Privacy Policy

Last updated: 2 September 2026

DRAFT — pending legal review

This is a draft. It is not legal advice, and it is not fit to publish as-is. It needs a lawyer who knows both US and Israeli privacy law, since the operator would be US-based and most users are not. It is published here so that the app's behaviour is described openly while that review is arranged. Do not read it as a reviewed document.

Scope note, corrected. An earlier version of this draft described the app as storing “health information about third parties”. That overstated it. A request holds exactly five fields: a first name, a parent's first name, which parent it is, the subject's gender, and a category chosen from a fixed list. There is no surname, no date of birth, no address, no contact detail, no free text, and no way for the operator or the praying pilgrim to work out who the person is. “Yaakov son of Rivka” identifies almost nobody.

What remains true, and is the part to put to a lawyer: the health category is an inference about the wellbeing of whoever that name belongs to, and GDPR's identifiability test counts means available to anyone, including the requester who obviously knows. So the honest position is that this is probably not Article 9 special-category data in practice because the identification is so weak — but it is close enough to it that the engineering posture should not relax, and the legal call is not ours to make.

The part that actually matters

When you ask for a prayer, you give us a first name, a parent's first name, and a reason chosen from a fixed list — that they should recover, find a partner, have children. That person is not a user of this app and did not agree to anything.

We keep that deliberately thin. There is no surname, no contact detail, and no free-text box, because a free-text box is exactly where a diagnosis, a hospital, or a phone number would end up. Three fields is the least we can ask for and still have a prayer said.

We treat that as the most sensitive thing we hold, and it is why several things in this app are stricter than they need to be:

What we collect

From you: your email address, a display name you choose (shown to others as a first name and an initial), and your requests — the category, the name you are praying for, and that person's parent's name.

From your device, only while the app is open: your location, and only to confirm you are physically at a holy site. It is checked against that site and not stored as a trail.

Audio: if you pray for someone, the recording you make.

We do not collect contacts, photos, advertising identifiers, or your location in the background.

What we do not do

We do not sell anything to anyone. We do not use any of this for advertising. We do not share it with third parties except the infrastructure needed to run the app (see below).

Who processes it

Supabase (database, authentication, file storage), hosted in Frankfurt.
Apple and Google process payments; we never see your card details.

How long we keep it

Recordings are deleted automatically after a retention period. Requests expire. Everything tied to your account is destroyed when you delete it, which you can do inside the app at any time from the Account tab.

Your rights

You can delete your account and everything in it from inside the app. If you are in the EU or UK you additionally have rights of access, correction, portability and objection under GDPR; if you are in California, rights under the CCPA.

Pending legal review This section must be completed properly by a lawyer — the operator's obligations depend on the entity structure, which is not settled yet.

Children

This app is not directed at children.

Contact

Privacy questions: support@yadavshalom.org
Account deletion: delete@yadavshalom.org, or see Delete your account.