Home

Privacy

This is a study tool, and I have built it to need as little about you as a study tool can. I don’t sell your data, I don’t share it for advertising, and there are no ads on this site. What follows is the whole of it, written plainly.

What I collect

If you never sign in, I hold nothing about you. You can search, read the Tanakh, open the Talmud and follow the daily learning without an account, and none of it is recorded against your name, because there is no name.

If you make an account, I store your email address. That is the only personal detail I ask for — there is no name field, no address, no phone number, no date of birth. You sign in either by a one-time link sent to that address, or with a password if you choose to set one, and a password is stored only as a salted hash that cannot be turned back into what you typed.

What your account keeps for you is the work you do here: your bookmarks and any notes you write on them, your place in each book, the days you’ve checked off in the daily learning, which prayers you’ve marked as davened, how far you’ve listened in an audio reading, and your saved searches. Search history is yours to switch off in your account settings, and when it is off nothing further is written.

Payments

Payments run through Stripe, and you enter your card on Stripe’s own checkout page, not on mine. Card numbers, expiry dates and security codes never touch this site — I never see them and could not store them if I wanted to. What comes back to me is your Stripe customer and subscription identifier, your plan, and whether it is active, which is all I need to know to open the door. Cancelling and updating a card are handled in Stripe’s billing portal.

If you buy a gift membership, the recipient’s email address, your name and your note travel with the payment so the gift can be delivered and so the recipient knows who it’s from. Your message stays with the payment record; I don’t copy it into my own database.

Cookies, and what stays on your device

This site sets four small first-party cookies. Two are strictly necessary and http-only: one that keeps you signed in, and a short-lived one that remembers which email address you’re signing in with so it needn’t ride in the address bar. Two carry no identifier at all: one remembers, for ninety days, where your first visit came from — the page you landed on, the referring site, and any campaign labels on the address, never the full address — so that if you create an account I can tell whether it came from a search, an ad or a link; and one holds a single character, for a week, saying whether this browser has seen the front page and run its test search, so the tally below can count browsers rather than page loads. None of them is sent to anyone else. There are no advertising cookies, no third-party cookies, and nothing that follows you to other sites.

Your settings live in your own browser’s storage and are never sent to me: your theme, your nusach, reverent display of the Divine Names, which commentary you read alongside the text, how each reader is laid out, where the audio player left off, and the free-search counter. If you ask for candle-lighting times and give the browser permission for your location, those coordinates stay on your device too — they are used to compute the times and are not stored on the server. Clearing your browser data clears all of it.

Analytics

I use Cloudflare Web Analytics to see roughly how many people visit and which pages they open. It is the privacy-preserving kind: it sets no cookies, builds no profile of you, and does not follow you to any other site. It is the only third-party analytics on this site — there is no Google Analytics, no advertising pixel, no session recorder and no third-party tracker of any other description.

I also keep an anonymous first-party tally of how the home page is used — which sections were opened, which buttons were pressed, and how long a visit to the front page lasted, in five broad bands. It also counts how many times the iPhone and Android apps are opened for the first time. It records no personal information, no IP address, no account identifier and nothing you typed; it is a counter, not a profile.

Who else touches your data

Stripe — payments and subscription billing

Resend — sends the transactional email described below

Render — hosts the application and its database

Cloudflare — sits in front of the site as CDN and protection, and provides the analytics above

That is the entire list. None of them are given your data to use for their own purposes, and nothing is sold, rented or handed to a data broker — not now, and not as some future change of policy.

Email I send

Only email you’ve caused: a sign-in link when you ask for one, confirmation of a purchase, and the notices around a gift membership. There is no newsletter, no mailing list and no marketing. There are no tracking pixels and no click-wrapped links in any message I send, so I have no idea whether you opened it.

Logs

I keep no access log of who searched for what. To stop abuse, the server does briefly hold IP addresses against a counter: failed password attempts for fifteen minutes, request counters for about an hour, and a record for thirty days when a rate limit is tripped. When something goes wrong — an email that would not send, a payment that failed — the error written to the server log can include the email address involved, because otherwise the problem cannot be traced. My host keeps the ordinary web-server records any host keeps.

The Android app

The app on Google Play is this website in a thin wrapper. It asks for no device permissions, collects nothing from your phone, sends no notifications, and reads no contacts, files, camera or microphone. Everything above applies to it word for word.

Deleting your data

You can delete your account yourself, at any time, without asking me. Sign in, open your account page, and Delete account is the last thing on it. It shows you exactly what is about to go, asks you to type the word DELETE, and then does it immediately: the account and its email address, your bookmarks and the notes on them, your saved searches and search history, the days you’ve checked off and the davening beside them, what you’ve listened to, where you are holding in every book, your membership standing, and every session on every device. It is one operation and it cannot be undone — there is no recycle bin and no restore, by me or by anyone.

Two things outlive it, and both are named here rather than discovered later. Stripe keeps its own record of any payment for as long as tax and accounting law requires, and deleting your account here does not cancel a subscription there — cancel it in Manage billing first if you have one, or write to me and I’ll do it. And my backups age out on their own schedule, so a copy may sit in one for a short while before it expires. Everything I keep about the deletion itself is a dated line saying an account was deleted, with no address and nothing that could identify whose it was.

If you would rather I did it, email me and I will — that door hasn’t closed. You can also do less than all of it: switch search history off, remove individual bookmarks and saved searches, and sign out, which ends that session immediately.

Children

The Gematria is for everyone and holds nothing unsuitable for any age, but it is not directed at children, and I don’t knowingly collect anything from a child under 13.

Changes

If this policy changes in substance, the date below changes with it. I won’t quietly widen what I collect and leave this page as it was.

Contact

Questions, corrections, or a deletion request: [email protected]. More about the app and every source behind it is on the about page.

Effective 2 September 2026 · The Gematria · TheGematria.com