YallaDira — Privacy Policy

Effective date: 26 July 2026
Extension version covered: 0.1.4

YallaDira is a browser extension that reads Hebrew apartment-listing posts on Facebook and adds a summary chip to each one. This page describes exactly what data the extension touches, where it goes, and what your options are.

TL;DR

Who is responsible for this data

YallaDira is an independent project by Ido Zahavy, who is the data controller for the one kind of data that actually reaches the developer: the contents of an issue report you choose to submit.

For everything else the extension does, the processing happens locally in your own browser and nothing is transferred to the developer. There is no controller-side copy of it to ask about.

What YallaDira accesses

When you visit https://www.facebook.com/*, the extension's content script runs on the page and:

  1. Reads the visible text of apartment listings shown in your feed or in groups you're already viewing.
  2. Extracts structured fields from that text — price, rooms, location, parking, entry date, deal type, phone number when present in the post, and similar.
  3. Displays those fields as a chip overlay on the post.

The extension does not:

What YallaDira stores, and where

All data lives in your browser, on your device, in two stores:

StoreWhat's in itWhy
chrome.storage.local / browser.storage.local Your filter settings, language preference, favorites list (with the notes you write and any field values you correct by hand), group labels, and the lists of posts you hid or collapsed Settings persistence; favorites, notes and corrections you've explicitly saved
IndexedDB (yalladira database, posts store) Cache of recently-seen post text and the fields YallaDira extracted from it Avoid re-extracting the same post each time you scroll back

The post cache is capped at 5,000 entries and trims itself automatically. Cached entries are also evicted after 30 days so post text doesn't accumulate indefinitely.

One detail worth knowing: because the cache is written by the content script running on Facebook, the browser files that IndexedDB database under www.facebook.com's site storage rather than under the extension's own storage. That matters for uninstalling — see "Your controls".

What kind of personal data ends up there?

Because the cache mirrors what Facebook already showed you, it's bounded by what you've actually viewed.

Other people's data in listings

Apartment posts usually contain someone else's contact details. YallaDira reads that text, extracts a phone number when it finds one, keeps it in the local cache, and — if you save the post as a favorite — in your favorites list. The favorites page can copy that number to your clipboard when you click the phone button.

What YallaDira does not do

Network activity

The extension makes no requests on its own. There are exactly three ways data leaves your browser, and all three require an explicit click by you:

ActionWhere it goesWhat is disclosed
"Report issue" → Submit Web3Forms, which emails it to the developer The report payload shown to you on screen before you send it
🗺️ Map button on a favorite Google Maps (www.google.com), opened in a new tab The address in the query — either the listing's street and city, or the location you typed as a manual correction
"Buy Me a Coffee" support button buymeacoffee.com, opened in a new tab Nothing from the extension — it's a plain link, so what the site sees is whatever any visit to a website reveals

The map and support buttons are normal outbound links. Clicking them hands the request to Google or to Buy Me a Coffee, under their own privacy policies, not this one. The extension does not fetch anything from either service in the background, and neither one is contacted unless you click.

Optional: issue reports

YallaDira's chip context menu includes a "Report issue" action. If you click it, the extension opens a report page that:

  1. Shows you the full payload (post text, the post's HTML snapshot, the chip evaluation, your settings, extension version, locale, user-agent string, timestamp, post permalink) before any submission.
  2. Lets you add an optional note and an optional reply-to email.
  3. Submits the report — only when you click Submit — to Web3Forms, which forwards it by email to the developer.

What this means:

Legal basis for the issue report

For users in the EEA/UK, the legal basis for processing an issue report is your consent (GDPR Art. 6(1)(a)). You give it by clicking Submit on the report page, after the full payload has been shown to you. You can withdraw it at any time by emailing yalladira@gmail.com — withdrawal means the report is deleted and not used further; it doesn't undo processing that already happened. Not submitting a report has no effect on the extension: every other feature works the same.

One distinction worth being precise about: your consent covers your own data in the report (your note, the optional reply-to email, your settings and browser details). The post you are reporting usually also contains someone else's personal data — typically the listing author's name or phone number. For that data the developer relies on legitimate interest (GDPR Art. 6(1)(f)): the narrow interest of diagnosing and fixing the reported extraction defect, using no more of the post than the report needs, deleting the report once it is resolved, and replacing personal identifiers with synthetic placeholders before any of it becomes a test fixture.

The rest of what the extension does is local processing on your own device, with no transfer to the developer, so no legal basis for a transfer to us is engaged.

Retention

A submitted report arrives as an email in the developer's mailbox. It is kept only as long as it takes to diagnose and fix what you reported, then deleted. If a report's post text is turned into a regression test fixture, identifiers of natural persons are replaced with synthetic placeholders first. Web3Forms is a relay in the middle and does not retain report bodies long-term — see their privacy page.

Local data (settings, favorites, cache) is kept until you delete it. The post cache also evicts itself: entries older than 30 days are dropped, and the store is capped at 5,000 entries.

Transfer outside Israel and the EEA

Web3Forms is operated from the United States — a third country from an EEA/UK and Israeli perspective. Submitting an issue report therefore transfers the payload outside Israel and the EEA. That transfer happens only when you click Submit. Their handling of it is described on their privacy page. If you'd rather not have data leave your region, don't submit reports — email the developer directly instead, or open an issue in the repository with only what you're comfortable sharing.

Your rights

With respect to a report you submitted, you can ask for:

Email yalladira@gmail.com to exercise any of these. One practical limit: reports are identified by the post id and, if you supplied one, your reply-to email. If you submitted a report with no email address and can't tell us which post it was about, we may be unable to locate it.

For data that never left your device, you don't need us at all — the "Wipe all data" button and your browser's own storage controls give you direct access and deletion.

You also have the right to complain to a supervisory authority. In the EEA/UK, that is your national data protection authority. In Israel, it is the Privacy Protection Authority (הרשות להגנת הפרטיות). This policy is written to address what the GDPR's transparency articles and Israel's Privacy Protection Law, 5741-1981 (as amended, including Amendment 13) expect a notice to tell you.

No profiling, no sale, no ads

Permissions

The extension requests these browser permissions:

PermissionWhy
storageTo save settings, favorites, and group labels locally.
scriptingTo re-inject content scripts after the user clicks "רענן תוסף" / refresh.
Host access to https://www.facebook.com/*To read post text and draw chips on listings you're viewing. No other site is accessed.

There is no host permission for any other domain. The issue-report submit, the map lookup and the support link all leave the extension's own reach — the first is a request from the extension's report page, the other two open a new browser tab.

Your controls

Children

YallaDira is not directed at children. It does not knowingly collect data from anyone.

Third-party code

The extension bundles one third-party library:

The full attribution, license notice, version shipped and source location are in THIRD-PARTY-NOTICES.md, which ships inside the extension package next to this page.

Non-affiliation and trademarks

Facebook and Meta are trademarks of Meta Platforms, Inc. Google, Google Maps and Chrome are trademarks of Google LLC. Firefox is a trademark of the Mozilla Foundation. YallaDira is an independent project and is not affiliated with, endorsed by, or sponsored by any of them. Those names are used only to describe what the extension works with.

Changes to this policy

If the policy changes, the "Effective date" above will be updated. Material changes (e.g., adding any network call) would be called out in the extension's listing notes.

Contact

For questions about this policy, to exercise any of the rights above, or to withdraw consent for a report you sent, contact yalladira@gmail.com.

You can also report a problem directly from the extension's built-in "Report issue" page, which shows you exactly what would be sent before you submit.