[ Privacy policy ]
Privacy Policy
Last updated: August 2026
This Privacy Policy explains how the Bereshit app collects, processes, stores and protects information when you use the app and its services.
The service is operated by Oshri Ben Yizhak, Jerusalem, Israel.
The app is intended for users aged 13 and over.
Information we process
Bereshit is a browser that provides content filtering and protection features.
To evaluate image safety, the app may send the URL of an image detected on a web page to the service’s servers. The app does not directly upload the image file itself; the server retrieves the image from the URL for safety analysis.
Safety-check results may be stored on the server keyed by a content hash of the image and are not linked to a personal user account.
Local browsing history, visited page URLs, search queries, keyword filtering, and domain filtering are handled and stored on the device only and are not sent to Bereshit servers for filtering. Please note that image URLs may be transmitted as part of the safety analysis.
The system may also process operational information required to provide the service, including:
- Job identifiers
- Installation identifiers
- App version
- Model or decision version
- Safety-check results
- Timestamps
- Technical information required for security, abuse prevention and troubleshooting
IP addresses and security data
Client IP addresses may be processed for rate limiting, service security, and abuse prevention.
IP addresses are not maintained as a dedicated user-profile or database field.
Standard request metadata, including IP addresses, may appear in server access logs for operations, security, and troubleshooting purposes.
Information we do not collect
Bereshit does not collect as part of its normal service operation:
- Your full name
- Home address
- Phone number
- Contacts
- Precise location
- Camera or microphone data
- Financial information
- Payment details
- Advertising identifiers
- Information for targeted advertising
- Full web-page content
- Website passwords or login credentials
- Cookies or form data for server-side processing
How we use information
Information is used for:
- Evaluating image safety
- Operating the filtering system
- Returning filtering results to the app
- Protecting the service
- Preventing abuse
- Diagnosing technical issues
- Improving stability and performance
- Handling support and deletion requests
- Complying with legal requirements when applicable
Infrastructure providers
We may use external infrastructure providers, including hosting, server, database, network and GPU-processing providers.
During the beta stage, the service may also use Vast.ai as a temporary GPU infrastructure provider.
These providers process information only as required to provide the technical infrastructure used by Bereshit.
We do not sell personal information and we do not share information with advertisers.
SDKs and tracking
The current production version of the app does not use an advertising SDK, an analytics SDK, or a crash-reporting SDK.
We do not track user activity for targeted advertising and we do not share information with advertising networks.
Data retention
Information is retained only for as long as reasonably required to operate the service, protect it, maintain system integrity, prevent abuse, investigate technical issues, process support and deletion requests and comply with applicable legal requirements.
Raw image URL values in job records are automatically redacted after 7 days.
Other records may be retained as reasonably required for security, operations, support and legal compliance.
We are working to reduce retention periods and remove raw information when it is no longer required.
This policy will be updated when additional automatic retention controls become operational.
Installation and access data
The app does not create a personal user account.
On first launch, the app automatically creates a random installation identifier. This identifier is not derived from a phone number, device serial number, or permanent hardware identifier.
On first launch, the server issues an access credential to the app. The raw credential value is stored in the app using secure storage, and the server stores only a cryptographic digest for authentication.
The information stored on the server does not enable direct personal identification of the user and is required only to operate the service and authenticate the installation.
Information stored on the device
Certain information is stored locally on the device, including app settings, local browsing history, tabs, bookmarks, filtering preferences and operational data.
This local information is not automatically sent to Bereshit servers unless it is specifically required to provide a feature.
Android cloud backup is disabled in the current app version being prepared for distribution, reducing the automatic backup of local browser data to cloud backup services.
Information security
We use reasonable technical and organizational measures to protect information, including:
- Encrypted communication
- Access authentication
- Environment separation
- Permission restrictions
- Keeping secrets outside source code
- Security testing
- Minimizing sensitive information in logs
- Protections against unsafe URLs and abuse
No system can be completely secure, and we cannot guarantee absolute protection in every situation.
Data deletion requests
You may request deletion of information associated with an installation of the Bereshit app.
Requests are reviewed and processed manually.
Opening the request page or sending an email does not immediately delete information.
When an installation can be reasonably identified, we may revoke its associated access and delete or anonymize information that can be linked to it.
Limited non-identifying, aggregated or security-related records may be retained when required for security, abuse prevention or legal compliance.
We aim to respond to and process requests within 30 days.
Open the data deletion pageChildren and teenagers
The service is intended for users aged 13 and over.
We do not knowingly request personal information from children under 13.
If we become aware that personal information was collected from a child under 13 without appropriate authorization, we will take reasonable steps to delete it.
Your rights
Depending on the applicable law, you may have rights concerning your information, including rights to request access, correction, deletion, restriction or objection.
Requests may be sent to:
Changes to this policy
We may update this policy when the service, infrastructure, legal requirements or information-handling practices change.
The latest update date will appear at the top of this page.
Material changes may also be displayed on the website or in the app.
Contact us
For questions about this Privacy Policy or how information is handled, contact:
- Oshri Ben Yizhak
- Jerusalem, Israel
להורדה