Last updated: 30 September 2026

Your privacy is not a formality. KodeshWay was built with a deliberate philosophy: your personal data belongs to you. This policy explains clearly and honestly what is collected, why, and what is never touched.

What is collected

Sign-in identifier

When you sign in — with Apple on iPhone, or with Google on Android — KodeshWay receives a unique identifier from that provider: a random string, not your name or email address. The sign-in also hands the app the email address Apple or Google shares, and on iPhone the name; on iPhone that may be Apple's private relay address. They stay on your phone, to show on the Account page, and the server keeps only the identifier. On iPhone the server also keeps the token Apple issues for the sign-in, solely so that deleting the account can revoke KodeshWay's access with Apple. The identifier is what the server files your account under: your subscription tier and the other records described below. Signing in is needed only for Lumen, a subscription and the reminders the server sends; the Scriptures never ask for it.

Subscription information

If you subscribe to Pilgrim or Scribe, your subscription tier, its expiry date and the identifier the store gives the purchase — the App Store on iPhone, Google Play on Android — are stored. A random token derived from your sign-in identifier is attached to the purchase, so that the store's notices of renewals and refunds reach the right account. This is the minimum needed to provide the service you paid for.

Device token

While you are signed in, the push token the platform assigns to your phone — Apple's on iPhone, Google's on Android — is stored, and on iPhone the Shabbat countdown's own token while one is running. It is used only to send the reminders that are on in the app's notification settings, and to keep the countdown on time. It is not used for any other purpose and is never shared with third parties.

Approximate location, while you are signed in

Some reminders that land at sundown — the Shabbat reminder, the Shabbat Live Activity, and the verse for the day — are timed by the sunset where you are, and the server is what sends them. So while you are signed in and have set a place in the app, the app sends that place with the device token, rounded on your phone to the nearest half a degree — about 50 km — before it leaves the device, together with your time zone. It does so whether the place came from your phone's location or was chosen from the list, and whether or not those reminders are turned on. What is stored is a region, not a place: it is not precise enough to identify a town, a street, or a building.

It is used for one thing: computing the time of sunset so a notification arrives at the right moment. It is never shared, never used for advertising or analytics, and is deleted when you delete your account. If you are not signed in, or have set no place, no location is sent (while signed in, your time zone still is) — everything else in the app works unchanged.

Support messages

The support form on this website sends nothing itself: it opens your own email app with the message written, and what arrives is an ordinary email with your address, used only to answer you. Inside the app, Send Feedback sends your note to the server with the app's version and build, your phone's system version and its model. It is tied to your account only if you switch on Include Apple ID (Include your account on Android). Notes are kept with the support messages; deleting the account removes their link to you.

Printed-volume requests

Requests for the printed Yochanan are closed, and none is held. If you request the printed Yochanan through the printed-volume page, the name, email address and postal address you enter are stored. A parcel cannot be posted without them. They are used to send the book and to write to you about that book — nothing else.

No mailing list exists, and none will be started. Your address is never sold, never shared, never rented, and is never used to send you anything you did not ask for. The details are erased as soon as the book is posted — see Data retention below. To withdraw a request before then, make contact through the support page.

To limit repeated automated submissions, a one-way salted hash of the network address the request came from is stored alongside it. It is not the address itself, cannot be reversed back into one, and is not used to identify anybody.

Lumen usage records

When you ask Lumen, two kinds of record are kept. The first is a line about the request itself: which kind of request it was, how long it took and whether it worked. It carries no sign-in identifier and no network address, and is deleted after thirty days. The second is a count against your sign-in identifier: your requests today and this month, and each day's requests by model, so that each tier's limits can be kept. The daily counts are deleted after ninety days, and the running counts when the account is deleted. Your question and the conversation are never stored. A reply may be kept for up to a day, so the same question can be answered again without asking the AI provider twice. A verse insight, which carries no question of yours, may be kept for up to a week. Replies are filed by their verse and a one-way fingerprint of the question, never by who asked.

Crash reports

When the app crashes or meets an error, it sends a report to the server: what went wrong, the screen it was on, the app's version, and your phone's system version and model. No sign-in identifier or personal detail is attached. Reports are deleted after ninety days.

What is not collected

Beyond the sign-in identifier, the server keeps no name, email address, phone number or other personally identifying information: the name and email address a sign-in hands the app stay on your phone. The only exceptions are what you send yourself — an email to support, and the postal details for a printed volume when requests are open. Your precise location is never collected — only the coarse region described above, and only while you are signed in with a place set. No third-party analytics SDKs, advertising trackers, or behavioural-tracking tools are run.

What you keep inside the KodeshWay app — your highlights, notes, bookmarks, kept verses, reflections, plans, journey progress and Lumen conversations — stays with you. On iPhone it is stored in your personal iCloud account, or on the phone alone if iCloud is off. On Android it is stored on the phone, and Android's own backup carries it to your next one through your Google account. None of it is stored on the service's servers. Two things pass through them, and both are named here: each chapter you finish while signed in (below), and the short note about your reading that goes with a question to Lumen (see Lumen's AI providers).

One exception is kept small and named. Each time you finish reading a chapter while signed in, the book, the chapter and the time are recorded against your sign-in identifier. They are used for two things only: the Continue Your Walk reminder, sent to Pilgrim and Scribe readers who read yesterday and not yet today, and Lumen's word when you finish a book. No verse position, no text, no highlights — only that a chapter was read through. These rows are removed when the account is deleted.

The website keeps the same kind of thing in the same kind of place. These are held in your browser's local storage: your reading position; your reading preferences (type size and reading width); the look you chose; where you stopped listening and the voice you chose; your recent searches in the web reader; and which cards Today on the home page shows, in what order and at what size. So are the coordinates your browser provides if you tap Use your location on the sundown clock or on Today, so the sun and moon can be worked out for where you are. None of it is transmitted. It lives in that browser alone, and clearing the site's data removes it.

How collected data is used

The data that is stored serves exactly one purpose: providing the KodeshWay service to you. Your sign-in identifier indicates which subscription tier you have. Your device token lets the server send the reminders that are on in the app's notification settings. A postal address, if you gave one, addresses the parcel it was given for. Nothing else.

Your data is not used for advertising. Your data is not sold. Your data is not shared with third parties except as described below.

Third parties

Apple

On iPhone, sign-in, subscription billing, push delivery and iCloud storage are handled by Apple. Apple's privacy policy governs the data Apple collects in those services. Only what Apple provides is received, and nothing more.

Google

On Android, sign-in is Sign in with Google, subscription billing is Google Play, and reminders are delivered through Google's push service. Google's privacy policy governs the data Google collects in those services. The token Google's sign-in hands back carries your email address: the phone keeps it for the Account page, and the server reads only the identifier. The app runs no Google analytics or advertising service. Google Play Integrity may be asked whether the app is a genuine install; its answer is a signal the server records, never a gate.

Lumen's AI providers

When you ask Lumen, your request passes through the KodeshWay server to an AI provider, which writes the reply. For Pilgrim and Scribe that is Anthropic, which also answers a Free-tier question about a date. For the rest of the Free tier and for Lumen Lite it is a third-party AI inference provider. What is sent is your question, the conversation so far, the passage it is about and the day's calendar context. Unless you turn off Send context to Lumen (Settings → Lumen Memory), it also carries a short note built on your phone from what you are reading, your active plan, your recent reflections and your recent conversations with Lumen. Your sign-in identifier, name, email address and place are never sent. Each provider's own policy governs how it handles the requests it receives.

Audio narration

Audio narration in KodeshWay uses pre-generated voice recordings hosted on the service's servers. When you download audio for a book or chapter, the files are stored locally on your device. No personal data is sent as part of audio downloads — only the book and chapter identifiers needed to retrieve the correct files.

Server infrastructure

The backend runs on standard cloud infrastructure in the United States, and this website is served through a global edge network. Like every responsible host, the edge layer keeps short-lived request logs — IP address, user agent, timestamp, requested URL — for abuse prevention and DDoS mitigation. Those logs are not queried for analytics.

Inside the application a limited audit log of authentication and subscription events is kept, linked to your opaque sign-in identifier (IP address, event type, timestamp). It is retained for thirty days and then automatically deleted.

Backups

A daily copy of the application database is taken and stored in encrypted cloud storage for disaster recovery. Copies are kept for seven days and then automatically pruned. Each holds what the database held that day: the account records described above, including the rounded place and time zone, the chapters recorded as finished and the Lumen counts; the notes sent through Send Feedback; and the short-lived store of Lumen replies. It never holds your questions to Lumen, your highlights or your notes in the app, or a crash report.

Data retention

Your account data is kept for as long as the account exists. If you delete your account from within the app, the following are removed from the live database immediately, in a single transaction: your subscriber record (with its push token, rounded place, reminder settings and Lumen counts), all session data, audit log entries, the chapters recorded as finished, the daily Lumen counts, and device-check records. On iPhone, KodeshWay's access to your Apple sign-in is revoked with Apple. A note sent through Send Feedback is kept, with its link to your account removed. Daily backups (kept for seven days, then automatically pruned) may still hold a copy of your account record until they age out. The app erases the reading data it keeps with you — in iCloud on iPhone, on the phone on Android — at the same moment. Without deleting the account, you can delete it at any time through your iCloud settings or by clearing the app's data.

A printed-volume request is erased the moment the book is posted. The name, email address and postal address are blanked in the same action that marks it sent; what remains is a record that a book went out and the state it went to, which identifies nobody. Nothing is kept in case, and no copy is held anywhere else. The practical consequence is accepted deliberately: a parcel that goes missing cannot be re-sent without asking you for the address again. A request withdrawn before posting is deleted straight away. At any moment, the only addresses held are those for books not yet sent.

Your rights

You have the right to request a copy of the data held about you, request deletion of your data, and opt out of push notifications at any time in the app's notification settings or your phone's. You can delete your account directly within the app under Settings → Account → Delete Account. For a copy of what the server holds, make contact through the support page.

European users (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, the following additional rights and information apply to you under the General Data Protection Regulation.

Legal basis for processing

Your data is processed under the following legal bases:

Your GDPR rights

In addition to the rights listed above, you have the right to:

To exercise any of these rights, make contact through the support page, or delete your account directly within the app under Settings → Account → Delete Account.

Data transfers

Your data may be processed in the United States, where the servers are hosted, and a Lumen request wherever its AI provider processes it. KodeshWay relies on the data processing agreements of its service providers (Apple or Google for sign-in and billing, Anthropic and a third-party AI inference provider for Lumen, and the cloud hosting provider) to protect your data.

Data controller

The data controller for your personal data is KodeshWay LLC, a Texas limited liability company. Make contact through the support page for any data protection enquiries.

California users (CCPA)

If you are a California resident, the California Consumer Privacy Act provides you with additional rights regarding your personal information.

Your CCPA rights

Categories of personal information collected

In the preceding 12 months, the following categories of personal information have been collected:

Sensitive personal information as defined by the CCPA is not collected. Personal information is not shared with third parties for cross-context behavioural advertising.

Account deletion

You can delete your account and all associated data at any time from within the app under Settings → Account → Delete Account. Upon deletion, your subscriber record (with its push token, rounded place, reminder settings and Lumen counts), all session data, audit log entries, the chapters recorded as finished, the daily Lumen counts and device-check records are removed from the live database immediately, in a single transaction. On iPhone, KodeshWay's access to your Apple sign-in is revoked with Apple. A note sent through Send Feedback is kept, with its link to your account removed. Daily backups (kept for seven days, then automatically pruned) may still contain a copy of your account record until they age out. Deleting the account in the app also erases your reading data (progress, highlights, bookmarks, notes and reflections) from the phone and, on iPhone, from your iCloud. Without deleting the account, it can be deleted through your iCloud settings or by clearing the app's data.

Children's privacy

KodeshWay is not directed at children under the age of 13. Personal information is not knowingly collected from children under 13. If a child has provided personal information, make contact through the support page and it will be deleted promptly.

Changes to this policy

If material changes are made to this privacy policy, the date at the top of this page will be updated and, where appropriate, users will be notified through the app. Continued use of KodeshWay after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy? Reach the ministry here or email yeshua@kodeshway.com.