Privacy Policy

← Back

Last updated: September 28, 2026

Safety & Crisis Resources

This Privacy Policy explains what IsraelGPT ("the Service," "we," or "us") collects when you use israelgpt.site, why, who can see it, how long we keep it, and the choices you have. Read it together with our Terms of Service and our Safety & Crisis Resources page. IsraelGPT is operated privately, under an alias, from the United States. It is a satirical entertainment product and is not affiliated with, endorsed by, or operated on behalf of the government of Israel, any political party, or any religious organization.

The short version

  • We keep what you send and what IsraelGPT replies, encrypted, with your IP address (also encrypted) and network details, for up to 3 years, to investigate abuse and meet legal duties.
  • Your conversation goes to the AI model providers that write the replies. Your IP address, identity and location do not.
  • There are no ads, no advertising or tracking cookies, and we don't sell or share your information for advertising.
  • Your exact location is collected only if you choose Agree and your browser allows it.
  • The chat room is public: anyone can read what you post there.
  • Voice calls are never recorded or logged, and neither person on a call can see the other's IP address.
  • Messages that appear to involve child sexual abuse material are blocked, kept, and reported as the law requires.

1. What We Collect

1.1 When you chat

Every message you send and every reply is kept in a chat log, together with:

  • The message and the reply, encrypted. When a message is blocked for child sexual abuse material, the chat log keeps neither; the text is kept only in the restricted safety record described in Section 3.
  • Your IP address, encrypted, plus a keyed hash of it used to match repeat abuse.
  • Your network (the internet provider or company that owns the address), the data center that served you, and your approximate country, region and city, which our hosting provider works out from your IP address.
  • Your browser's user agent, language and time zone, as your browser reports them.
  • The model, persona and settings you used (such as effort and Uncensored Mode), the length of your message and the reply, how many messages the conversation had, and whether the reply finished, failed or was blocked.
  • Your exact location (GPS coordinates), encrypted, but only if you chose Agree before chatting (Section 8) and then allowed your browser's location prompt. Reject, or denying the browser prompt, means it's never collected.
  • If you are signed in, your account, and your account's email address (encrypted, and cleared if you delete your account).

1.2 Your browser's identity

The first time you chat, after a quick automated check that you are a person (Section 6), your browser is given a random identity. We keep its random id, a private generated handle (never shown to you or anyone else), when it was created and last used, a keyed hash of the IP address and the network and country it was created from, one of our built-in caller names and pictures chosen at random (how you show to others if you are not signed in), and any suspension. A signed cookie in your browser carries this identity (Section 9).

1.3 Accounts

Accounts are optional and free. You can sign in in two ways, neither with a password:

  • With a sign-in provider you choose. The provider tells us your account id with them and your email address. We don't receive your name or profile picture from them.
  • With a code sent to your email. We send a one-time code to the address you enter. The code lasts 10 minutes and is stored only as a keyed hash.

We keep the username and caller picture you choose (shown to others in the chat room and in calls), your email address (encrypted), keyed hashes of your sign-in methods, when you created the account and last signed in, and, for each browser signed in to it, how it signed in, when it was last used, a keyed hash of its IP address, its country and its browser. Settings shows you that list, and you can sign any of them out.

1.4 Saved chats (accounts)

Signed in, your chats are saved to your account so they follow you to every device: each chat's title and messages (encrypted), the pictures and songs replies showed, and when. Guests' chats are not saved on our servers; they last as long as the page. Deleting a saved chat deletes it from your account, but the chat log (Section 1.1) keeps its own copy of each exchange for its retention period.

1.5 About Me and memories (accounts)

You can write a short About Me (up to 500 characters), and while auto-memory is on, IsraelGPT saves short facts about you from your chats (up to 50). Both are encrypted, shown to you in Settings, and editable and deletable there; auto-memory can be switched off. They are added to the AI's instructions in every chat you have while signed in, so they go to the AI model providers along with your conversation (Section 5). Guests have neither.

1.6 The chat room

The chat room is public. Everyone who opens it sees each message's name and caller picture (as they were when it was posted), its text and its time, and, for a reply shared from a chat, the question and the reply (up to 1,500 characters) with the persona and model. They never see your account, identity, IP address or location. For each message we also keep, encrypted where noted: the text and any shared question (encrypted), your browser's identity and account, your IP address (encrypted) with its keyed hash, your network and country, and whether it read as a crisis disclosure. A message taken out of the room (by moderation, or because its account was deleted) disappears from every screen but is kept for the retention period. Reports made with the Report button keep the message reported, who reported it, their optional note (encrypted) and a keyed hash of their IP address, and are emailed to our abuse mailbox.

1.7 Voice calls

  • The online list. While IsraelGPT is open, anyone who takes calls is listed for everyone else by their caller name and picture and a stable, keyed-hash id (never your account or identity). You can switch "Take calls" off in the call list or in Settings, and you won't be listed or called.
  • Never recorded, and no call log. We never receive or store the audio. While a call lasts, our servers hold only what they need to connect and end it: both sides' identities and accounts, names and caller pictures, a keyed hash of each side's IP address, which browser tab each is in, the names of their relay credentials, and when it started. All of it is deleted when the call ends. The operator can see which calls are going on and end one, but can't listen.
  • Nobody sees the other's IP address. Calls always go through a relay run by our hosting provider, and our servers remove addresses from what each browser sends the other. The relay handles both sides' IP addresses and the call's audio, which is encrypted end to end between the two browsers, so the relay can't listen to it.
  • Microphone. Your browser asks for the microphone when you place or answer a call, and the call uses it only while it lasts.
  • Blocks. If you block someone, we keep, for your browser or account, their keyed-hash id and the name and caller picture they had, until you unblock them.

1.8 Contact Support

The Contact Support form sends us your message and, if you give one, a reply-to email address (both encrypted), with your identity, a keyed hash of your IP address, your network and country, and a reference number shown to you so a follow-up can be matched. Each message is also emailed to our support mailbox so we can reply.

1.9 The public API (accounts)

If you make API keys on the dashboard, we store each key only as a keyed hash (plus its last four characters) and its name, encrypted. For each request made with your keys we keep a log you can see on the dashboard: the time, status, model and persona, token counts, how long it took, the calling app's user agent, and the network and country it came from. That log never contains message content or IP addresses. The messages themselves are kept in the chat log (Section 1.1) like web chats, marked with the key.

1.10 Voice input

The microphone button in the message box uses your browser's built-in speech recognition. Your browser (and, for some browsers, its maker's speech service) turns your speech into text. We never receive the audio, only the text you then send.

1.11 What we don't collect

  • No payment details: the Service is free.
  • No advertising: no ads, ad networks or advertising trackers, and no third-party analytics scripts in the page.
  • No uploaded images or files: you can't upload them.
  • No passwords: sign-in uses a provider or an emailed code.
  • Your IP address, identity and location are never put into the AI's instructions.

Please don't put passwords, financial details, or other people's private information into chats. Anything you write is handled as described here.

2. Crisis Messages

Every message you send is checked on our servers for language associated with suicide and self-harm, about yourself or someone else. When one matches, it is not sent to the AI: you get crisis resources instead, and the crisis help appears on screen. The AI is also instructed to stop and point you to help if crisis language reaches it, and when it does, the same help appears. A chat room post that matches is still posted, and the sender is shown the help.

Each time this happens we keep a small safety record: when, the kind of match, whether it was about you or someone else, your identity, a keyed hash of your IP address, and your network and country. That record does not contain your message. The message itself is kept, encrypted, in the chat log like every other message (Section 1.1), and text that reads as a crisis disclosure is never saved as a memory. Details are on our Safety & Crisis Resources page.

3. Child Sexual Abuse Material (CSAM)

IsraelGPT has zero tolerance for child sexual abuse material. What people write is checked on our servers for language referring to it, by any term or euphemism: chat messages (and the earlier messages in a conversation), About Me and memories you write, usernames and API key names, chat room posts and reports, support messages, and requests to the public API. A match is blocked before it reaches the AI or anyone else. The AI's replies, and chats your browser brings into your account, aren't checked; a chat brought over is checked again before any of it is sent to the AI.

What we keep. A match is recorded in a separate, access-restricted safety database: what kind of match it was, where it was found, your identity (and, for the API, the key), your IP address (encrypted) and its keyed hash, your network and country, and the text (encrypted) with a keyed fingerprint of it. Most matches get a refusal and nothing more until a person reviews them. An explicit request for the material automatically suspends the identity and account (for the API, the account) for 24 hours while it is reviewed, and, for someone not signed in, their IP address from most of the Service for as long. The reviewer decides whether to lift the suspension, extend it, or make it permanent.

Review and reporting. Every record is reviewed by a person, and no report is made on the strength of an automated flag alone. Where the review finds apparent child sexual abuse material, we report it, with the information above, to the National Center for Missing & Exploited Children (NCMEC) and/or the appropriate law-enforcement authority, as US law requires (18 U.S.C. § 2258A). These records may be disclosed to law enforcement in response to valid legal process, and are kept for 3 years, even if you delete your account or ask us to erase your data. Automated checking is imperfect: it can miss things and can occasionally flag an innocent message, which is why a person reviews every record.

4. How We Use Information

  • To run the Service: answering your messages, saving your chats and memories, the chat room, calls, and the public API.
  • To personalize replies with your About Me and memories, if you're signed in.
  • To keep the Service safe: rate limits, bot checks, moderation, the crisis and CSAM protocols (Sections 2 and 3), and investigating abuse and attacks.
  • To send you email you asked for or need: sign-in codes, and, if we revoke one of your API keys or suspend your account, the reason, sent to your account's own address. We don't send marketing email.
  • To understand how the Service is used, through counts that contain no message content, IP addresses or identities.
  • To comply with the law, including reporting under Section 3 and responding to valid legal process.

5. Who Can See It and Who We Share It With

We don't sell your information, and we don't share it for advertising. It is seen or handled only by:

  • The operator, through admin tools that require an admin key and a code from an authenticator app. Encrypted fields are decrypted only on the operator's own device. Every admin action (viewing a saved chat, exporting or erasing data, moderation, bans) is written to an audit log that can't be edited.
  • Our hosting and infrastructure provider, which runs the Service, its databases, the automated check that you're a person, rate limiting, usage counts, and the voice call relay, and so handles everything the Service handles, including your IP address. Encrypted fields stay encrypted in its databases.
  • AI model providers, reached through an AI routing service, which receive the AI's instructions and your conversation to write each reply. The instructions include your time zone and when the chat started and, if you're signed in, your About Me and memories. They never include your IP address, identity or location.
  • The sign-in provider you choose, if you sign in with one. It learns that you signed in to IsraelGPT.
  • Our email provider, which delivers sign-in codes and moderation emails to you, and carries support messages and chat room reports to our own mailboxes.
  • A picture service. Pictures in IsraelGPT's replies are loaded by your browser straight from a picture service, which sees your IP address and browser, as with any website. Our own pictures, songs and podcasts come from our servers.
  • Other people, for what's public by design: your posts, name and caller picture in the chat room, and your caller name and picture in the online list and in calls.
  • Law enforcement and NCMEC, as described in Section 3, and anyone we are required to disclose to by law or valid legal process.

These providers handle information only to provide their services to us, under their own terms and privacy policies. If the Service is ever part of a merger, acquisition or sale of assets, information may be transferred as part of it, and we will require any successor to treat it consistently with this Policy. We may share aggregated counts that don't identify anyone.

6. The Check That You're a Person

When the Service is under unusual load, or a lot of new identities come from one network, an automated check run by our hosting provider confirms you're a person before your browser gets or renews its identity, usually without you doing anything. It also runs before we email you a sign-in code. It looks at signals from your browser. Sometimes it asks you to tick a box. This protects the Service from automated abuse.

7. Legal Bases for Processing

If a law that requires a legal basis (such as the GDPR) applies to you, we rely on:

  • Performance of a contract: running the Service you asked to use, including your account, saved chats, memories, the chat room, calls and API keys.
  • Consent: your exact location (only after Agree and your browser's permission), and the microphone for calls. You can withdraw either at any time (Section 8).
  • Legitimate interests: security, preventing abuse and fraud, keeping the chat log to investigate misuse, debugging, and defending legal claims.
  • Legal obligation: the CSAM protocol in Section 3, and responding to valid legal process.

8. Your Choices

  • Agree or Reject. Before you chat, you choose Agree or Reject. Both confirm you're 18 or older and accept the Terms of Service and this Policy. Agree also asks your browser for your location once, and it is kept with your chats. Reject keeps location off. You can change your choice with "Privacy choices" at the top of this page, and turn location off in your browser at any time.
  • Take calls. Switch it off (in the call list or Settings) to leave the online list and stop being called. Block anyone who bothers you.
  • Auto-memory. Switch it off in Settings, and edit or delete your About Me and memories there.
  • Chat room pop-ups. Mute them in the room.
  • Saved chats and your account. Delete chats, sign out other browsers, or delete your account in Settings (Section 11).

We don't give a worse service to anyone who rejects location or turns these off.

9. Cookies and Browser Storage

We use no advertising or tracking cookies. We use:

  • One session cookie, strictly necessary: it identifies your browser to our servers (your random identity, when you last passed the person check, and your account if you're signed in). It is signed, can't be read by the page, and is sent only to IsraelGPT. The identity lasts a year; it's renewed every two hours, which can repeat the person check while the Service is under load.
  • Two short-lived cookies while you sign in: one for the trip to the sign-in provider and back (10 minutes), and one while you finish creating an account (5 minutes).
  • Your browser's local storage, which never leaves your device: your settings (theme, background, model, persona, effort, and switches such as Uncensored Mode and follow-up questions), your Agree or Reject choice, whether you denied the location prompt, how you show (caller picture and username, for display), whether you're signed in, how many messages you've sent as a guest (so the sign-up suggestion shows once), the chat room's mute and how far you've read, whether you take calls, and whether you dismissed the install prompt. Chats a browser kept as a guest before September 27, 2026 also stay there until they're saved to an account or cleared.
  • Session storage, for one tab only: the chat on screen while you go to a sign-in provider and back (deleted as soon as you return), and when the crisis help last appeared, so it doesn't pop up again for ten minutes.

Clearing your browser's data removes all of these; you'll get a new identity and your settings will reset.

10. How Long We Keep It

  • 3 years, then deleted automatically: the chat log (including location and IP addresses), chat room messages and reports, support messages, crisis and CSAM safety records, and moderation emails.
  • Until you delete it (or delete your account): saved chats, About Me, memories, API keys, and call blocks.
  • 30 days: signed-in browsers after their last use, API request logs, and revoked API keys.
  • 10 minutes: sign-in codes. 5 minutes: an unfinished account sign-up.
  • While it lasts: a voice call. Nothing about it is kept afterwards.
  • About a day: rate-limit counters (keyed hashes, never text), or 7 days after a ban. Our hosting provider also keeps short-lived technical logs of requests.
  • Browser identities are kept while in use, with any suspension, and we'll erase yours on request (Section 11). Email in our own mailboxes (support messages and reports we received, and copies of emails we sent) and the admin audit log have no fixed limit.

11. Deleting and Getting a Copy of Your Data

Deleting your account (Settings → Account) removes the account, its sign-in methods and signed-in browsers, saved chats, About Me, memories, API keys and their logs, and call blocks. Your chat room messages are taken out of the room. Some things are kept for their retention period (Section 10), because they exist to investigate abuse: the chat log (with your email removed), your chat room messages, and safety records.

Anything else, including for guests: email support@israelgpt.site to ask for a copy of your data or to have it erased. A copy includes everything tied to your identity and account except CSAM records (which the law requires us to keep and which could compromise an investigation) and internal moderation notes. Erasing removes your identity, its chat log, support messages, crisis records, moderation history, chat room messages (and reports on them), reports you made, and call blocks. CSAM records are kept, as is a suspension that is still running. We may ask you to prove the data is yours, for example from the browser or email address it belongs to.

12. Your Privacy Rights

12.1 General rights

Depending on where you live, you may have the right to access, correct, delete, or get a portable copy of your personal information, to restrict or object to some processing, and to withdraw consent. Section 11 explains how. We won't treat you differently for using these rights.

12.2 California (CCPA/CPRA)

In the last 12 months we collected these categories of personal information: identifiers (such as IP address, email address, and browser and account identifiers); internet activity (your chats and how you use the Service); and precise geolocation, only if you chose Agree and allowed it. We use sensitive personal information (precise geolocation and account sign-in details) only to provide and secure the Service. We do not sell personal information and do not share it for cross-context behavioral advertising. To use your rights, see Section 11.

12.3 Nevada

We do not sell covered information. Nevada residents can still send a request to the address in Section 11.

12.4 European Economic Area, UK, and other international users

You have the rights in Section 12.1 and may complain to your local data protection authority. Because this is a small, privately operated Service, we don't have a representative or data protection officer in the EEA or UK; use the address in Section 11.

13. International Transfers

IsraelGPT is run from the United States and is used worldwide. Your information is processed in the United States and wherever our providers operate, where privacy laws may be less protective than where you live. We rely on our providers' own safeguards for international transfers.

14. Automated Decisions

Some decisions are made automatically. A message matching the crisis check isn't sent to the AI (Section 2). A message matching the CSAM check is blocked, and an explicit request for the material suspends the identity or account for 24 hours until a person reviews it (Section 3). Rate limits can refuse requests for a while, and repeated abuse can block an identity, network or address for a time. If you think an automatic decision was wrong, email abuse@israelgpt.site and a person will look at it. We don't profile you to decide what you're eligible for.

15. Children

The Service is for adults 18 and older and isn't directed at children. We don't knowingly collect information from anyone under 18, and we don't use an age-verification service: we rely on your confirmation when you choose Agree or Reject. If you believe a minor has given us information, contact us and we'll delete it, except where the CSAM protocol (Section 3) requires us to keep records.

16. Security

Connections are encrypted. Message text, IP addresses, locations, email addresses, About Me, memories and other sensitive fields are encrypted before they are stored, and the operator decrypts them only on their own device. Admin access needs two factors, and every admin action is logged. No system is perfectly secure, so we can't guarantee absolute security. If a breach affects your personal information, we will notify you and regulators where the law requires.

17. Other Websites

The Service links to sites we don't run, such as crisis lines, our community spaces, and links people post in the chat room (which open in a new tab). Their own privacy policies apply.

18. Changes to This Policy

When we change this Policy, we update the date at the top, and for significant changes we'll make reasonable efforts to tell you, for example with a notice on the Service. Using the Service after a change means you accept the updated Policy.

19. Contact Us

Privacy questions and requests: support@israelgpt.site. Abuse, or a decision you think was wrong: abuse@israelgpt.site.

IsraelGPT is operated privately, under an alias, and has no public mailing address; email is the way to reach us. Neither address is monitored around the clock: never use them to report an emergency. See our Safety & Crisis Resources page.