Last updated: September 15, 2026
This Privacy Policy explains what information is collected when you use the Personal IT Guy software (the "Software") and its website (the "Site"), where it comes from, why it is collected, to whom it may be disclosed, how long it is kept and what rights you have over it.
It is written in accordance with the Israeli Protection of Privacy Law, 1981, including the Protection of Privacy Law (Amendment No. 13), 2024, and the regulations enacted under it - chiefly the Protection of Privacy (Data Security) Regulations, 2017, and the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001.
Scope - both systems
- The Software: what is stored on your computer, what it sends to us, and what it sends directly to an outside service.
- The Site: cookies, browser local storage, details submitted through it, and server logs.
This policy covers both. Where the two differ, it says so explicitly.
What is not here, and is better said up front: there is no online sale, no card processing, no marketing mailing list, no paid advertising, no pixels, no analytics tooling and no audience targeting - neither on the Site nor in the Software. The service is not built on collecting information, so the amount of information it collects is deliberately small.
1. Who is responsible for the data
Service operator and owner of the database: Personal IT Guy.
Address: Rishon LeZion, Israel
Email: info@pitguy.com
The contact person for privacy matters is the service operator. Every privacy enquiry is handled by them directly, at the email address above.
1.1 The database's status under Amendment 13
Amendment 13 to the Protection of Privacy Law, which came into force on 14 August 2025, abolished the duty to register most private databases with the Database Registrar and replaced it with internal management and documentation duties. Our database is not one of the kinds that remain registrable: its main purpose is not collecting information in order to pass it to others, it does not belong to a public body, and it does not hold specially sensitive information about a large number of people.
The scale of the activity and of the data also does not require appointing a data protection officer or a data security officer. That said, we keep the internal documentation the law requires, including a database definitions document, and we work to the data security regulations at the security level that applies to us.
2. The guiding principle - your diagnostics stay on your machine
Every check the Software runs - processor, memory, drives, graphics card, battery, network, temperatures, processes, services, installed software, display, audio, camera, microphone, input devices, machine security and the server tools - runs locally on your computer. Its results, the reports, the chat history and the settings are stored on your machine only.
We do not scan your computer remotely, we do not run commands on it remotely, we do not upload files from it, we do not see its contents, and we do not know what you checked, when, or what came out of it. The Software does not transmit results automatically, and it collects no usage data (telemetry) of any kind.
The one exception is remote monitoring (section 4.8) - an option that is off by default, and runs only on a machine where you explicitly switched it on, and only until you stop it. On such a machine, and only there, the Software reports the machine's state to our server and carries out a fixed set of actions the administrator asks for. On a machine where remote monitoring was never switched on, everything in the paragraph above holds in full.
3. What is stored on your computer and never reaches us
The Software keeps an encrypted settings file in your user's own data folder. Among other things it holds:
- Your personal API key for the artificial-intelligence service.
- Chat ratings and your conversation history with the assistant.
- The console accounts you saved (SSH, Telnet, ADB), including usernames and passwords.
- The unlock code for the system log - stored as a one-way hash (SHA-256), never as text.
- The registration details you gave in the setup wizard, your preferences, language, text size and window position.
- Reports you produced and stress-test results, as files on your own machine.
Not one item on that list is sent to us or backed up by us. The reports the Software produces never include the settings file - so no API key, no conversation history and no console accounts.
Please note: a report you choose to send to a technician or anyone else does contain your machine's hardware and software details, and who receives it is entirely under your control.
4. What does reach us, and where it comes from
4.1 Registration details
Provided by you in the setup wizard.
A full name and an email address are required to complete the wizard, and the email address serves as your user identifier. Phone number, business name and headcount are optional and may be left blank. The details are stored in our database together with the date you registered.
4.2 Activity marker
Created in the course of use.
If an email address was provided, it is sent to our server each time the Software starts in order to update your last-used date. That is all that is recorded: the email address and the latest timestamp. We do not record what you did in the Software, which screens you visited or which checks you ran.
4.3 Routine requests to our server
Collected automatically.
The Software contacts our server to check whether a new version has been published, to fetch system messages, to read operational settings and to show the legal documents in their current wording. As with any browsing, these requests expose your IP address, the time of the request and its technical details, and they are written to the server log for operations and security.
4.4 The feedback form inside the Software
Provided by you.
If you send feedback from within the Software, what reaches us is the kind of enquiry, the text you wrote, your name and email address if you filled them in, the version number, the operating system, the interface language and the screen the message was sent from - along with a screenshot, if you chose to attach one. The message reaches us as an email and is not stored in the database.
Screenshots: a screenshot may include personal information that happened to be on screen at that moment. Attaching it is your choice, and it is worth checking what is visible in it before sending.
To prevent abuse of the form we keep a send-rate counter identified by a one-way hash of the IP address, which deletes itself after a day.
4.5 Enquiries to us by email
Provided by you.
We keep the enquiry and the contact details in it in order to handle it and to record how it was handled.
4.6 Requests for public information through our server
Created in the course of use.
When the Software checks who owns a domain or an IP address, it asks the authorised registry directly. Only when the network you are connected to blocks that direct request does the query pass through our server, which forwards it to the registry. In that case the query is exposed to our server in passing only and is not stored.
A lookup of your public IP address is answered from tables held on our own server rather than against an outside location service - precisely so that no outside party receives a list of which users were online and when.
4.7 The Site's admin area
For the service operator only.
It holds a username, a password as a one-way hash, the last sign-in time, "remember me" tokens and a failed-login counter keyed by IP address. There are no outside users in this area.
4.8 Remote monitoring (opt-in only)
Sent from the machine, only after you switched it on yourself.
The Software includes an option, off by default, to report the machine's state to our server so that the administrator can follow it remotely and receive alerts. It is switched on only if you explicitly approved it on the consent screen inside the Software and typed an enrolment code, or a username and password, you received from us.
While it is on, the Software checks with the server every few seconds whether the administrator is watching the machine (that check sends no data), and tells the server in a single word when it closes, when the machine goes to sleep or when it shuts down (that word carries no data either).
The routine report is sent every few minutes - and every few seconds while the machine is being watched - and carries: processor load, memory in use, free space on each drive, network rate, time since power-on, the name of the program using the most processor, the processor, graphics card and drive temperatures and the graphics card load where they are measured, whether a restart is pending, the notices the Software itself shows in its bell when they change, the Software version, the machine's address on its own network, its time zone and its own time, whether the Software is locked with an entry code, and the answers to the actions the administrator asked for, where there are any.
The hardware and software description is sent once a day, and whenever the administrator asks, and carries: the machine's name and the Windows user name, the email address entered in the Software, machine and board model, processor, memory, drives (including serial numbers), graphics card, battery if there is one, the Windows version and which of its features are on, protection state (Defender and the firewall), whether an update is pending, the number of installed programs, the list of installed programs (name, version and publisher) and which of them winget can update, the notices the app itself shows in its bell, the last Computer Doctor score, and how the Software is installed on the machine - for every user or for one, and whether the helper service is running.
What is never sent: files, browsing history, passwords, document contents or screenshots.
The data is encrypted in transit and stored encrypted on our server, and it is seen by the administrator and, for the machines they connected with them, by whoever received a username and password from us.
A helper service on the machine. When monitoring is switched on with a username and password, a Windows service named "Personal IT Guy" is installed on the machine as well. It is needed for the things the operating system does not allow without administrator rights - installing updates, reading drive temperatures, updating the Software itself, and a handful of checks that have no answer without it. Windows asks for administrator approval once, at installation. The service runs a fixed list of predetermined operations and collects nothing of its own; everything sent from the machine is what this section describes. It is removed when monitoring is stopped or the Software is uninstalled.
The actions the administrator can ask for remotely, and these are all of them:
- Ask for a fresh hardware and software inventory, and change the report rate.
- Ask for the installed programs to be updated, all of them or one. The update runs in the background, with no window and at low priority, only when the machine is not busy, touches only programs that install silently, and restarts nothing.
- Install the waiting Windows updates. This needs administrator rights on the machine - the helper service supplies them, and without it the Software has to be running as administrator. The machine is never restarted by itself.
- Update the Software itself to the release on the site. It is installed quietly only while nobody is using the Software, which then opens again by itself.
- Run an internet speed test - the Software moves test data to and from a measurement server for about half a minute, and reports only the speeds, the round-trip time and the kind of link.
- Check the activation state of Windows and its updates - the licence state and kind, the last five characters of the key, the version, the date of the last update and the list of waiting updates are sent.
- Check the machine's network - its internal and public address, the router, the kind of link, the network adapters, and the findings of the network doctor and the slowness check.
- Scan the local network - the address, hardware address, name, maker and kind of every device that answers.
- Send a ping from the machine to an address of their choosing.
- Trace the route (traceroute) from the machine to an address of their choosing, and find the bottleneck along the way.
- Run the computer doctor - the Software's own troubleshooting findings.
- Read a technical sheet of the machine - identity, hardware, drives, and the network adapters with their MAC addresses.
- Check the machine's heat - every temperature the sensors expose (processor, graphics card, drives, board, battery and fans) watched for about twenty seconds.
- Measure the read and write speed of a drive of their choosing - a 256 MB test file is written, read back and deleted.
- Read the last days' failures (a day up to a week, the administrator's pick) from the Windows event log - program crashes, Windows failures, hardware errors, blue screens and unexpected shutdowns, with the explanation the Software gives them.
- Collect the machine's network data - the adapters and their addresses, the router, the wireless network, the DNS servers, the routing table, the proxy, the open connections and their processes, the neighbours on the network and the hosts file.
- Ask the machine to send a Wake-on-LAN packet to wake another machine of yours on the same network - only the wake packet is sent.
- Restart the machine with a normal restart - half a minute's notice; open programs are asked to close and are never forced.
- Reset the graphics driver - Windows' own Win+Ctrl+Shift+B combination; the screen flickers for a second and no program closes.
- See the processes running on the machine - name, path, and how much processor and memory each uses - and close a process or restart it, as in Task Manager. System processes themselves are never closed.
- Set or clear an entry code for the Software on this machine. The code locks the Software and nothing else; the files and the machine itself are not locked.
- Empty the Software's own activity log on the machine.
The administrator cannot run other commands, see the screen or reach files.
You can stop monitoring at any moment from the same screen in the Software; stopping deletes the identification key from the computer and tells the server, and the administrator can also remove the machine from their side. The Software shows exactly what is sent, before consent and after it.
4.9 The machine's location (only on machines where remote monitoring was switched on)
Sent from the machine, only while monitoring is on.
So that the administrator can tell where each machine on their list is, the report also carries the place the machine is in: a country, a region and a city, and nothing finer. This clause applies only to machines on which you switched remote monitoring on under section 4.8, and only while it is on; on a machine without remote monitoring no location information is collected or sent at all.
All of it can be switched off. The settings screen inside the Software carries a switch, in the "The machine’s location" row, that stops everything in this clause: the position is neither measured nor sent, the Software does not ask Windows for a position at all, and Windows does not contact Microsoft’s location service on this machine’s behalf. The report carries an explicit refusal, so the machine is not given a position by another of your machines on the same network either (see below). The administrator’s screen then shows the internet address alone - the same address every website you visit can see - and nothing else about the report changes. The switch can only be turned back on at the machine itself.
The place is worked out in this order:
- First Windows' location service, if it is switched on and desktop applications are allowed to use it.
- If not, the position another of your machines measured for itself, where that machine is on the same local network and behind the same internet address. In that case the screen names the machine the position came from, and nothing further is collected from any machine.
- If that is not available either, the country set in that machine's own Windows region settings, which is read from the machine itself and needs neither a permission nor an internet connection.
- And if that is unknown too, from the connection's public internet address, as before.
When Windows' location service is the source, the coordinates are sent to our server, matched there to the nearest place name from local tables held on the server, and deleted immediately afterwards - they are not stored, not displayed and not passed to anybody; what is kept is the name of the place only.
A reading whose accuracy is worse than five kilometres is not treated as a position and is not sent at all - a machine with no Wi-Fi and no receiver is given a circle tens of kilometres wide by Windows, which is an answer about a country rather than a location.
Windows' location service is Microsoft's: when it derives a position from the wireless networks around the machine, the operating system itself contacts Microsoft's location service - that is Windows doing its own work, not our Software. You can switch location access off at any moment in the Windows settings, and the place is then worked out by the other means.
The Software's monitoring settings say which of them the current answer came from. That screen also shows the point that was measured and can open it on Google Maps - opening the map is your own request to Google from your own browser, not a request made by the Software.
5. Purposes of use, the basis for processing, and the statutory disclosure
In accordance with the disclosure duty in section 11 of the Protection of Privacy Law we clarify: you are under no legal obligation to give us any information, and providing it is done of your own free will and with your consent. That said, a full name and an email address are needed to complete registration in the Software, and without contact details we cannot identify you, provide personal support or notify you about updates. The information is stored in the service's database, and access to it is limited to the service operator alone.
| Purpose | Basis for processing |
| Identifying the user and managing the relationship | Your consent at registration, and providing the service you asked for |
| Support, answering enquiries and handling feedback | Providing the service you asked for, at your request |
| Recording a registered user's most recent activity | A legitimate interest in running the service and identifying accounts no longer in use |
| Version updates and operational system messages | Providing the service, and a legitimate interest in keeping it sound and secure |
| Server logs, the failed-login counter and rate limits | A legitimate interest in protecting the system, and a duty under the data security regulations |
| The artificial-intelligence capabilities | Your separate, explicit consent in a dedicated document, using your own personal key |
| Remote monitoring of a machine, alerts, and maintenance actions at the administrator's request | Your separate, explicit consent on the consent screen inside the Software, and providing the service you asked for |
| Meeting legal duties and legal proceedings | A legal obligation |
We carry out no marketing mailing, no marketing segmentation, no behavioural analysis and no consumer profiling.
6. Artificial intelligence - what is sent, to whom, and when
The AI capabilities work against Google LLC's Google Gemini service, and only after you approve the dedicated "Use of AI" document and enter your own personal API key. Until that document is approved the capabilities stay frozen, and the approval can be withdrawn at any time from the About screen - withdrawal freezes them immediately.
- The key is stored encrypted on your computer and is never sent to us.
- Queries go directly from your computer to Google's servers, not through our servers. We do not see, collect or store the content of your conversations.
- Relevant diagnostic data from the machine may be sent alongside your question - the processor model, the amount of memory or a test result, for example - so that the answer is accurate.
- To save repeated queries, the Software produces a numeric representation of your question (an
embedding), also against Google's service, and compares it with earlier questions. This means the text of the question used for that comparison also goes to Google.
- You must use a key with Billing enabled. On the free tier Google may use submitted content to train and improve its models, so a free-tier key must not be used.
- Such use is also subject to Google's terms of service and privacy policy.
Warning: do not enter sensitive information into the AI fields - ID numbers, payment-card details, medical information, passwords or trade secrets.
7. Outside services the Software contacts directly from your computer
Some checks cannot be made without reaching outside the machine. In those requests your computer is exposed to the service it contacted, exactly as in ordinary browsing - the request leaves from you and does not pass through us, and we do not see it.
| Service | When, and what for |
| Google (the Gemini service) | The AI queries, only after your approval and with your own key |
| Cloudflare | The connection speed test and the line-under-load test. Only data packets are sent and received, with no identifying details |
| ipify, ifconfig.me, icanhazip | Public-IP lookup, as a fallback only, if our own server is unreachable at that moment |
| Domain and address registries (RDAP and WHOIS), and IANA's referral table | In ownership checks for a domain or an address |
| DNS servers, routers and devices on your own network | In the network checks, according to what you asked to check |
| GitHub | Only if you explicitly choose to install the optional sensor driver. The file's digital signature is verified before it is run |
| OpenStreetMap | Only if you press the map button. The coordinates are handed to your browser, and no map is embedded in the Software |
| Microsoft (Windows' location service) | Only on a machine where remote monitoring was switched on and Windows' location service is on. That request is made by the operating system itself, not by the Software - see section 4.9 |
| Our own server | Version check, system messages, operational settings, legal documents and downloading the installer |
These requests follow the action you asked for. We receive nothing from them, and we do not know which sites, addresses or devices you contacted.
8. Cookies and local storage on the Site
These are all the cookies the Site sets, and it sets no others:
| Cookie | What for | How long |
| The session cookie | A secure sign-in to the admin area and the security tokens (CSRF) that protect the forms | Deleted when the browser closes |
PITG_REMEMBER | The admin's "remember me" token. Set only when it was explicitly requested at sign-in | 7 days, renewed on each sign-in |
pitg_lang | The interface language you chose. Set only when you actually change the language | A year |
pitg_cookie_ok | A marker that the cookie notice has been shown to you, so it does not reappear on every visit | A year |
The first two are essential to the Site's operation and security and cannot be disabled; the last two hold a preference and nothing more. None of them contains a personal identifier, and none of them follows you across sites.
Browser local storage holds the display mode (light/dark) and the accessibility settings you chose. These stay in your browser and are not sent to the server.
The Site has no advertising cookies, no pixels, no traffic analytics, no session recording and no third-party tracking of any kind.
The Site's fonts: the Site loads its Hebrew fonts from Google's font service, so when a page loads, your browser's IP address is exposed to Google's servers. There is no cookie in that, no persistent identifier and no tracking of your browsing - but it is a request to an outside server, and so it is stated here explicitly.
You may block or delete cookies through your browser settings; some Site functionality may be impaired.
9. Disclosure to third parties
We do not sell, rent, trade or transfer your personal information to any third party for any commercial purpose. Information will be disclosed to a third party only where:
- You gave explicit consent.
- A legal duty, a judicial order or a demand from a competent authority applies - and only to the extent required.
- It is needed to defend our legal rights in proceedings.
The hosting and infrastructure provider that hosts our server acts as a data holder on our behalf, is bound to confidentiality and to reasonable security measures under the law, and may not make independent use of the data.
10. Transfers outside Israel
Our database, which holds the registration details, is hosted in Israel.
Two transfers outside Israel take place as part of the service, and both leave from your computer or your browser rather than from our database:
- The AI queries, transferred to Google's servers outside Israel, under the separate consent you gave and subject to Google's policies.
- Operational requests to the outside services listed in section 7, including the loading of the Site's fonts.
These transfers are made in accordance with the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 2001, to countries and to bodies subject to a duty of confidentiality and an adequate level of data security.
11. Data security and backups
We apply reasonable and accepted technical and organisational security measures, suited to the security level that applies to the database under the Protection of Privacy (Data Security) Regulations, 2017. Among them:
- An encrypted connection (HTTPS/TLS) for all Site and API traffic.
- Passwords stored only as one-way hashes, which cannot be reversed.
- A strict content security policy in the browser (CSP), CSRF tokens and security headers on every page.
- Protection against SQL injection through prepared statements only.
- Rate limiting and a temporary lock after failed sign-in attempts.
- Direct access to the database file and to the internal folders blocked from the network.
- Permissions kept to the minimum required, on a need-to-know basis.
- The Software's feedback form is cryptographically signed with a timestamp, so a message that did not come from the Software itself is refused.
- The Software's settings file on your computer is stored encrypted.
- Remote monitoring reports are encrypted in transit and stored encrypted on the server, and each machine is identified by a key of its own that is deleted from the machine the moment monitoring is stopped.
- An automatic daily backup of the database, kept in a folder unreachable from the network, and verified.
That said, no online system can be guaranteed absolutely secure. We are not responsible for malicious acts by third parties that could not have been foreseen or prevented by reasonable effort.
12. Retention periods
| Kind of information | Retention period | Reason |
| Registration details (name, email, phone, business, headcount) | While the account is active, and up to 24 months from the last use | Running the service and providing support |
| The last-used date | Updated on each launch, and deleted together with the registration details | Identifying accounts no longer in use |
| Feedback messages and email enquiries | Up to 24 months after the matter is closed | The record, and repeat handling |
| Screenshots attached to feedback | Deleted together with the message they were attached to | No separate retention needed |
| Server logs | Up to 12 months | Operations and security |
| Remote monitoring reports - full detail | One day | Following the machine's state from moment to moment |
| Remote monitoring reports - hourly summaries | 30 days | Graphs and comparison over time |
| A monitored machine's hardware and software description, including the place it is in (country, region and town) | Replaced by each new report; when monitoring is stopped, all of that machine's data is deleted within 30 days | Identifying the machine and supporting it |
| The feedback send-rate counter | Deleted automatically after 24 hours | Preventing abuse |
| The admin-area failed-login counter | Deleted automatically within 15 minutes | Protection against intrusion attempts |
| The admin's "remember me" tokens | 7 days, and deleted by themselves on expiry | Convenient secure sign-in |
| Database backups | Up to 30 daily copies; an older one is deleted as a new one takes its place | Recovery after a failure |
| Information subject to a retention duty in law | For as long as the law requires | A legal obligation |
| Information after a deletion request | Deleted within 30 days, except what the law requires us to keep | The data subject's right |
At the end of the period the information is deleted or de-identified.
13. Your rights
Under the Protection of Privacy Law, 1981, and Amendment 13 to it, you have the following rights:
- The right of access (section 13 of the Law) - to review the information held about you in the database.
- The right of correction (section 14 of the Law) - to ask that information which is inaccurate, incomplete, unclear or out of date be corrected.
- The right of deletion - to ask that the information be deleted, subject to retention duties in law.
- The right to know the source of the information - where it was not provided by you directly.
- The right to withdraw consent - including withdrawing approval for the use of artificial intelligence and stopping remote monitoring, at any time and without giving a reason.
- The right to object to direct marketing (section 17f of the Law) - the right is yours at any time, even though we carry out no marketing mailing.
- The right to complain - to the Privacy Protection Authority at the Ministry of Justice.
To exercise any of these rights, email us at info@pitguy.com with "Privacy" in the subject line and details that allow us to identify you. We may ask you to verify your identity before releasing information, so that personal information is never handed to someone it does not belong to.
We will respond within 5 business days, and in any event no later than the period set by law - 30 days.
14. Automated decisions, recommendations and profiling
We carry out no profiling, no user segmentation and no automated decision-making with legal or financial consequences for you.
The Software presents scores, recommendations and explanations - including answers produced by the AI assistant. These are aids only: they rest on measurements from your own machine and on a model that is not always accurate, they do not constitute professional advice, and they change nothing on your computer by themselves. Any action that changes your computer is taken only with your explicit approval, and the decision whether to act on a recommendation is yours.
15. Messages and marketing
System messages are shown inside the Software and concern its operation - a new version, for example, or an operational notice. They are not advertising material.
We will not send you advertising material by email, SMS or any other means without your prior explicit consent. Should we wish to send such mailing in future, we will ask for your consent separately and in advance, every message will carry a simple and immediate way to opt out, and an opt-out will be honoured without your having to give a reason - all in accordance with section 30A of the Communications (Telecommunications and Broadcasting) Law, 1982. Opting out of mailing will not affect essential service messages concerning your use of the Software.
16. Minors
The service is not intended for minors under 18 without the consent of a parent or guardian. We do not knowingly collect information from minors without such consent. If you learn that a minor has given us information, contact us and it will be deleted without delay.
17. Security incidents
In accordance with the Protection of Privacy (Data Security) Regulations, 2017, and Amendment 13 to the Law, in the event of a serious security incident involving personal data:
- We will act immediately to stop the incident, limit the damage and prevent a recurrence.
- We will report to the Privacy Protection Authority with reasonable speed, as the law requires.
- We will inform you of the incident, its extent, the kind of information affected and the steps we recommend you take, where that is required.
- We will document the incident and how it was handled.
18. Changes to this policy
We may update this policy from time to time. The updated wording will be published on this page, with the last-updated date at the top. A material change - broader collection, a new purpose or a new recipient, for example - will be brought to your attention in advance by reasonable means, including a notice inside the Software, and at least 14 days before it takes effect.
The binding wording is the one published on this page at the time of use, and continued use after the effective date constitutes acceptance of it.
19. Contact
For any question, request to exercise a right or privacy complaint, write to us at info@pitguy.com
We would be glad if you came to us first - most requests are settled quickly and with no need for anything further. Alongside that, you are entitled at any time to approach the Privacy Protection Authority at the Ministry of Justice.