משפטי
מדיניות פרטיות
עודכן לאחרונה: 20 במאי 2026
מה השירות עושה
SafeList מאפשר להורים לאצור אוסף סרטונים מאושרים מ-YouTube עבור הילדים שלהם, בסביבה ללא הסחות דעת. אנו מספקים כלים לחיפוש, סימון, וארגון סרטונים בקטגוריות, וכן ייבוא של פלייליסטים שכבר יצרת ב-YouTube אל הספרייה הפרטית שלך באפליקציה.
אילו נתונים אנו אוספים
- פרטי חשבון Google בסיסיים - שם, כתובת אימייל, ותמונת פרופיל. נדרש לזיהוי ייחודי שלך באפליקציה.
- גישה לפלייליסטים שלך מ-YouTube (קריאה בלבד, scope
youtube.readonly) - רק כדי להציג לך את שמות הפלייליסטים שלך כדי שתוכל לבחור איזה לייבא לספרייה הפרטית שלך באפליקציה.
- תוכן שאתה יוצר באפליקציה - סרטונים שהוספת, קטגוריות שיצרת, פלייליסטים שייבאת, היסטוריית צפייה (במצב סשן).
שימוש בנתוני Google API
השימוש שלנו במידע המתקבל מ-Google APIs יציית למדיניות Google API Services User Data Policy, כולל דרישות Limited Use:
- נשתמש בנתוני YouTube שלך אך ורק כדי לאפשר לך לייבא פלייליסטים לספרייה הפרטית שלך באפליקציה.
- לא נמכור או נעביר את הנתונים שלך לצדדים שלישיים.
- לא נשתמש בנתונים לפרסום או לשירותים שאינם רלוונטיים לפעולת האפליקציה.
- לא נאפשר לבני אדם לקרוא את הנתונים שלך, אלא אם אישרת זאת באופן ספציפי, או שיש צורך מסיבות אבטחה (חקירת תקלה / הונאה), או שהדבר נדרש על פי חוק.
איך אנחנו שומרים את הנתונים
- נתוני המשתמש (אוסף הסרטונים, קטגוריות) מאוחסנים בבסיס נתונים מאובטח (Upstash Redis), במפתחות מרושתים לפי מזהה המשתמש.
- refresh tokens של Google מאוחסנים בצד השרת בלבד ולעולם לא נחשפים בדפדפן או לצדדים שלישיים.
- אנו משתמשים ב-HTTPS עבור כל התקשורת בין הדפדפן שלך לבין השרת.
הזכויות שלך
- ביטול הגישה - בכל רגע אתה יכול לבטל את הגישה של SafeList לחשבון Google שלך דרך myaccount.google.com/permissions.
- מחיקת חשבון - צור איתנו קשר ונמחק את כל הנתונים שלך מהשרת תוך 7 ימים.
- גישה לנתונים שלך - אתה יכול לבקש להוריד עותק של כל הנתונים שאנו מחזיקים עליך.
עוגיות (Cookies) ואחסון מקומי
אין באתר עוגיות פרסום ואין עוגיות מעקב. אין לנו Google Analytics, אין פיקסלים של רשתות חברתיות ואיננו מוכרים או משתפים נתונים עם מפרסמים. אלה כל העוגיות והאחסון המקומי שבשימוש:
חיוניות - תמיד פעילות
נדרשות כדי לספק את השירות שביקשתם. לפי הדין אינן טעונות הסכמה, אך אנחנו מפרטים אותן במלואן:
sl_session - עוגיית סשן מסוג HttpOnly ששומרת אתכם מחוברים בין ביקורים.
oauth_nonce, last_oauth_done - אבטחת תהליך ההתחברות מול Google ומניעת בקשת הרשאה חוזרת מיותרת.
safelist_auth (אחסון מקומי) - אסימון הזיהוי הפעיל.
safelist_lang (אחסון מקומי) - שפת הממשק שבחרתם.
- אחסון מקומי של קוד ההורים ומגבלות זמן המסך - לב הפונקציונליות של השירות.
safelist_consent (אחסון מקומי) - הבחירה שלכם בחלון העוגיות. בלעדיה היינו שואלים אתכם שוב בכל ביקור.
זכירת החשבון האחרון - בהסכמה בלבד
last_login_email, last_login_name, last_login_picture - שומרות את פרטי החשבון האחרון שהתחבר כדי שההתחברות הבאה תהיה בקליק אחד. אם לא אישרתם, הן נמחקות מהדפדפן ומסך ההתחברות מציג כפתור Google רגיל.
נגן YouTube מוטמע - בהסכמה בלבד
זהו הצד השלישי היחיד שמציב עוגיות באתר. אם אישרתם, הסרטונים נטענים מ-youtube.com ו-Google מציבה עוגיות משלה (כך גם מנויי YouTube Premium צופים ללא פרסומות). אם לא אישרתם, הסרטונים נטענים מ-youtube-nocookie.com והצפייה עובדת בדיוק אותו הדבר. בכל מקרה חלה על נתוני הצפייה מדיניות הפרטיות של Google.
שירותים חיצוניים נוספים
הדפים טוענים גופנים מ-Google Fonts ואת ספריית ההתחברות של Google. שירותים אלה אינם מציבים עוגיות, אך כתובת ה-IP שלכם נחשפת אליהם מעצם טעינת הקובץ.
שינוי או ביטול ההסכמה
אפשר לשנות את הבחירה בכל רגע, וביטול הסכמה קל בדיוק כמו נתינתה: פתיחת הגדרות העוגיות. אפשר גם למחוק עוגיות ישירות דרך הגדרות הדפדפן.
מי אחראי
השירות מנוהל על ידי Roy Shalem. ליצירת קשר בנושאי פרטיות: royshalem@gmail.com.
שינויים במדיניות
ייתכן שנעדכן את מדיניות הפרטיות הזו מעת לעת. תאריך העדכון האחרון יופיע בראש העמוד. שימוש מתמשך בשירות לאחר עדכון מהווה הסכמה למדיניות המעודכנת.
חזרה לאפליקציה
Legal
Privacy Policy
Last updated: May 20, 2026
What the service does
SafeList lets parents curate a collection of approved videos from YouTube for their children, in a distraction-free environment. We provide tools to search, mark, and organize videos into categories, as well as import playlists you've already created on YouTube into your private library inside the app.
What data we collect
- Basic Google account details - name, email address, and profile picture. Required to uniquely identify you in the app.
- Access to your YouTube playlists (read-only,
youtube.readonly scope) - only so we can show you your playlist names so you can choose which to import into your private library inside the app.
- Content you create in the app - videos you added, categories you created, playlists you imported, viewing history (session-only).
Use of Google API data
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements:
- We use your YouTube data solely to let you import playlists into your private library inside the app.
- We do not sell or transfer your data to third parties.
- We do not use the data for advertising or for services unrelated to operating the app.
- We do not allow humans to read your data unless you specifically approve it, or it is necessary for security reasons (debugging / fraud investigation), or required by law.
How we store the data
- User data (video library, categories) is stored in a secure database (Upstash Redis), in keys namespaced by user ID.
- Google refresh tokens are stored server-side only and are never exposed to the browser or to third parties.
- We use HTTPS for all communication between your browser and the server.
Your rights
- Revoke access - at any moment you can revoke SafeList's access to your Google account through myaccount.google.com/permissions.
- Account deletion - contact us and we'll delete all your data from the server within 7 days.
- Access to your data - you can request a copy of all the data we hold about you.
Cookies and local storage
There are no advertising cookies and no tracking cookies on this site. We run no Google Analytics, no social pixels, and we neither sell nor share data with advertisers. This is the complete list of what is stored:
Essential - always on
Required to deliver the service you asked for. These need no consent under the law, but we list them in full anyway:
sl_session - an HttpOnly session cookie that keeps you signed in between visits.
oauth_nonce, last_oauth_done - secure the Google sign-in exchange and avoid asking you for the same permission twice.
safelist_auth (local storage) - your active identity token.
safelist_lang (local storage) - the interface language you chose.
- Local storage for the parent PIN and screen-time limits - the core functionality of the service.
safelist_consent (local storage) - your choice in the cookie dialog. Without it we would have to ask you again on every visit.
Remember my last account - consent only
last_login_email, last_login_name, last_login_picture - store the details of the account that signed in last so your next sign-in is a single click. If you decline, they are deleted from your browser and the sign-in screen shows a plain Google button.
Embedded YouTube player - consent only
This is the only third party that sets cookies on the site. If you allow it, videos load from youtube.com and Google sets its own cookies (this is also what lets YouTube Premium subscribers watch without ads). If you decline, videos load from youtube-nocookie.com and playback works exactly the same. Either way, Google's privacy policy applies to the playback data.
Other third-party requests
Pages load fonts from Google Fonts and Google's sign-in library. These set no cookies, but your IP address is exposed to them simply by fetching the file.
Changing or withdrawing consent
You can change your choice at any time, and withdrawing consent is exactly as easy as giving it: open cookie settings. You can also delete cookies directly from your browser settings.
Who is responsible
The service is operated by Roy Shalem. For privacy-related contact: royshalem@gmail.com.
Changes to this policy
We may update this privacy policy from time to time. The last updated date will appear at the top of the page. Continued use of the service after an update constitutes acceptance of the updated policy.
Back to the app