Effective September 14, 2026

Privacy Policy

Torah and Chassidus Translate is a mobile app for capturing, organizing, translating, and exporting Torah and Chassidus study material.

Data stored on your device

The app stores your projects, imported or captured page images, imported PDF-derived pages, edited images, OCR text, translation results, summaries, tags, provider settings, usage estimates, exported files, reader preferences, and downloaded offline assets on your device. API keys are stored using platform secure storage.

Backup and sync

If you enable backup, the app can store a backup of your projects, page images, OCR text, translation results, summaries, prompt templates, tags, source links, usage estimates, and selected settings in your own iCloud Drive app container on iOS or Google Drive appDataFolder on Android. Provider API keys are not included in backups.

Downloaded Sefaria libraries, OCR data, local model files, temporary optimized images, and exported documents are not included in cloud backups because they can be re-downloaded or recreated.

Data sent to translation providers

When you use your own provider key, the app sends the selected page image, OCR or source text, prompt, output settings, and instructions directly to the provider you selected. The provider processes the request under its own terms and privacy policy.

When you explicitly select an optional managed action, the app shows the data that will leave the device before you confirm it. Depending on that action, this can include a selected page image, OCR or source text, language and output settings, bounded guidance, selected project excerpts, a word and its nearby context, or a tutor question with bounded cited excerpts, recent conversation context, and response-style settings. The content is sent over encrypted HTTPS to the Torah Translate backend and then to the managed Google service for that action. Gemini processes translation, OCR validation, summaries, tags, document metadata, Word Lens context, and text-tutor turns. Google Gemini Live processes managed voice, Gemini text-to-speech processes managed narration, and Google Cloud Translation processes formatted-document translation.

For ordinary managed Gemini actions, request content is removed by Torah Translate after provider processing. A validated result is encrypted for no more than 24 hours so an interrupted operation can be recovered without a second charge. For managed narration, the selected narration text and voice settings are encrypted while the queued job is processed. For formatted documents, encrypted document chunks, file type, page ranges, and language settings are kept only while the confirmed job is processed and delivered. Unclaimed narration and formatted-document outputs follow the artifact retention schedule below. Torah Translate does not use customer documents to train models and does not put page images, document bytes, source text, prompts, translations, tutor content, microphone audio, or provider keys in application logs. Google processing remains subject to the paid-service terms and can include limited safety and abuse retention.

Voice Tutor

When you start the study tutor, the app may send your microphone audio, finalized speech transcript, and small relevant excerpts from the open project to the provider you selected. Raw microphone audio is not saved by Torah and Chassidus Translate. You can choose whether tutor transcripts and citations are saved on the device. Saved tutor data may be included in user-controlled encrypted backup and Device Sync; temporary transcripts are deleted when the session ends.

When you use your own provider key, the key remains in platform secure storage and requests are billed to your provider account. During a managed voice session, live microphone audio and bounded project excerpts pass through the Torah Translate service so the managed provider credential never reaches the device and connected time can be measured. Raw live microphone audio is relayed in memory and is not retained by the Torah Translate backend. The bounded project excerpts and session setup context are encrypted at rest only while the session is connecting or active, and are deleted when the session ends or reaches its confirmed deadline. The service also keeps only bounded entitlement, duration, usage, reliability, and cost metadata under the retention schedule below.

Global Library contributions

Global Library publishing is optional. If you choose to contribute, the app submits text-only project translations, tags, source references, a generated contributor username, and coarse country or region information for private review. Original scans, API keys, local file paths, precise location, downloaded models, and backup ZIPs are not published.

Approved contributions may become publicly browsable. Contributors can unpublish their own submissions, and readers can report approved submissions from inside the app.

Offline mode

Downloaded Sefaria libraries, OCR data, local translation model files, and local AI voice model files are stored on your device. Offline translation, lookup, and local read-aloud features are designed to run locally when supported by the installed assets and model.

Reader Mode and text-to-speech

Reader Mode can use operating-system text-to-speech voices or supported local AI voice engines. Text spoken through native system voices is handled by the device platform. Local AI voice playback is generated on device from the text being read.

Optional managed-service account

No account is required for local projects or bring-your-own-key features. An optional managed account uses an email address for passwordless verification. The commercial account database stores a keyed hash of the normalized email, not the raw address. The mail-delivery system necessarily receives the address to send a one-time code. The backend stores the one-time-code hash, delivery identifier and status, pseudonymous sessions, and an immutable random billing UUID.

The account also stores the minimum product, transaction, subscription, credit-ledger, refund, usage, and safe diagnostic data needed to verify purchases and operate the managed service. Stripe receives the billing UUID—not the email address or internal database account ID—as provider metadata.

Purchases

Apple and Google process mobile purchases. Stripe Checkout processes web and Windows purchases, and Stripe Customer Portal provides hosted subscription management. These merchants collect payment, tax, contact, and transaction data under their own policies. Torah Translate receives the customer, product, transaction, subscription, refund, dispute, and status information needed to maintain entitlements; it does not receive full payment card numbers.

Account deletion does not cancel a merchant subscription. Cancel it in the applicable app store or Stripe Customer Portal first. Ending a plan never removes local projects or disables bring-your-own-key features.

Analytics and tracking

The app has no third-party advertising tracker and does not sell personal information. Bounded commercial reliability and fraud-prevention events are used to operate the managed service, not to track users across other companies’ apps or websites.

Website forms

Beta, support, and account-deletion requests submitted through this website go to a private Cloudflare intake queue. The queue may contain the contact email, name, platform, subject, and message you submit, plus an abuse-prevention hash derived from network information. The forms use Cloudflare Turnstile for abuse prevention. Do not include API keys, passwords, full receipts, or private source content.

Retention and deletion

One-time codes expire after 10 minutes and terminal challenge records are removed after 30 days. Raw managed request content is processed in memory where possible. Encrypted replayable responses are removed no later than 24 hours after an operation. Unclaimed narration and formatted-document artifacts are removed within seven days and normally within 24 hours after retrieval. Content-free operation metadata is kept for 30 days, and aggregated cost and service-health metrics may be kept for 13 months. Raw notification bodies are not retained. Transaction, ledger, refund, dispute, tax, security, and audit records are normally kept for seven years, or longer only when required by accounting or law, and are pseudonymized or separated from a deleted identity where feasible.

You can delete a managed account immediately in the app or, after email verification, on the account-deletion page. Deletion revokes active sessions and removes or irreversibly detaches account identity and managed-service data that is not subject to a legitimate retention requirement. Local projects, user-controlled backups, exports, and independently published contributions are outside this account process. Temporary processor artifacts are removed by the retention workers on the schedule above; legally required financial and audit records remain pseudonymized for their stated retention period.

Exports and sharing

When you export or share translations, exported files are handled by iOS, Android, macOS, or the apps and services you choose from the share sheet. Review the destination before sharing.

Children

The optional managed service is for people at least 13 years old and does not knowingly create a managed account for a child under 13. Local study features do not require an account.

Contact

For privacy questions, use the private support form on the Support page.

Changes

This policy may be updated as features change. The effective date above reflects the current version.