Privacy and cookies
This is a free catalog. There are no accounts, no signup forms, no ads, and no marketing trackers. The site measures a few basic things, but the measurement writes nothing to your device and reads nothing from it, which is why there is no cookie banner to click. Your accessibility settings stay in your own browser and are never sent anywhere.
Who runs this site
Roye Cristal Libhaber runs this site as a private individual in Israel. Under the GDPR he is the data controller. For anything to do with privacy, write to royecr@gmail.com.
There are no user accounts, no signup forms, no purchases, no targeted advertising, and no visitor profiles. The catalog is free and is not a commercial activity.
No data protection officer is required here, and none has been appointed. Article 37 of the GDPR requires one only for public authorities, for large scale regular and systematic monitoring of people, or for large scale processing of special category data. None of those apply to a small free catalog, so you can write to Roye directly.
Where the site is hosted
The site runs as a Cloudflare Worker inside the operator's own Cloudflare account, on his own domain. Cloudflare is the only hosting provider, and it acts as a processor on the operator's behalf and on his instructions.
To serve a page and protect it, Cloudflare handles ordinary request data: your IP address, your browser type, the time of the request, and the address of the page you asked for. The operator does not build a profile from any of it, does not learn who you are from it, and does not keep a separate copy. The legal basis is legitimate interest under Article 6(1)(f), and the interest is simply getting the page to you and keeping malicious traffic out.
Cloudflare may set a short lived, strictly necessary security cookie to filter automated traffic and block abuse. A cookie like that is part of the infrastructure protection. It is not used for marketing, advertising, or tracking. Its name, domain, and lifetime are set by Cloudflare and can change, so this page does not claim specific values for them.
What the site measures
The site runs its own measurement endpoint. It is same origin, it lives on the site's own Cloudflare Worker, and there is no outside analytics provider, no third party script, and no tracking pixel.
It writes nothing to your device and reads nothing from it. No analytics cookie, no localStorage, no sessionStorage, no browser fingerprinting.
Here is everything a measurement event records:
- The path of the page you viewed.
- The page language, Hebrew or English.
- Which command you copied, when you press a copy button.
- Which category you filtered by, when you pick one.
- How many results a search returned, as a number only.
What the site never records
These things are not collected at all:
- The words you typed into the search box. Only the number of results is kept, never the text.
- Your name, your email address, or any other personal identifier.
- Anything you create in ChatGPT or any other tool. The site never sees it and never touches it.
- Your raw IP address.
- Your browsing on other sites, or any kind of cross site tracking.
What is deliberately not measured
The site computes no visitor identifier of any kind. No cookie, no fingerprint, no hash. A measurement record holds nothing that could link it to another record or to a person.
Said plainly so there is no confusion: the site does not count unique visitors at all. It counts events, not people.
Your raw IP address is not stored and is never written anywhere by the operator.
Why there is no consent banner here
Article 5(3) of the ePrivacy Directive requires consent when a site stores information on your device or reads information already stored there. This measurement does neither, so that rule is not engaged and no consent is required. That is why you were not asked to click a cookie banner.
The processing that happens on the server relies on legitimate interest under Article 6(1)(f) of the GDPR. The interest, stated plainly: to understand which parts of this free catalog are actually useful to people, so that it can be maintained and improved. That means fixing what is broken, removing what does not work, and adding what is missing. Without some form of measurement there is no way to know whether a page or a command serves anyone.
The processing was deliberately kept to the minimum that achieves this. That is why the site keeps the number of search results but not the search words, and why no visitor is identified over time. You have the right to object to this processing, and that right is set out separately below.
What is stored in your browser
Your accessibility choices (text size, high contrast, grayscale, underlined links, reduced motion) and the fact that you dismissed the privacy notice are saved in your browser using localStorage.
They stay on your device. They are never sent to the operator, to Cloudflare, or to anyone else, and they are never used for identification, measurement, or advertising. They exist for one reason: to honor a choice you made, so you do not have to make it again on every visit.
Clearing site data in your browser, or pressing Reset in the accessibility menu, removes them immediately.
The promise about non-essential tools
The commitment that appeared here before still stands, and it is now worded more precisely. No tool will be turned on that writes information to your device or reads information stored on it, without showing you a choice and getting your consent first. That covers non-essential cookies, storage used for measurement, browser fingerprinting, and any persistent identifier.
The measurement described above was built on purpose so that it does neither of those things, which is why it did not trigger this commitment. It was added without asking for consent because consent is not required, not because the promise was dropped.
If a form, advertising, a third party tool, or measurement that does touch device storage is ever added, you will be shown a choice before it runs, and this policy will be updated first.
Emailing the operator
Writing in is entirely up to you. If you do, your email address, your name if you give one, the content of your message, and any files you attach will be kept so the message can be answered, an accessibility request handled, a bug fixed, a privacy question resolved, or a legal right defended. The legal basis is legitimate interest under Article 6(1)(f), and the interest is answering people who get in touch and keeping a reasonable record of what was asked and what was done.
There is no legal or contractual obligation to give any of this, and you are not required to provide it. The only consequence is practical: without a reply address, we cannot write back.
One disclosure worth knowing. The contact address is a Gmail address. That means Google acts as a processor for incoming mail, and the correspondence is stored on Google servers, including in the United States, under the transfer safeguards Google publishes for that service. If you would rather your message did not pass through Google, do not send sensitive details by email. Describe the issue briefly and another channel can be arranged.
Who the data is shared with
Data is never sold, rented, or handed over for advertising or marketing. There are no ad networks, tracking pixels, or social network buttons on the site.
There are exactly two processors: Cloudflare, which hosts, serves, and protects the site, and Google, which handles incoming mail to the contact address.
Beyond that, data would only be disclosed if the law requires it, if a competent authority orders it, or if it is needed to establish or defend a legal claim.
International transfers
The operator is in Israel, and Israel has an EU adequacy decision: Commission Decision 2011/61/EU of 31 January 2011, which the European Commission reconfirmed on 15 January 2024. Transfers from the EEA to Israel therefore need no Standard Contractual Clauses and no extra safeguards.
Cloudflare runs a global network, so request data may be handled outside the EEA. Those transfers rely on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), and for the United Kingdom on the ICO's International Data Transfer Addendum.
Incoming email is stored on Google servers, including in the United States, under the transfer mechanisms Google publishes for that service.
How long anything is kept
These are the actual retention periods:
- Request and security data at Cloudflare: kept by Cloudflare for the short periods it sets for its own security services. The operator holds no separate copy and cannot look up an individual visitor in it.
- Measurement records: written to the hosting platform’s own logs and kept only for the short log-retention window it provides, measured in days. The operator keeps no separate copy and cannot look up an individual visitor in them, because they carry no identifier.
- Emails: kept while the matter is open, and for up to 12 months after it closes as a reasonable record. A message tied to a legal claim, a dispute, or a legal obligation is kept until that need ends and for as long as the relevant limitation period runs.
- Preferences saved in localStorage: they stay on your device until you clear them. The operator does not control them, cannot see them, and cannot delete them for you.
Your rights
Subject to the law that applies to you, which may be the EU GDPR, UK law, or the Israeli Privacy Protection Law including Amendment 13, you have the following rights:
- Access: to find out whether data about you is held, and to get a copy of it (Article 15).
- Rectification: to correct data that is wrong, incomplete, unclear, or out of date (Article 16).
- Erasure: to have data deleted when there is no longer a lawful reason to keep it (Article 17).
- Restriction: to have processing paused instead of deleted, for example while a dispute about accuracy is sorted out (Article 18).
- Portability: to receive data you provided in a structured, commonly used, machine readable format, and to move it elsewhere (Article 20).
- Objection: to object to processing based on legitimate interest (Article 21). Set out separately below.
- Complaint: to lodge a complaint with a supervisory authority. Set out separately below.
How to exercise a right
To use any of these rights, write to royecr@gmail.com and say what you want. There is no fee. You will get an answer within one month. If the request is complicated, or several requests come in at once, you will be told within that month and the answer will follow within three months at the outside.
You may be asked for one extra detail to confirm the request really is yours. It will be used only to verify that, and then deleted.
One honest note, because it matters here. Much of what the site processes cannot identify you at all, especially the measurement records. When there is no way to connect a record to you, it cannot be found, corrected, or deleted for you, and no new identifying information will be collected in order to try. If that happens you will be told so plainly, rather than being told a search was run.
Your right to object
You have the right to object at any time to processing of your data that relies on legitimate interest. On this site that means the measurement described above and the handling of emails you send.
You can object on grounds relating to your particular situation. No legal reasoning and no special wording is needed. A short note to royecr@gmail.com is enough. If you object, the processing stops, unless there are compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish or defend a legal claim.
In practice this is measurement on a free catalog run by a private individual. There is no commercial interest here that would justify refusing an objection, so a request to stop will be honored.
Complaining to a supervisory authority
If you think the processing breaches your rights, you can complain to a supervisory authority. This is in addition to any other remedy, and you do not have to contact us first, although we would welcome the chance to put something right.
The relevant routes are:
- If you are in the EEA: any national supervisory authority you choose, in the country where you live, where you work, or where you believe the breach happened.
- In the United Kingdom: the Information Commissioner's Office (ICO).
- In Israel: the Privacy Protection Authority at the Ministry of Justice.
No automated decision making and no profiling
The site does not carry out automated decision making and does not build profiles, including the kind described in Articles 22(1) and 22(4) of the GDPR.
Nobody is scored or ranked, no automated decision produces a legal effect or anything similar, and content is never tailored to past behavior. Every visitor sees the same catalog.
For visitors in the United States
California's privacy laws, the CCPA and the CPRA, do not apply to this site. The statutory definition of a business requires an entity operated for profit, and this is a free, non-commercial catalog run by a private individual, so the revenue and data volume thresholds are never reached in the first place.
That is why you will not find a "Do Not Sell or Share My Personal Information" link here, and no CCPA notice. Claiming obligations that do not apply would be its own kind of inaccuracy, and we would rather tell you the truth.
What is true for every visitor, whatever law applies: personal information is not sold, it is not shared for cross-context behavioral advertising, and there are no ad networks on the site. A Global Privacy Control signal sent by your browser is honored, although in practice there is nothing here for it to stop.
Privacy laws in other US states, including Colorado, Connecticut, Virginia, Utah, and Texas, set similar applicability thresholds, and those are not met here either.
Security
The site is served over HTTPS only, with HSTS, a Content Security Policy, framing restrictions, and an allowlist of permitted HTTP methods. There are no forms, no file uploads, and no logins.
No security is perfect. The strongest protection here is that the amount of data is deliberately small. What is never collected cannot leak.
Changes to this policy
This policy will be updated if a form, advertising, a third party tool, measurement that touches device storage, or any other service that processes data is added to the site. The date at the bottom marks the current version.
Any material change involving a non-essential tool will be shown to you before it runs, not after.
Official sources on Israeli law
You can read the official sources directly. They are published in Hebrew.
Last updated: 11 September 2026