Privacy policy
Last updated: 29 August 2026
This policy explains what information is collected about you when you use the NES Defense website, community, course and library, operated by Scaling Ltd, why it is collected, who receives it, how long it is kept and what rights you have over it. It is written under Israel's Privacy Protection Law, 5741-1981 and its regulations, and it describes what our systems actually do, including the parts that are uncomfortable to write down.
Who is responsible, and how to reach us
Scaling Ltd, a private company registered in Israel under number 517190609, at Herzl Street, Kiryat Shmona, which operates the NES Defense brand, is the controlling owner of the database for the purposes of the Privacy Protection Law. This policy covers the website nes-defense.com, the community, the digital course, the library and enrolment in training.
It also describes what the mobile app actually does, so that the picture in front of you is complete. The app itself currently displays a separate, earlier policy screen, which is due to be replaced by this text. Four things stated on that screen do not describe the service. It says your details may be transferred or sold to third parties for their own purposes, whereas we do not sell personal information and do not currently pass it to third parties for their own commercial purposes. It says consent to marketing is given in a separate tick box, whereas when you open an account it is given in a single combined tick together with the terms of use and this privacy policy. It says target photos are stored in our storage, whereas target analysis runs on the device itself and the target photo is never sent to us or stored by us. And it says the app offers data export and account deletion, and neither exists in the app or anywhere in the service. Until that screen is replaced, what is written here is the accurate description of what our systems do.
Any privacy enquiry, including a request to inspect, to correct or to delete information, reaches us through the contact form on this site.
We have not appointed a privacy protection officer. We examined the criteria in section 17B1(a) of the Privacy Protection Law, and on our assessment we are not among the bodies that section requires to appoint one. If that changes, or if we appoint one of our own accord, we will add their name and contact details here.
In short, the things to know up front
- What you post in the community, and your profile page, are visible to anyone on the internet, not only to community members.
- The monthly national ranking is a public page that needs no sign-in, and community activity alone, without a single training, is enough to place you on it. There is currently no way to take yourself off it without closing your account.
- When you start a training in the app, the device's latitude and longitude are sent to our server and stored permanently on the training record.
- Course lessons play from youtube.com inside our own player, so Google receives information about your viewing.
- To stop course access being passed between people, we log and keep the devices and IP addresses you watched lessons from, and exceeding what is allowed blocks access automatically.
- Every enquiry sent through the contact form is stored with us as a full record in the database, not merely forwarded by email.
- The Google Analytics tag loads on every page of the site from the first view and regardless of your consent decision, so Google receives your IP address, your browser details and the page address before you have answered the dialog. The consent mechanism blocks storage on your device, not the loading of the tag and not those requests.
- The consent dialog does not put analytics, mailing or customer relationship management to a choice; it presents them as part of using the service. The only thing you can decline is sharing with commercial partners. Once a decision is recorded there is no way on the site to reopen the dialog and change it. The app has no consent dialog at all, and usage events are sent with no consent mechanism.
- We currently run no automatic deletion process, and an account cannot be deleted from inside the service. Information is kept until we act on a deletion request from you, or until we delete it in the annual review.
Giving us information, and what happens if you do not
In most places where we ask you for information, providing it depends on your will and your consent, and refusing has a practical consequence only, stated in that same section. There is one exception, a purchase, where some of the details are required by tax law in order to issue an invoice.
Some of the technical information described below, such as your IP address and the sign-in record, is created by the act of using the service and is not something you hand over. There is no situation in which refusing to give us information exposes you to any penalty from us. This detail is given under section 11 of the Privacy Protection Law.
Account and registration
Buying the course also opens an account for someone who did not have one, and a temporary password is emailed to the address you gave at checkout.
- What is collected: first and last name, email address, phone number, date of birth, a profile picture if you upload one, and your role in the service.
- Why: to identify you, allow secure sign-in, attach purchases, trainings and content to your account, and contact you about operational matters.
- If you do not provide it: first and last name, email address, phone number and date of birth are all required to open an account, and registration cannot be completed without them. Only the profile picture is optional, and leaving it out does not affect your use of the service.
- Your profile picture is stored inside our database rather than in separate file storage, and is served from a public address that needs no sign-in.
Community, profile and public content
The control that removes your post from the service hides it, so that replies to it survive, and does not remove the record from the database. Comments are not hidden this way: a comment you wrote stays visible in its thread after the post it replied to is hidden, and after your account is closed. If you want a post or a comment deleted outright, ask us through the contact form on this site. If you do not take part: you can use the whole of the rest of the service without posting in the community at all.
- Posts, comments and photos you upload to the community are shown to anyone, including people who are not registered and not signed in.
- Your public profile page shows your name, profile picture, a community badge derived from your seniority and activity, your join date, reputation earned from votes, your post and comment counts, and your most recent posts and comments.
- Photos you attach to posts are stored by us in Cloudflare file storage and served from a fixed public address that can be reached without going through the site. When that storage is unavailable, the post is saved without the photos.
- Your votes are stored and linked to your account, and are not displayed under your name.
- When someone replies to you, we keep an extract of their reply inside the notification, so a later edit does not change what was sent to you.
The monthly national ranking
The ranking is a public page that needs no sign-in. For up to two hundred members it shows the rank, name, profile picture, a community badge such as admin or newcomer, the number of trainings that month, and points. The public interface behind the page additionally returns reputation earned from votes and the post and comment counts for that month.
You appear in the ranking if, during that month, you logged a training, posted or replied in the community, or received a vote on something you wrote. Community activity alone, without a single training, is therefore enough to place you on this public page.
There is currently no switch in the service for turning your appearance off, and we have no way to take one member off the page while leaving their account active. The one thing that can be done is to close the account: ask us through the contact form on this site and we will close it, and a closed account stops appearing in the ranking. Closing an account ends your access to the whole service, deletes the session records and hides every post you wrote in the community. The comments you wrote stay visible in their threads, and your training records stay in the database. If that outcome is broader than you want, weigh it before you ask.
Trainings, ranges and location
If you do not provide it: you can refuse the location permission. The range list will then appear in its usual order rather than by distance, and you will not be able to start a logged training at all, because starting one depends on confirming you are within about half a kilometre of a known range.
Training takes place at licensed external ranges that we do not own, subject to the range's rules and the law that applies to it, and we do not pass your location to them.
- Training record: training type, goal, round count, the range, start and finish times and points.
- Location: when you start a training in the app, the device's latitude and longitude are sent to our server and stored on the training row, to verify the training took place at a range. The coordinates stay with the training record permanently and are not cleared when it ends.
- To show the name of the place you are in on screen, the device passes your point to its operating system's own mapping service.
- Range list: if you allow location access, your point is sent to the server in the request address with each request for the range list, so it can be sorted by distance. That request is not stored as a record of its own.
- Booking guided training: we store a link between your account and the session you booked, and the session itself carries the place it is held at.
Camera and photos in the app
We ask for access to the camera and the photo library in three places: when you photograph a target for analysis, when you upload a profile picture, and when you attach a photo to a community post.
Target analysis runs on the device itself, and the target photo is not sent to us and not stored by us. A profile picture and photos attached to a post are sent to us and stored. If you do not provide it: you can refuse access, in which case those features are unavailable to you and the rest of the service works as usual.
The digital course
This technical logging has one purpose: to stop paid course access being passed between people. Our administrators can view an account's device and IP history, including the browser identification and the viewing times, in order to handle blocks and unblock requests.
An automatic block does not cancel your purchase and does not affect your right to the course. If you are blocked, send an unblock request from the screen you are shown or through the contact form on this site, and we will answer within two business days. We are aware that a shared office network or moving between mobile networks can trip the limit through no fault of yours, and an unblock request in such a case will be granted. Lifting a block deletes the devices and IP addresses recorded for that account, and the count starts again from zero.
If you do not provide it: this information is created by the act of watching a lesson, and the course cannot be watched without it.
- Enrolment, your progress through each lesson including the stop position in seconds, and whether a lesson is marked complete. Progress is kept on our server, not only on your device.
- A device identifier stored in your browser, your browser identification, and the IP addresses you watched from, including the first and last address on each device.
- A list of every distinct IP address lessons were watched from, and how much video was served to you each day.
- Automatic blocking of access when the number of devices or distinct IP addresses goes above three, and the unblock request you wrote if you sent one.
- Email addresses of people granted course access before they had an account.
Lesson video is hosted on YouTube
Course lessons and some library clips are stored on YouTube as unlisted videos and shown inside our own player. This means that while you watch, Google receives your IP address, your browser details and the page the video was played from, and may use them under its own privacy policy. Video thumbnails are also loaded from Google's servers.
On lesson pages and library cards the player is loaded from the ordinary youtube.com address, not from YouTube's reduced-tracking host. The reduced-tracking host is used on the home page only.
Purchases and payment
If you do not provide it: a purchase cannot be made without these details, and some of them are required by tax law in order to issue an invoice.
- Payment is taken on a secure iCount payment page. Card details go directly to iCount, never pass through our servers and are not stored by us.
- We pass iCount your full name, first and last name, email address, phone number, an alternative invoice name if you gave one, and the amount. iCount creates a customer record on its side in order to issue the invoice.
- We keep an order record: email, full name, phone, amount, number of instalments, status, the iCount customer and document identifiers, and the payment date.
- If you arrived through an advertising campaign, the campaign source details attached to the link you followed are stored too.
Library downloads and leaving your details
The purpose is to send you the file, and to contact you later with content and offers in this field. Accepting the terms on these pages also carries your agreement to that contact, and it is not presented as a separate tick. You can ask us to stop at any time from the unsubscribe link in every marketing message, or through the contact form on this site.
If you do not provide it: without a name and email address these two pages cannot deliver the files. The rest of the site, the community and the magazine are open without it.
- In two places in the library, the targets download and the firearms licence paperwork, we ask for a name and email address before the download.
- Stored alongside them: the source of the request, the file chosen, answers to a short questionnaire if you answered it, the version of the terms you accepted, the time of consent and the IP address it was given from.
The mailing list
There are two ways onto the mailing list. Through the sign-up box at the foot of the website, joining is a separate, explicit action. When you open an account, on the website and in the app alike, a single tick accepts the terms of use, the privacy policy and joining the mailing list together, with no separate box for the mailing, and registration cannot be completed without it.
Either way we store the email address, the language, the source of the sign-up and the consent record itself. You can remove yourself at any time from the unsubscribe link in every marketing message, or through the contact form on this site.
If you do not provide it: not joining the mailing list has no effect on any other part of the service, and leaving it has no effect on your account.
Contact form
Every enquiry sent through the form is stored by us in the database as a full record: name, email address, phone, topic, area of interest, the body of the message, the language of the enquiry, and your account if you were signed in when you sent it. The record is not deleted once the enquiry is dealt with, and our administrators can read it back.
A notification carrying the content of the enquiry is also sent to a company mailbox hosted on a Google mail service.
If you do not provide it: an enquiry cannot be sent without the details the form asks for, but you are not obliged to use it.
Technical information we keep
- Each sign-in creates a session record holding your IP address and your browser identification.
- Consent records hold a visitor identifier, your account if you were signed in, browser identification, the policy version shown and the time of the decision.
- Sign-in attempts are counted per IP address in order to block automated attempts, and the IP address itself is held inside the counting key.
- On a first visit to the home page the site infers the country you arrived from, using a value the hosting platform derives from your IP address, in order to choose Hebrew or English. Where that value is absent, the language your browser states is used instead. Once a language is chosen it is kept in a cookie and this check is not repeated.
- IP addresses and browser identifiers are stored in our database itself, not only in short-lived log files: IP addresses in five separate tables, and browser identifiers in three.
Cookies and storage in your browser and device
You can clear the cookies and the local storage at any time from your browser settings. Doing so also clears the consent decision held in your browser, but the record of that decision kept with us remains, and there is no way on the site to reopen the consent dialog and change a decision already recorded. To change or withdraw a consent, write to us through the contact form on this site.
- A session cookie, which keeps you signed in to your account.
- A language cookie, which remembers whether you chose Hebrew or English, for one year.
- Google Analytics cookies, namely _ga and _ga_G-ETCNQZY9HV, which recognise a returning browser and allow visits and referral sources to be measured. They are written to your device once your consent decision is recorded, as described in the measurement and analytics section.
- Local storage in the browser: your consent decision, a visitor identifier, a device identifier for the course, and your accessibility widget preferences, that is text size, contrast, readable font, underlined links and reduced motion.
- Storage for the visit only: if you arrived through a link carrying campaign parameters, those parameters are kept in the browser until the tab is closed, so they can be attached to a purchase if you make one.
- In the app: the sign-in token is held in the device's secure store, and the range list is cached locally to speed up loading.
Measurement, analytics and the consent dialog
On the website we use Google Analytics 4, measurement id G-ETCNQZY9HV. The measurement tag is loaded from Google Tag Manager's servers on every page of the site, from the first view and before you have answered the consent dialog. This means Google receives, at that same moment, your IP address, your browser details and the address of the page you are looking at. The tool runs in consent mode, and consent mode blocks storage on your device, that is the analytics and advertising cookies, until your decision is recorded. It does not prevent the tag from loading and it does not prevent those requests to Google. Two operational categories, functionality storage and security storage, are enabled from the start, and advertising personalisation is never enabled by us.
The measurement and advertising tools we use on the website, or may use, are Google Analytics 4, a Meta pixel for Facebook and Instagram, and a TikTok pixel. As at the date of this update, the only one actually running on the site is Google Analytics 4, and as described above it loads on every page regardless of your consent decision, while the consent mechanism governs only its storage on your device. The Meta and TikTok pixels are not running on the site today, and if we switch them on we will update this page first.
The app has no consent dialog and no consent mechanism of any kind. From installation it creates a random install identifier, and usage events such as screen view, sign-in, sign-up, lesson start, lesson complete, training created, training completed and purchase started are sent from our server to the same Google Analytics property. Those events carry only the install identifier and a session identifier; they are not tied to your account and do not carry your name. There is currently no switch in the app for turning this collection off, and because the events never reach an account, we cannot find them and stop them for a particular account. We would rather not promise here something we cannot deliver.
The consent dialog on the website says we use cookies to run the site and improve it, and links here for the detail. Analytics, mailing and customer relationship management are not put to a choice in it: they are presented as part of using the service, and the dialog offers no way to decline them. The only thing that can be declined is sharing with commercial partners, which is ticked by default and granted by the main accept button too, though you can open Options, untick it and save without it. Once a decision is recorded there is no way on the site to reopen the dialog and change it, so changing or withdrawing a consent is done by writing to us through the contact form on this site. We are aware that this design does not put measurement and mailing to a choice, and we are reconsidering it. Every decision is recorded against the policy version you were shown at that moment.
Who receives your information
These are the parties that actually receive personal information from us, and what for. The measurement and advertising tools are described in the previous section. It matters that you know the Google Analytics tag loads on every page of the site regardless of your consent decision, so Google receives your IP address, your browser details and the page address from the first view, and the consent mechanism governs only storage on your device.
- Klaviyo, United States, customer relationship management and mailing. It receives every account holder, every mailing list subscriber and everyone who left details on the library pages: email address, first and last name, language, role, registration date, the source of the enquiry and whether the sign-up happened in the app. The sync runs once a day and on every change. Closing an account with us does not delete the profile created there.
- Brevo, European Union, operational email: address verification at sign-up, contact-form notifications, notices about course access, and the temporary password sent after a purchase.
- iCount, Israel, payment processing and invoicing.
- Google, in three separate roles: measurement and analytics, both from every page of the site and from the app's events, hosting the lesson video on YouTube, and the mailbox that receives contact-form notifications together with their content.
- Cloudflare, outside Israel, running the server, the database and storage of the photos you upload.
- Vercel, outside Israel, hosting the website, including inferring the country you arrived from in order to choose the language.
- Cloudflare's automatic translation service. The feature is built to send text you wrote in the community there for translation between Hebrew and English, caching the result with us, but it is not switched on today and in practice no text reaches it. We will update this page before enabling it.
- Competent authorities, if and when we are required to disclose by law or court order.
- Range data on the site is gathered from Google's places service. The query we send it contains no personal information about you.
Selling and commercial sharing
We do not sell personal information, and we do not currently pass it to third parties for their own commercial purposes. The consent dialog asks for your consent to such sharing, and that is the only item in the dialog you can decline. Declining has no effect on the service.
If we ever begin to rely on that consent, we will update this policy, name the recipients and the purpose of the transfer, and show the consent dialog again for the new version. You can withdraw the consent at any time through the contact form on this site, and withdrawal applies from the moment you tell us onwards.
Transfers outside Israel
The website, the server, the database and the photos you upload are stored outside Israel, with Vercel and Cloudflare. Klaviyo and Google operate from the United States, and Brevo operates from the European Union.
Transfers are made under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, relying on your consent to the transfer as it is set out here. Alongside that consent we are working to put in place, with each of these providers, a written undertaking to use the information only for the purpose it was given for, to take sufficient security measures, to keep it confidential, to let us give effect to your rights of access and correction, and not to pass the information to anyone else. We will update this page when that is complete.
If you do not agree: the service is built on these platforms, so it cannot be provided without this transfer.
Direct mail
Marketing messages we send by email are advertisements under section 30A of the Communications (Telecommunications and Broadcasts) Law, 5742-1982, and they are also a direct-mail approach under the Privacy Protection Law.
The information the approach is based on came from you: from opening an account, from a purchase, from leaving details on the library pages, or from signing up to the mailing list. When you open an account, consent to the mailing is given in a combined tick box rather than a separate one, as the mailing list section describes, and we are working to separate it.
You may at any time, free of charge, send a refusal notice and demand that we remove you from the database used for direct mail. You can do that from the unsubscribe link in every message, which takes effect immediately, or through the contact form on this site, in which case we will carry out the removal and confirm it to you in writing.
A removal is recorded with its date, and we do not delete the original sign-up row, so that we can show the removal was carried out and when.
How long we keep it
Here we would rather tell the truth than promise a schedule we do not run.
- We currently run no automatic process that deletes information. Once a year we examine, as the Privacy Protection (Data Security) Regulations, 5777-2017 require, whether the information we keep exceeds what the purposes it was collected for require, and delete information that is no longer needed. Information is also deleted in response to your request.
- Purchase records and invoices are kept for seven years from the end of the tax year they relate to, or six years from the filing of that year's return, whichever is later, as the bookkeeping rules require.
- Consent records and unsubscribe records are kept as evidence that the consent or the removal was given, including after an account is closed.
- An account cannot be deleted from inside the service. When we close or block an account, access ends, the session records are deleted, and every post that member wrote in the community is hidden. The comments they wrote are not hidden and stay visible in their threads, and the account records themselves stay in the database.
- Information collected about a closed account, including the account details, order records, contact-form enquiries and the course device and IP history, is kept until we act on a deletion request or until the annual review. The course device and IP history is also cleared earlier, every time we lift a block on that account.
How to ask for deletion
Deletion requests are handled by hand. Send one through the contact form on this site in whatever form suits you; no special form and no registered letter is needed. Within thirty days we will tell you what was deleted, what was kept and why.
If you ask us to close the account, know in advance what that does: access ends, the session records are deleted and every post you wrote is hidden, but the comments you wrote stay visible in their threads. Deleting a particular comment is done by hand on request.
A request to be removed from the mailing list is carried out immediately and confirmed in writing. Information we are required to keep by law, such as invoices, and consent and unsubscribe records, is kept even after a deletion request.
Your rights
Under sections 13 and 14 of the Privacy Protection Law you have the right to inspect the information we hold about you, and the right to ask us to correct or delete information that is incorrect, incomplete, unclear or out of date.
An inspection request is made through the contact form on this site. You may make it yourself, through an agent holding a written power of attorney, or through a guardian. We reply within thirty days, and provide the information in Hebrew, Arabic or English, as section 13(b) of the law provides. If you prefer one of the three, say so in your request and we will try to meet it. The regulations permit a fee for an inspection request, and we do not charge it.
If we refuse an inspection request, we will tell you in writing within twenty one days of receiving it. If we refuse a correction or deletion request, we will tell you in writing within thirty days of receiving it, and give our reason. No answer within those periods counts as a refusal. You may appeal a refusal to the Magistrates' Court within thirty days of the refusal notice, and you may also apply to the Privacy Protection Authority.
If we agree to correct or delete information, we will also notify the parties that received it from us in the three years preceding the correction or deletion. Documents issued as the law requires, such as invoices, cannot be altered after the fact.
You may withdraw any consent you gave at any time. Withdrawal applies from the moment you tell us onwards and does not undo uses already made. You can withdraw by unsubscribing from the link in every marketing message, or by writing to us through the contact form on this site. There is currently no button on the site that reopens the consent dialog, and no way for you to change a decision that has already been recorded, so writing to us is how it is done.
Security
Traffic to the website and the app is encrypted, passwords are stored hashed rather than in readable form, access to personal information is limited by role, and the number of authorised staff is small. We work to the Privacy Protection (Data Security) Regulations, 5777-2017, and are completing an internal database definition document recording the information in the database, its purposes and its transfers outside Israel.
No system is perfectly secure, so we cannot promise absolute security. If a security incident affecting your information occurs, we will deal with it, document it and act on whatever duties apply to us at that time.
Minors
The service is intended for adults. Live-fire training, buying the course and taking part in the community are not intended for anyone under eighteen, regardless of any guardian's consent. Accounts are opened for adults only. Training takes place at licensed ranges only, subject to the range's rules and the law that applies to it.
In the app, registration is automatically refused when the date of birth given shows the person is under eighteen. On the website the same date of birth is collected but is not currently checked, so no automatic refusal happens there. We do not verify the date given against any document.
If a guardian contacts us through the contact form on this site about a minor's account, we will close the account and act on a request to delete the information collected.
Changes to this policy
Every version of this policy carries a date, shown at the top of the page. When we make a material change we publish a new version and show the consent dialog for that new version, so that consent is given to the version you actually read rather than to an earlier one.
This policy describes what our systems do as at the date of update. If you find a gap between what is written here and what the service actually does, please tell us through the contact form on this site and we will fix it.

