Privacy Policy
Last updated: September 13, 2026
This policy explains what personal data the Makor service processes, where, why, and what you can ask of us. Identity documents and cheques contain sensitive personal data, and we process it under the Israeli Privacy Protection Law, 5741-1981, as amended (Amendment 13). Use of the service is also governed by the Terms of Use.
1. Who is responsible
The service is operated by the operator of this site, who is the owner of the database described here. For any privacy matter, write to us.
This policy covers the hosted service only. A self-hosted copy is operated by whoever installs it; with a local model its data never reaches us or any third party.
2. Where data is kept
The service, its database and its logs run on servers in Israel, hosted by Kamatera.
Reading the documents and signing in are performed by providers abroad — see Transfers abroad below.
3. Uploaded documents
An uploaded image or PDF is used only to extract its fields. It is not stored: it is held in memory while the request runs and discarded when the result is returned. An upload larger than 1 MB is buffered in a temporary file on the server for the duration of the request and deleted when the request ends.
The image, its file name and its size are never recorded, and uploads are never logged.
Extracted values are returned to you. They are saved only if you turn on Store extraction results in the settings; the full result is then kept encrypted until you delete it — one document at a time or all at once.
Documents contain data of special sensitivity, such as identity numbers, dates of birth and bank accounts. When you upload someone else's document, you are responsible for having a lawful basis to do so (see the Terms of Use).
4. What we store
Account: your e-mail address, an internal user id, your role, the time you signed up and were last seen; invitation records (the invited address, who sent the invitation, dates and status).
Per document: time, status, document type, validation verdict, whether a sefach was present, mode (trial or own key), source (web or API), the API key used, engine and model, token counts, processing time, estimated cost, an error code, and a registry summary that names the lists that matched and how many times — without any values.
Settings: your preferences, and your Anthropic API key, encrypted, if you add one.
API keys: a SHA-256 hash, the first 8 characters, the key's name and when it was created, last used and revoked. The key itself is shown once and never stored.
5. Why
To provide the service: to sign you in, run extractions, enforce the trial and rate limits, show you your history and costs, and protect the service against abuse.
We do not sell your data, do not use it for advertising or profiling, do not train models on it, and share it with no one except the providers named below.
6. Transfers abroad
Anthropic (United States) reads the documents: the image, or parts of it, is sent to the Anthropic API for extraction, on our account or on your own key. Under Anthropic's commercial terms, it does not train models on this data, and it deletes API inputs and outputs within 30 days, except where it must keep them longer to enforce its usage policy or to comply with the law.
Clerk (United States) runs sign-in: your e-mail address, sign-in sessions and invitation e-mails are handled by Clerk under its privacy policy, and may be stored in the United States or other countries.
By using the hosted service you consent to these transfers, under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001. If you do not consent, do not use the hosted service — the self-hosted variant with a local model keeps everything on your own machine.
7. Registry checks
Public registries are downloaded to the server in Israel, and documents are checked against them there. No extracted value, name or number is sent to any registry or third party, and searches are not logged.
8. Logs
The extraction engine logs counts and timings — image dimensions, token counts, durations — never images, prompts or extracted values. The web app logs internal ids when an error occurs. The reverse proxy keeps no access log.
9. Cookies and browser storage
Only what the service needs to work: Clerk's sign-in session cookies, NEXT_LOCALE (your language), sidebar_state (the app's sidebar) and theme in local storage. There are no analytics, tracking or advertising cookies.
10. Retention
Stored results are kept until you delete them or the account is deleted. The account, its document records and settings are kept for as long as the account exists. A revoked API key remains as a record. A temporary upload file exists only until its request ends.
When an account is deleted, its document records, stored results, API keys and settings are deleted with it; the invitation record (address and dates) is kept as the record of the access that was granted.
11. Your rights
You may ask to see the personal data we hold about you, to correct it or to delete it — including your account and all its document records — under sections 13 and 14 of the Privacy Protection Law. Send us the request by e-mail; we answer within 30 days.
You can delete stored results and remove your Anthropic key yourself at any time in the settings.
If you believe your data has been mishandled, you may file a complaint with the Privacy Protection Authority.
12. Security
Connections are HTTPS only. Stored results and Anthropic keys are encrypted at rest with AES-256-GCM, API keys are kept only as hashes, and accounts are by invitation.
No system is perfectly secure. If a security incident affects your data, we will act as the law requires, including notifying the Privacy Protection Authority and, where required, you.
13. Changes
We may update this policy. The date at the top shows when it last changed; using the service after a change means you accept the new version.