Effective date: 2026-09-22 (owner A1 approval and publication confirmed) Last updated: 2026-09-22 Controller: Yakov Elbaz, trading as Sterogent, Osek Patur (Exempt Dealer), Mispar Asak 027123140
Yakov Elbaz ("I", "me", "my", or where context reads more naturally: "we", "us", "our") operates the Shelly AI personal assistant service (the "Service"). I am an individual operating as a registered Osek Patur (Exempt Dealer) under Israeli law. I am the data controller for your personal data under the Israeli Privacy Protection Law 5741-1981 (as amended by Amendment 13, in force 2025) ("PPL").
For all data-related matters, please contact me by email:
This notice applies to you if you are a participant in the Shelly cohort-1 pilot.
Cohort 1 scope: The Service in this pilot is offered exclusively to Israeli residents who have received and accepted a personal invitation. There is no public sign-up. This notice governs data processing for this pilot programme. It will be updated before any change to the Service's scope, user base, or channels.
GDPR: Because enrollment is restricted to Israeli residents only, GDPR does not apply to cohort-1 users. If enrollment is extended to any EU resident at any time, GDPR applies to that user's data from the moment of enrollment, and this notice will be updated before that occurs.
3.1 Account data:
3.2 Content you provide:
3.3 Calendar data you choose to share: If you choose to share your calendar with the assistant, you do so by providing an ICS calendar link or file directly to the Service. We process the calendar event data contained in that link or file (event titles, dates, times, and descriptions) to help you manage your schedule. This is a one-time, user-initiated share: we do not maintain a live connection to your calendar application and we do not access your calendar account.
You control this entirely: you choose whether to share an ICS link, and you can stop the assistant from using calendar data at any time by telling it to discard your calendar.
What we do NOT collect in this pilot:
3.4 Usage data:
Primary legal basis: We process your personal data primarily on the basis of CONTRACT -- processing is necessary to perform the personal AI assistant service you requested (PPL s.3(b)).
| Purpose | Lawful basis | Data categories |
|---|---|---|
| Delivering the Service (briefings, replies, reminders) | CONTRACT | 3.1, 3.2, 3.3 |
| AI processing of your messages and calendar context | CONTRACT | 3.2, 3.3 |
| Scheduled features (morning brief, deadline nudges) | CONTRACT | 3.1, 3.2, 3.3 |
| Account management | CONTRACT | 3.1 |
| Service improvement (aggregated, de-identified only) | Legitimate interests | 3.4 (anonymized) |
We do not use your data to train AI models. Your messages and calendar data are processed to respond to your requests; they are not used to train Anthropic's models (see Section 5.1 for Anthropic's data use policy).
We use the following third parties in delivering this pilot.
Role: We instruct Anthropic to process your message content and calendar context to generate AI responses on our behalf. Anthropic processes this data only on our instructions and for our stated purposes.
What data is shared: The content of each AI request -- your message, relevant calendar context, and the assistant's prior responses in the conversation window. We send only what is necessary for each request. Your name, Telegram identifier, and account details are NOT sent to Anthropic.
Agreement: Anthropic Commercial Terms of Service and Data Processing Addendum (DPA). The DPA incorporates EU Standard Contractual Clauses (SCCs, 2021) as a cross-border transfer mechanism.
Data location: Anthropic infrastructure in the United States.
Transfer mechanism: Anthropic DPA incorporates EU Standard Contractual Clauses (Modules 2 and 3). Israel holds an EU adequacy decision (Commission Decision 2011/61/EU).
Retention at Anthropic: Anthropic retains submitted data for up to 30 days for safety and quality purposes under the standard retention setting. Your data is not used to train Anthropic's models under the commercial terms.
Deletion: When you request account deletion, we notify Anthropic to delete your data within 5 business days of validating your request. Anthropic processes deletion within 30 days of our notification.
Anthropic's privacy policy: https://www.anthropic.com/legal/privacy
This is a materially different disclosure from Section 5.1 above. Read it.
Telegram is NOT our data processor. Telegram is an independent data controller that processes your message data under Telegram's own Privacy Policy and Terms of Service -- the terms you accepted when you created your Telegram account. We have no agreement with Telegram that governs the processing of your personal data. We do not instruct Telegram on how to handle your data.
What data is involved: Messages you send to and receive from the assistant via Telegram, your Telegram user identifier, and message metadata (timestamps, delivery status).
Consequences for your rights:
within 30 days of a validated deletion request).
to its own policies.
or exercise your rights directly with Telegram.
Telegram's privacy policy: https://telegram.org/privacy
Your message and calendar data is deleted automatically. The default retention period for raw message content and ICS calendar data is 90 days from creation or last update. You do not need to request deletion for this to happen.
The Service builds a personalisation layer about you over time: task state, nudge history, rolling summaries, user profile, preference models, and related derived data. This data is what makes the assistant useful to you specifically.
This data is retained until one of the following:
(a) You request deletion. We delete your personalisation data along with all other personal data we hold within 30 days of validating your identity.
(b) You have been inactive for 12 months. If you have not used the Service for 12 consecutive months, we will contact you via Telegram (or your registered contact channel) to ask whether you want to keep your personalisation data for another year or have it deleted now.
same process applies.
We do not treat silence as consent to continued processing. If we do not hear from you, we delete.
If you request deletion of your personal data at any time, we delete all personal data we hold about you within 30 days of validating your identity. This includes raw message data, calendar data, personalisation data, and account data.
Anonymised aggregate data: Data that has been genuinely anonymised -- reduced to aggregate, non-individual-level learnings that cannot be re-linked to any identifiable person by any means available to us -- is not personal data and is not subject to the deletion right. Replacing your user identifier with a code we hold the key to (pseudonymisation) does not qualify as anonymisation.
| Data category | Normal retention | On inactivity trigger (12 months) | On deletion request |
|---|---|---|---|
| Raw messages and AI conversation history | 90 days from creation, then auto-deleted | Not applicable -- auto-deleted at 90 days regardless | Deleted within 30 days of validated request |
| ICS calendar data and extracted calendar events | 90 days from creation, then auto-deleted | Not applicable | Deleted within 30 days of validated request |
| Personalisation data (task state, nudge history, rolling summaries, user profile, preference models, embeddings, learned preferences) | Retained while you use the Service and the inactivity trigger has not fired | Notification sent; if no response within 30 days, deleted | Deleted within 30 days of validated request |
| Account data (name, Telegram ID, timezone, language) | Retained while account is active | Deleted with personalisation data if inactivity trigger fires | Deleted within 30 days of validated request |
| Genuinely anonymised aggregate data (no individual can be re-identified by any means available to us) | Retained indefinitely for product improvement -- this is not personal data | Unaffected | Not subject to deletion |
| Operational metering records (individual rows: token counts, model name, timestamps, cost figures; no user content) | Retained while account is active | Deleted with personalisation data if inactivity trigger fires | Deleted within 30 days of validated request |
| Security audit events (2SV and recovery attempt events; event type and timestamp only; no message content) | Retained on a 90-day rolling cycle during account lifetime | Deleted with personalisation data if inactivity trigger fires | Deleted within 30 days of validated deletion request |
| Active legal dispute data | Retained for the duration of the dispute plus 1 year | Unaffected while dispute is active | Not subject to earlier deletion while dispute is active |
Backup lag: Automated backup systems may retain a copy of your data for up to 7 days beyond the date your data is deleted from our live systems. Backup copies are inaccessible for ordinary use and are overwritten on the backup cycle.
You have the following rights under Israeli PPL. All requests are processed within 30 days of validation of your identity.
| Right | What it covers | How to exercise |
|---|---|---|
| Access | Request a copy of the personal data we hold about you | Email privacy@sterogent.com |
| Correction | Request correction of inaccurate or incomplete data | Email privacy@sterogent.com |
| Deletion | Request deletion of your personal data (subject to the retention obligations above) | Email privacy@sterogent.com |
| Objection | Object to processing based on legitimate interests (usage telemetry) | Email privacy@sterogent.com |
| Complaint | Lodge a complaint with the Privacy Protection Authority | https://www.gov.il/en/departments/the-privacy-protection-authority |
Full deletion procedure:
On receipt of a validated deletion request:
request; Anthropic processes deletion within 30 days of our notification.
app.
1 year.
We will send you a confirmation when deletion is complete.
Leaving the Service (asking to stop and be removed from the pilot) means we stop processing your data and remove you from the pilot. This does NOT automatically delete the data we already hold. You may request deletion separately.
Data deletion request triggers the process in Section 7. Deletion is irreversible. Once deleted, your account and data cannot be recovered.
Your personal data may be processed outside Israel:
Anthropic's DPA. Israel holds an EU adequacy decision (Commission Decision 2011/61/EU); the SCC mechanism provides an adequate transfer basis for Israeli user data.
under its own Privacy Policy and its own transfer mechanisms. See Section 5.2.
We implement security measures including:
Regulations (Data Security) 5777-2017
In the event of a security breach affecting your personal data, we will notify the Privacy Protection Authority (PPA) within 72 hours of confirmation and notify affected users without undue delay.
This service uses artificial intelligence. Responses and content generated by the assistant are produced by an AI system powered by Anthropic's Claude. AI-generated content may be inaccurate, incomplete, or unsuitable for your specific situation. Do not rely on AI-generated responses for medical, financial, legal, or other professional decisions without independent verification. We do not warrant the accuracy or completeness of any AI-generated response.
This Service is not directed to users under 18. We do not knowingly collect personal data from children. If you believe a child under 18 has provided data through the Service, contact us at privacy@sterogent.com.
We may update this notice. If we make material changes, we will notify you via Telegram or your registered contact details at least 30 days before the changes take effect. The "last updated" date at the top reflects the most recent revision.
Yakov Elbaz privacy@sterogent.com
Israeli Privacy Protection Authority: https://www.gov.il/en/departments/the-privacy-protection-authority