Last updated: August 15, 2026
This Privacy Policy explains what information is collected when you use the Personal IT Guy software (the "Software") and its website (the "Site"), where it comes from, why it is collected, to whom it may be disclosed, how long it is kept and what rights you have over it.
It is written in accordance with the Israeli Protection of Privacy Law, 1981, including the Protection of Privacy Law (Amendment No. 13), 2024, and the regulations enacted under it - chiefly the Protection of Privacy (Data Security) Regulations, 2017, and the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001.
Scope - both systems
- The Software: what is stored on your computer, what it sends to us, and what it sends directly to an outside service.
- The Site: cookies, browser local storage, details submitted through it, and server logs.
This policy covers both. Where the two differ, it says so explicitly.
What is not here, and is better said up front: there is no online sale, no card processing, no marketing mailing list, no paid advertising, no pixels, no analytics tooling and no audience targeting - neither on the Site nor in the Software. The service is not built on collecting information, so the amount of information it collects is deliberately small.
1. Who is responsible for the data
Service operator and owner of the database: Personal IT Guy.
Address: Rishon LeZion, Israel
Email: info@pitguy.com
The contact person for privacy matters is the service operator. Every privacy enquiry is handled by them directly, at the email address above.
1.1 The database's status under Amendment 13
Amendment 13 to the Protection of Privacy Law, which came into force on 14 August 2025, abolished the duty to register most private databases with the Database Registrar and replaced it with internal management and documentation duties. Our database is not one of the kinds that remain registrable: its main purpose is not collecting information in order to pass it to others, it does not belong to a public body, and it does not hold specially sensitive information about a large number of people.
The scale of the activity and of the data also does not require appointing a data protection officer or a data security officer. That said, we keep the internal documentation the law requires, including a database definitions document, and we work to the data security regulations at the security level that applies to us.
2. The guiding principle - your diagnostics stay on your machine
Every check the Software runs - processor, memory, drives, graphics card, battery, network, temperatures, processes, services, installed software, display, audio, camera, microphone, input devices, machine security and the server tools - runs locally on your computer. Its results, the reports, the chat history and the settings are stored on your machine only.
We do not scan your computer remotely, we do not run commands on it remotely, we do not upload files from it, we do not see its contents, and we do not know what you checked, when, or what came out of it. The Software does not transmit results automatically, and it collects no usage data (telemetry) of any kind.
3. What is stored on your computer and never reaches us
The Software keeps an encrypted settings file in your user's own data folder. Among other things it holds:
- Your personal API key for the artificial-intelligence service.
- Chat ratings and your conversation history with the assistant.
- The console accounts you saved (SSH, Telnet, ADB), including usernames and passwords.
- The unlock code for the system log - stored as a one-way hash (SHA-256), never as text.
- The registration details you gave in the setup wizard, your preferences, language, text size and window position.
- Reports you produced and stress-test results, as files on your own machine.
Not one item on that list is sent to us or backed up by us. The reports the Software produces never include the settings file - so no API key, no conversation history and no console accounts.
Please note: a report you choose to send to a technician or anyone else does contain your machine's hardware and software details, and who receives it is entirely under your control.
4. What does reach us, and where it comes from
4.1 Registration details
Provided by you in the setup wizard.
A full name and an email address are required to complete the wizard, and the email address serves as your user identifier. Phone number, business name and headcount are optional and may be left blank. The details are stored in our database together with the date you registered.
4.2 Activity marker
Created in the course of use.
If an email address was provided, it is sent to our server each time the Software starts in order to update your last-used date. That is all that is recorded: the email address and the latest timestamp. We do not record what you did in the Software, which screens you visited or which checks you ran.
4.3 Routine requests to our server
Collected automatically.
The Software contacts our server to check whether a new version has been published, to fetch system messages, to read operational settings and to show the legal documents in their current wording. As with any browsing, these requests expose your IP address, the time of the request and its technical details, and they are written to the server log for operations and security.
4.4 The feedback form inside the Software
Provided by you.
If you send feedback from within the Software, what reaches us is the kind of enquiry, the text you wrote, your name and email address if you filled them in, the version number, the operating system, the interface language and the screen the message was sent from - along with a screenshot, if you chose to attach one. The message reaches us as an email and is not stored in the database.
Screenshots: a screenshot may include personal information that happened to be on screen at that moment. Attaching it is your choice, and it is worth checking what is visible in it before sending.
To prevent abuse of the form we keep a send-rate counter identified by a one-way hash of the IP address, which deletes itself after a day.
4.5 Enquiries to us by email
Provided by you.
We keep the enquiry and the contact details in it in order to handle it and to record how it was handled.
4.6 Requests for public information through our server
Created in the course of use.
When the Software checks who owns a domain or an IP address, it asks the authorised registry directly. Only when the network you are connected to blocks that direct request does the query pass through our server, which forwards it to the registry. In that case the query is exposed to our server in passing only and is not stored.
A lookup of your public IP address is answered from tables held on our own server rather than against an outside location service - precisely so that no outside party receives a list of which users were online and when.
4.7 The Site's admin area
For the service operator only.
It holds a username, a password as a one-way hash, the last sign-in time, "remember me" tokens and a failed-login counter keyed by IP address. There are no outside users in this area.
5. Purposes of use, the basis for processing, and the statutory disclosure
In accordance with the disclosure duty in section 11 of the Protection of Privacy Law we clarify: you are under no legal obligation to give us any information, and providing it is done of your own free will and with your consent. That said, a full name and an email address are needed to complete registration in the Software, and without contact details we cannot identify you, provide personal support or notify you about updates. The information is stored in the service's database, and access to it is limited to the service operator alone.
| Purpose | Basis for processing |
| Identifying the user and managing the relationship | Your consent at registration, and providing the service you asked for |
| Support, answering enquiries and handling feedback | Providing the service you asked for, at your request |
| Recording a registered user's most recent activity | A legitimate interest in running the service and identifying accounts no longer in use |
| Version updates and operational system messages | Providing the service, and a legitimate interest in keeping it sound and secure |
| Server logs, the failed-login counter and rate limits | A legitimate interest in protecting the system, and a duty under the data security regulations |
| The artificial-intelligence capabilities | Your separate, explicit consent in a dedicated document, using your own personal key |
| Meeting legal duties and legal proceedings | A legal obligation |
We carry out no marketing mailing, no marketing segmentation, no behavioural analysis and no consumer profiling.
6. Artificial intelligence - what is sent, to whom, and when
The AI capabilities work against Google LLC's Google Gemini service, and only after you approve the dedicated "Use of AI" document and enter your own personal API key. Until that document is approved the capabilities stay frozen, and the approval can be withdrawn at any time from the About screen - withdrawal freezes them immediately.
- The key is stored encrypted on your computer and is never sent to us.
- Queries go directly from your computer to Google's servers, not through our servers. We do not see, collect or store the content of your conversations.
- Relevant diagnostic data from the machine may be sent alongside your question - the processor model, the amount of memory or a test result, for example - so that the answer is accurate.
- To save repeated queries, the Software produces a numeric representation of your question (an
embedding), also against Google's service, and compares it with earlier questions. This means the text of the question used for that comparison also goes to Google.
- You must use a key with Billing enabled. On the free tier Google may use submitted content to train and improve its models, so a free-tier key must not be used.
- Such use is also subject to Google's terms of service and privacy policy.
Warning: do not enter sensitive information into the AI fields - ID numbers, payment-card details, medical information, passwords or trade secrets.
7. Outside services the Software contacts directly from your computer
Some checks cannot be made without reaching outside the machine. In those requests your computer is exposed to the service it contacted, exactly as in ordinary browsing - the request leaves from you and does not pass through us, and we do not see it.
| Service | When, and what for |
| Google (the Gemini service) | The AI queries, only after your approval and with your own key |
| Cloudflare | The connection speed test and the line-under-load test. Only data packets are sent and received, with no identifying details |
| ipify, ifconfig.me, icanhazip | Public-IP lookup, as a fallback only, if our own server is unreachable at that moment |
| Domain and address registries (RDAP and WHOIS), and IANA's referral table | In ownership checks for a domain or an address |
| DNS servers, routers and devices on your own network | In the network checks, according to what you asked to check |
| GitHub | Only if you explicitly choose to install the optional sensor driver. The file's digital signature is verified before it is run |
| OpenStreetMap | Only if you press the map button. The coordinates are handed to your browser, and no map is embedded in the Software |
| Our own server | Version check, system messages, operational settings, legal documents and downloading the installer |
These requests follow the action you asked for. We receive nothing from them, and we do not know which sites, addresses or devices you contacted.
8. Cookies and local storage on the Site
These are all the cookies the Site sets, and it sets no others:
| Cookie | What for | How long |
| The session cookie | A secure sign-in to the admin area and the security tokens (CSRF) that protect the forms | Deleted when the browser closes |
PITG_REMEMBER | The admin's "remember me" token. Set only when it was explicitly requested at sign-in | 7 days, renewed on each sign-in |
pitg_lang | The interface language you chose. Set only when you actually change the language | A year |
pitg_cookie_ok | A marker that the cookie notice has been shown to you, so it does not reappear on every visit | A year |
The first two are essential to the Site's operation and security and cannot be disabled; the last two hold a preference and nothing more. None of them contains a personal identifier, and none of them follows you across sites.
Browser local storage holds the display mode (light/dark) and the accessibility settings you chose. These stay in your browser and are not sent to the server.
The Site has no advertising cookies, no pixels, no traffic analytics, no session recording and no third-party tracking of any kind.
The Site's fonts: the Site loads its Hebrew fonts from Google's font service, so when a page loads, your browser's IP address is exposed to Google's servers. There is no cookie in that, no persistent identifier and no tracking of your browsing - but it is a request to an outside server, and so it is stated here explicitly.
You may block or delete cookies through your browser settings; some Site functionality may be impaired.
9. Disclosure to third parties
We do not sell, rent, trade or transfer your personal information to any third party for any commercial purpose. Information will be disclosed to a third party only where:
- You gave explicit consent.
- A legal duty, a judicial order or a demand from a competent authority applies - and only to the extent required.
- It is needed to defend our legal rights in proceedings.
The hosting and infrastructure provider that hosts our server acts as a data holder on our behalf, is bound to confidentiality and to reasonable security measures under the law, and may not make independent use of the data.
10. Transfers outside Israel
Our database, which holds the registration details, is hosted in Israel.
Two transfers outside Israel take place as part of the service, and both leave from your computer or your browser rather than from our database:
- The AI queries, transferred to Google's servers outside Israel, under the separate consent you gave and subject to Google's policies.
- Operational requests to the outside services listed in section 7, including the loading of the Site's fonts.
These transfers are made in accordance with the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001, to countries and to bodies subject to a duty of confidentiality and an adequate level of data security.
11. Data security and backups
We apply reasonable and accepted technical and organisational security measures, suited to the security level that applies to the database under the Protection of Privacy (Data Security) Regulations, 2017. Among them:
- An encrypted connection (HTTPS/TLS) for all Site and API traffic.
- Passwords stored only as one-way hashes, which cannot be reversed.
- A strict content security policy in the browser (CSP), CSRF tokens and security headers on every page.
- Protection against SQL injection through prepared statements only.
- Rate limiting and a temporary lock after failed sign-in attempts.
- Direct access to the database file and to the internal folders blocked from the network.
- Permissions kept to the minimum required, on a need-to-know basis.
- The Software's feedback form is cryptographically signed with a timestamp, so a message that did not come from the Software itself is refused.
- The Software's settings file on your computer is stored encrypted.
- An automatic daily backup of the database, kept in a folder unreachable from the network, and verified.
That said, no online system can be guaranteed absolutely secure. We are not responsible for malicious acts by third parties that could not have been foreseen or prevented by reasonable effort.
12. Retention periods
| Kind of information | Retention period | Reason |
| Registration details (name, email, phone, business, headcount) | While the account is active, and up to 24 months from the last use | Running the service and providing support |
| The last-used date | Updated on each launch, and deleted together with the registration details | Identifying accounts no longer in use |
| Feedback messages and email enquiries | Up to 24 months after the matter is closed | The record, and repeat handling |
| Screenshots attached to feedback | Deleted together with the message they were attached to | No separate retention needed |
| Server logs | Up to 12 months | Operations and security |
| The feedback send-rate counter | Deleted automatically after 24 hours | Preventing abuse |
| The admin-area failed-login counter | Deleted automatically within 15 minutes | Protection against intrusion attempts |
| The admin's "remember me" tokens | 7 days, and deleted by themselves on expiry | Convenient secure sign-in |
| Database backups | Up to 30 daily copies; an older one is deleted as a new one takes its place | Recovery after a failure |
| Information subject to a retention duty in law | For as long as the law requires | A legal obligation |
| Information after a deletion request | Deleted within 30 days, except what the law requires us to keep | The data subject's right |
At the end of the period the information is deleted or de-identified.
13. Your rights
Under the Protection of Privacy Law, 1981, and Amendment 13 to it, you have the following rights:
- The right of access (section 13 of the Law) - to review the information held about you in the database.
- The right of correction (section 14 of the Law) - to ask that information which is inaccurate, incomplete, unclear or out of date be corrected.
- The right of deletion - to ask that the information be deleted, subject to retention duties in law.
- The right to know the source of the information - where it was not provided by you directly.
- The right to withdraw consent - including withdrawing approval for the use of artificial intelligence, at any time and without giving a reason.
- The right to object to direct marketing (section 17f of the Law) - the right is yours at any time, even though we carry out no marketing mailing.
- The right to complain - to the Privacy Protection Authority at the Ministry of Justice.
To exercise any of these rights, email us at info@pitguy.com with "Privacy" in the subject line and details that allow us to identify you. We may ask you to verify your identity before releasing information, so that personal information is never handed to someone it does not belong to.
We will respond within 5 business days, and in any event no later than the period set by law - 30 days.
14. Automated decisions, recommendations and profiling
We carry out no profiling, no user segmentation and no automated decision-making with legal or financial consequences for you.
The Software presents scores, recommendations and explanations - including answers produced by the AI assistant. These are aids only: they rest on measurements from your own machine and on a model that is not always accurate, they do not constitute professional advice, and they change nothing on your computer by themselves. Any action that changes your computer is taken only with your explicit approval, and the decision whether to act on a recommendation is yours.
15. Messages and marketing
System messages are shown inside the Software and concern its operation - a new version, for example, or an operational notice. They are not advertising material.
We will not send you advertising material by email, SMS or any other means without your prior explicit consent. Should we wish to send such mailing in future, we will ask for your consent separately and in advance, every message will carry a simple and immediate way to opt out, and an opt-out will be honoured without your having to give a reason - all in accordance with section 30A of the Communications (Telecommunications and Broadcasting) Law, 1982. Opting out of mailing will not affect essential service messages concerning your use of the Software.
16. Minors
The service is not intended for minors under 18 without the consent of a parent or guardian. We do not knowingly collect information from minors without such consent. If you learn that a minor has given us information, contact us and it will be deleted without delay.
17. Security incidents
In accordance with the Protection of Privacy (Data Security) Regulations, 2017, and Amendment 13 to the Law, in the event of a serious security incident involving personal data:
- We will act immediately to stop the incident, limit the damage and prevent a recurrence.
- We will report to the Privacy Protection Authority with reasonable speed, as the law requires.
- We will inform you of the incident, its extent, the kind of information affected and the steps we recommend you take, where that is required.
- We will document the incident and how it was handled.
18. Changes to this policy
We may update this policy from time to time. The updated wording will be published on this page, with the last-updated date at the top. A material change - broader collection, a new purpose or a new recipient, for example - will be brought to your attention in advance by reasonable means, including a notice inside the Software, and at least 14 days before it takes effect.
The binding wording is the one published on this page at the time of use, and continued use after the effective date constitutes acceptance of it.
19. Contact
For any question, request to exercise a right or privacy complaint, write to us at info@pitguy.com
We would be glad if you came to us first - most requests are settled quickly and with no need for anything further. Alongside that, you are entitled at any time to approach the Privacy Protection Authority at the Ministry of Justice.