Privacy Policy
Last updated: September 18, 2026 · Version 1.0
At a glance.
- What we collect: your sign-in email and name, the profile you build, what you post, the communities you join, what you open in the app, and a few technical details about your device. No location, no contacts, no advertising identifiers.
- Why: to run Shoresh, show your posts to the right people, send the notifications you ask for, power the AI study tools, keep the community safe, and fix bugs.
- We do not sell your information, we do not show ads, and we do not track you across other apps or websites. Shoresh is funded by the optional Shoresh Plus subscription.
- Religious beliefs are sensitive. Using a Jewish learning app says something about you. We ask for your explicit consent to process that, use it only to run the service, and never for advertising or profiling.
- Who helps us: a small set of providers (Supabase, Apple, Google, OneSignal, Mux, Anthropic, Cloudflare, Sefaria and, for subscriptions, RevenueCat). Section 6 lists what each one receives.
- Your controls: edit or delete anything you posted, tune notifications, block people, and delete your whole account from Settings, instantly. Email us for anything else.
This box is a summary. The full policy below is what applies.
Contents
- Who we are and what this policy covers
- Information we collect
- Sensitive information: religious beliefs
- How we use information, and our legal bases
- Who can see what on Shoresh
- Who we share information with
- Third-party content, embedded players and links
- Device permissions and what we do not collect
- Video viewing information
- How long we keep information
- Your choices and controls
- Your privacy rights and how to use them
- Children and minimum age
- Security
- Where your information is stored and international transfers
- Notices for specific regions
- Our website
- Changes to this policy
- Contact
- Change log
1. Who we are and what this policy covers
Shoresh is operated by Talking Ventures LLC, a Delaware limited liability company with its mailing address at 614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States ("Shoresh", "we", "us" or "our"). We are the data controller of the personal information described here. This policy covers the Shoresh iOS app, the website at shoresh.app, and our communications with you (for example, when you email us). It does not cover Apple, Google, Sefaria or any other third party whose services you use alongside Shoresh; their own policies apply to them. Our Terms and Conditions govern your use of Shoresh.
2. Information we collect
In short: the table below is the complete inventory. "You" means you gave it to us; "the app" means the app generated it as you used Shoresh.
| Category | What it includes | Source | Why we have it |
|---|---|---|---|
| Sign-in details | Your email address, the name your sign-in provider gives us (used only to pre-fill your profile), which provider you used (Apple or Google), and the stable account identifier the provider assigns. If you use Apple's "Hide My Email", we receive a relay address instead of your real one. | Apple or Google, when you sign in | To create and secure your account and to contact you about it. |
| Profile | Username, display name, profile photo, bio, and optional links (website, Instagram, X, YouTube, Substack). If you are verified, a short credentials line approved by our team. | You | To identify you to other members. All of this is public to signed-in members. |
| Date of birth | The birth date you enter during sign-up. | You | To confirm you are at least 16. Stored privately, never shown to anyone, and not used for anything else. |
| Learning profile | Optional answers to three sign-up questions: your level of experience with Jewish texts, the affiliations or background you choose to share (with a "prefer not to say" option), and the themes you are interested in. | You | To suggest communities, texts and themes. Visible only to you; even our team's admin tools cannot read it. Editable in Settings. |
| Content you post | Discussions, responses and comments (text, formatting, citations of Torah texts), images, voice notes and other audio, video, documents and other files, links you paste (and the title, description and image our server fetches from the linked page to show a preview), plus the time you posted or edited. | You | To show your contributions to the people your community settings allow. |
| Community activity | Communities and chaburot you belong to, your role in each, join requests and their outcome, invitations sent to you, invite links you used, and community-level removals or bans with the reason given. | You, community leaders, the app | To run communities and enforce their settings. |
| Engagement | Your reactions, saves (of posts, communities, profiles, texts and topics), shares (including "copy link"), "notify me" subscriptions to posts and communities, and hidden posts. | You | To power those features and their counts. Reactions are visible to anyone who can see the post; saves and notification subscriptions are private to you. |
| View history | Which posts, profiles, communities, texts and topics you opened, and when. Roughly one record per item per session. | The app | To show your "Recently viewed" lists, unread indicators and "mark all as read". Visible only to you. Not shared with anyone, including the people whose profiles or posts you viewed. |
| Notifications | Your in-app notification feed, which kinds of push notifications you have turned on, per-community notification preferences, and a record of what you have seen. | The app, you | To deliver the notifications you asked for. |
| AI study tool usage | For each AI action: the kind of action, the passage it concerned, the outcome, and the number of tokens used. Explanations themselves are stored in a shared cache that carries no information about who requested them. If we add tools that take your own words as input (for example, a study assistant), the conversation will be stored with your account so you can revisit it, and this policy will say so. | The app | To apply monthly allowances and fair-use limits, and to operate and improve the tools. |
| Subscription and entitlements | Whether you have Shoresh Plus, how you got it (App Store purchase, invite code or complimentary access), its expiry, the Apple transaction identifier, and any invite codes you redeemed. We never receive your card or bank details; Apple keeps those. | Apple, RevenueCat, you | To unlock the features you are entitled to. Applies only once Plus is offered. |
| Verification application | If you apply to be verified: your credentials, ordination (smicha) source, affiliation, a link to sample writings, references, and our reviewers' notes and decision. | You, our team | To review your application. Visible only to you and our verification team. |
| Reports, blocks and moderation records | Reports you file (category, note, outcome), people you block, and records of moderation actions taken by community leaders or our team about your content or account, with the reasons given. If you delete a post that has replies, a copy of its text is kept in a restricted store. | You, community leaders, our team | To keep Shoresh safe, handle reports, and investigate abuse. Reports are confidential; the person you report never learns who reported them. |
| App activity and device details | When you last used the app, how many times you have opened it, the app version, iOS version, device model (for example "iPhone16,2"), language, time zone, whether push notifications are allowed, and your appearance preferences. | The app | To understand usage, support you, and fix problems that affect specific versions or devices. |
| Diagnostics | When a Torah text fails to load or is unavailable because of its license, the app sends us the reference, the endpoint, the error and the app version. These reports carry no user identifier. Separately, if the app crashes or hits an unexpected error, a crash report goes to our crash-reporting provider (Sentry, see section 6.1) with the app version, iOS version, device model, the technical details of the failure, and your account identifier (a random ID, never your name or email) so we can tell one person's repeated crash from many people's. Crash reports never include what you were typing or reading. | The app | To fix text-loading problems and crashes. |
| Support communications | Emails you send us and our replies, including any requests you make under this policy. | You | To help you and keep a record of what we agreed. |
| Infrastructure logs | Our hosting providers (Supabase for the app's backend, Cloudflare for the website) keep standard server logs that include your IP address, request times and the app or browser version. We do not build profiles from them. | The app, your browser | Security, abuse prevention and debugging. |
What is required. To use Shoresh you need to sign in, choose a username and display name, and give your date of birth; without those we cannot create your account. Everything else, including the learning profile questions, a profile photo, a bio and anything you post, is optional.
What we do not collect. We do not collect your location, your contacts, your photo library (you pick individual images through Apple's picker, which shares only what you choose), advertising identifiers, biometrics, health information, or precise device fingerprints. The app contains no advertising or analytics SDKs; the only third-party SDK that sends anything about you is the crash reporter described above. See section 8.
3. Sensitive information: religious beliefs
In short: being on Shoresh may reveal your religion. We treat that as sensitive, ask for your explicit consent, and use it only to run the service.
Shoresh is built for Orthodox Jewish learning. The fact that you have an account, the communities you join, the affiliations you choose to share in your learning profile, and what you post may reveal your religious beliefs and practice. Laws in the United Kingdom, the European Union, Israel, several US states and elsewhere treat information about religious beliefs as sensitive. Here is how we handle it:
- Consent. During sign-up we ask for your explicit consent to process information that may reveal your religious beliefs, separately from your agreement to the Terms. You can withdraw that consent at any time by deleting your account (section 11), which is the only way to stop the processing because the service cannot run without it.
- Strictly necessary use only. We use this information only to provide what you asked for (showing you your communities, delivering your notifications, running the AI tools you invoke, suggesting content based on the learning profile you chose to fill in) and to keep Shoresh safe.
- Never for advertising, profiling or sale. We do not sell it, do not use it for advertising, do not use it to make automated decisions about you, and do not share it with anyone other than the service providers who process it on our instructions (section 6).
- The learning profile is private. Your answers to the sign-up questions are visible only to you. Our own admin tools are deliberately built so they cannot read them.
- What you post is your choice. Anything you post is visible to the people your community settings allow, by your decision.
- Verification applications are seen only by our verification team.
4. How we use information, and our legal bases
In short: to run Shoresh, keep it safe, and improve it. The right-hand column is for readers in the UK, the EEA and other places whose law requires a "legal basis" for each purpose.
| Purpose | What we use | Legal basis |
|---|---|---|
| Provide the service | Sign-in details, profile, content, community activity, engagement, view history, notifications, entitlements | Performance of our contract with you (the Terms); explicit consent for information revealing religious beliefs |
| Check your age | Date of birth | Legal obligation and legitimate interest in keeping the service to people 16 and over |
| Suggest communities, texts and themes | Learning profile, view history, community activity | Consent (the learning profile is optional) and performance of the contract |
| Send notifications | Notification preferences, activity that triggers a notification, the device record held by OneSignal | Consent (you allow push notifications on your device and choose the kinds); performance of the contract for the in-app feed |
| Run the AI study tools | The passage you ask about, your usage record, your entitlement | Performance of the contract |
| Process subscriptions | Apple transaction identifier, entitlement, invite codes | Performance of the contract; legal obligation (tax and accounting records) |
| Safety, moderation and enforcement | Reports, blocks, moderation records, content, account activity, verification applications | Legitimate interests in keeping the service safe and enforcing the Terms; legal obligation where the law requires action |
| Support you | Support communications, account details | Performance of the contract; legitimate interest in answering you |
| Fix bugs and improve Shoresh | App activity and device details, diagnostics, infrastructure logs, aggregated usage | Legitimate interests in a reliable, improving product |
| Security and fraud prevention | Infrastructure logs, account activity, entitlements | Legitimate interests in protecting the service and its members; legal obligation |
| Comply with the law and defend claims | Whatever is relevant to the obligation or claim | Legal obligation; legitimate interests in establishing, exercising or defending legal claims |
| Tell you about changes to Shoresh | Email address, in-app notices | Performance of the contract; legitimate interest in keeping you informed |
No automated decisions. We do not make decisions about you by automated means that have legal or similarly significant effects. Usage limits on the AI tools are applied automatically, but they are simple counters, not judgments about you.
No marketing email. We do not currently send marketing email. If we start, we will only do so with your permission where the law requires it, and every message will include a way to stop.
5. Who can see what on Shoresh
In short: nothing on Shoresh is visible to the public internet. Within Shoresh, your profile is visible to signed-in members, and your posts are visible according to the community they are in.
- No signed-out access. Nothing in Shoresh can be read without a Shoresh account. Our website never displays posts, profiles or any member content; a shared link opened on the web shows only a generic "open this in the app" page.
- Your profile (username, display name, photo, bio, links, verified badge and credentials line, join date, and counts of your posts) is visible to every signed-in member. Which of your posts a member can see depends on the communities they belong to.
- Posts are visible according to their community's setting: public (any member), unlisted (anyone with the link), restricted (members of that community only) or private (members only, and the community is invisible to others). Chaburot are always members-only. Community leaders can also see posts awaiting approval and moderation records for their community.
- Reactions are visible to anyone who can see the post, including who reacted. Saves and notification subscriptions are private; only totals are shown. Shares are recorded, and only totals are shown.
- Media files (images, audio, documents and video posters) are served from long, random web addresses that are not listed anywhere. Anyone who obtains such an address can open the file, even if the post is in a private community. Video streams are protected by short-lived tokens issued only to people allowed to see the post.
- Share links contain an opaque identifier, not your name. Whoever receives a link can open the post only if their account is allowed to see it.
- Deleted accounts. Posts you did not delete before deleting your account remain in their communities under a "deleted user" label, without your name or profile.
- Our team can access account and content information as needed to run the service, respond to reports, provide support and investigate abuse, except the learning profile, which is walled off.
6. Who we share information with
In short: with the providers that run pieces of Shoresh for us, with other members as your settings allow, and with authorities when the law requires. Never with advertisers or data brokers.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in US state privacy laws. We have not done so in the past 12 months. Shoresh is funded by the optional Shoresh Plus subscription, not by advertising.
6.1 Service providers
These companies process information on our behalf, under contracts that limit them to providing their service to us and require them to protect it. Each has its own privacy policy covering how it operates its service.
| Provider | What it does for Shoresh | What it receives |
|---|---|---|
| Supabase (Supabase Pte. Ltd.), on Amazon Web Services | Database, authentication, file storage and server-side functions. Our data lives in the AWS "us-east-1" region in the United States. | Everything in section 2, because it is where Shoresh's data is stored. |
| Apple | Sign in with Apple, App Store and TestFlight distribution, In-App Purchase billing, push notification delivery (APNs), and on-device speech recognition for dictation (which may send audio to Apple's servers). | Your Apple Account interactions with Shoresh (sign-in, purchases), push delivery to your device, and dictation audio if you use the microphone dictation feature. Apple's privacy policy applies. |
| Sign in with Google. | The fact that you signed in to Shoresh with your Google Account. Google's privacy policy applies. | |
| OneSignal | Sends push notifications to your device. | A pseudonymous identifier for your account (not your email or name), your device's push token, and the text of each notification we send you (which can include other members' display names and post titles). OneSignal holds the device token; we do not. |
| Mux | Stores, processes and streams videos that members upload. | The video files themselves. Mux does not receive your name, account identifier or any other information about who uploads or watches; see section 9. |
| Anthropic | Provides the AI models behind the AI study tools. | For "Explain": the licensed source passage and its context, with no information about you and nothing you wrote. For any future tool that works on your own words, your input, which the tool will tell you before you use it. Under Anthropic's commercial terms, it does not use this data to train its models and deletes API inputs and outputs within about 30 days. |
| Sefaria | Provides the Torah texts, translations, commentaries, search and topic data that Shoresh displays. Sefaria is a data source, not a processor working for us. | Your device talks to Sefaria's servers directly, so Sefaria sees your device's IP address and the requests it makes: which texts you open, your text searches, and the text of a post you are composing when the app checks it for citations to link. We never send Sefaria your name or account identifier. Sefaria's own privacy policy applies to what it does with that traffic. |
| RevenueCat | Confirms and manages Shoresh Plus subscriptions (once Plus is offered). | A pseudonymous identifier for your account, Apple purchase receipts and transaction identifiers, device type and app version. Never your name, email or payment details. |
| Sentry (Functional Software, Inc.) | Crash reporting for the app. | Crash and error reports: app version, iOS version, device model, the technical details of the failure, and your account identifier. No name, email, IP-based location or content. Kept for 90 days. |
| Cloudflare | Hosts and serves our website, shoresh.app. | Standard web request logs (IP address, browser, pages requested) when you visit the website. |
6.2 Other members and the public
Information is visible to other members as described in section 5. Nothing is visible to the public.
6.3 Community leaders
Leaders of a community you belong to can see your membership, your role, your join request, the posts you make in that community, and moderation records within that community. They cannot see your email, date of birth, learning profile, saves, view history or activity in other communities.
6.4 Legal, safety and business reasons
- Legal requests. We may disclose information to comply with a law, regulation, court order, subpoena or other legal process, or a lawful request from a public authority. Where the law allows, we will try to notify you before disclosing your information in response to a request that names you.
- Safety. We may disclose information where we believe in good faith it is necessary to prevent harm to a person, to investigate fraud, abuse or security issues, or to protect the rights and property of Shoresh and its members. We report child sexual exploitation material to the National Center for Missing and Exploited Children.
- Business transfers. If Shoresh is involved in a merger, acquisition, financing, reorganization or sale of assets, your information may be transferred as part of that transaction. We will notify you and this policy will continue to apply until it is changed with notice.
- With your direction. When you share a link, embed content from another service, or ask us to send information somewhere, we do what you asked.
- Aggregated information. We may share statistics that do not identify anyone (for example, how many people use a feature).
7. Third-party content, embedded players and links
In short: when a post embeds a YouTube video or you open a link, the other service sees you, not us.
- Embedded players. Posts can embed content from YouTube, Vimeo, Spotify, SoundCloud and Apple Podcasts. When such a post is on your screen, the app loads the player from that service, which can see your IP address and set its own cookies under its own privacy policy. We use YouTube's privacy-enhanced embed mode. The app also fetches titles and artwork for such links directly from those services.
- Links you open. Links in posts open in an in-app browser. The site you open sees you as any website would.
- Links you paste. When you paste a link into a post, our server fetches the page to build a preview (title, description, image). The preview is cached for up to 14 days without any record of who pasted it. The linked site sees a request from our server, not from your device.
8. Device permissions and what we do not collect
- Camera: only when you choose to record a video for a post or take a profile photo. Nothing is captured otherwise.
- Microphone: only when you record a voice note or use dictation. Voice notes are uploaded as part of your post. Dictation uses Apple's speech recognition, which may process audio on Apple's servers; we receive only the resulting text.
- Photos and files: you choose individual items through Apple's pickers and the Files app. We never scan your library. Images are resized and re-encoded before upload, which removes embedded metadata such as the location a photo was taken.
- Notifications: only if you allow them; you can change this any time in iOS Settings.
- Not used: location, contacts, Bluetooth, health data, advertising tracking (we do not use Apple's App Tracking Transparency because we do not track), Face ID or other biometrics, background location. The app does not read your clipboard.
- Stored on your device only: drafts you are composing, cached texts and images so pages load quickly, audio and video playback positions, and in-app tips you have seen. Signing out clears cached media.
9. Video viewing information
When you watch a video on Shoresh, the app records that you opened the post (as part of your view history) and asks our server for a short-lived playback token. Our video provider, Mux, receives the token and streams the video; it does not receive your identity, and we do not send it any viewer identifier. We treat your viewing history as personal information. We do not disclose which videos you have watched to anyone outside the service providers in section 6, and we will not share it with any third party for that party's own purposes without your separate, informed, written consent, which you could withdraw at any time.
10. How long we keep information
In short: most things live as long as your account does and are deleted the moment you delete it. A few things are kept for legal, safety or technical reasons, listed below.
| Information | How long |
|---|---|
| Account, sign-in details, profile, date of birth, learning profile | Until you delete your account. Deleted immediately when you do. |
| Posts and attachments | Until you delete them. Media files are deleted with the post; files that end up unreferenced are swept within about 30 days. Posts you have not deleted remain after account deletion under a "deleted user" label, with your name and profile removed and their attached media deleted. |
| Text of a deleted post that had replies | Kept in a restricted store for as long as needed for abuse investigations and support-side restores, then deleted. |
| Videos | Deleted from Mux when you delete the post or your account. Uploads that never attach to a post are deleted within about a day. |
| Community activity, engagement, view history, notifications, notification preferences, AI usage records, entitlements, invite code redemptions, verification applications, reports you filed, blocks | Until you delete your account; deleted immediately when you do. |
| App activity and device details | One current snapshot per account, overwritten as you use the app; deleted with your account. |
| Moderation records about actions taken in a community | Kept with the community as its audit record. When an account is deleted, its identifier is removed from those records. |
| Cached AI explanations | Kept and shared; they contain no personal information. |
| Link previews | Up to 14 days; they contain no personal information. |
| Diagnostics (text loading errors) | Kept as engineering records; they contain no personal information. |
| Support communications | As long as needed to resolve your request and keep a record of it, typically up to three years. |
| Purchase records held by Apple and RevenueCat | Under their own retention rules (RevenueCat states up to six years after the account ends), as required for tax and accounting. |
| Push notification device record held by OneSignal | Until your device unsubscribes or OneSignal's retention period ends. After you delete your account, the record is no longer linked to any Shoresh account. |
| Data sent to Anthropic | Deleted by Anthropic within about 30 days under its commercial terms. |
| Infrastructure logs | A short period set by the hosting provider, typically under 30 days. |
| Backups | Routine database backups are overwritten within 30 days. Deleted data may persist in a backup until then. |
| Legal holds | If information is needed for a legal claim, investigation or legal obligation, we keep only what is needed for as long as that lasts. |
11. Your choices and controls
In short: almost everything is in Settings, and account deletion is immediate.
- Edit your profile and your learning profile ("About you") in Settings at any time.
- Edit or delete your posts from the post itself. Deleting a post with replies removes its text and leaves a "deleted" marker so the replies still make sense.
- Notifications: choose which kinds send a push in Settings, set per-community preferences, turn "notify me" on or off for individual posts and communities, or revoke the permission in iOS Settings. The in-app feed always shows your notifications.
- Block any member from their profile; manage the list in Settings under Privacy. Blocking hides your content and theirs from each other and is never revealed to them.
- Leave a community at any time from the community's page.
- Subscriptions: manage or cancel Shoresh Plus in your Apple Account settings. Deleting your Shoresh account does not cancel a subscription.
- Sign in with Apple: if you chose "Hide My Email", Apple forwards our messages to your real address. You can stop forwarding or stop using Apple ID with Shoresh in your Apple Account settings; if you do, our emails will not reach you.
- Delete your account: in the app, open the You tab, then Settings, then tap "Delete account" and confirm. Deletion happens immediately: your profile, sign-in details, date of birth, learning profile, saves, view history, notifications, entitlements, reports, blocks, verification application, media files and videos are deleted. Posts you did not delete first remain under a "deleted user" label (section 5). If you cannot access the app, email us and we will verify your identity and delete the account for you.
- Withdraw consent: for the learning profile, clear your answers in Settings. For information revealing religious beliefs, delete your account (section 3).
12. Your privacy rights and how to use them
In short: you can ask to see, correct, delete or receive a copy of your information, object to some uses, and complain to a regulator. Email us; we answer within a month.
Depending on where you live, you may have the right to:
- Access the personal information we hold about you, and learn the categories we collect, the sources, the purposes, and the categories (or, in some states, the specific names) of third parties we have shared it with;
- Correct inaccurate information;
- Delete your information (the fastest way is deleting your account in the app);
- Receive a copy of the information you gave us in a portable, machine-readable format;
- Object to processing based on our legitimate interests, or ask us to restrict processing, in the situations your law provides;
- Withdraw consent where processing is based on consent, without affecting what was done before;
- Opt out of the sale of your information, of sharing for targeted advertising, and of profiling that produces legal or similarly significant effects. We do none of these, so there is nothing to opt out of, but you may still send us the request;
- Limit the use of sensitive information to what is necessary to provide the service. We already do this (section 3);
- Not be discriminated against for exercising any of these rights. We will not deny you the service, charge you differently or give you a different level of service because you exercised a right; and
- Complain to a data protection authority (section 16 lists them).
12.1 How to make a request
Email hello@shoresh.app with "Privacy request" in the subject, or write to us at 614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States. Tell us which right you are exercising and, if you have an account, send the request from the email address on it or tell us your username. We will need to verify that the request comes from you, which we usually do by matching the email address on your account, and we may ask for more information if we cannot. You may use an authorized agent to make a request on your behalf; we will ask the agent for proof of your written permission and may ask you to confirm directly. We do not charge for requests unless they are manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable fee or decline, and will explain why.
12.2 Timing
We respond within one month, or 45 days where US state law provides that period. If a request is complex we may take longer, up to the further period your law allows, and we will tell you why. Account deletion in the app is immediate.
12.3 Appeals
If we decline all or part of a request, we will tell you why and how to appeal. To appeal, reply to our decision or email us with "Privacy appeal" in the subject within 60 days. A different person will review the decision and respond within 45 days (60 days where your law allows) explaining the outcome. If your appeal is denied, you may complain to the attorney general or data protection authority where you live; section 16 explains how.
13. Children and minimum age
Shoresh is for people aged 16 and over. We ask for your date of birth at sign-up and do not create accounts for anyone younger. We do not knowingly collect personal information from anyone under 16, and Shoresh is not directed to children under 13. If we learn that an account belongs to someone under 16, we delete the account and its information. If you believe a child is using Shoresh, email hello@shoresh.app. Parents and guardians who believe we have collected information from a child may contact us at the same address to have it deleted.
14. Security
We protect your information with measures that include encryption in transit (TLS) and at rest; row-level access rules in our database so that each account can reach only the data it is allowed to see; short-lived access tokens for video; least-privilege access for our team; and providers that hold recognized security certifications (Supabase is SOC 2 Type II and ISO 27001 certified). No system is perfectly secure, so we cannot guarantee security. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as the law requires. If you discover a security problem in Shoresh, please email hello@shoresh.app with "Security" in the subject rather than posting it publicly.
15. Where your information is stored and international transfers
We are based in the United States, and our database and files are stored on Amazon Web Services in the United States (region us-east-1) through Supabase. Our other providers operate in the United States and elsewhere. If you use Shoresh from outside the United States, your information is transferred to and processed in the United States, whose privacy laws may differ from those of your country.
For transfers of personal information from the United Kingdom, the European Economic Area and Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum and the Swiss adaptations) in our contracts with providers, and on adequacy decisions where they apply. Some providers are also certified under the EU-US, UK and Swiss-US Data Privacy Framework (Mux is). You can ask us for a copy of the safeguards we use.
16. Notices for specific regions
In short: everything above applies to everyone. This section adds the details particular laws require.
16.1 United States
Categories of personal information. In the past 12 months we have collected the categories listed in section 2, which correspond to these categories under California law: identifiers (email, name, username, account identifiers); personal information described in Cal. Civ. Code §1798.80(e) (name, contact details); characteristics of protected classifications (age, and religious affiliation you choose to share or that may be inferred from use); commercial information (subscription records); internet or network activity (app activity, view history, infrastructure logs); audio, electronic or visual information (voice notes, videos, images you post); professional information (verification applications); inferences (community and text suggestions drawn from your learning profile and activity); and sensitive personal information (religious beliefs). The sources, purposes and recipients are in sections 2, 4 and 6; retention is in section 10.
Sale, sharing and sensitive information. We do not sell personal information, do not share it for cross-context behavioral advertising, and have not done so in the past 12 months. We do not use or disclose sensitive personal information for purposes other than those permitted by Cal. Civ. Code §1798.121 and Cal. Code Regs. tit. 11 §7027(m), so no "Limit the Use of My Sensitive Personal Information" link is required. We do not knowingly sell or share the personal information of anyone under 16.
Your California rights. California residents have the rights to know, delete, correct, port, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against, described in section 12, and may exercise them by email or post as described there. Under California's "Shine the Light" law (Cal. Civ. Code §1798.83), you may ask whether we have disclosed personal information to third parties for their direct marketing purposes; we do not.
Other states. Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and other states with comprehensive privacy laws have the rights described in section 12, including the right to appeal (section 12.3). Where your state gives it, you may ask for a list of the specific third parties to which we have disclosed your personal information, and you may question the result of any profiling (we do none). Maryland residents: we process sensitive data only where strictly necessary to provide the service you requested, and never sell it. If an appeal is denied, you may contact your state attorney general.
Do Not Track and Global Privacy Control. The app contains no cookies or third-party trackers, so there is nothing for such signals to switch off. Our website sets no cookies. Because we do not sell or share personal information, an opt-out preference signal such as Global Privacy Control does not change how we treat you; we do not respond to "Do Not Track" signals, for which there is no accepted standard.
16.2 United Kingdom, European Economic Area and Switzerland
Controller. Talking Ventures LLC, 614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States. We have not appointed a data protection officer; our privacy contact is hello@shoresh.app. Where the law requires us to appoint a representative in your region, we will name them here.
Legal bases are listed in section 4. Where we rely on legitimate interests, we have balanced them against your interests and rights, and you may object (section 12). Information revealing religious beliefs is processed on the basis of your explicit consent under Article 9(2)(a) (section 3).
Your rights under the UK GDPR and the GDPR are those in section 12: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and not being subject to solely automated decisions with legal or similarly significant effects. We respond within one month, extendable by up to two further months for complex requests.
Complaints. You can complain to us at any time by email, and we will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority of the member state where you live or work; in Switzerland, the Federal Data Protection and Information Commissioner.
Transfers are described in section 15. Retention is in section 10. Providing your sign-in details, username, display name and date of birth is required to create an account; everything else is optional.
16.3 Canada
We comply with the Personal Information Protection and Electronic Documents Act and applicable provincial laws. Our privacy officer can be reached at hello@shoresh.app. Your information is stored and processed in the United States, where it may be accessible to authorities under US law. You may access and correct your information and withdraw consent as described in sections 11 and 12, and you may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.
16.4 Israel
In accordance with the Protection of Privacy Law, 5741-1981: you are not legally required to provide us with any information; providing your sign-in details, username, display name and date of birth is required to create an account, and without them we cannot provide the service. The information is collected for the purposes in section 4 and is stored in our database, held by the providers in section 6, and not transferred to anyone else except as described in section 6. Information about religious beliefs is especially sensitive data, handled as described in section 3. You have the right to inspect and correct information about you (section 12) and to complain to the Privacy Protection Authority.
16.5 Other countries
If you use Shoresh from a country not listed above, the rights in section 12 are available to you to the extent your law provides them, and you may contact us with any question.
17. Our website
shoresh.app is a static website served by Cloudflare. It sets no cookies and includes no analytics or advertising scripts. Cloudflare keeps standard request logs (section 2) for a short period for security and performance. Pages that a shared link opens on the web show only generic text and never display member content.
18. Changes to this policy
We will update this policy when our practices, the law or Shoresh change. If a change is material, for example a new category of information, a new purpose, or a new kind of recipient, we will tell you at least 30 days before it takes effect with a notice in the app, by email, or both, and where the law requires it we will ask for your consent. Other changes take effect when posted, with the date at the top updated. The change log below records what changed and when.
19. Contact
Talking Ventures LLC
614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States
hello@shoresh.app
Use "Privacy request" in the subject for requests under section 12, "Privacy appeal" for appeals, and "Security" for security issues.
20. Change log
- September 18, 2026 (version 1.0). Added crash reporting: the Diagnostics row in section 2 and the Sentry entry in section 6.1. No other change.
- September 17, 2026 (version 1.0). First published version. Replaces the pre-launch draft, adding the full inventory of information, the sensitive-information consent, the provider list (Google, Mux, Anthropic, Sefaria, Cloudflare, RevenueCat), view history, the learning profile, immediate account deletion, and region-specific notices.