Privacy notice
This notice explains how M.S.I NAOR LTD, operating Qeravio, handles personal data when you browse the site, create or use an account, contact us, use member features or buy a subscription.
Who is responsible
M.S.I NAOR LTD, Israeli company number 515893055, is responsible for Qeravio's handling of personal data. Registered address: 32 Heil HaHimush, Rishon LeZion 7571234, Israel. Privacy and account requests may be sent to support@qeravio.com.
When this notice applies
This notice applies to Qeravio's public pages, member area, authentication, contact routes, research requests, moderated community features, academy progress, product measurement and subscription fulfilment. A linked third-party service applies its own notice when you leave Qeravio or use its checkout.
Data we handle
Depending on what you use, we may handle your email address, optional name, account and session identifiers, language and time-zone choices, membership and delivery preferences, personal worlds, goals, projects, stack metadata, controlled-memory choices, outcome records, contact messages, research requests, moderated community submissions, course progress, saved-item choices, consent records and limited product-use events. Naming a tool, service or repository in a personal stack does not give Qeravio access to its account or code. Security systems may process network and request metadata to prevent abuse. For a purchase, we may receive Paddle customer, transaction and subscription identifiers, selected plan, price, currency, payment status, renewal period, cancellation state, refund or chargeback status and the version and time of your purchase acceptance. Qeravio does not request or store full card numbers.
How we receive data
We receive data directly from you, from your browser or device when you make a choice, from first-party product events after optional consent, and from service providers when needed to authenticate you, fulfil a subscription, protect the service or answer a request. Paddle sends signed purchase and subscription events to Qeravio after a transaction.
Why we use data
We use personal data to provide and secure accounts, verify membership, deliver requested content and email, remember preferences, answer contact and research requests, moderate community submissions, record learning progress, administer subscriptions and refunds, measure the product when permitted, detect fraud and abuse, maintain evidence of consent, comply with legal duties and establish or defend legal claims. Depending on the activity and the law that applies, the basis is performance of a contract or steps you request before a contract, consent, compliance with a legal duty, or our legitimate interests in operating, securing and improving Qeravio without overriding your rights.
Payments and Paddle
Paid transactions are conducted by Paddle, the authorised reseller and merchant of record. Paddle collects and controls the payment details needed for checkout, tax, fraud review, receipts and buyer support under Paddle's own Buyer Terms and Privacy Notice. Paddle shares limited buyer and transaction data with Qeravio so we can provide access, support, cancellation and refund handling. Qeravio and Paddle each act as an independent controller for the data each determines how to use.
Device storage, cookies and measurement
Essential storage keeps your session, consent record, language, theme and saved items. Optional first-party analytics starts only after you choose it and records an anonymous identifier, page or product event, locale and a small set of campaign or action labels. We do not use optional analytics before consent, sell personal data or run third-party advertising cookies in the current service. You can reopen privacy settings and withdraw optional analytics consent; related product events are then deleted.
Who receives data
We disclose only what is needed to service providers that host and protect Qeravio, deliver authentication or member email, process and administer purchases, provide a user-requested AI feature, or support operations. Current core providers are Cloudflare for hosting, security, data services and configured AI infrastructure; Paddle for checkout, recurring billing, tax, receipts, refunds and buyer support as Merchant of Record; Resend for authentication, transactional and opted-in member email; and OpenAI for the member implementation-pack generator when that feature is enabled and the member submits a request. Qeravio's own optional product analytics is stored in its Cloudflare data service after consent; the current service does not run third-party advertising analytics. We may also disclose information to professional advisers, courts, regulators or law enforcement where lawfully required, and in a documented business transfer subject to appropriate safeguards. We do not give member email addresses to content sources or affiliate partners for their marketing.
User input and external AI
Most account, learning, saved-item, contact and community data is processed within Qeravio's Cloudflare-hosted application and is not automatically sent to an external model. When an enabled feature expressly says it will generate an implementation pack with AI, the idea and the bounded project details submitted for that request are sent to OpenAI to produce the requested output. The request is configured with provider-side storage disabled. Qeravio does not use member input to train or fine-tune its own models, and does not grant a provider broader rights than needed to supply the requested feature. Editorial source material may be processed separately to create Qeravio publications and is not member-submitted personal content. Do not submit secrets or sensitive personal data to an AI feature.
International processing
Qeravio is operated from Israel and its service providers may process data in Israel, the European Economic Area, the United Kingdom, the United States and other countries where they operate. Where applicable law requires it, we rely on recognised transfer mechanisms, contractual safeguards or another lawful basis. Foreign laws may permit public authorities to access data in limited circumstances.
How long data is kept
Authentication links expire after 20 minutes, and active account sessions are limited to 30 days unless revoked sooner. Optional product events are scheduled for deletion after 90 days and consent records after 365 days. Resolved or closed contact requests are scheduled for deletion 90 days after resolution unless a legal hold applies. Device-local preferences remain until you remove them or clear site data. Account, member submissions, course progress and subscription records are kept while needed to provide the account or service. Purchase, consent, accounting, fraud, refund, chargeback and dispute records are kept for the period required to administer the subscription, meet legal and financial duties, and establish or defend claims. We delete or de-identify data when those purposes no longer require it, unless a legal hold or mandatory duty requires longer. Paddle applies its own retention periods to data it controls.
Your choices and rights
Depending on applicable law, you may ask for access, a copy, correction, deletion, restriction or portability of personal data, object to certain processing, withdraw consent, or complain to a competent data-protection authority. Withdrawing consent does not affect earlier lawful processing. We may need to verify your identity and may retain limited evidence where a request conflicts with a legal duty or another person's rights. Use the privacy settings for optional analytics, the member settings for member email, the billing portal for cancellation, or contact support@qeravio.com for another privacy request.
Security
We use access controls, encrypted transport, secret management, bounded requests, rate limits, signed payment events, private member responses and operational logs designed to reduce risk. No internet service can promise absolute security. Please protect access to your email account and tell us promptly if you suspect unauthorised access.
Children
A person must be at least 16 to create or use a Qeravio account. A person must be at least 18, or the age of legal majority where they live if higher, and have legal capacity to purchase a subscription. Qeravio is not directed to children under 16 and does not knowingly create accounts for them. If you believe a child provided personal data without valid permission, contact us so we can investigate and take appropriate action.
Accessibility and assistance
Qeravio is working to provide an accessible service and maintains an accessibility page with a contact route for requests and reported barriers. This notice does not claim legal conformance or replace an applicable accessibility statement. If a person cannot use a digital route, we will consider a reasonable alternative through support@qeravio.com, subject to identity and security checks.
Updates and contact
We may update this notice when the product, providers or law changes. Material changes will be presented with a new effective date and, where required, notice or renewed consent. The English and Hebrew versions are intended to describe the same policy; mandatory rights under applicable law are not limited by a translation. Questions and requests may be sent to support@qeravio.com or by post to the registered address above.