1. Who we are
ORIGO is provided by Lishi Studio, based in Israel. This policy explains what ORIGO does with information when you use the mobile app and this website. Questions: origo@lirshir.com.
We do not sell your personal information. ORIGO does not require an account and does not sync your history to the cloud.
2. What ORIGO is — and is not
ORIGO compares content you choose to check (a message, link, QR code, or — when available — a screenshot) against a local official directory, on-device rules, and optional cloud lookups described below.
ORIGO is not:
- an antivirus, firewall, or call/SMS blocker;
- a police, bank, or government service;
- legal, financial, or security advice;
- proof that a domain, brand, or sender is authentic in every case;
- a promise that “no warning signs” or “official match” means the situation is safe.
The official directory is a curated Israel-first seed, not a complete list of every legitimate organization in the world. A domain that is missing from the directory is not automatically fraud. A domain that matches the directory is not automatically harmless.
3. Information processed on your device
Most analysis runs locally. Depending on what you paste, share, type, or scan, ORIGO may process on the device:
- the text of a message or page you submit;
- URLs, email addresses, phone numbers, and tracking-style identifiers found in that text;
- an optional sender name or number you enter;
- QR payload from the camera, only after you choose to scan;
- text recognized from an image you select, when that feature is available — the image is not uploaded for OCR;
- language and appearance settings;
- a local history of checks, stored only on the device, with secrets such as one-time codes, passwords, and full card numbers redacted before saving.
You can delete history in the app. Uninstalling the app removes local ORIGO data on that device.
4. What leaves the device
ORIGO does not send the full message to look up a URL. When a cloud check runs, only the minimum needed for that check is sent to ORIGO’s backend (hosted on Cloudflare):
- Known-threat URL check. The URL (and, if redirect inspection is used, resolved hop URLs) is sent so the backend can query Google Web Risk. The message body is not sent for this check.
- Optional language assist. In ambiguous cases, a short redacted excerpt, related domains, and candidate organization IDs may be sent so the backend can call a language model (currently Google Gemini via the ORIGO server). One-time codes, passwords, and full card numbers are stripped first. This assist cannot override hard local security rules.
- Official directory updates. The app may download a public directory snapshot (organization names and official domains). This is not tied to your identity.
If the network is unavailable, local analysis still runs. A “no known threat” Web Risk result only means Google did not list that URL at check time — it is not a safety certificate.
5. Permissions
- Internet — optional URL threat checks, directory updates, and language assist.
- Camera — only if you scan a QR code. ORIGO does not record video or use the microphone for analysis.
- Photos / files — only if you pick an image. The image stays on the device for text recognition.
- Share sheet — if you share text or a link into ORIGO from another app, that content is treated as a check you initiated.
ORIGO does not use your location. Clipboard is read only if you tap paste.
6. Third parties
- Cloudflare — hosts the ORIGO API and this website. Standard request logs (IP, time, URL path) may be processed to operate and secure the service.
- Google Web Risk — receives the URL being checked, not your message. See Google’s privacy documentation for that API.
- Google Gemini (AI Studio) — may receive redacted text and domains for optional assist, only through ORIGO’s server, never as a client-side API key in the app.
App stores (Google Play, Apple) have their own privacy practices when you download or pay for apps.
7. This website
origo.lirshir.com is a public information site. It does not require login. We do not run advertising or cross-site tracking pixels on these pages. The server may keep ordinary access logs. You may contact us by email; we use that email only to respond.
8. Children
ORIGO is not directed at children under 13 (or the equivalent age of digital consent in your country). Do not submit other people’s messages that contain a child’s personal data.
9. Retention and your choices
- Device history: until you delete it or uninstall.
- URL checks: cached on the server by a hash of the URL for a short period to reduce repeat lookups — not as a profile of you.
- Email you send us: kept as needed to answer and for a reasonable legal record.
Because there is no account, we cannot remotely wipe a phone. Delete history or uninstall on the device itself.
10. International users
The operator is in Israel. Cloudflare and Google may process data in other countries. If you use ORIGO from the EEA/UK, the legal bases we rely on are providing the service you request (contract / legitimate interest in operating a security helper) and, where required, your consent for optional network checks.
11. Accuracy, limitation of liability
To the fullest extent permitted by law, Lishi Studio is not liable for decisions you make after seeing an ORIGO result — including clicking a link, ignoring a warning, or trusting a match that later proves wrong. Phishing, impersonation, and lookalike domains change constantly. ORIGO can be incomplete, outdated, or incorrect.
12. Changes
We may update this policy. The “Last updated” date will change. Continued use of the app after an update means you accept the revised policy.
13. Contact
Lishi Studio
Email: origo@lirshir.com
Policy URL: https://origo.lirshir.com/privacy/