Privacy Policy
PickOk is a dating app built to hold as little as possible about you. This document explains exactly what we collect, why, how long we keep it, and how to make us stop.
PickOk Privacy Policy
Version 2.0 — effective 12 August 2026. This replaces the version dated 10 August 2026. A list of what changed is at the end, under Changes to this policy.
PickOk tells you that another single person is physically near you, right now, so you can look up and walk over. Doing that means knowing where you are, often, including while your phone is in your pocket, and it means your phone transmits a short radio signal that other PickOk phones can hear.
That is more than most apps ask for. This policy is written to be read rather than skimmed, and it says the uncomfortable parts out loud. Where a number exists, the number is here.
1. Who is responsible for your data
PickOk is operated by Bar Carmi, an Israeli sole proprietor (עוסק פטור).
That is the data controller for everything described in this policy — the person who decides what is collected and why, and who is answerable for it.
Contact email, for anything in this document, including a request to see, correct, export or delete your data: [email protected]
The address above is a contact address for privacy correspondence. It is not the controller's statutory registered address, and nothing in this policy should be read as saying it is.
Governing law and jurisdiction: the laws of the State of Israel, with the competent courts of Haifa. This matches clause 15 of the Terms of Service, and the two must stay identical if either is ever changed.
EU/UK representative (GDPR Article 27): PickOk is currently offered in Israel only. If we make it available to people in the EEA or the UK, we will appoint a representative established there and name them here before we do.
Data Protection Officer: none appointed. Write to the address above and it reaches the person who runs PickOk.
If you are in the EEA or the UK you have the right to complain to your national data protection supervisory authority. If you are in Israel you may complain to the Privacy Protection Authority (הרשות להגנת הפרטיות).
2. Where this policy applies
This policy covers the PickOk mobile app on iOS and Android, the PickOk website at pickok.live, and any email you send us about them.
It does not cover other companies' services that you reach through PickOk. Signing in with Google or with Apple, and the Google map drawn inside the app, are each also governed by that company's own privacy policy. Section 12 names them.
3. The short version
Five things, all of which are set out in full further down.
- We know where you are, roughly every 30 seconds, including in the background. We keep exactly one position per person and overwrite it. It expires 15 minutes after it was reported and is deleted within 10 minutes of expiring. There is no table of where you have been.
- We do keep a record of who you were near. When you are told about someone, we write a row holding the two user IDs, the time, and the venue. It is deleted after 7 days. You can read your own; nobody else can. An earlier version of this policy said no such record existed. That was wrong, and section 6 now describes it properly.
- Your phone transmits over Bluetooth, with the screen off. It advertises a random 11-character token that changes every 14 minutes, on a fixed radio identifier that is the same on every PickOk phone in the world. Section 7 explains what that does and does not hide.
- No other user is ever shown your position. They are shown your photo, your gender, your age in years, a coarse closeness word, and the name of the venue you are at. That last one is a place, disclosed to one specific person, and it deserves to be listed rather than discovered.
- We do not sell your data and there is no advertising, analytics or crash-reporting SDK in the app. We checked the dependency list, the iOS pod lockfile and the Android build; there is none.
4. What we collect
Account data
You sign in with Google or Apple. Either way we receive your email address, the provider's account identifier for you, and the name held on that account.
Phone and email sign-in are not currently offered. They were withdrawn on 12 August 2026 — there is no SMS provider configured and no sender for one-time codes — so PickOk holds no phone number for anyone. If we bring either back, this policy will say so before it collects anything.
PickOk never asks you to type a name and gives you nowhere to edit one. Our profile table has no name column at all. The name from Google or Apple is displayed back to you on your own profile screen and is shown to no other user, ever. If you use Sign in with Apple and choose Apple's private relay address, we only ever see the relay address.
Profile data
| What | Why we need it | Shown to other users? |
|---|---|---|
| Gender | To match you, and it is on your card | Yes |
| Date of birth | To enforce 18+, and to compute your age | No — only your age in whole years leaves the database |
| Who you want to meet | The whole matching rule | No |
| Age range you want | Filters who you are told about | No |
| One photo of your face | The thing a stranger recognises you by | Yes, under the four conditions in section 9 |
| "Stay old school" (offered to women) | When switched off, no man sees you until you have picked him | No |
| Notifications on/off | Whether we may buzz your phone | No |
"Who you want to meet", set against your own gender, reveals your sexual orientation. Under GDPR Article 9 that is special-category data, and it is the most sensitive thing we hold. We ask for it only because a matching product cannot exist without it; we process it on your explicit consent; it is never shown to another user, never used for advertising, and never shared.
Location
Your position while detection is switched on, including while the app is in the background and your screen is locked. This is the part to read twice.
- On Android the app requests
ACCESS_FINE_LOCATIONandACCESS_BACKGROUND_LOCATION. On iOS it requests "Always". You will see your operating system's own prompt and you can refuse. If you refuse background access the app still works while it is open on screen. - The fix we ask the operating system for is its balanced, roughly-100-metre power tier
(
kCLLocationAccuracyHundredMeterson iOS,PRIORITY_BALANCED_POWER_ACCURACYon Android) — not the tightest one your phone can produce. In practice a modern phone often returns far better than that, and we declare precise location to Apple and Google because that is the honest declaration. Treat what we hold as a precise coordinate. - Your phone reports at most once every 30 seconds while detection is on.
- Before storage the coordinate is rounded to five decimal places, about one metre. That is a real limit on our precision, not a privacy claim of any size.
- We store one row per person: your latest position, its stated accuracy, whether your radio is on, which venue you resolved to, and whether you are inside your own home zone. Each report overwrites the previous one.
- There is no location history table in this product. Not redacted, not aggregated.
Switching detection off is enforced on the server, not in the interface. Your position row is deleted, your phone stops reporting and stops broadcasting, and you are counted nowhere.
Home location, if you set one
The coordinates of the point you drop on the map, and two radii around it. Defaults are 75 metres for the hidden radius (you may set 25–500) and 400 metres for the blank radius.
A home address is the single most identifying coordinate a person can hand an app, so it gets its own paragraph rather than a clause. Section 8 says exactly what it does. It is never given to another user, is not part of the ordinary profile load, and comes back through one dedicated request to you alone.
Proximity data
A short-lived Bluetooth token your phone broadcasts, the tokens it hears from other phones, and — for a pair we resolve — the fact of the encounter and an estimated distance. Section 7 sets out what each of these is and how long each survives.
Detection records
That you were told about a specific person, at which venue, and when. Section 6.
Device and technical data
A push notification token and which platform it belongs to, iOS or Android. That is the whole list.
We do not collect your device model, your operating system version, or your app version, and there is no crash-reporting or analytics tool built into the app. Our hosting provider records IP addresses in its own server logs as part of operating the service.
Support data
Anything you write to us, and the address you wrote from.
Safety data
If someone reports you, we keep who reported you, the reason they picked from a fixed list of five, the path to your profile photo as it was at that moment, and the time. The photo snapshot exists so that a report still means something if you change your picture afterwards.
What we do not collect
No contacts, no photo library beyond the single image you pick, no advertising identifiers, no health, religion or ethnicity data, no payment data — the service is free today and takes no payment. Please do not put sensitive information in your profile; there is nowhere to type any.
And no message content, because there are no messages. PickOk has no chat, no inbox, and no way for one user to send another anything. There is nothing here for us to store, read, scan or hand over.
5. Why we use it, and our legal basis
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Create and run your account | You asked for the service | Contract — Art. 6(1)(b) |
| Match you with people nearby and send the notification | This is the product | Contract — Art. 6(1)(b) |
| Collect location and use Bluetooth | Nothing works without it | Your consent, given at the operating system prompt and withdrawable there or by switching detection off — Art. 6(1)(a) |
| Process who you want to meet, and your photo insofar as the pair reveals orientation | Matching is impossible without it | Your explicit consent — Art. 9(2)(a). Withdraw it and the only remaining option is to delete your account |
| Enforce 18+ | Legal obligation and platform rule | Legal obligation — Art. 6(1)(c), and legitimate interests — Art. 6(1)(f) |
| Act on blocks and reports, and keep the service secure | Users have to be able to make someone go away | Legitimate interests — Art. 6(1)(f) |
| Answer your support email | You wrote to us | Legitimate interests — Art. 6(1)(f) |
We claim no legal basis for diagnostics, analytics or advertising, because we do none of those things.
No automated decision with a legal or similarly significant effect is made about you. The matcher is a set of explicit rules — preferences, blocks, distance, dwell time — not a scoring model, and no profiling is performed.
6. Detections: the record of who you were near
This is the section the previous version of this policy got wrong, so it is set out fully.
When our server decides that two matching people are in the same place, it writes a detection row. That row holds: who was told, who they were told about, the timestamp, the venue, whether Bluetooth confirmed it, and the confirmed distance if it did.
The row is a record of physical co-presence, naming a venue and a time. It exists for 7 days, then a sweep deletes it.
Three separate things follow from one detection, on three different clocks:
- The permission to see that person lasts 24 hours. After that their gender, age and photo stop resolving for you entirely, and their card goes dark.
- The row itself lasts 7 days. You can read your own rows — the ones recording who you were told about — for the full week, because the app uses them to tell you when you have crossed paths with the same person before. The other person cannot read the row about them, and no other user can read any of it.
- The live "are they still here" signal lasts 24 hours, not 7 days. See below.
The live proximity signal, and its bound
While a detection is inside its 24-hour window, your app can ask our server whether that specific person is, at this moment, within pairing range of you and whether their phone is currently reporting. It cannot ask where they are — only near-or-not, and how many seconds ago their phone last spoke.
This is what keeps a card honest: it goes quiet when they leave the room. It also means that for up to 24 hours after one detection, one person can repeatedly learn whether another is nearby.
Until migration 0077 this had no time bound at all, and ran for the full 7 days — six days after the card itself had gone dark. It is now bounded to the same 24 hours the card lives for. We are telling you it used to be worse because a policy that only describes the fixed version is not a policy you can check.
If you do not want this, block them: a block deletes the pair's detections in both directions immediately, and severs the card, the photo, the profile fields and the Bluetooth resolution. Blocks can be lifted from the Blocked list in the app.
7. Bluetooth: what your phone transmits
GPS finds candidates at a venue; it cannot tell you someone is in the same room. Bluetooth Low Energy does the close confirmation, and it does it by transmitting.
What goes over the air. Your phone advertises eight random bytes, encoded as an 11-character string. It is minted by our server on request, is valid for 15 minutes, and your phone replaces it every 14 minutes. Only one is live for you at a time. It is not derived from your account, and it is meaningless to anyone who cannot ask our server to resolve it — and our server only answers for someone you would already be matched with, and refuses outright if either of you is inside a home zone.
What that does not hide, stated plainly. PickOk advertises on a fixed, published Bluetooth service identifier — the same 128-bit value compiled into every copy of the app on both platforms. Anyone standing near you with an ordinary Bluetooth scanner can tell that a PickOk device is present, continuously, and can follow one token for up to a quarter of an hour, without ever learning who you are. This is inherent to how two phones find each other without a server in the middle. We would rather write it here than tell you our identifiers "cannot be used to follow a device".
The radio runs in the background. Since 8 August 2026 scanning and advertising follow the
detection toggle rather than whether the app is on screen, using the iOS bluetooth-central and
bluetooth-peripheral background modes and an Android foreground service. Your phone transmits
from your pocket with the screen off, whenever detection is on and you are outside your home
zone.What we store, and for how long.
| Table | What it holds | Kept |
|---|---|---|
ble_tokens |
The map from a live token back to your account | 15 minutes, then swept. During that window the token is not anonymous to us. It is anonymous to everybody else, permanently |
ble_sightings |
Which account heard which, and the measured distance in metres | 2 hours. Readable by no user — there is no read policy on the table at all |
detection_sightings |
The per-pair working ledger used to decide whether an encounter is real: venue, first seen, last seen, a count | 2 hours. Readable by no user |
"Two devices were in range" and "we know which two people, how far apart, and where" are not the same sentence. The second one is the true one, for two hours.
8. Your home zone
You can optionally mark where you live. It does two different jobs, and only one of them is about other people.
Job one — you disappear. Inside the hidden radius (75 metres by default, adjustable between 25 and 500), PickOk switches itself off: you are counted at no venue on anybody's map, you appear in nobody's nearby list, no card can be made from your phone, our server refuses to resolve your Bluetooth token to anyone, and your phone stops broadcasting altogether. Turning the radio off matters as much as the server refusing, because a scanner outside your building would otherwise still see a PickOk device inside it.
Job two — the world disappears. Venues within 400 metres of your home point are removed from your own map, so PickOk never draws you a map of your own street. This affects only your screen. Other people's maps are unchanged by it.
Your home point is never shown to another user, is not returned by the ordinary profile load, and is not cached on your device. It comes back through a single dedicated request, to you and only to you, so that you can check the pin is on the right building. Anyone holding your unlocked phone could see it there. That trade-off was deliberate: a protection you cannot inspect is one you cannot trust. You can clear it at any time.
9. What other users can see about you
Four fields, and this is the complete list: your user identifier, your gender, your age in whole years, and your photo.
They resolve only while all four of the following are true at the moment somebody looks:
- the server told them, within the last 24 hours, that you were near them;
- neither of you has blocked the other;
- each of you is looking for what the other is — re-checked on every single read, so if either of you changes preferences the card goes dark immediately;
- if you are a woman who has switched "stay old school" off, you have picked them first.
Your photo is under exactly the same four tests. It lives in a private storage bucket, not on a guessable URL, and since migration 0077 the storage rule defers to the same view the profile fields come from — so when a preference change or a block retracts a card, the image bytes stop being fetchable at the same instant, not at the end of the day. Before 0077 they did not, and that was a real defect for as long as it lasted.
Elsewhere in the app, a matched peer is also told:
- roughly how close you are — a word such as "very close" or "nearby", never a number of metres, because Bluetooth signal strength cannot support one; and
- the name of the venue you are at, when you are at a catalogued one.
A venue name is not a coordinate, but it is a place, and it is disclosed to one specific person rather than published as a count. It is also the most actionable thing the app tells anybody, since walking over is the entire product. We list it here rather than let you find it.
What another user never sees, under any circumstances: your position, your distance in metres, your date of birth, your name, your home zone, your phone number, your email address, who you are looking for, your age range, whether notifications are on, or anything at all about anyone else you have been near.
Nobody can message you. There is no chat in PickOk.
10. The singles map
The map shows public venues, drawn from Google Places, each with a single number: how many single PickOk users who match you are there right now. Counts, never identities. No faces, no pins on people, and tapping a marker gives you a number, not a list.
Two things about that number, said plainly rather than buried.
A marker counts people within 30 metres of the venue's own map point, and only those who have been there at least 2 minutes. The venue list uses a wider catchment — each venue's own radius, 40 to 75 metres — which is why a list and a marker can disagree about the same bar.
A marker can read 1. PickOk used to hide any venue with fewer than three people at it. That floor was removed on 9 August 2026, deliberately, because it made the map useless in a small town on a quiet night. The cost was understood and accepted: in a quiet place at a quiet hour, a marker reading 1 tells you that one specific person is within 30 metres of that point — and if you know who is there, you have identified them.
We would rather you knew that before you leave detection on somewhere small. Two things take you off the map completely: switching detection off, and being inside your home zone.
11. Notifications
If you allow them, we store one push token per device you sign in on, and which platform it is.
The notification itself contains no name, no age, no photo and no venue — only that someone is near. Your lock screen is not always in your hands, and it should not give you away.
What the delivery route learns. We send every notification through Expo's push service in the United States, which passes it to Apple's APNs or Google's FCM to reach your phone. Those three companies therefore learn your device token and the exact time you were alerted that someone was nearby — which is a timing signal about your social life even though the text says nothing. There is no way to deliver a push notification on iOS or Android without this being true.
We also keep a delivery receipt for each notification: the ticket ID, the token, your user ID, which detection it belonged to, and whether it succeeded. These receipts currently have no expiry rule and are retained for at most seven days. Every other table in this schema is swept; this one is not. We are stating it rather than implying otherwise. It is deleted when you delete your account.
12. Who else processes your data
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We use a small number of processors, and no more:
| Processor | What they handle | Where |
|---|---|---|
| Supabase | The database, authentication, your photo, and the server functions that do the matching | AWS eu-west-1 — Ireland (verified against the project record) |
| Expo (Expo Application Services) | Stores your push token, relays every notification, and delivers over-the-air JavaScript updates to the app | United States |
| Apple (APNs, Sign in with Apple) | Carries push notifications; authenticates you if you choose Apple sign-in | Apple infrastructure |
| Google (FCM, Sign in with Google, Google Maps SDK) | Carries Android push; authenticates you if you choose Google; draws the map inside the app, and therefore receives the part of the world your screen is showing | Google infrastructure |
Our venue catalogue is built from Google Places by a scheduled job on our server. That job asks Google about places, never about people, and sends Google no user data.
We may disclose data to law enforcement, a court or a regulator where we are legally compelled to. If PickOk is ever sold or transferred, your data would move with it, and we would tell you before that happened.
There is no analytics provider, no advertising network, no attribution SDK and no crash-reporting tool. Verified against the app's dependency list, the iOS pod lockfile and the Android build.
13. International transfers
Your data is stored in Ireland, in the European Union, whichever country you are in. This is true even for users in Israel, and it means an international transfer happens from the first day of service.
- If you are in Israel: your data leaves Israel and is stored in the EU. The European Commission has recognised Israel as providing adequate protection, and the EU is a jurisdiction Israeli law treats as offering adequate protection in return, so the transfer sits on that footing. Push notifications additionally travel through the United States, via Expo.
- If you are in the EEA or the UK: your data stays in the EU for storage. The transfer that needs a mechanism is the one to Expo in the United States for push delivery and app updates, and to the controller in Israel for administration. We will put the appropriate transfer mechanism in place before offering PickOk in the EEA or the UK.
- If you are in the United States: your data is stored in Ireland and administered from Israel.
14. How long we keep things
Every number below was read out of the live database on 12 August 2026, not copied from an earlier document.
| What | How long | How it goes |
|---|---|---|
| Your current position | 15 minutes from the moment it was reported | The row carries its own expiry; a sweep runs every 10 minutes, so nothing survives past about 25 minutes |
| Bluetooth token → account map | 15 minutes | Same sweep. Your phone also retires its own older tokens each time it takes a new one |
| Bluetooth sightings (who heard whom, and how far) | 2 hours | Swept |
Per-pair working ledger (detection_sightings) |
2 hours | Swept |
| Detections (who you were told about, which venue, when) | 7 days | Swept. Visible as a card for the first 24 hours only |
| Notification cooldowns | 24 hours | Swept |
| Push notification tokens | Until you delete your account | When a device tells us a token is dead we stop using it immediately and mark it revoked. We keep the row so the same device can be reactivated rather than duplicated |
| Push delivery receipts | 24 hours if never checked, seven days otherwise | A sweep rule added in migration 0099 deletes them; deleted sooner if you delete your account. See section 11 |
| Your profile, photo, home location, blocks and PickOk approvals | Until you delete your account | — |
| Safety reports | For as long as both accounts exist | A report is destroyed if either the reporter or the reported person deletes their account. See below |
| Support correspondence | Two years | Manually |
One consequence worth stating rather than hiding. Because every record hangs off the account by a cascading key, deleting an account also destroys the safety reports filed about it. That is a strong privacy outcome and a weak moderation outcome, and it is the honest description of what the database does today. We have not written a sentence claiming we retain reports for safety purposes, because we do not.
15. Your rights
Wherever you are, you can ask us to:
- See what we hold about you, and get a copy in a portable format;
- Correct anything wrong;
- Delete your account and everything in it;
- Restrict or object to how we use it;
- Withdraw consent at any time — for location and Bluetooth this is your operating system's permission screen or the detection toggle in the app; for the special-category data in section 4 the only complete withdrawal is to delete your account.
If you are in the EEA or the UK these are your rights under GDPR Articles 15 to 22. If you are in Israel they are your rights under the Privacy Protection Law, 5741-1981. Section 16 covers California.
How to use them, honestly described.
- Deleting your account you do yourself, in the app: the You tab, then Delete account. Not under Edit profile.
- Correcting your profile you do yourself: the You tab, then Edit profile.
- Access and portability have no button. There is no export screen in the app today. Write to [email protected] and we will send you a copy within 30 days. It is a manual process, and we would rather say so than point you at a feature that does not exist.
We will never charge you for a request or make you justify it, and we will not make PickOk worse for you because you exercised a right.
16. If you are in California
This section applies to California residents and uses the CCPA/CPRA's own vocabulary.
Categories of personal information collected in the last 12 months: identifiers (user ID, email address, push token); characteristics protected under California or federal law (age, gender); precise geolocation; internet or network activity (IP address in our hosting provider's logs); sensory information (your photograph); and sensitive personal information — specifically precise geolocation and information about your sex life or sexual orientation, derived from who you say you want to meet.
We have not sold, and have not shared for cross-context behavioural advertising, any personal information in the preceding twelve months, and we do not do so now. We have no advertising partners and no ad SDK. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" link to offer.
We use sensitive personal information only to provide the service you asked for — matching and proximity — and never to infer characteristics about you. That is a use the CCPA does not require us to let you limit, but you can stop it entirely at any moment by switching detection off or deleting your account.
Your California rights are to know, to access, to correct, to delete, to portability, and to non-discrimination. Use them the same way as section 15. We respond within 45 days and will tell you if we need a further 45.
We do not knowingly collect personal information from anyone under 16. PickOk is 18+.
17. Children
PickOk is for adults, 18 and over. There is no under-18 tier and no teen mode.
The age floor is enforced twice, independently. The app blocks a birthday under 18 before you can continue, and — because an app can be modified — the database itself refuses the write: a trigger rejects any profile whose date of birth makes the holder under 18, with the error "PickOk is 18+". A patched client cannot get past it.
We do not knowingly collect data from anyone under 18. If you believe a minor is using PickOk, report the profile in the app using the underage reason, or write to [email protected], and we will remove the account.
18. Security, and its limits
- Access is enforced by the database, not only by the app. Every table carries row-level security. The tables that would be most damaging to leak — Bluetooth sightings, the per-pair ledger, push receipts and safety reports — have row-level security switched on and no read policy at all, so no signed-in user can read a row from any of them under any circumstances.
- The rules that decide who may see whom run on the server, where a modified app cannot reach them, and are re-evaluated on every read rather than cached.
- Your photo lives in a private bucket, capped at 2 MB, JPEG/PNG/WebP only, behind the same four-part rule as your profile.
- Data is encrypted in transit.
- Bluetooth is a broadcast medium and we cannot secure it. Section 7 says what that costs you.
- No system is perfect. If a breach affects you we will tell you and the relevant authority, without undue delay.
19. Changes to this policy
We will change the version number and the date at the top, and we will tell you inside the app before any change that materially affects what we collect or who can see it.
What changed in version 2.0 (12 August 2026)
This version was written by reading the running code and querying the live database, and it corrects the 10 August version in several places where that document was wrong about the product:
- Detections are disclosed. The previous version said there was no history of who you had been near and no way to reconstruct one. There is: a 7-day, venue-named, timestamped record. Section 6 is new.
- The retention number was wrong. The previous version said detections were deleted after 24 hours. 24 hours is the card-visibility window; the rows live 7 days.
- The Bluetooth section no longer claims what it cannot deliver. The previous version said rotating identifiers meant a device could not be followed over time. The service identifier is fixed and public, and one token is followable for a quarter of an hour. Section 7 now says so.
- Background Bluetooth is disclosed. The radio now scans and advertises with the screen off, not only in the foreground.
- The live proximity signal is disclosed, and is now bounded to 24 hours rather than running for the full 7 days.
- The map's 30-metre marker radius and the removal of the three-person floor are stated. The previous version quoted 15 metres, which was superseded.
- Home location is listed as data we collect, with its own section, instead of being a clause in a sentence about the map. The two radii are told apart because they do opposite jobs.
- Expo, the Google Maps SDK and Apple sign-in are named as processors. The previous list omitted them.
- The claim that we collect device model, OS version, app version and crash diagnostics is gone. We collect none of those, and the "legitimate interest in aggregated diagnostics" legal basis has been removed because there is no such processing.
- The claim that safety reports survive account deletion is gone, and replaced with what actually happens: they are destroyed with the account.
- Push receipts are disclosed as deleted after 24 hours when never checked, and after seven days otherwise, because that is what the sweep does.
- Access and portability are described as a manual email route, because there is no export feature.
- The hosting region is stated: Ireland, and international transfer is addressed for Israel, the EEA/UK and the United States.
- The self-certification "and describes the product accurately" is gone. That sentence turned each of the above into a declaration that we had checked and certified a document we had not.
- The entity details are in section 1, where they belong. The previous version promised them "at the end of this document" and the document ended without them.
- A California section was added, and Israel's Privacy Protection Law is named.
20. How to contact us
[email protected] — for any privacy question, any request under section 15 or 16, or anything in this document.
Postal address and registered details: see section 1.
We aim to answer within 30 days, and within 45 for California requests.