Privacy Policy
Last updated: 2 August 2026
This Privacy Policy explains how Pebble Learning, Ltd. ("Pebble", "we", "us") collects, uses, and protects personal data in connection with the Pebble platform and the pebblearning website (the "Service"). It is written to align with Israel’s Protection of Privacy Law and its 2025 amendment (Amendment 13). For questions, contact [email protected].
Our role
For data about diagnosticians and other professional users, Pebble acts as the data controller. For the student and assessment data that a diagnostician or clinic enters into the Service, Pebble acts as a processor on their behalf: the diagnostician or clinic is the controller and is responsible for the lawful basis and consents for that data.
Information we collect
- Account and professional data — name, email, phone, role, organisation, and authentication identifiers.
- Assessment data entered by diagnosticians — student identifiers, intake and background information, test responses and scores, and the reports generated from them. This may include data about minors and sensitive data.
- Billing data — credit-pack purchases and invoices, processed by our payment provider (we do not store full card details).
- Technical and usage data — log data, device and browser information, and basic analytics needed to operate and secure the Service.
How we use information
- To provide the Service — manage accounts, run screenings, and draft and render reports.
- To secure the Service — authentication, abuse prevention, audit logging, and incident response.
- To support and communicate with you about the Service.
- To improve the Service, using aggregated or de-identified data where feasible.
- To comply with legal obligations and enforce our Terms.
Legal basis and consent
We process personal data on the bases permitted by Israel’s Protection of Privacy Law, including consent and the performance of our agreement with you. Where a diagnostician or clinic enters personal data about a student, they are responsible for obtaining the consents required by law before entering it into the Service.
Minors and sensitive data
Pebble is used in a clinical context that can involve data about minors and sensitive data. Under Israeli law, information about a minor under 14, and sensitive information about a minor under 18, may not be collected without the consent of a parent or guardian. The diagnostician or clinic that enters such data is responsible for obtaining that consent and for the lawful basis to process it. We apply heightened security to this data and limit access to it.
AI processing of report data
To draft reports, intake and assessment data are sent to a third-party AI model provider under a contract that prohibits using your data to train the provider’s models. We send only the data needed to produce the report and retain the provider’s output as part of the report. AI-generated content is a starting point and does not replace clinical judgment.
Sharing and sub-processors
We do not sell personal data. We share data only with service providers that help us run the Service — for example, cloud hosting, the AI model provider, and the payment processor — under contracts that require them to protect the data and use it only on our instructions. We may also disclose data where required by law.
Referring your child to a diagnostician
When you refer your child to a diagnostician and that diagnostician accepts the referral, they gain access to your child’s screening history and practice-run history: the date of each run, the per-domain scores, and which runs were practice rather than measurement. Practice runs are included because a diagnostician reading a score needs to know whether your child had already been shown the answers.
Screening is a sorting tool, not a diagnostic instrument, and these results are not part of a diagnostic report. Until a diagnostician accepts the referral they see only that a request exists — not your child’s results. Withdrawing consent removes your child from the diagnostician’s caseload and revokes any report links already shared.
International processing
Pebble’s data is hosted in Israel. Some processing — in particular AI inference for report drafting — may take place on servers located in the European Union or elsewhere, under contractual safeguards. This is the same category of cross-border processing that applies when intake data is sent to an AI provider.
Data retention
We retain personal data for as long as needed to provide the Service and to meet legal, accounting, and security obligations, after which it is deleted or de-identified. Controllers (diagnosticians or clinics) may request deletion of the data they entered, subject to legal retention requirements.
Security
We use technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit, access controls and least-privilege, audit logging, and regular review. No system is perfectly secure, but we work to protect your data and to respond promptly to incidents.
Your rights
Subject to Israeli law, you may request access to, correction of, or deletion of your personal data, and may object to certain processing. To exercise these rights, contact [email protected]. Where Pebble acts as a processor, we will refer requests about student data to the relevant controller.
Cookies
The Service uses only the cookies and local storage needed to operate (for example, to keep you signed in and to remember your accessibility preferences). We do not use advertising cookies.
Changes
We may update this Policy from time to time. Material changes will be reflected by the "last updated" date and, where appropriate, by additional notice.
Contact
For privacy questions or to exercise your rights: [email protected].