Privacy Policy
This policy explains what the Safer Browser app ("the browser") keeps on your device, what it sends to Safer's server and why, how long we keep it, and how to ask us to delete it.
In short:
- The browser has no ads and no third-party analytics, and we don't sell data.
- No account is needed. Your history, bookmarks and tabs stay on your device.
- Most filtering runs on the device. Some checks need our server; then only what the check needs is sent, without details that identify you.
- Reports and requests you send are kept by us, so you can see our answer in "My requests".
1. Who we are
The browser is developed and operated by א. אפשטיין טכנולוגיות בע"מ, 24 HaSivim St., Petah Tikva, Israel ("Safer", "we").
For any privacy question, write to [email protected].
2. What stays on your device
This data is kept on your device and is not sent to us:
- Browsing history, bookmarks and open tabs.
- Cookies and data that websites store, and your downloads.
- The picture filter's log: addresses of checked pictures and the result, so the same picture isn't checked again.
- The parental password (only as a one-way hash) and the e-mail address for recovering it.
- Reports and requests not sent yet.
"Clear browsing data" in the menu deletes history, cookies and site data. Clearing the app's data in Android settings, or uninstalling the app, deletes everything on the device.
3. What is sent to Safer's server
3.1 A random installation ID
On installation the browser creates a random ID and sends it to the server to get an access token. The server does not store the ID itself, only a value derived from it (HMAC). It is not the Android device ID or any hardware ID. It is used:
- to limit load and prevent abuse of the server;
- to link your reports and requests to "My requests", so you can see our answers.
Uninstalling the app or clearing its data creates a new ID. After that your earlier requests no longer show in the app, but they stay on our server until you ask us to delete them (section 7).
3.2 Picture and video checks (only after consent)
On first launch, after the terms of use, the browser shows a screen that explains what is sent, and nothing is sent before you tap "Agree". This check is part of the filtering, so consent is a condition of using the browser: without it the browser doesn't open. After consent it sends:
- For each picture checked: a fingerprint (hash) of the picture, the result of the check on the device, and the picture's address with anything that looks like an identifier or key removed. The picture itself, the page's content and the page's address are not sent.
- For a video that opens: the video's ID, to know whether it was reviewed and approved.
- In the open track: once a day, the names of new sites you visited (site name only), without any identifier, so we know which sites to check.
Picture check results are stored with a tag per picture. The tag doesn't tell who sent it; Safer could link it to an installation only with the server's secret key, and we don't. Video IDs and site names are not stored with any identifier of yours.
The browser also downloads the files of the picture model from the server. Only the access token (3.1) is sent for that.
3.3 Allow-list tracks
In the tracks that open only sites we checked, the browser sends the server the address of the site you open (site name and path, without parameters), to know whether to open it. The server answers and does not store the address. The answer is kept on the device for 24 hours so it isn't asked again.
3.4 Block-list updates
From time to time the browser downloads updated lists of sites and ads to block, without any identifier. As with any internet request, the server sees the IP address and the usual technical details of the request (such as the device model and Android version).
3.5 In incognito
From incognito tabs no pictures and no site names are sent. Only video IDs (3.2) and addresses in allow-list tracks (3.3) are sent, because without them the browser can't tell whether to open them, and reports and requests you send yourself (section 4).
4. Reports and requests you send
When you report a page or a picture, ask to open a site, ask to change a category or send a video for review, the dialog shows what will be sent, and nothing is sent before you tap "Send". Depending on the request, it sends:
- the page's address and title, and the picture's or video's address;
- a screenshot and the page's content. Anything typed in forms, e-mail addresses and long numbers (such as phone, ID or credit card numbers) are hidden before sending;
- what you wrote in the note and in messages to our team.
The request is stored with the installation ID (3.1), so you can see it and our answer in "My requests". Only Safer team members who handle requests can see them.
5. Third-party services you use
- Websites: as in any browser, the sites you visit receive your requests, under their own privacy terms.
- The search engine you chose in settings receives what you search for.
- AI services (such as ChatGPT): to keep browsing clean, the browser adds instructions to the questions you send to these services. The instructions limit answers on unsuitable subjects and aren't shown in the conversation. They go to the service itself, not to us, and with a signed-in account the service keeps them as part of the conversation.
- The device's autofill service (such as Google or Samsung Pass), if you chose one in Android's settings: it saves and offers passwords and details you typed in forms on websites. They are kept by that service, not by us. From incognito tabs the browser doesn't pass forms to it.
- Google Translate: when you ask to translate a page, its address and content are sent to Google. The browser says so before every translation.
- Google Pay: when a site offers Google Pay, the payment goes through Google. The browser doesn't receive payment details.
- Google Safe Browsing: Android's web view (WebView) checks addresses against Google's list of dangerous sites, to warn about phishing and malware.
6. Device permissions
- Camera, microphone and location: only when a site asks, through Android's permission dialog. The data goes directly to the site, not to us.
- Notifications: only for background playback and for an answer in "My requests".
- We have no access to your contacts, messages, calls, photos or other apps.
7. How long we keep data, and how to delete it
| Data | Kept |
|---|---|
| Screenshots and page content from reports | Deleted 30 days after the request is closed |
| Request details, notes and messages | Until you delete them in "My requests", or ask us to |
| The installation ID (as an HMAC) | Kept without any content, only to limit load and block abuse |
| Picture check results, video IDs and site names | Without limit; they are not linked to you (section 3.2) |
You can delete all your requests at any time: "My requests" → ⋮ → "Delete all requests". They are deleted from the device and from the server, with their conversations and screenshots. What was already decided because of them (a site opened or blocked, a video approved or blocked) stays. See Deleting your data.
8. Where data is kept and how it is secured
Our servers are hosted by a cloud provider in Europe, so data is stored outside Israel. Traffic between the browser and the server is encrypted (HTTPS). Access to requests is limited to authorized team members, each with a password and their own permissions.
9. Children
The browser is not directed at children under [13 / 18, per the target-audience decision]. Parents can install it on a child's device and lock the filter settings with a password.
10. Your rights
Under Israel's Privacy Protection Law you may ask to see the data kept about you, correct it or delete it. Write to [email protected] and we will answer within 30 days.
11. Changes to this policy
When we change the policy we update the date here. If a change widens what is sent to us, the browser asks for your consent again.