Privacy Policy
Last updated: September 23, 2026
This Privacy Policy explains how Shoresh collects, uses, stores, shares and protects your personal data when you use the Shoresh mobile application for iOS and Android (the "App"), the website at hebrewtutor.app (the "Website") and related services (together, the "Service"). Please read it together with our Terms of Use.
A separate Russian-language policy applies to users in the Russian Federation, where the Service is operated by a Russian sole proprietor: Политика конфиденциальности.
1. Who We Are (Data Controller)
The Service is operated by Arkadii Broun, an individual, … ("we", "us", "our"). We are the data controller for the personal data described in this Policy.
For any privacy-related question or request, contact show e-mail.
We are established in Israel, a country recognised by the European Commission as providing an adequate level of data protection. We have not appointed a separate representative in the European Union; you can reach us directly at the e-mail address above for all matters covered by the EU General Data Protection Regulation ("GDPR").
2. Scope and Age
This Policy applies to everyone who uses the App, visits the Website or contacts us. The Service is a language-learning tool and is not directed at children under 13. If you are between 13 and 18, you may use the Service only with the permission of a parent or guardian. We do not knowingly collect personal data from children under 13; if we learn that we have, we delete it.
3. Personal Data We Process
Depending on how you use the Service, we may process the following categories of personal data.
3.1 Account data
- when you sign in with Apple: the Apple user identifier and the e-mail address Apple provides (which may be an Apple "Hide My Email" relay address);
- when you sign in with Google (Android): the Google user identifier, e-mail address and, if provided, your first and last name;
- when you use the App without signing in (iOS): a pseudonymous installation identifier generated by the Apphud SDK, which lets us keep your progress without knowing who you are;
- your Shoresh user identifier, registration date, date of last visit, interface language and learning settings (for example pause lengths, words per session, days between reviews, auto-play of audio).
3.2 Learning data
- your progress in alphabet courses, word sets and grammar trainers: which letters and words you have learned, review dates, answers and results of sessions;
- the words you add to "My words", including words you type in yourself.
3.3 Purchase and subscription data
- subscription status, product identifier, purchase, renewal and expiry dates and transaction identifiers provided by the Apple App Store or Google Play;
- promo codes you redeem and the resulting access period.
We never receive or store your payment card details. Payments through the App Store and Google Play are processed entirely by Apple or Google.
3.4 Device, technical and diagnostic data
- device model, operating system version, App version, language and time zone;
- IP address and the approximate region derived from it (in server logs);
- on iOS, a push notification token (Apple Push Notification service), if you allow notifications; the Android App does not send push notifications;
- crash reports, error logs and diagnostic data: on iOS, masked screen recordings of a small sample of sessions and of sessions in which an error occurred; on Android, a description of the screen layout (without its contents) taken at the moment of a crash or error (see Section 8);
- events describing how the App is used (for example that a session was started or completed and its result).
3.5 Website data
- analytics data collected through cookies and similar technologies, only after you accept them (see Section 12);
- technical data received by our hosting provider when a page is loaded (IP address, browser, pages requested).
3.6 Communications
- e-mails and support requests you send us, and our replies;
- replies and notices we send to the address on your account (see Section 9).
4. Where the Data Comes From
We receive data directly from you (when you sign in, learn, add words, make purchases or contact us), automatically from your device and the App (technical, diagnostic and usage data), and from Apple and Google (sign-in and purchase data).
5. Purposes and Legal Bases
We process personal data only where we have a legal basis to do so. Under the GDPR the relevant bases are:
- Performance of a contract (Article 6(1)(b)): creating and managing your account, storing your progress and word lists, providing courses, trainers, the dictionary and the textbook, subscriptions, promo codes and support.
- Consent (Article 6(1)(a)): sending push notifications and setting non-essential Website cookies. You can withdraw consent at any time as described in Section 10.
- Legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing abuse and fraud, diagnosing errors, understanding how the Service is used and improving it, and defending legal claims. We balance these interests against your rights and do not rely on this basis where your interests override ours.
- Legal obligation (Article 6(1)(c)): complying with laws that apply to us, including tax and accounting law, and responding to lawful requests from authorities.
Where the laws of your country require a different or additional basis (for example the Israeli Protection of Privacy Law), we rely on the closest equivalent basis under that law.
6. Dictionary Examples Generated by AI
Usage examples in the dictionary are generated by an artificial-intelligence model on our server's request. Only the dictionary word itself and the interface language are used for that; no account data, identifiers or other personal data are involved, so this feature does not process your personal data. Generated examples may be cached on our server and on your device.
7. Push Notifications
On iOS, with your permission, the App sends reminders to practise and occasionally information about the Service, including special offers. Notifications are delivered through the Apple Push Notification service. You can turn them off at any time in your device settings. The Android App does not send push notifications.
8. Crash Reporting and Session Recordings
Both Apps use Sentry to report crashes and errors, together with diagnostic logs (technical messages the App writes while running) and the user identifier of your account, so that we can find the reports that concern you when you write to support. Your e-mail address is not sent to Sentry.
Android. When a crash or error occurs, the App attaches a description of the screen layout (the structure of the screen, without its text or images) to the report. No screenshots are taken.
iOS. The iOS App In addition to technical data and the error context, Sentry records a replay of the screen layout for a small random sample of sessions and for sessions in which an error occurred, so that we can reproduce the problem. All text and images in these replays are masked: they show which screens and controls were used, not what was displayed or typed. Replays are linked to your pseudonymous installation identifier, not to your name, and are stored on Sentry's servers in the European Union for a limited time.
9. E-mails
We do not send newsletters or promotional e-mails. The only e-mails you may receive from us are replies to your own requests and, where the law requires it, a notice about a material change to these documents.
10. Your Rights and Choices
Subject to applicable law, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that has legal or similar effects (we do not make such decisions);
- lodge a complaint with a data protection authority, in particular in the EU/EEA member state of your residence or workplace, or with the Israeli Privacy Protection Authority.
How to exercise these rights:
- notifications: change the App's permissions in your device settings;
- learning settings and interface language: change them in the App;
- account deletion: use "Delete my account" in the App settings, or see how to delete your account;
- all other requests: e-mail show e-mail.
We respond to requests within 30 calendar days. We may ask you to verify your identity before acting on a request. We do not discriminate against you for exercising your rights.
11. Service Providers and Other Recipients
We share personal data only with providers that help us operate the Service, and only to the extent needed. They act on our instructions under data processing agreements, or as independent controllers where noted.
- Heroku (Salesforce), European Union region: hosting of our server and database.
- Cloudflare: network security and traffic routing in front of our server; Cloudflare sees the IP address and requests of every connection.
- Apple: Sign in with Apple, App Store purchases and subscriptions, Apple Push Notification service. Apple is an independent controller for your Apple ID and purchases.
- Google: Sign in with Google and Google Play purchases and subscriptions (Android); hosting of the Website (Firebase Hosting); web fonts loaded from Google Fonts when you open the Website, which sends your IP address to Google. Google is an independent controller for your Google account.
- Apphud (iOS): generation of the pseudonymous installation identifier.
- Sentry, European Union: crash reporting, error diagnostics, logs and masked session recordings (iOS) (Section 8).
- Better Stack: storage of server logs (which contain IP addresses and request data) for a limited time.
- Yandex Metrika: Website analytics, only after you accept analytics cookies (Section 12). Not used inside the App.
We may also disclose personal data:
- to comply with a law, regulation, court order or lawful request from a public authority;
- to enforce our Terms, protect our rights or protect the safety of any person;
- to a successor in the event the Service or its assets are transferred to another operator, who will be bound by this Policy.
We do not sell personal data, we do not show advertising and we do not share personal data with advertising networks.
12. Website Cookies and Analytics
The Website uses Yandex Metrika to understand how visitors use it. The Metrika script is loaded only after you click "Accept" in the cookie banner; if you decline, it is never loaded, and your choice is remembered in your browser. When enabled, Yandex Metrika sets cookies and collects pages viewed, clicks, the referring page and device and browser information. We do not use session recording on the Website. You can change your mind at any time by clearing the Website's data in your browser, after which the banner is shown again.
The Website also uses local storage for settings that stay on your device and are not sent to us: your cookie choice and your preferred language.
13. International Data Transfers
Our server and database are located in the European Union. We, the operator, access data from Israel, which benefits from a European Commission adequacy decision. Some providers listed in Section 11 process data in the United States or other countries. Where this involves data of users in the European Economic Area, the United Kingdom or Switzerland, we rely on the provider's certification under the EU-US Data Privacy Framework or on Standard Contractual Clauses approved by the European Commission, together with additional technical and organisational safeguards.
14. Data Retention
We keep personal data only as long as necessary for the purposes described above:
- account, settings, learning progress and word lists: until you delete your account;
- purchase and subscription records: as long as required by tax and accounting law (typically 7 years);
- crash reports, masked session replays and technical logs: up to 90 days;
- usage events: up to 24 months, in aggregated or pseudonymised form where possible;
- support correspondence: up to 24 months after the request is closed;
- Website analytics: according to Yandex Metrika's retention settings, in aggregated form.
When you delete your account, everything linked to it is deleted: identifiers, e-mail address, settings, progress and word lists. The only exceptions are records we are legally required to keep (for example purchase records held for tax purposes) and records needed to handle an ongoing dispute.
15. Data Security
We apply technical and organisational measures appropriate to the risk, including encrypted connections (TLS), access controls, authentication of all administrative access, logging and hosting with certified providers. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a high risk to you, we will notify you and the competent authority as required by law.
16. Children
The Service is not directed at children under 13, and we do not knowingly process their personal data. If you believe a child under 13 has created an account, contact us and we will delete it.
17. Changes to This Policy
We may update this Policy from time to time. The current version is always available at hebrewtutor.app/en/privacy and takes effect on the "Last updated" date shown above. If a change materially reduces your rights or introduces a new purpose, we will notify you in the App or on the Website before it takes effect and, where required, ask for your consent.
18. Contact
For privacy questions, requests or complaints, contact show e-mail or write to Arkadii Broun, ….