שומר ישראל | KidWebGuard
מדיניות פרטיות
הרחבת שומר ישראל עבור Microsoft Edge ו־Google Chrome פועלת עם תוכנה המותקנת במחשב. היא משתמשת במידע על הגלישה כדי לבדוק הרשאות אתרים, זמני גלישה ואישורי תוכן ב־YouTube, וכדי להעביר בקשות אישור להורה.
הגורם האחראי ופניות בנושא פרטיות
Datalog, עוסק מורשה, היא הגורם העסקי האחראי לשומר ישראל. לפניות בנושא מדיניות זו ובקשות עיון, תיקון או מחיקה של מידע שמצוי בידי Datalog, כתבו אל Datalog@outlook.co.il.
בפנייה ציינו את נושא הבקשה ואת פרטי הקשר הדרושים למענה. אל תשלחו סיסמאות, מפתחות פרטיים או מידע שאינו נחוץ לפנייה. מחיקת מידע במחשב, בקובצי יצוא, בגיבויים או אצל ספק חיצוני היא פעולה נפרדת; מגבלות השמירה והמחיקה מתוארות במדיניות זו.
איזה מידע ההרחבה מטפלת בו
- כתובות ותארי דפיםכתובת הדף המלאה וכותרתו, לצורך בדיקת גישה, מדידת שימוש במסגרת הגבלת זמן ובקשת אישור. כתובת מלאה עשויה להכיל פרטי חיפוש ומידע אישי.
- מצב פעילות בגלישהמצב נראות הדף, המיקוד בו והלשונית הפעילה. ב־YouTube נצפים גם אירועי ניגון ואינטראקציה לצורך בקרת המדיה. בבדיקת החבילה לא נמצאה שליחת יומן הקלדות.
- פרטי תוכן ב־YouTubeמזהי סרטון, ערוץ ורשימת השמעה, כותרות, קישורים וקישור לתמונה ממוזערת. בבדיקת החבילה לא נמצאה העלאת קובץ הווידאו או האודיו עצמו.
- הודעה בבקשת אישורהטקסט שהמשתמש בוחר להזין להורה, יחד עם פרטי האתר או תוכן YouTube המבוקש.
- מידע ציבורי לאימות השירותההרחבה קוראת מפתח ציבורי וטביעה שלו ממדיניות הדפדפן ומרכיב מקומי. הטביעה משמשת לאימות תשובות השירות. היא שונה ממזהי ההתקנה והרישוי של התוכנה, ואינה סיסמה או מפתח פרטי.
אין להסיק מתיאור זה שההרחבה אינה מטפלת במידע אישי. כתובות דפים והודעות שהמשתמש מזין עלולות להכיל מידע רגיש.
לאן המידע מועבר
ההרחבה שולחת את נתוני הגלישה ואת בקשות האישור לשירות שומר ישראל באותו מחשב, בכתובת המקומית http://127.0.0.1:18765. השירות מחזיר מצב הגנה, תוצאות בדיקת גישה והחלטות על בקשות.
במקורות שנבדקו לא נמצא מסלול אוטומטי להעלאת היסטוריית הגלישה לשרת Datalog. עם זאת, התוכנה מבצעת פניות חיצוניות לפרטי תוכן ולתמונות, ומאפשרת פעולות תמיכה ויצוא ידני. פעולות אלה מתוארות בהמשך. אין התחייבות שכל נתוני המוצר נשארים במחשב.
ההרחבה משתמשת במידע הציבורי על זהות ההתקנה כדי לבדוק תשובות חתומות של השירות. מנגנון זה אינו הצפנת תוכן התעבורה, ואינו הוכחה שכל חיבור במוצר מוצפן.
מה נשמר בתוך ההרחבה
אחסון ההרחבה המקומי מכיל כתובות יעד של דפים שנחסמו ופרטי חזרה אליהם, סימוני החלטה על בקשות וקישורי יעד של התראות. הפרטים משמשים להצגת החסימה, לחזרה לאתר ולפתיחת הקישור המתאים מהתראה.
קוד ההרחבה מנסה להסיר את רשומת היעד של דף חסום בעת סגירת הלשונית. סימוני החלטות וקישורי התראות מוחלפים לפי רשימת הבקשות העדכנית שהשירות מחזיר. אין בכך הבטחה שכל נתוני ההרחבה או התוכנה נמחקים אחרי זמן קבוע.
כותרת של בקשת אישור יכולה להופיע בהתראת Windows. אדם שיכול לראות את המסך עשוי לראות אותה. במקור שנבדק לא נמצא שימוש בסנכרון האחסון של ההרחבה; גיבוי או סנכרון של Windows ושל פרופיל הדפדפן אינם מכוסים בממצא זה.
מה נשמר בתוכנה המקומית ולמי יש גישה
הנתונים נשמרים בתיקיית הנתונים המשותפת של שומר ישראל במחשב. חלקם מוחזקים גם בזיכרון התוכנה, בעותקים תקינים אחרונים ובגיבויים.
- אירועי גלישהאצל משתמש מוגן שהשירות זיהה, מעבר לכתובת או לדפדפן אחרים יכול ליצור אירוע עם כותרת וכתובת דף מלאה. אין בכך טענה שכל דף או כל פעימת פעילות נשמרים.
- בקשות והחלטות של ההורהפרטי משתמש Windows, יעד, כתובת מקור, כותרת, דפדפן, טקסט הבקשה, מזהה, סטטוס ומועדי יצירה והחלטה. בקשה טקסטואלית יכולה להישמר ללא כתובת.
- זמן שימושסיכומי זמן לכל משתמש ויום, וזמן שימוש במשאב לפי כלל, כגון אתר או יישום. סיכום הזמן אינו רשומת כתובת וכותרת לכל שנייה.
- נתוני YouTubeבקשות ואישורים יכולים לכלול מזהי תוכן, כותרת, ערוץ, תיאור, קטגוריה, משך וקישורי תמונה. חלק מפרטי התוכן נשמרים גם במטמון זמני בזיכרון.
- משפחה, הגדרות ורישוימזהה משתמש Windows ושמות חשבון ותצוגה, תפקיד, כללים, שעות ומכסות; נתוני אימות מקומיים לכניסת ההורה ולשחזור; מזהים המקשרים התקנה ומחשב לבקשה, לרישיון ולמנוי. רישיון ישן עשוי להכיל שם לקוח. גיבוב של מזהה מחשב אינו הופך אותו בהכרח לאנונימי.
אזור ההורה מציג נתוני משפחה ובקשות לאחר אימות. שירות הבקשות של הילד מסנן לפי משתמש Windows מאומת ומחזיר פרטים מצומצמים על בקשותיו. מנהל Windows, שירות המערכת או אדם בעל גישה לקבצים ולמסך עשויים לקבל גישה נוספת בהתאם להרשאות המחשב. ההגנה בפועל של הקבצים וההתקנה לא נבדקה בסקירה הזאת.
משך שמירה, איפוס והסרה
ברירת המחדל לשמירת היומן היא 90 יום. ניקוי בקוד השירות מתבצע פעם ביום כשהשירות פועל והלולאה מגיעה לשלב הניקוי. הוא מסיר אירועים וסיכומי זמן כלליים ישנים, וכן בקשות שהוחלט בהן ושמועד יצירתן קודם לגבול השמירה.
90 יום אינם כלל מחיקה לכל המידע. בקשות שממתינות להחלטה נשמרות מעבר לחלון הזה. במסלול שנסקר לא נמצא ניקוי לפי גיל של שימוש במשאבים. גם הגדרות, זהות, רישוי, גיבויים וקובצי יצוא אינם נמחקים לפי כלל גיל היומן. כשהשירות אינו פועל, אין הבטחת ניקוי במועד.
איפוס נתוני משתמש מסיר בקשות, זמן שימוש, שימוש במשאבים ואירועים שמשויכים אליו, לאחר שמירת גיבוי של ההגדרות. איפוס כללי שומר גיבוי ונתוני אימות, ניסיון וחשבונות Windows. לכן איפוס אינו מחיקה של כל המידע וכל עותקיו.
תוכנית ההסרה משמרת נתוני הגדרות, בקשות, שימוש, רישוי וזהות לצורך התקנה מחדש ושימור הניסיון והמכסות. ניקוי יומנים, מצב וגיבויים מותנה בשחזור ובתוכנית הנתונים. התנהגות ההסרה במוצר מותקן עדיין לא אומתה כאן. הסרה אינה הבטחה למחיקה מלאה, ואינה מוחקת קבצים שיוצאו או נשלחו לגורם אחר.
פניות מחוץ למחשב
- בדיקת פרטי תוכן עשויה לפנות ב־HTTPS ל־YouTube ול־YouTube Music עם מזהי תוכן והקשר הבקשה.
- הצגת פרטי בקשה או ערוץ עשויה להוריד תמונה מספקי Google/YouTube. בירור או הוספת ערוץ עשויים לפנות ל־YouTube.
- כשאין אייקון אתר במטמון או במשאב מובנה, תוכנת ההורה עשויה לבקש מהאתר את קובץ האייקון שלו. במסלול שנבדק לא מתווספים לבקשת האייקון מזהה משתמש Windows, הודעת ילד או כתובת הגלישה המלאה.
הספק שאליו פונים עשוי לראות את בקשת הרשת ואת כתובת הרשת לפי החיבור והפרוקסי. זו מסקנה מן הפניות בקוד; תעבורה אמיתית ומדיניות השמירה של הספקים לא נמדדו בסקירה הזאת.
Datalog: שימוש במידע ללא מכירה וללא פרסום
Datalog היא הגורם העסקי האחראי למוצר שומר ישראל. Datalog מתחייבת לא למכור מידע אישי ולא להשתמש בו למטרות פרסום. ההתחייבות חלה על מידע אישי שמטופל בידי Datalog בקשר למוצר, לרבות מידע שמתקבל לצורך רישוי או תמיכה.
הטיפול במידע לצורך פעולת התוכנה, רישוי ותמיכה מתואר בסעיפי מדיניות זו. פניות לשירותים חיצוניים מתוארות בנפרד; טיפול אותם ספקים במידע כפוף גם למדיניות שלהם.
קבצי יצוא ופנייה לתמיכה
הכנת ZIP תמיכה יוצרת קובץ במיקום שההורה בוחר. היא אינה שולחת אותו. הקובץ אינו מוצפן. נתוני פעילות ורשימת תוכנות אינם נבחרים כברירת מחדל. בפעילות שנבחרה ליצוא נשמר מידע מצומצם: זמן, סוג, כינוי משתמש וכתובת בסיס של האתר, ללא נתיב ופרמטרי חיפוש. רשימת תוכנות שנבחרה יכולה לכלול שם, ספק, גרסה וסוג מקור.
המידע המצומצם עדיין יכול להעיד על תחומי עניין או להכיל טקסט אישי. יצירת הקובץ אינה משחירה את היומן המקורי במחשב, ולא נמצא ניקוי אוטומטי של קובצי יצוא.
קובצי יצוא אחרים מכילים מידע אחר. בקשת עזרה בהגדרה יכולה לכלול שם הורה, גילי ילדים, שעות, אתרים ויישומים מבוקשים והערות. בקשת רישוי כוללת מזהי התקנה ומחשב ופרטי רישוי לפי המצב. פרופיל ילד שמיוצא כולל כללים והערות. אין להניח שכל יצוא מצומצם כמו ZIP התמיכה.
- כפתור דוא״ל פותח טיוטה עם נושא וטקסט. הוא אינו מצרף קובץ או שולח הודעה אוטומטית.
- פתיחת WhatsApp יכולה להעביר טקסט מוכן לספק בתוך כתובת הפתיחה, עוד לפני שליחת הודעת צ׳אט. הפתיחה עצמה אינה שליחת ההודעה.
- פעולת עזרה מרחוק יכולה להפעיל TeamViewer או לפתוח את דף ההורדה שלו לאחר אישור בממשק. תנאי הגישה בפועל אינם מוכחים מההודעה המוצגת.
אם בחרתם לשלוח מידע דרך דוא״ל או שירות חיצוני, גם ספק השירות מטפל בהעברה לפי תנאיו ומדיניותו. הטיפול של Datalog בקובצי אבחון שהתקבלו לתמיכה מתואר בסעיף הבא.
הטיפול של Datalog בקובצי אבחון ובהיסטוריית השירות
לקובצי אבחון גולמיים שנשלחו לתמיכה יש גישה רק לבעלים של Datalog ולאנשי תמיכה שהבעלים יסמיך. הקבצים משמשים רק לטיפול בתקלה שבגינה נשלחו.
Datalog מוחקת את קובצי האבחון הגולמיים שבידיה בתוך 30 יום מסגירת הפנייה. זהו נוהל הטיפול של Datalog בקבצים שהתקבלו לתמיכה. הוא אינו מנגנון מחיקה אוטומטי בתוכנת שומר ישראל ואינו מוחק קבצים מהמחשב של הלקוח.
אפשר לשמור ידע כללי על פתרון התקלה, ללא פרטים מזהים. היסטוריית השירות נשמרת בנפרד: פניית הלקוח, ההתכתבות, פעולות הטיפול והפתרון. כלל 30 הימים אינו חל על היסטוריית השירות, ובמדיניות זו לא נקבע עבורה משך שמירה קבוע.
הכלל אינו חל על מסמכי מנוי או מסמכים שיש חובה לשמור. הוא אינו מבטיח מחיקה של עותקים אצל ספקי דואר או שירותים חיצוניים. לבקשת עיון, תיקון או מחיקה של מידע שבידי Datalog, פנו אל Datalog@outlook.co.il.
ביקור באתר הזה
דפי האתר מתארחים בשירות Sites של OpenAI, באמצעות תשתית Cloudflare. בקוד דפים אלה אין טופסי איסוף, כלי ניתוח שימוש או פרסום, ואין חיבור לתוכנת שומר ישראל או להיסטוריית הגלישה במחשב.
כדי להגיש את הדף, בקשת הרשת מגיעה לספק האירוח. ספקי התשתית עשויים לעבד מידע טכני כגון כתובת IP, מידע דפדפן, זמן וכתובת הבקשה לצורכי תפעול ואבטחה. מדיניות הספקים חלה גם על טיפול זה; אין כאן התחייבות שאין רישום טכני או שכל עותק אצלם נמחק במועד מסוים.
Privacy policy
Updated: 8 October 2026. Datalog — Shomer Israel / KidWebGuard.
KidWebGuard is the browser extension for Microsoft Edge and Google Chrome that works with a parental-control application installed on the same computer. It processes browsing information to check parent-managed website access, browsing-time limits and YouTube content approvals, and to let the protected user request parental approval.
Information processed by the extension
- Full page URLs and titles. These support access checks, time-limit activity reporting and approval requests. Full URLs can contain search terms or other personal information.
- Browsing activity state. Page visibility, focus and active-tab state are processed. Playback and interaction events are also observed for YouTube media controls. The package review did not find transmission of a keystroke log.
- YouTube content metadata. Video, channel and playlist identifiers, titles, links and a thumbnail link are processed. The review did not find upload of the video or audio file itself.
- Parental approval messages. The message a user chooses to enter is sent with the requested website or YouTube content details.
- Public service trust information. The extension reads a public key and its fingerprint from managed browser policy and a local native component to verify service responses. The trust fingerprint is distinct from the application's trial and licensing installation identifiers. It is not a password or private key.
Local transfer and extension storage
The extension sends browsing information and approval requests to the KidWebGuard service on the same computer at http://127.0.0.1:18765. The service returns protection state, access-check results and request decisions.
The reviewed source did not reveal an automatic route that uploads browsing history to a Datalog server. The application does make external content, image and website-icon requests and can open support tools or prepare manual exports, as described below. This policy does not claim that all product data stays on the computer.
The extension uses public installation trust information to verify signed service responses. Signature verification is not transport encryption and does not establish that every product connection is encrypted.
Local extension storage contains blocked-page destination URLs and restoration metadata, parental-request decision markers and notification destination links. The code attempts to remove a blocked target when its tab closes, and replaces request markers and notification links with the latest request list returned by the service. This does not establish a fixed retention period or complete deletion of all extension or application data.
Request titles may appear in Windows notifications and be visible to anyone who can view the screen. The reviewed extension does not use synchronized extension storage. This finding does not cover operating-system or browser-profile backup or synchronization.
Information stored by the local application and access
Data is stored in the application's shared data directory on the computer, with some information also in process memory, last-known-good copies and backups.
- Browsing events. For a recognized protected user, a change of URL or browser can create an event containing the full URL and title. This does not establish that every page or activity heartbeat is retained.
- Approval requests. Windows user identity and display name, target, source URL, title, browser, message, request identifier, status, creation time and decision time can be stored. A text-only request may have no URL.
- Usage. Time totals per user and day, and resource usage per rule, such as a website or application. Time totals are not a URL-and-title record for every second.
- YouTube details. Requests and approvals can include content identifiers, title, channel, description, category, duration and image links. Temporary content caches are also held in memory.
- Family settings and licensing. Windows user identifiers, account and display names, roles, rules, schedules and quotas; local parental sign-in and recovery authentication data; identifiers linking an installation and computer to a request, licence or subscription. An older licence may contain a customer name. A hashed computer identifier is not necessarily anonymous.
The authenticated parent area displays family information and requests. The child's request API filters by authenticated Windows user and returns limited information about that user's requests. Windows administrators, the system service or people with access to files or the screen may have additional access under the computer's permissions. Installed file protections and isolation were not validated by this review.
Retention, reset and uninstall
The default log retention setting is 90 days. The service's cleanup path runs once per day when the service is running and its loop reaches cleanup. It removes old events, general usage totals and decided requests whose creation time is older than the retention boundary.
This is not a 90-day deletion rule for all data. Pending requests are retained beyond the window. No age-based resource-usage pruning was found in the reviewed path. Settings, identity, licensing data, backups and manual exports are not deleted by the log-age rule. Cleanup timing is not guaranteed while the service is stopped.
A user-data reset removes associated requests, general and resource usage, and events after saving a settings backup. A general reset keeps a backup and authentication, trial and Windows-account information. Reset therefore does not erase all data and all copies.
The uninstall plan retains settings, requests, usage, licensing and identity for reinstallation and continuity of trial and quotas. Cleanup of logs, state and backups depends on restoration and the data plan; installed uninstall behavior remains unverified here. Uninstall is not a promise of complete erasure and does not remove files exported or sent elsewhere.
Requests outside the computer
- Content checks can send HTTPS requests to YouTube and YouTube Music with content identifiers and request context.
- Viewing request or channel details can load images from permitted Google/YouTube providers. Channel lookup or addition can contact YouTube.
- When an icon is not cached or built in, the parent application can request a website's favicon. The reviewed icon-request path does not append the Windows user identifier, child message or full browsing URL.
A destination provider may see the network request and network address depending on the connection or proxy. This is an inference from the code's requests; live traffic and the providers' retention policies were not measured by this review.
Datalog: no sale and no advertising use
Datalog is the business responsible for Shomer Israel. Datalog commits not to sell personal information and not to use it for advertising purposes. This commitment applies to personal information handled by Datalog in connection with the product, including information received for licensing or support.
Processing for application operation, licensing and support is described in this policy. Requests to external services are described separately; those providers also process information under their own policies.
Manual exports and support tools
Preparing a support ZIP writes a file to a location chosen by the parent and does not send it. The file is not encrypted. Activity and application-list inclusion are off by default. Selected activity is reduced to time, event type, a user alias and website origin without path or query. A selected application list can include names, vendors, versions and source types.
Reduced data can still reveal interests or contain personal text. Export does not redact the original local log, and no automatic export-file cleanup was found.
Other exports contain different information. Setup-assistance requests can contain a parent's name, children's ages, desired schedules, websites, applications and notes. Licensing requests contain installation/computer identifiers and current licensing details as applicable. A child-profile export includes rules and notes. The support ZIP's reduced-data properties must not be assumed for every export.
- An email action opens a draft subject and body; it does not automatically attach the file or send the message.
- Opening WhatsApp may already transmit prepared text through the opening URL, before a chat message is sent. Opening is not itself sending the chat message.
- A remote-help action can launch TeamViewer or open its download page after UI confirmation. Actual remote-access conditions are not established by the message shown in the application.
If you choose to send information by email or another external service, that provider also handles the transfer under its terms and privacy policy. Datalog's handling of diagnostic files received for support is described below.
Diagnostic files and service history held by Datalog
Only Datalog's owner and support staff authorized by the owner may access raw diagnostic files sent for support. The files are used only to address the problem for which they were sent.
Datalog deletes raw diagnostic files in its possession within 30 days after the support case is closed. This is Datalog's handling procedure for files received for support. It is not an automatic deletion mechanism in the Shomer Israel application and does not delete files from the customer's computer.
General knowledge about the solution may be retained without identifying details. Service history is retained separately: the customer's request, correspondence, support actions and solution. The 30-day rule does not apply to service history, and this policy does not set a fixed retention period for it.
The rule does not apply to subscription documents or documents that must be retained. It does not promise deletion of copies held by email or other external providers. To request access, correction or deletion of information held by Datalog, contact Datalog@outlook.co.il.
Privacy contact
Datalog, an Israeli licensed sole trader, is the business responsible for Shomer Israel. Contact Datalog@outlook.co.il about this policy or requests to access, correct or delete information held by Datalog. Do not send passwords, private keys or information unnecessary to your request. Local computer files, exports, backups and external-provider copies require separate handling as described above.
This website
These static pages are hosted through OpenAI Sites and Cloudflare infrastructure. Their source includes no data-collection forms, usage-analytics or advertising tools, and does not connect to the local Shomer Israel application or browsing history. Hosting providers may process technical request information such as IP address, browser details, time and requested URL for operation and security. Their privacy policies also apply; no universal provider-log deletion period is promised here.