Privacy policy
Last updated: 2026-07-29.
Who we are
Sipurly is a digital library for Hebrew books, operating as a managed pilot. For any privacy question you can reach us through the contact form or at arielbenzikri@gmail.com.
What information is collected, and why
- Anonymous browsing: the public pages do not require signing in and do not collect identifying information, apart from operational security logs (see "Logs" below).
- Contact form: name, email or phone, and your message — used solely to answer your inquiry. The details are sent to us by email and are not stored in the website's database.
- Reader account: name, email address, and password (stored as a one-way hash) — used to manage your personal library.
- Purchases: order details (the book, the amount, a transaction reference). Credit-card details are provided directly to the payment provider PayPlus and do not pass through our servers.
- Logs: security and purchase events are recorded with the IP address and browser data (User-Agent), for service security, abuse prevention, and troubleshooting. Records are kept for a reasonable period required for these purposes.
Who receives the information
- The operational email provider — for system messages and contact-form inquiries.
- PayPlus — the payment provider, for purchasers only.
- Railway — the infrastructure hosting provider the service runs on.
- Cloudflare Turnstile — for the security check on the public contact form only.
- Meta/Facebook — only when an author chooses to connect a Facebook account, and for publication to the Facebook Business Page that author selected.
The information is not sold. It is shared only with the service providers described in this policy, for the purposes set out here, or when required by law.
Cookies and local storage
The website uses essential cookies only — no advertising, measurement, or tracking cookies. There are no analytics tools on the site.
| Name | Purpose |
|---|---|
| ym_customer_session | Keeps readers signed in |
| ym_staff_session | Keeps staff signed in (does not affect visitors) |
| csrf_token | Protects forms against forged submissions |
| ym_device / ym_customer_device | Device identification protecting book access |
Display and accessibility preferences (text size, contrast, color theme, language) are saved only in your browser's local storage and are never sent to the server.
Third-party services in the browser
The fonts are hosted on the website itself. Apart from the security check on the contact page, described immediately below, the public pages load no resources from external servers. A WhatsApp link, when shown, leads to an external Meta service only if you choose to use it.
Security check on the contact form (Cloudflare Turnstile)
On the contact page only, we use Cloudflare Turnstile as an essential security measure, to prevent automated spam submissions and to protect the form from abuse. The check is loaded from Cloudflare's servers and appears on that page alone.
To detect automated submissions, Cloudflare may process security and browser signals, including: your IP address, browser and device information (User-Agent), signals relating to the connection and to TLS encryption, the public site key, the page origin and hostname the check was loaded from, and the challenge and verification metadata itself.
The content of your message is not sent to Cloudflare. Your name, email, phone, subject and message text are handled solely by our existing email flow, as described above. The only thing sent to Cloudflare is the temporary verification token, so that we can confirm the check was completed.
Use of this service is subject to Cloudflare's own privacy policy.
Facebook connection for automatic book publication (authors)
An author may choose to connect a Facebook Business Page so that Sipurly automatically publishes a post about a newly released book. The connection uses Meta's official authorization flow (OAuth). As part of it we store a Facebook Page identifier and name, a Page access token in encrypted form, information about the permissions granted, and basic publication status and history. We do not store Facebook passwords. Publishing the post is performed by Meta/Facebook as external processing and is subject to Meta's own policies.
The connection can be disconnected at any time from the Automation area. Disconnecting immediately erases the encrypted access token, disables automatic publication, and cancels pending publications. Disconnecting does not delete posts already published on Facebook — those are removed directly on Facebook.
Beyond disconnecting, an author may delete all Facebook data stored by Sipurly, including the Page identifier and name, the permissions granted, and the publication history. Full instructions are on the Facebook data deletion page.
Your rights
Under Sections 13 and 14 of the Israeli Privacy Protection Law, 5741-1981, you have the right to review information held about you and to request its correction or deletion. Reader-account holders can also request account deletion from their personal account area. For any request, use the contact form.
Document language
This policy is published in Hebrew and in English. In case of any inconsistency, the Hebrew version prevails.