Privacy Policy
This policy describes how Sheva Studios (“we,” “us,” or “our”) collects, uses, stores, and shares information when you use the mobile application currently published as Siddur and branded in-app as 24/7 (the “App”), our admin analytics dashboard, shared Tehillim links, and related websites or APIs (together, the “Services”). It is written to match how the App actually works today. It is not legal advice.
1. Who we are
The Services are operated by Sheva Studios (project by Avi Taub). The App is a Jewish davening and daily-life companion: siddur, Tehillim, calendar/zmanim, reminders, Mizrach compass, learning texts, and personal tracking tools.
Contact for privacy requests: shevastudios@gmail.com.
iOS bundle identifier: com.siddur.app. We do not currently require you to create an account or provide an email address to use the App.
2. Scope
This policy covers:
- The iOS and Android App (including Expo / TestFlight / App Store / Play builds);
- Our first-party analytics and Tehillim campaign API hosted on Railway;
- The password-protected admin dashboard at
/dashboard; - Shared Tehillim web links (for example on siddur24seven.com or our Railway domain) that open the App.
It does not control third-party sites you open from the App (for example Sefaria.org), Apple, Google, or your device operating system.
3. Information we collect
We collect only what is needed to run the App. Most personal and spiritual content stays on your device.
3.1 Information stored only on your device
The following is saved locally (typically via device storage / AsyncStorage) and is not uploaded to our servers as part of normal App use:
- Preferences: nusach, display settings (text size, fonts, theme), spiritual goals, home-panel layout, autoscroll speed, Hebrew birthday if you enter one.
- Notification settings and custom reminders: times, titles, and messages you create.
- Precise location (latitude, longitude, and an approximate city name) after you grant location permission, used for zmanim, sunset-based reminders, and the Mizrach compass.
- Refuah names: Hebrew names and mother’s names you optionally add for the Amidah “Refa’einu” insertion.
- Gratitude journal entries (free-text notes you write).
- Tzedakah log: amounts, organization names, and dates you enter.
- Progress trackers: Tehillim completions, brachos counts, habits, daily goals, gratitude streaks, davening streaks, Shnayim Mikra progress, Omer widget state, and similar on-device counters.
- Cached Jewish texts downloaded from Sefaria or bundled offline packs, so reading can work with poor connectivity.
- An analytics event queue waiting to be sent (see 3.3).
Uninstalling the App, using the in-App “Reset App” control, or clearing app data on the device deletes this local information. We cannot recover it from our servers because we do not hold a copy.
3.2 Location, sensors, and notifications
| Category | What we access | Why | Leaves the device? |
|---|---|---|---|
| Precise location | GPS coordinates and reverse-geocoded city name, if you allow location | Zmanim (sunrise, sunset, candle lighting, etc.), location-aware reminders, and bearing toward Jerusalem for Mizrach | Stored on device. Not sent in analytics events. Device OS may geocode locally or via Apple/Google geocoding. |
| Motion / compass sensors | Magnetometer, accelerometer, and heading (when available) | Mizrach compass only; processed on device | No |
| Notifications | Permission status; locally scheduled reminder content | Davening, zmanim, Tehillim, Omer, Shabbos clock, and custom reminders you enable | Scheduled on device. Apple/Google deliver local or OS-managed notifications. We do not currently collect your push token as a marketing identifier. |
Location is optional. If you deny permission, you can still use the App; zmanim and Mizrach may use a saved or default location and will be less accurate. We request location while the App is in use (foreground), not for advertising.
3.3 Product analytics (sent to our servers)
The App sends product-analytics events to our first-party backend (currently hosted by Railway). Events are tied to a random anonymous ID created on the device. We do not collect your name, email, phone number, or address in these events.
Typical event fields include:
- Anonymous ID, session ID, and (only if we later add login) a user ID;
- Event name and time (for example app_open, screen_view, onboarding steps, feature use, Tehillim perek completed, reliability/error codes);
- App version, build number, platform (iOS/Android/web), OS version, a coarse device model label, locale, timezone, network type (wifi/cellular/offline/unknown), environment, and screen name;
- Optional campaign/UTM fields if present.
We do not include gratitude text, tzedakah amounts, Refuah names, precise GPS coordinates, reminder message bodies, or other journal content in analytics payloads.
The admin dashboard is for the operator of Sheva Studios. It shows aggregated usage (DAU/WAU/MAU, funnels, retention) and event timelines by anonymous ID. Access is password-protected. Dashboard use is not a consumer-facing account.
3.4 Shared Tehillim campaigns
If you create or join a shared / split Tehillim campaign, we store on our servers:
- Campaign type, optional title, optional reason, optional deadline;
- A random campaign ID and share link;
- Anonymous participant IDs (not legal names);
- Which perakim were claimed or marked complete.
Anyone with the share link can open the campaign. Do not put private medical, financial, or identifying details in a campaign title or reason. You can leave a campaign; the creator can delete a campaign they created.
3.5 Information we do not collect today
- No required user account, password, or email for App use;
- No contacts, photos, camera, microphone, calendar write access, or files outside App storage;
- No advertising SDKs, no sale of personal information, no cross-app tracking for ads;
- No payment card numbers processed by us (the App does not currently run in-app purchases);
- No health, fitness, or government-ID data.
3.6 Information collected automatically by infrastructure
Our hosting provider (Railway), Apple, Google, and Expo may process standard technical logs (IP address, user-agent, request time, device diagnostics) when the App, dashboard, or API is reached. We use this to operate, secure, and debug the Services, not to build advertising profiles.
4. How we use information
- Provide siddur/Tehillim/learning text, calendar, zmanim, and reminders;
- Point Mizrach using your location and device sensors;
- Remember your settings and on-device progress;
- Operate shared Tehillim campaigns you choose to create or join;
- Understand how the App is used, find crashes, and improve reliability;
- Secure the Services, prevent abuse, and comply with law;
- Respond to support emails you send us.
We do not use your data for targeted advertising. We do not sell or “share” personal information for cross-context behavioral advertising as those terms are used in the CCPA/CPRA.
5. Legal bases (EEA/UK/Switzerland)
If GDPR or UK GDPR applies, we process personal data on these bases:
- Contract / requested service: providing the App features you use (including optional shared Tehillim);
- Consent: location, notifications, and sensors, which you can revoke in device settings;
- Legitimate interests: first-party product analytics with anonymous IDs, security, and service improvement, balanced against your rights;
- Legal obligation: if we must retain or disclose information to comply with law.
You may withdraw consent in iOS/Android Settings without affecting the lawfulness of processing before withdrawal.
6. How we share information
We share information only as follows:
| Recipient | Role | What they may process |
|---|---|---|
| Railway | Cloud hosting for our API, dashboard, and database | Analytics events, Tehillim campaign records, server logs |
| Expo / EAS | App builds and over-the-air updates | Install/update diagnostics as described by Expo |
| Apple / Google | App distribution, OS permissions, local notifications, device services | Standard store and OS data; location/geocoding if you grant permission |
| Sefaria | Independent library of Jewish texts | Text-fetch requests (IP and request URL) when the App loads a text that is not already bundled or cached. We do not send your name or journal content to Sefaria. |
| You / people you invite | Shared Tehillim | Campaign title, reason, progress visible to anyone with the link |
| Professional advisers or authorities | Legal, security, or compliance | Only as reasonably necessary or required by law |
We do not sell your personal information. If we ever use a new processor that materially changes this policy, we will update this page.
7. Retention
- On-device data: until you delete it, reset the App, or uninstall.
- Analytics events: kept as long as reasonably needed to operate the product and understand usage, then deleted or aggregated. You may email us to request deletion of records associated with an anonymous ID if you can provide it.
- Tehillim campaigns: until the creator deletes the campaign or we remove inactive/abusive campaigns.
- Support emails: as long as needed to handle your request and keep a reasonable business record.
- Server logs: typically short periods consistent with hosting defaults and security needs.
8. Security
We use HTTPS, least-privilege hosting, a password on the admin dashboard, and on-device storage for sensitive journal and name data. No method of transmission or storage is 100% secure. Do not put secrets, medical diagnoses, or other highly sensitive material in shared Tehillim titles. Refuah names and gratitude notes are stored on the device; protect the device with a passcode and OS-level privacy settings.
9. International transfers
We are based in the United States. Hosting (Railway) and device platforms may process data in the United States or other countries. If you use the App from the EEA, UK, or elsewhere, you understand that your information may be transferred to the U.S., which may have different data-protection rules. We rely on appropriate transfer mechanisms used by our providers and on your use of the Services.
10. Your rights
Depending on where you live, you may have the right to:
- Access, correct, or delete personal information we hold;
- Port a copy of data we store on our servers;
- Object to or restrict certain processing;
- Withdraw consent for location, notifications, or sensors in device settings;
- Appeal a denial of a privacy request (California and similar laws);
- Lodge a complaint with a supervisory authority (EEA/UK).
Because most App data is on your device, the fastest deletion method is uninstalling the App or using Reset App in Settings. For server-side analytics or a Tehillim campaign, email shevastudios@gmail.com with a description of your request. If you still have the App, include your anonymous ID if you can locate it, or describe the campaign link. We will not discriminate against you for exercising privacy rights. We do not sell personal information, so there is no “Do Not Sell” opt-out for a sale we do not perform.
Authorized agents (California) may submit requests to the same email with proof of authority. We may need to verify identity to a reasonable degree.
11. Children
The App is a general religious companion. It is not directed at children under 13 (or under 16 in the EEA where consent-age rules require it), and we do not knowingly collect personal information from children for accounts or marketing. We do not ask for a child’s name, email, or photos. If you believe a child has submitted personal information to our servers (for example in a shared Tehillim title), contact us and we will delete it. Parents and educators may use the App themselves; device-level parental controls remain your responsibility.
12. Push notifications and tracking
Reminders are scheduled locally on your device based on settings you choose. You can disable notifications in the App and in system settings. We do not use the App to track you across other companies’ apps and websites for advertising. On iOS, we do not use the App Tracking Transparency advertising identifier for ads.
13. Religious texts and third-party content
Prayer and learning texts may be bundled offline or fetched from Sefaria and similar sources and are provided under their licenses (including Creative Commons CC-BY-SA where applicable). Fetching a text may expose your IP address to that provider. See Sefaria’s own privacy policy at sefaria.org.
14. Apple / Google privacy labels (summary)
For store questionnaires, the following is an accurate high-level summary of current practice:
- Precise Location — used for App functionality (zmanim, reminders, Mizrach); not used for third-party advertising; linked to your device, not to an account name.
- Product Interaction / Usage Data — screens, features, and reliability events for first-party analytics.
- Identifiers — random anonymous/device IDs we generate; not your email.
- Diagnostics — crash and API-error events.
- User Content — Tehillim campaign metadata if you use sharing; journal/tzedakah/names stay on device.
- Not collected: contact info, financial info, health records, browsing history for ads, purchases in-app (none today).
15. Changes
We may update this policy when the App or the law changes. The “Last updated” date will change. Material changes will be posted on this page. Continued use after the effective date means you accept the updated policy. If we add accounts, payments, or new data types, we will revise this policy before those features collect new personal data.
16. Contact
Sheva Studios
Privacy requests: shevastudios@gmail.com
This policy: this URL
Support: /support
Terms of Use: /terms