Privacy Policy

Last updated: September 18, 2026 · Version 1.0

At a glance.

  • What we collect: your sign-in email and name, the profile you build, what you post, the communities you join, what you open in the app, and a few technical details about your device. No location, no contacts, no advertising identifiers.
  • Why: to run Shoresh, show your posts to the right people, send the notifications you ask for, power the AI study tools, keep the community safe, and fix bugs.
  • We do not sell your information, we do not show ads, and we do not track you across other apps or websites. Shoresh is funded by the optional Shoresh Plus subscription.
  • Religious beliefs are sensitive. Using a Jewish learning app says something about you. We ask for your explicit consent to process that, use it only to run the service, and never for advertising or profiling.
  • Who helps us: a small set of providers (Supabase, Apple, Google, OneSignal, Mux, Anthropic, Cloudflare, Sefaria and, for subscriptions, RevenueCat). Section 6 lists what each one receives.
  • Your controls: edit or delete anything you posted, tune notifications, block people, and delete your whole account from Settings, instantly. Email us for anything else.

This box is a summary. The full policy below is what applies.

Contents

  1. Who we are and what this policy covers
  2. Information we collect
  3. Sensitive information: religious beliefs
  4. How we use information, and our legal bases
  5. Who can see what on Shoresh
  6. Who we share information with
  7. Third-party content, embedded players and links
  8. Device permissions and what we do not collect
  9. Video viewing information
  10. How long we keep information
  11. Your choices and controls
  12. Your privacy rights and how to use them
  13. Children and minimum age
  14. Security
  15. Where your information is stored and international transfers
  16. Notices for specific regions
  17. Our website
  18. Changes to this policy
  19. Contact
  20. Change log

1. Who we are and what this policy covers

Shoresh is operated by Talking Ventures LLC, a Delaware limited liability company with its mailing address at 614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States ("Shoresh", "we", "us" or "our"). We are the data controller of the personal information described here. This policy covers the Shoresh iOS app, the website at shoresh.app, and our communications with you (for example, when you email us). It does not cover Apple, Google, Sefaria or any other third party whose services you use alongside Shoresh; their own policies apply to them. Our Terms and Conditions govern your use of Shoresh.

2. Information we collect

In short: the table below is the complete inventory. "You" means you gave it to us; "the app" means the app generated it as you used Shoresh.

Category What it includes Source Why we have it
Sign-in details Your email address, the name your sign-in provider gives us (used only to pre-fill your profile), which provider you used (Apple or Google), and the stable account identifier the provider assigns. If you use Apple's "Hide My Email", we receive a relay address instead of your real one. Apple or Google, when you sign in To create and secure your account and to contact you about it.
Profile Username, display name, profile photo, bio, and optional links (website, Instagram, X, YouTube, Substack). If you are verified, a short credentials line approved by our team. You To identify you to other members. All of this is public to signed-in members.
Date of birth The birth date you enter during sign-up. You To confirm you are at least 16. Stored privately, never shown to anyone, and not used for anything else.
Learning profile Optional answers to three sign-up questions: your level of experience with Jewish texts, the affiliations or background you choose to share (with a "prefer not to say" option), and the themes you are interested in. You To suggest communities, texts and themes. Visible only to you; even our team's admin tools cannot read it. Editable in Settings.
Content you post Discussions, responses and comments (text, formatting, citations of Torah texts), images, voice notes and other audio, video, documents and other files, links you paste (and the title, description and image our server fetches from the linked page to show a preview), plus the time you posted or edited. You To show your contributions to the people your community settings allow.
Community activity Communities and chaburot you belong to, your role in each, join requests and their outcome, invitations sent to you, invite links you used, and community-level removals or bans with the reason given. You, community leaders, the app To run communities and enforce their settings.
Engagement Your reactions, saves (of posts, communities, profiles, texts and topics), shares (including "copy link"), "notify me" subscriptions to posts and communities, and hidden posts. You To power those features and their counts. Reactions are visible to anyone who can see the post; saves and notification subscriptions are private to you.
View history Which posts, profiles, communities, texts and topics you opened, and when. Roughly one record per item per session. The app To show your "Recently viewed" lists, unread indicators and "mark all as read". Visible only to you. Not shared with anyone, including the people whose profiles or posts you viewed.
Notifications Your in-app notification feed, which kinds of push notifications you have turned on, per-community notification preferences, and a record of what you have seen. The app, you To deliver the notifications you asked for.
AI study tool usage For each AI action: the kind of action, the passage it concerned, the outcome, and the number of tokens used. Explanations themselves are stored in a shared cache that carries no information about who requested them. If we add tools that take your own words as input (for example, a study assistant), the conversation will be stored with your account so you can revisit it, and this policy will say so. The app To apply monthly allowances and fair-use limits, and to operate and improve the tools.
Subscription and entitlements Whether you have Shoresh Plus, how you got it (App Store purchase, invite code or complimentary access), its expiry, the Apple transaction identifier, and any invite codes you redeemed. We never receive your card or bank details; Apple keeps those. Apple, RevenueCat, you To unlock the features you are entitled to. Applies only once Plus is offered.
Verification application If you apply to be verified: your credentials, ordination (smicha) source, affiliation, a link to sample writings, references, and our reviewers' notes and decision. You, our team To review your application. Visible only to you and our verification team.
Reports, blocks and moderation records Reports you file (category, note, outcome), people you block, and records of moderation actions taken by community leaders or our team about your content or account, with the reasons given. If you delete a post that has replies, a copy of its text is kept in a restricted store. You, community leaders, our team To keep Shoresh safe, handle reports, and investigate abuse. Reports are confidential; the person you report never learns who reported them.
App activity and device details When you last used the app, how many times you have opened it, the app version, iOS version, device model (for example "iPhone16,2"), language, time zone, whether push notifications are allowed, and your appearance preferences. The app To understand usage, support you, and fix problems that affect specific versions or devices.
Diagnostics When a Torah text fails to load or is unavailable because of its license, the app sends us the reference, the endpoint, the error and the app version. These reports carry no user identifier. Separately, if the app crashes or hits an unexpected error, a crash report goes to our crash-reporting provider (Sentry, see section 6.1) with the app version, iOS version, device model, the technical details of the failure, and your account identifier (a random ID, never your name or email) so we can tell one person's repeated crash from many people's. Crash reports never include what you were typing or reading. The app To fix text-loading problems and crashes.
Support communications Emails you send us and our replies, including any requests you make under this policy. You To help you and keep a record of what we agreed.
Infrastructure logs Our hosting providers (Supabase for the app's backend, Cloudflare for the website) keep standard server logs that include your IP address, request times and the app or browser version. We do not build profiles from them. The app, your browser Security, abuse prevention and debugging.

What is required. To use Shoresh you need to sign in, choose a username and display name, and give your date of birth; without those we cannot create your account. Everything else, including the learning profile questions, a profile photo, a bio and anything you post, is optional.

What we do not collect. We do not collect your location, your contacts, your photo library (you pick individual images through Apple's picker, which shares only what you choose), advertising identifiers, biometrics, health information, or precise device fingerprints. The app contains no advertising or analytics SDKs; the only third-party SDK that sends anything about you is the crash reporter described above. See section 8.

3. Sensitive information: religious beliefs

In short: being on Shoresh may reveal your religion. We treat that as sensitive, ask for your explicit consent, and use it only to run the service.

Shoresh is built for Orthodox Jewish learning. The fact that you have an account, the communities you join, the affiliations you choose to share in your learning profile, and what you post may reveal your religious beliefs and practice. Laws in the United Kingdom, the European Union, Israel, several US states and elsewhere treat information about religious beliefs as sensitive. Here is how we handle it:

4. How we use information, and our legal bases

In short: to run Shoresh, keep it safe, and improve it. The right-hand column is for readers in the UK, the EEA and other places whose law requires a "legal basis" for each purpose.

Purpose What we use Legal basis
Provide the service Sign-in details, profile, content, community activity, engagement, view history, notifications, entitlements Performance of our contract with you (the Terms); explicit consent for information revealing religious beliefs
Check your age Date of birth Legal obligation and legitimate interest in keeping the service to people 16 and over
Suggest communities, texts and themes Learning profile, view history, community activity Consent (the learning profile is optional) and performance of the contract
Send notifications Notification preferences, activity that triggers a notification, the device record held by OneSignal Consent (you allow push notifications on your device and choose the kinds); performance of the contract for the in-app feed
Run the AI study tools The passage you ask about, your usage record, your entitlement Performance of the contract
Process subscriptions Apple transaction identifier, entitlement, invite codes Performance of the contract; legal obligation (tax and accounting records)
Safety, moderation and enforcement Reports, blocks, moderation records, content, account activity, verification applications Legitimate interests in keeping the service safe and enforcing the Terms; legal obligation where the law requires action
Support you Support communications, account details Performance of the contract; legitimate interest in answering you
Fix bugs and improve Shoresh App activity and device details, diagnostics, infrastructure logs, aggregated usage Legitimate interests in a reliable, improving product
Security and fraud prevention Infrastructure logs, account activity, entitlements Legitimate interests in protecting the service and its members; legal obligation
Comply with the law and defend claims Whatever is relevant to the obligation or claim Legal obligation; legitimate interests in establishing, exercising or defending legal claims
Tell you about changes to Shoresh Email address, in-app notices Performance of the contract; legitimate interest in keeping you informed

No automated decisions. We do not make decisions about you by automated means that have legal or similarly significant effects. Usage limits on the AI tools are applied automatically, but they are simple counters, not judgments about you.

No marketing email. We do not currently send marketing email. If we start, we will only do so with your permission where the law requires it, and every message will include a way to stop.

5. Who can see what on Shoresh

In short: nothing on Shoresh is visible to the public internet. Within Shoresh, your profile is visible to signed-in members, and your posts are visible according to the community they are in.

6. Who we share information with

In short: with the providers that run pieces of Shoresh for us, with other members as your settings allow, and with authorities when the law requires. Never with advertisers or data brokers.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in US state privacy laws. We have not done so in the past 12 months. Shoresh is funded by the optional Shoresh Plus subscription, not by advertising.

6.1 Service providers

These companies process information on our behalf, under contracts that limit them to providing their service to us and require them to protect it. Each has its own privacy policy covering how it operates its service.

Provider What it does for Shoresh What it receives
Supabase (Supabase Pte. Ltd.), on Amazon Web Services Database, authentication, file storage and server-side functions. Our data lives in the AWS "us-east-1" region in the United States. Everything in section 2, because it is where Shoresh's data is stored.
Apple Sign in with Apple, App Store and TestFlight distribution, In-App Purchase billing, push notification delivery (APNs), and on-device speech recognition for dictation (which may send audio to Apple's servers). Your Apple Account interactions with Shoresh (sign-in, purchases), push delivery to your device, and dictation audio if you use the microphone dictation feature. Apple's privacy policy applies.
Google Sign in with Google. The fact that you signed in to Shoresh with your Google Account. Google's privacy policy applies.
OneSignal Sends push notifications to your device. A pseudonymous identifier for your account (not your email or name), your device's push token, and the text of each notification we send you (which can include other members' display names and post titles). OneSignal holds the device token; we do not.
Mux Stores, processes and streams videos that members upload. The video files themselves. Mux does not receive your name, account identifier or any other information about who uploads or watches; see section 9.
Anthropic Provides the AI models behind the AI study tools. For "Explain": the licensed source passage and its context, with no information about you and nothing you wrote. For any future tool that works on your own words, your input, which the tool will tell you before you use it. Under Anthropic's commercial terms, it does not use this data to train its models and deletes API inputs and outputs within about 30 days.
Sefaria Provides the Torah texts, translations, commentaries, search and topic data that Shoresh displays. Sefaria is a data source, not a processor working for us. Your device talks to Sefaria's servers directly, so Sefaria sees your device's IP address and the requests it makes: which texts you open, your text searches, and the text of a post you are composing when the app checks it for citations to link. We never send Sefaria your name or account identifier. Sefaria's own privacy policy applies to what it does with that traffic.
RevenueCat Confirms and manages Shoresh Plus subscriptions (once Plus is offered). A pseudonymous identifier for your account, Apple purchase receipts and transaction identifiers, device type and app version. Never your name, email or payment details.
Sentry (Functional Software, Inc.) Crash reporting for the app. Crash and error reports: app version, iOS version, device model, the technical details of the failure, and your account identifier. No name, email, IP-based location or content. Kept for 90 days.
Cloudflare Hosts and serves our website, shoresh.app. Standard web request logs (IP address, browser, pages requested) when you visit the website.

6.2 Other members and the public

Information is visible to other members as described in section 5. Nothing is visible to the public.

6.3 Community leaders

Leaders of a community you belong to can see your membership, your role, your join request, the posts you make in that community, and moderation records within that community. They cannot see your email, date of birth, learning profile, saves, view history or activity in other communities.

6.4 Legal, safety and business reasons

7. Third-party content, embedded players and links

In short: when a post embeds a YouTube video or you open a link, the other service sees you, not us.

8. Device permissions and what we do not collect

9. Video viewing information

When you watch a video on Shoresh, the app records that you opened the post (as part of your view history) and asks our server for a short-lived playback token. Our video provider, Mux, receives the token and streams the video; it does not receive your identity, and we do not send it any viewer identifier. We treat your viewing history as personal information. We do not disclose which videos you have watched to anyone outside the service providers in section 6, and we will not share it with any third party for that party's own purposes without your separate, informed, written consent, which you could withdraw at any time.

10. How long we keep information

In short: most things live as long as your account does and are deleted the moment you delete it. A few things are kept for legal, safety or technical reasons, listed below.

Information How long
Account, sign-in details, profile, date of birth, learning profile Until you delete your account. Deleted immediately when you do.
Posts and attachments Until you delete them. Media files are deleted with the post; files that end up unreferenced are swept within about 30 days. Posts you have not deleted remain after account deletion under a "deleted user" label, with your name and profile removed and their attached media deleted.
Text of a deleted post that had replies Kept in a restricted store for as long as needed for abuse investigations and support-side restores, then deleted.
Videos Deleted from Mux when you delete the post or your account. Uploads that never attach to a post are deleted within about a day.
Community activity, engagement, view history, notifications, notification preferences, AI usage records, entitlements, invite code redemptions, verification applications, reports you filed, blocks Until you delete your account; deleted immediately when you do.
App activity and device details One current snapshot per account, overwritten as you use the app; deleted with your account.
Moderation records about actions taken in a community Kept with the community as its audit record. When an account is deleted, its identifier is removed from those records.
Cached AI explanations Kept and shared; they contain no personal information.
Link previews Up to 14 days; they contain no personal information.
Diagnostics (text loading errors) Kept as engineering records; they contain no personal information.
Support communications As long as needed to resolve your request and keep a record of it, typically up to three years.
Purchase records held by Apple and RevenueCat Under their own retention rules (RevenueCat states up to six years after the account ends), as required for tax and accounting.
Push notification device record held by OneSignal Until your device unsubscribes or OneSignal's retention period ends. After you delete your account, the record is no longer linked to any Shoresh account.
Data sent to Anthropic Deleted by Anthropic within about 30 days under its commercial terms.
Infrastructure logs A short period set by the hosting provider, typically under 30 days.
Backups Routine database backups are overwritten within 30 days. Deleted data may persist in a backup until then.
Legal holds If information is needed for a legal claim, investigation or legal obligation, we keep only what is needed for as long as that lasts.

11. Your choices and controls

In short: almost everything is in Settings, and account deletion is immediate.

12. Your privacy rights and how to use them

In short: you can ask to see, correct, delete or receive a copy of your information, object to some uses, and complain to a regulator. Email us; we answer within a month.

Depending on where you live, you may have the right to:

12.1 How to make a request

Email hello@shoresh.app with "Privacy request" in the subject, or write to us at 614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States. Tell us which right you are exercising and, if you have an account, send the request from the email address on it or tell us your username. We will need to verify that the request comes from you, which we usually do by matching the email address on your account, and we may ask for more information if we cannot. You may use an authorized agent to make a request on your behalf; we will ask the agent for proof of your written permission and may ask you to confirm directly. We do not charge for requests unless they are manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable fee or decline, and will explain why.

12.2 Timing

We respond within one month, or 45 days where US state law provides that period. If a request is complex we may take longer, up to the further period your law allows, and we will tell you why. Account deletion in the app is immediate.

12.3 Appeals

If we decline all or part of a request, we will tell you why and how to appeal. To appeal, reply to our decision or email us with "Privacy appeal" in the subject within 60 days. A different person will review the decision and respond within 45 days (60 days where your law allows) explaining the outcome. If your appeal is denied, you may complain to the attorney general or data protection authority where you live; section 16 explains how.

13. Children and minimum age

Shoresh is for people aged 16 and over. We ask for your date of birth at sign-up and do not create accounts for anyone younger. We do not knowingly collect personal information from anyone under 16, and Shoresh is not directed to children under 13. If we learn that an account belongs to someone under 16, we delete the account and its information. If you believe a child is using Shoresh, email hello@shoresh.app. Parents and guardians who believe we have collected information from a child may contact us at the same address to have it deleted.

14. Security

We protect your information with measures that include encryption in transit (TLS) and at rest; row-level access rules in our database so that each account can reach only the data it is allowed to see; short-lived access tokens for video; least-privilege access for our team; and providers that hold recognized security certifications (Supabase is SOC 2 Type II and ISO 27001 certified). No system is perfectly secure, so we cannot guarantee security. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as the law requires. If you discover a security problem in Shoresh, please email hello@shoresh.app with "Security" in the subject rather than posting it publicly.

15. Where your information is stored and international transfers

We are based in the United States, and our database and files are stored on Amazon Web Services in the United States (region us-east-1) through Supabase. Our other providers operate in the United States and elsewhere. If you use Shoresh from outside the United States, your information is transferred to and processed in the United States, whose privacy laws may differ from those of your country.

For transfers of personal information from the United Kingdom, the European Economic Area and Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum and the Swiss adaptations) in our contracts with providers, and on adequacy decisions where they apply. Some providers are also certified under the EU-US, UK and Swiss-US Data Privacy Framework (Mux is). You can ask us for a copy of the safeguards we use.

16. Notices for specific regions

In short: everything above applies to everyone. This section adds the details particular laws require.

16.1 United States

Categories of personal information. In the past 12 months we have collected the categories listed in section 2, which correspond to these categories under California law: identifiers (email, name, username, account identifiers); personal information described in Cal. Civ. Code §1798.80(e) (name, contact details); characteristics of protected classifications (age, and religious affiliation you choose to share or that may be inferred from use); commercial information (subscription records); internet or network activity (app activity, view history, infrastructure logs); audio, electronic or visual information (voice notes, videos, images you post); professional information (verification applications); inferences (community and text suggestions drawn from your learning profile and activity); and sensitive personal information (religious beliefs). The sources, purposes and recipients are in sections 2, 4 and 6; retention is in section 10.

Sale, sharing and sensitive information. We do not sell personal information, do not share it for cross-context behavioral advertising, and have not done so in the past 12 months. We do not use or disclose sensitive personal information for purposes other than those permitted by Cal. Civ. Code §1798.121 and Cal. Code Regs. tit. 11 §7027(m), so no "Limit the Use of My Sensitive Personal Information" link is required. We do not knowingly sell or share the personal information of anyone under 16.

Your California rights. California residents have the rights to know, delete, correct, port, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against, described in section 12, and may exercise them by email or post as described there. Under California's "Shine the Light" law (Cal. Civ. Code §1798.83), you may ask whether we have disclosed personal information to third parties for their direct marketing purposes; we do not.

Other states. Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and other states with comprehensive privacy laws have the rights described in section 12, including the right to appeal (section 12.3). Where your state gives it, you may ask for a list of the specific third parties to which we have disclosed your personal information, and you may question the result of any profiling (we do none). Maryland residents: we process sensitive data only where strictly necessary to provide the service you requested, and never sell it. If an appeal is denied, you may contact your state attorney general.

Do Not Track and Global Privacy Control. The app contains no cookies or third-party trackers, so there is nothing for such signals to switch off. Our website sets no cookies. Because we do not sell or share personal information, an opt-out preference signal such as Global Privacy Control does not change how we treat you; we do not respond to "Do Not Track" signals, for which there is no accepted standard.

16.2 United Kingdom, European Economic Area and Switzerland

Controller. Talking Ventures LLC, 614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States. We have not appointed a data protection officer; our privacy contact is hello@shoresh.app. Where the law requires us to appoint a representative in your region, we will name them here.

Legal bases are listed in section 4. Where we rely on legitimate interests, we have balanced them against your interests and rights, and you may object (section 12). Information revealing religious beliefs is processed on the basis of your explicit consent under Article 9(2)(a) (section 3).

Your rights under the UK GDPR and the GDPR are those in section 12: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and not being subject to solely automated decisions with legal or similarly significant effects. We respond within one month, extendable by up to two further months for complex requests.

Complaints. You can complain to us at any time by email, and we will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority of the member state where you live or work; in Switzerland, the Federal Data Protection and Information Commissioner.

Transfers are described in section 15. Retention is in section 10. Providing your sign-in details, username, display name and date of birth is required to create an account; everything else is optional.

16.3 Canada

We comply with the Personal Information Protection and Electronic Documents Act and applicable provincial laws. Our privacy officer can be reached at hello@shoresh.app. Your information is stored and processed in the United States, where it may be accessible to authorities under US law. You may access and correct your information and withdraw consent as described in sections 11 and 12, and you may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.

16.4 Israel

In accordance with the Protection of Privacy Law, 5741-1981: you are not legally required to provide us with any information; providing your sign-in details, username, display name and date of birth is required to create an account, and without them we cannot provide the service. The information is collected for the purposes in section 4 and is stored in our database, held by the providers in section 6, and not transferred to anyone else except as described in section 6. Information about religious beliefs is especially sensitive data, handled as described in section 3. You have the right to inspect and correct information about you (section 12) and to complain to the Privacy Protection Authority.

16.5 Other countries

If you use Shoresh from a country not listed above, the rights in section 12 are available to you to the extent your law provides them, and you may contact us with any question.

17. Our website

shoresh.app is a static website served by Cloudflare. It sets no cookies and includes no analytics or advertising scripts. Cloudflare keeps standard request logs (section 2) for a short period for security and performance. Pages that a shared link opens on the web show only generic text and never display member content.

18. Changes to this policy

We will update this policy when our practices, the law or Shoresh change. If a change is material, for example a new category of information, a new purpose, or a new kind of recipient, we will tell you at least 30 days before it takes effect with a notice in the app, by email, or both, and where the law requires it we will ask for your consent. Other changes take effect when posted, with the date at the top updated. The change log below records what changed and when.

19. Contact

Talking Ventures LLC
614 N. Dupont Hwy, Suite 210, Dover, DE 19901, United States
hello@shoresh.app

Use "Privacy request" in the subject for requests under section 12, "Privacy appeal" for appeals, and "Security" for security issues.

20. Change log