Skip to main content
Personal IT Guy
עב Home→

Privacy policy

Last updated: August 15, 2026

This Privacy Policy explains what information is collected when you use the Personal IT Guy software (the "Software") and its website (the "Site"), where it comes from, why it is collected, to whom it may be disclosed, how long it is kept and what rights you have over it.

It is written in accordance with the Israeli Protection of Privacy Law, 1981, including the Protection of Privacy Law (Amendment No. 13), 2024, and the regulations enacted under it - chiefly the Protection of Privacy (Data Security) Regulations, 2017, and the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001.

Scope - both systems

  • The Software: what is stored on your computer, what it sends to us, and what it sends directly to an outside service.
  • The Site: cookies, browser local storage, details submitted through it, and server logs.

This policy covers both. Where the two differ, it says so explicitly.

What is not here, and is better said up front: there is no online sale, no card processing, no marketing mailing list, no paid advertising, no pixels, no analytics tooling and no audience targeting - neither on the Site nor in the Software. The service is not built on collecting information, so the amount of information it collects is deliberately small.

1. Who is responsible for the data

Service operator and owner of the database: Personal IT Guy.

Address: Rishon LeZion, Israel

Email: info@pitguy.com

The contact person for privacy matters is the service operator. Every privacy enquiry is handled by them directly, at the email address above.

1.1 The database's status under Amendment 13

Amendment 13 to the Protection of Privacy Law, which came into force on 14 August 2025, abolished the duty to register most private databases with the Database Registrar and replaced it with internal management and documentation duties. Our database is not one of the kinds that remain registrable: its main purpose is not collecting information in order to pass it to others, it does not belong to a public body, and it does not hold specially sensitive information about a large number of people.

The scale of the activity and of the data also does not require appointing a data protection officer or a data security officer. That said, we keep the internal documentation the law requires, including a database definitions document, and we work to the data security regulations at the security level that applies to us.

2. The guiding principle - your diagnostics stay on your machine

Every check the Software runs - processor, memory, drives, graphics card, battery, network, temperatures, processes, services, installed software, display, audio, camera, microphone, input devices, machine security and the server tools - runs locally on your computer. Its results, the reports, the chat history and the settings are stored on your machine only.

We do not scan your computer remotely, we do not run commands on it remotely, we do not upload files from it, we do not see its contents, and we do not know what you checked, when, or what came out of it. The Software does not transmit results automatically, and it collects no usage data (telemetry) of any kind.

3. What is stored on your computer and never reaches us

The Software keeps an encrypted settings file in your user's own data folder. Among other things it holds:

  • Your personal API key for the artificial-intelligence service.
  • Chat ratings and your conversation history with the assistant.
  • The console accounts you saved (SSH, Telnet, ADB), including usernames and passwords.
  • The unlock code for the system log - stored as a one-way hash (SHA-256), never as text.
  • The registration details you gave in the setup wizard, your preferences, language, text size and window position.
  • Reports you produced and stress-test results, as files on your own machine.

Not one item on that list is sent to us or backed up by us. The reports the Software produces never include the settings file - so no API key, no conversation history and no console accounts.

Please note: a report you choose to send to a technician or anyone else does contain your machine's hardware and software details, and who receives it is entirely under your control.

4. What does reach us, and where it comes from

4.1 Registration details

Provided by you in the setup wizard.

A full name and an email address are required to complete the wizard, and the email address serves as your user identifier. Phone number, business name and headcount are optional and may be left blank. The details are stored in our database together with the date you registered.

4.2 Activity marker

Created in the course of use.

If an email address was provided, it is sent to our server each time the Software starts in order to update your last-used date. That is all that is recorded: the email address and the latest timestamp. We do not record what you did in the Software, which screens you visited or which checks you ran.

4.3 Routine requests to our server

Collected automatically.

The Software contacts our server to check whether a new version has been published, to fetch system messages, to read operational settings and to show the legal documents in their current wording. As with any browsing, these requests expose your IP address, the time of the request and its technical details, and they are written to the server log for operations and security.

4.4 The feedback form inside the Software

Provided by you.

If you send feedback from within the Software, what reaches us is the kind of enquiry, the text you wrote, your name and email address if you filled them in, the version number, the operating system, the interface language and the screen the message was sent from - along with a screenshot, if you chose to attach one. The message reaches us as an email and is not stored in the database.

Screenshots: a screenshot may include personal information that happened to be on screen at that moment. Attaching it is your choice, and it is worth checking what is visible in it before sending.

To prevent abuse of the form we keep a send-rate counter identified by a one-way hash of the IP address, which deletes itself after a day.

4.5 Enquiries to us by email

Provided by you.

We keep the enquiry and the contact details in it in order to handle it and to record how it was handled.

4.6 Requests for public information through our server

Created in the course of use.

When the Software checks who owns a domain or an IP address, it asks the authorised registry directly. Only when the network you are connected to blocks that direct request does the query pass through our server, which forwards it to the registry. In that case the query is exposed to our server in passing only and is not stored.

A lookup of your public IP address is answered from tables held on our own server rather than against an outside location service - precisely so that no outside party receives a list of which users were online and when.

4.7 The Site's admin area

For the service operator only.

It holds a username, a password as a one-way hash, the last sign-in time, "remember me" tokens and a failed-login counter keyed by IP address. There are no outside users in this area.

5. Purposes of use, the basis for processing, and the statutory disclosure

In accordance with the disclosure duty in section 11 of the Protection of Privacy Law we clarify: you are under no legal obligation to give us any information, and providing it is done of your own free will and with your consent. That said, a full name and an email address are needed to complete registration in the Software, and without contact details we cannot identify you, provide personal support or notify you about updates. The information is stored in the service's database, and access to it is limited to the service operator alone.

PurposeBasis for processing
Identifying the user and managing the relationshipYour consent at registration, and providing the service you asked for
Support, answering enquiries and handling feedbackProviding the service you asked for, at your request
Recording a registered user's most recent activityA legitimate interest in running the service and identifying accounts no longer in use
Version updates and operational system messagesProviding the service, and a legitimate interest in keeping it sound and secure
Server logs, the failed-login counter and rate limitsA legitimate interest in protecting the system, and a duty under the data security regulations
The artificial-intelligence capabilitiesYour separate, explicit consent in a dedicated document, using your own personal key
Meeting legal duties and legal proceedingsA legal obligation

We carry out no marketing mailing, no marketing segmentation, no behavioural analysis and no consumer profiling.

6. Artificial intelligence - what is sent, to whom, and when

The AI capabilities work against Google LLC's Google Gemini service, and only after you approve the dedicated "Use of AI" document and enter your own personal API key. Until that document is approved the capabilities stay frozen, and the approval can be withdrawn at any time from the About screen - withdrawal freezes them immediately.

  • The key is stored encrypted on your computer and is never sent to us.
  • Queries go directly from your computer to Google's servers, not through our servers. We do not see, collect or store the content of your conversations.
  • Relevant diagnostic data from the machine may be sent alongside your question - the processor model, the amount of memory or a test result, for example - so that the answer is accurate.
  • To save repeated queries, the Software produces a numeric representation of your question (an embedding), also against Google's service, and compares it with earlier questions. This means the text of the question used for that comparison also goes to Google.
  • You must use a key with Billing enabled. On the free tier Google may use submitted content to train and improve its models, so a free-tier key must not be used.
  • Such use is also subject to Google's terms of service and privacy policy.

Warning: do not enter sensitive information into the AI fields - ID numbers, payment-card details, medical information, passwords or trade secrets.

7. Outside services the Software contacts directly from your computer

Some checks cannot be made without reaching outside the machine. In those requests your computer is exposed to the service it contacted, exactly as in ordinary browsing - the request leaves from you and does not pass through us, and we do not see it.

ServiceWhen, and what for
Google (the Gemini service)The AI queries, only after your approval and with your own key
CloudflareThe connection speed test and the line-under-load test. Only data packets are sent and received, with no identifying details
ipify, ifconfig.me, icanhazipPublic-IP lookup, as a fallback only, if our own server is unreachable at that moment
Domain and address registries (RDAP and WHOIS), and IANA's referral tableIn ownership checks for a domain or an address
DNS servers, routers and devices on your own networkIn the network checks, according to what you asked to check
GitHubOnly if you explicitly choose to install the optional sensor driver. The file's digital signature is verified before it is run
OpenStreetMapOnly if you press the map button. The coordinates are handed to your browser, and no map is embedded in the Software
Our own serverVersion check, system messages, operational settings, legal documents and downloading the installer

These requests follow the action you asked for. We receive nothing from them, and we do not know which sites, addresses or devices you contacted.

8. Cookies and local storage on the Site

These are all the cookies the Site sets, and it sets no others:

CookieWhat forHow long
The session cookieA secure sign-in to the admin area and the security tokens (CSRF) that protect the formsDeleted when the browser closes
PITG_REMEMBERThe admin's "remember me" token. Set only when it was explicitly requested at sign-in7 days, renewed on each sign-in
pitg_langThe interface language you chose. Set only when you actually change the languageA year
pitg_cookie_okA marker that the cookie notice has been shown to you, so it does not reappear on every visitA year

The first two are essential to the Site's operation and security and cannot be disabled; the last two hold a preference and nothing more. None of them contains a personal identifier, and none of them follows you across sites.

Browser local storage holds the display mode (light/dark) and the accessibility settings you chose. These stay in your browser and are not sent to the server.

The Site has no advertising cookies, no pixels, no traffic analytics, no session recording and no third-party tracking of any kind.

The Site's fonts: the Site loads its Hebrew fonts from Google's font service, so when a page loads, your browser's IP address is exposed to Google's servers. There is no cookie in that, no persistent identifier and no tracking of your browsing - but it is a request to an outside server, and so it is stated here explicitly.

You may block or delete cookies through your browser settings; some Site functionality may be impaired.

9. Disclosure to third parties

We do not sell, rent, trade or transfer your personal information to any third party for any commercial purpose. Information will be disclosed to a third party only where:

  • You gave explicit consent.
  • A legal duty, a judicial order or a demand from a competent authority applies - and only to the extent required.
  • It is needed to defend our legal rights in proceedings.

The hosting and infrastructure provider that hosts our server acts as a data holder on our behalf, is bound to confidentiality and to reasonable security measures under the law, and may not make independent use of the data.

10. Transfers outside Israel

Our database, which holds the registration details, is hosted in Israel.

Two transfers outside Israel take place as part of the service, and both leave from your computer or your browser rather than from our database:

  • The AI queries, transferred to Google's servers outside Israel, under the separate consent you gave and subject to Google's policies.
  • Operational requests to the outside services listed in section 7, including the loading of the Site's fonts.

These transfers are made in accordance with the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001, to countries and to bodies subject to a duty of confidentiality and an adequate level of data security.

11. Data security and backups

We apply reasonable and accepted technical and organisational security measures, suited to the security level that applies to the database under the Protection of Privacy (Data Security) Regulations, 2017. Among them:

  • An encrypted connection (HTTPS/TLS) for all Site and API traffic.
  • Passwords stored only as one-way hashes, which cannot be reversed.
  • A strict content security policy in the browser (CSP), CSRF tokens and security headers on every page.
  • Protection against SQL injection through prepared statements only.
  • Rate limiting and a temporary lock after failed sign-in attempts.
  • Direct access to the database file and to the internal folders blocked from the network.
  • Permissions kept to the minimum required, on a need-to-know basis.
  • The Software's feedback form is cryptographically signed with a timestamp, so a message that did not come from the Software itself is refused.
  • The Software's settings file on your computer is stored encrypted.
  • An automatic daily backup of the database, kept in a folder unreachable from the network, and verified.

That said, no online system can be guaranteed absolutely secure. We are not responsible for malicious acts by third parties that could not have been foreseen or prevented by reasonable effort.

12. Retention periods

Kind of informationRetention periodReason
Registration details (name, email, phone, business, headcount)While the account is active, and up to 24 months from the last useRunning the service and providing support
The last-used dateUpdated on each launch, and deleted together with the registration detailsIdentifying accounts no longer in use
Feedback messages and email enquiriesUp to 24 months after the matter is closedThe record, and repeat handling
Screenshots attached to feedbackDeleted together with the message they were attached toNo separate retention needed
Server logsUp to 12 monthsOperations and security
The feedback send-rate counterDeleted automatically after 24 hoursPreventing abuse
The admin-area failed-login counterDeleted automatically within 15 minutesProtection against intrusion attempts
The admin's "remember me" tokens7 days, and deleted by themselves on expiryConvenient secure sign-in
Database backupsUp to 30 daily copies; an older one is deleted as a new one takes its placeRecovery after a failure
Information subject to a retention duty in lawFor as long as the law requiresA legal obligation
Information after a deletion requestDeleted within 30 days, except what the law requires us to keepThe data subject's right

At the end of the period the information is deleted or de-identified.

13. Your rights

Under the Protection of Privacy Law, 1981, and Amendment 13 to it, you have the following rights:

  • The right of access (section 13 of the Law) - to review the information held about you in the database.
  • The right of correction (section 14 of the Law) - to ask that information which is inaccurate, incomplete, unclear or out of date be corrected.
  • The right of deletion - to ask that the information be deleted, subject to retention duties in law.
  • The right to know the source of the information - where it was not provided by you directly.
  • The right to withdraw consent - including withdrawing approval for the use of artificial intelligence, at any time and without giving a reason.
  • The right to object to direct marketing (section 17f of the Law) - the right is yours at any time, even though we carry out no marketing mailing.
  • The right to complain - to the Privacy Protection Authority at the Ministry of Justice.

To exercise any of these rights, email us at info@pitguy.com with "Privacy" in the subject line and details that allow us to identify you. We may ask you to verify your identity before releasing information, so that personal information is never handed to someone it does not belong to.

We will respond within 5 business days, and in any event no later than the period set by law - 30 days.

14. Automated decisions, recommendations and profiling

We carry out no profiling, no user segmentation and no automated decision-making with legal or financial consequences for you.

The Software presents scores, recommendations and explanations - including answers produced by the AI assistant. These are aids only: they rest on measurements from your own machine and on a model that is not always accurate, they do not constitute professional advice, and they change nothing on your computer by themselves. Any action that changes your computer is taken only with your explicit approval, and the decision whether to act on a recommendation is yours.

15. Messages and marketing

System messages are shown inside the Software and concern its operation - a new version, for example, or an operational notice. They are not advertising material.

We will not send you advertising material by email, SMS or any other means without your prior explicit consent. Should we wish to send such mailing in future, we will ask for your consent separately and in advance, every message will carry a simple and immediate way to opt out, and an opt-out will be honoured without your having to give a reason - all in accordance with section 30A of the Communications (Telecommunications and Broadcasting) Law, 1982. Opting out of mailing will not affect essential service messages concerning your use of the Software.

16. Minors

The service is not intended for minors under 18 without the consent of a parent or guardian. We do not knowingly collect information from minors without such consent. If you learn that a minor has given us information, contact us and it will be deleted without delay.

17. Security incidents

In accordance with the Protection of Privacy (Data Security) Regulations, 2017, and Amendment 13 to the Law, in the event of a serious security incident involving personal data:

  • We will act immediately to stop the incident, limit the damage and prevent a recurrence.
  • We will report to the Privacy Protection Authority with reasonable speed, as the law requires.
  • We will inform you of the incident, its extent, the kind of information affected and the steps we recommend you take, where that is required.
  • We will document the incident and how it was handled.

18. Changes to this policy

We may update this policy from time to time. The updated wording will be published on this page, with the last-updated date at the top. A material change - broader collection, a new purpose or a new recipient, for example - will be brought to your attention in advance by reasonable means, including a notice inside the Software, and at least 14 days before it takes effect.

The binding wording is the one published on this page at the time of use, and continued use after the effective date constitutes acceptance of it.

19. Contact

For any question, request to exercise a right or privacy complaint, write to us at info@pitguy.com

We would be glad if you came to us first - most requests are settled quickly and with no need for anything further. Alongside that, you are entitled at any time to approach the Privacy Protection Authority at the Ministry of Justice.

© Personal IT Guy. All rights reserved.Admin