercepted, we record the sender's IP address, the full text of the message, and account or session identifiers when available, in an access-restricted review queue. The sender is separately asked to enter an email address to view a response; if they do, that email address is attached to the same record.

Human review before any report. A detection flag alone is not a report. Every intercepted message is reviewed by a person. Automated screening is imperfect — it will miss some references phrased in ways it does not recognize, and it will occasionally flag an innocent message — which is why no report is made on the strength of an automated flag alone.

Reporting. Where manual review concludes that a message constitutes or solicits CSAM, we report it — including the message text, the sender's IP address, and any email or account identifiers on file — to the National Center for Missing & Exploited Children (NCMEC) and/or the appropriate law-enforcement authority, as required by US law (18 U.S.C. § 2258A). Records may also be disclosed to law enforcement in response to a valid legal request, and may be preserved for longer than we otherwise would, in order to comply with legal or investigative obligations. See Section 9 (Data Retention) and Section 13 (Children's Privacy) for how this interacts with our general treatment of minors' information.

This protocol applies no matter the sender's stated age, and it is not affected by any other privacy or consent choice described in this Policy. See also Section 8 (Zero Tolerance for Child Sexual Abuse Material) of our Terms of Service and Section 6 of our Safety & Crisis Resources page.

4. How We Use Information

We use collected information to:

  • Provide, maintain, and operate the Service, including generating AI responses and personalizing them using any "about me" note or memories you have saved.
  • Operate the Contact Support form, including routing your message and email address to us through a third-party form-processing service (see Section 6).
  • Operate the voice calling feature, including establishing connections through our TURN/STUN relay provider and recording basic call metadata (see Section 19).
  • Detect abuse, spam, fraud, or misuse.
  • Moderate content and investigate violations, including the crisis and CSAM protocols described in Sections 2 and 3.
  • Comply with legal obligations, such as reporting apparent CSAM to NCMEC and/or law enforcement, and responding to valid legal process.
  • Improve performance, reliability, and security, including through aggregated or de-identified analysis that does not identify you individually.
  • Send you marketing or product-update emails, but only if you opted in when creating your account. Every marketing email includes an unsubscribe link, and unsubscribing does not affect your ability to use the Service.
  • Analyze chat logs, in aggregated or de-identified form, to inform our own marketing, product-positioning, and promotional material about the Service. We do not sell individual chat message content to third parties for their own marketing use.

5. Legal Bases for Processing

If data protection laws that require a "legal basis" for processing (such as the GDPR) apply to you, we rely on the following, depending on the activity:

  • Performance of a contract — operating the Service you asked to use, such as generating chat responses and maintaining your account.
  • Consent — marketing emails, the Service's own optional location prompts, and the choices you make in the privacy choices bar. You may withdraw consent at any time using "Manage Privacy Choices" or the unsubscribe link in any marketing email, without affecting the lawfulness of processing carried out before withdrawal.
  • Legitimate interests — security, fraud and abuse prevention, debugging, service improvement, and defending legal claims, none of which we believe override your own interests and rights.
  • Legal obligation — detecting and reporting apparent CSAM as described in Section 3, and responding to valid legal process.

6. Data Access and Sharing

We do not sell your personal information for money. Whether any information is shared with advertising partners for interest-based advertising depends on the privacy choice described in Section 7 — we only share data with advertising partners for that purpose if you have clicked "Agree" in the privacy choices bar. If you click "Reject Optional Tracking", your information is not shared or sold to advertising partners for cross-context behavioral advertising.

Authorized staff members may access stored data, including chat messages, when necessary for moderation, abuse prevention, debugging, security, or legal compliance.

Reporting of apparent child sexual abuse material. See Section 3 for the complete CSAM detection and reporting protocol, including exactly what is disclosed to NCMEC and/or law enforcement.

Data may also be processed by infrastructure and AI systems that help operate the Service, including:

  • A third-party hosting and infrastructure provider (hosting, infrastructure, and cookieless analytics)
  • A managed database, authentication, and realtime-messaging provider (the realtime messaging used for chat, presence, and voice-call signaling, and file storage for uploaded and custom call-background images)
  • A third-party TURN/STUN relay provider (relay infrastructure for the voice calling feature — receives participants' IP addresses and a short-lived, auto-expiring connection credential to help establish a call; when a direct connection between callers isn't possible, encrypted call audio is relayed through its servers rather than recorded or stored by them. See Section 19)
  • A managed rate-limiting service for the public API — receives a cryptographic hash of your API key, not the key itself or any message content, to enforce request limits
  • A third-party identity provider (sign-in, if you choose that sign-in method)
  • In-house fine-tuned AI models (message content and uploaded images sent to the AI are processed by models the operator fine-tunes and runs in-house)
  • A third-party form-processing provider (receives and stores submissions from the Contact Support form — the email address and message you enter — and forwards them to us; your browser submits this information directly to that provider's servers)
  • Third-party image content sources
  • A third-party IP-based geolocation lookup service
  • A third-party news content provider
  • Third-party market data providers (cryptocurrency and stock market data for the GoyBeam Telepathic Trading feature, including an unofficial, undocumented fallback source)
  • A third-party advertising network - displays ads on the Service. The network receives standard ad-serving data (such as your IP address, device/browser information, and the page you're viewing) for all visitors, regardless of the privacy choice described in Section 7. See Section 7 for details.

These providers may process information as required to operate their services, under their own privacy policies and terms, which we encourage you to review (see Section 16).

Business transfers. If the Service is involved in a merger, acquisition, financing, or sale of some or all of its assets, information we hold may be transferred as part of that transaction. We will require any successor to handle your information consistently with this Policy.

Aggregated and de-identified data. We may share information that has been aggregated or de-identified such that it no longer reasonably identifies you, for any purpose, including analytics and research.

We may disclose information if required by applicable law, regulation, legal process, or governmental request.

7. Advertising, Analytics & Your Privacy Choices

When you first visit, and any time you reopen it, a privacy choices bar lets you choose between:

  • Agree - you confirm you are 18+ and accept the Terms of Service and this Privacy Policy.
  • Reject Optional Location - turns off the Service's own optional browser location requests (used for moderation/security purposes elsewhere in this policy). It does not disable ads, which display for all visitors regardless of this choice, and it does not affect any other required data collection described in Section 1.
  • Cancel - closes the bar without agreeing to the Terms of Service or Privacy Policy and leaves the Service.

Your choice is stored in local storage on your device (see Section 8) and applies until you change it. You can revisit it anytime using the "Manage Privacy Choices" control at the top of this page. We do not deny you access to the Service, or provide a lesser experience, because you rejected the optional location request.

The Service displays advertisements served by a third-party advertising network, to support the Service. Ads are not gated by the choice above - they load for every visitor, including those who click Reject. That network and its ad-delivery partners may independently use cookies, device identifiers, or similar technology to serve and measure ads; this is standard ad-network behavior that the privacy choices bar does not control.

Because the ad network receives standard ad-serving data for every visitor regardless of your choice above, this may be considered a "sale" or "share" of personal information under some state privacy laws, even though no money changes hands. To limit cross-context ad tracking, you can use your browser's Global Privacy Control or Do Not Track signal, or industry opt-out tools such as the Digital Advertising Alliance and the Network Advertising Initiative. The Service itself does not currently alter its own behavior based on a Do Not Track browser setting, and we cannot guarantee that Global Privacy Control or Do Not Track signals are honored by every advertiser. See Section 11.2 for California-specific detail.

8. Local Storage and Similar Technologies

We do not currently use cookies. Instead, the Service uses your browser's local storage and session storage to:

  • Maintain sessions and authentication.
  • Remember your app preferences and settings — for example, dark mode, your chosen AI model and persona, and toggles like Uncensored Mode, Silly Mode, and auto-memory.
  • Remember an anonymous username the Service generates for you if you are not signed in, and in-progress conversations.
  • Remember the display name and picture shown to whoever you call in the voice calling feature — auto-assigned at random the first time you open the Service, and changeable if you are signed in (see Section 1.7 and Section 19).
  • Store an optional App Lock PIN, if you set one. This PIN is stored only in your browser's local storage and is never transmitted to us.
  • Remember your privacy/tracking choice from Section 7.
  • Remember whether you dismissed the "install to home screen" prompt.

We also use a cookieless analytics service operated by our hosting provider, which operates without cookies. Our advertising partner may use cookies or similar technologies in your browser to serve and measure ads, for all visitors — this is independent of your privacy/location choice above (see Section 7). You can clear local storage, session storage, and cookies through your browser settings, though some features — including saved preferences, your App Lock PIN, and your privacy choice — will reset if you do.

9. Data Retention

We retain data for as long as reasonably necessary to operate, secure, and improve the service unless a longer retention period is required by law. We do not apply a single fixed deletion timer to every data category — the paragraphs below describe the criteria that govern retention for each one, rather than an exact day count, and we may retain information longer where needed for security, dispute resolution, or legal compliance.

Records of messages that appear to reference CSAM — including the message text, IP address, and any email or account identifiers, as described in Section 3 — are retained until the matter is resolved, and longer where required by law. These records are not deleted by the in-app "Delete Account" option, because legal and investigative requirements may obligate us to preserve them.

Crisis-detection event records (Section 2) contain no message text and are retained for as long as needed to compile the referral statistics we are required to report.

Voice call metadata (Section 19) — the time a call was placed and the anonymous usernames of the caller and callee — is kept for feature-usage purposes. It never includes call audio, which we do not record or store.

Using the in-app "Delete Account" option removes your saved chats, memories, and profile data, and signs you out. It does not delete your underlying authentication record or technical logs (such as IP, device, or approximate location logs). To request full deletion of your authentication account and logged technical data, contact us using the information in Section 18.

10. International Data Transfers

IsraelGPT is operated from the United States, and the Service is available globally. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from — and may be less protective than — those of your country or region.

Our infrastructure and service providers (Section 6) may also store or process information in other countries where they operate data centers. By using the Service, you consent to this transfer, storage, and processing. Given the scale of this privately-operated Service, we rely on our providers' own safeguards for international transfers rather than maintaining separate transfer agreements of our own.

11. Your Privacy Rights

11.1 General Rights

Depending on your jurisdiction, you may have rights to:

  • Access your personal data.
  • Correct inaccurate information.
  • Request deletion of your data.
  • Restrict or object to certain processing activities.
  • Receive a copy of your data in a portable format.
  • Control the Service's own optional browser location request using "Reject Optional Location" in the privacy choices bar, or "Manage Privacy Choices" at the top of this page, at any time. This does not opt you out of advertising - the Service does not currently offer a way to disable ads or the data our ad network collects to serve them (see Section 7).

11.2 California Privacy Rights (CCPA/CPRA)

If you are a California resident, in the preceding 12 months we have collected the following categories of personal information, as defined by the California Consumer Privacy Act: identifiers (such as email address, IP address, and device/account identifiers), internet or network activity (such as chat interactions and technical logs), geolocation data (only if you enabled the optional location prompt), and audio/visual information (images you upload). We do not knowingly collect sensitive personal information beyond what you choose to type into a chat message, which our Terms of Service ask you not to do.

We do not sell personal information for money. Because our advertising network receives standard ad-serving data for all visitors regardless of your privacy choice (Section 7), this may constitute "sharing" for cross-context behavioral advertising under the CPRA. The in-app privacy choices bar does not function as a "Do Not Sell or Share My Personal Information" control, because "Reject Optional Location" only turns off our own geolocation prompts. To limit this sharing, use your browser's Global Privacy Control signal, the industry opt-out tools in Section 7, or contact us at the address in Section 18 and we will do what is within our control as a service built on a third-party ad network.

California residents may exercise the rights in Section 11.1 by contacting us as described in Section 11.5. We do not discriminate against you for exercising any of these rights.

11.3 Nevada Privacy Rights

Nevada law (NRS 603A) gives Nevada residents the right to opt out of the sale of certain covered information. We do not sell covered information for monetary consideration, but Nevada residents may still submit a request through the contact details in Section 11.5, and we will honor verified requests.

11.4 European Economic Area, UK, and Other International Users

If the GDPR, the UK GDPR, or a similar law applies to you, you may have the rights listed in Section 11.1, as well as the right to withdraw consent at any time (Section 5) and the right to lodge a complaint with your local data protection supervisory authority. See Section 10 for how your information is transferred to and processed in the United States. Given the small, privately-operated nature of this Service, we do not maintain a dedicated representative or data protection officer in the EEA or UK; please use the contact details in Section 11.5 for any request.

11.5 How to Exercise Your Rights

Contact: support@israelgpt.site. We may ask you to verify your identity before fulfilling a request — for example, by confirming the email address on your account — to protect against fraudulent requests. We aim to respond within the time required by applicable law. If we decline a request, you may reply to our response to ask us to reconsider.

12. Automated Decision-Making

The only automated, content-based decisions the Service makes about your messages are the crisis-detection screening (Section 2) and the CSAM screening (Section 3). Both operate by matching your message text against maintained lists of patterns, and both can, at most, result in a message not being forwarded to the AI model and/or being logged for human review. Neither produces an automated account suspension, ban, or any decision that produces legal or similarly significant effects concerning you without human involvement. We do not use automated profiling to make decisions about your eligibility for any service, offer, or benefit.

13. Children's Privacy

The Service is intended for users 18 and older and is not directed at children. We do not knowingly collect personal information from anyone under 18, consistent with the Children's Online Privacy Protection Act (COPPA). If you believe a minor has provided us with personal information, contact us using the information in Section 18 and we will delete it.

We do not use an independent age-verification service. Age assurance relies on your own self-certification when you click Agree or Reject in the privacy choices bar, as described in our Terms of Service.

The one explicit exception to the above is the CSAM reporting requirement: if someone uses the Service in a way that appears to involve sexual abuse or exploitation of minors, we will report it to NCMEC and/or law enforcement regardless of the sender's stated age, and we will not delete the records that relate to that report (see Section 3 and Section 9).

14. Data Security

We use reasonable technical and organizational safeguards designed to protect stored information, including transport encryption between your browser and our servers and access controls that restrict who can view sensitive stored data, such as CSAM review records. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

You are responsible for keeping your account credentials confidential and for anything that happens under your account as a result of a failure to do so.

15. Data Breach Notification

If we become aware of a security incident that compromises your personal information, we will investigate and, where required by applicable law, notify affected individuals and/or the relevant regulators without undue delay.

16. Third-Party Links

This Policy and the Service link to resources we do not operate or control, including crisis hotlines and the referral organizations on our Safety & Crisis Resources page, industry ad opt-out tools (Section 7), the third-party hosted form endpoint used for Contact Support (Section 6), and our Discord community. We are not responsible for the privacy practices, content, or security of any third-party site or service. We encourage you to review the privacy policy of any third party before providing it with information.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, will make reasonable efforts to bring them to your attention — for example, through the privacy choices bar or a notice on the Service. Continued use of the service after changes become effective constitutes acceptance of the updated policy.

18. Contact Us

If you have questions about this Privacy Policy or how we handle your information, contact: support@israelgpt.site.

IsraelGPT is operated privately, under an alias, and does not maintain a public mailing address; email is the fastest and most reliable way to reach us. This address is not monitored around the clock and must never be used to report an emergency — see our Safety & Crisis Resources page.

19. Voice Calling & Microphone Data

This section explains, in full, how the optional voice calling feature works and what it collects — microphone access is never requested anywhere else on the Service.

Microphone access. Your microphone is only accessed after your browser's own native permission prompt, triggered the moment you place or accept a call — never in the background and never for any other feature. You can deny or revoke this permission at any time through your browser's site settings; doing so only disables the calling feature and does not affect the rest of the Service.

We do not record your calls. Call audio is transmitted using WebRTC, a real-time peer-to-peer protocol: whenever a direct connection between the two callers' devices can be established, audio flows directly between them and never touches our servers at all. Only the connection setup itself — the offer/answer handshake, network routing candidates, and the caller's display name — passes through our realtime messaging channels (Section 6), the same infrastructure used for chat and presence.

TURN relay. When a direct connection isn't possible — commonly because one or both callers are behind a restrictive network or firewall — the encrypted call audio is instead relayed through a third-party TURN/STUN provider (Section 6). That provider receives the participants' IP addresses and a short-lived, auto-expiring connection credential in order to do this. It relays encrypted media between the two callers and does not record or retain the content of the call.

Caller identity. The first time you open the Service, one of a small set of built-in names and pictures is assigned to you at random and shown to whoever you call; this is stored in your browser's local storage (Section 8). If you are signed in, you can change your display name and, optionally, upload a custom picture (JPG/PNG/WEBP/GIF, 1MB maximum), which is stored in a third-party file storage bucket that anyone can read — so the people you call can see it — but only you can replace.

Call metadata. When a call is placed, we log the time and the anonymous, short usernames (Section 8) of the caller and callee — not the calling feature's own freely-editable display name, and never the audio content — so that basic feature usage can be understood. See Section 9 for retention.

The voice calling feature is experimental, as described in our Terms of Service, and is provided with no guarantee of call quality or availability.