Unity Through Torah

Privacy policy

What we collect.

This describes what our apps actually do. Where something stays on your device it says so, and where somebody else sees your IP address it names them.

Last updated 19 August 2026. Applies to unitythroughtorah.org, the Kavua app on the web and as a native app, and the content API at api.unitythroughtorah.org.

The short version

  • You can use Kavua fully without an account. Signing in is optional.
  • Almost everything the app remembers — your place in each sefer, your fonts, sizes, layout and brightness — never leaves your device.
  • We do not sell personal information, and we do not share it with advertisers.
  • We have no advertising, and no advertising identifiers.
  • This website sets no cookies and runs no analytics. The only thing it loads from anyone else is the anti-spam check on the two pages that have a form.
  • The app does use Google Analytics and loads some things from other sites. Both are set out below.

This website

unitythroughtorah.org sets no cookies and runs no analytics. The typefaces are the ones already on your device and the one Hebrew face is served from here, so no fonts, images or scripts are loaded from anywhere else — except on the two pages with a form, which load the anti-spam check described below.

Our web server keeps ordinary access logs: the requesting IP address, the time, the page requested and the browser's user-agent string. These rotate daily and are deleted after fourteen days. They exist to diagnose faults and abuse, and are not used to build any profile of a visitor.

All traffic to our domains passes through Cloudflare, which serves as our CDN and protects against attack. Cloudflare necessarily sees the IP address of every request. Their handling of it is governed by Cloudflare's privacy policy.

The support form

When you write to us through the support form, we store the name and email address you gave, the topic you chose, the message itself, and your browser's user-agent string. We keep this while we deal with your message and afterwards as a record of the correspondence, so a follow-up months later still has context. Ask us and we will delete it.

We do not store the IP address a message came from. We store a keyed cryptographic hash of it, which lets us recognise forty messages from one source as a flood without retaining an identifier for the person who sent a genuine one. The hash cannot be reversed to an address.

To stop the form filling with spam, your browser solves a small arithmetic puzzle before it sends — a fraction of a second, done on your own machine. Nothing about you is sent anywhere to do it, and it works with any blocker turned on. We used this instead of Google reCAPTCHA on purpose: we didn't want to hand every visitor to an advertising company, least of all someone writing to us about privacy.

The form pages also load Cloudflare Turnstile, a second anti-spam check. It loads a script from challenges.cloudflare.com, and Cloudflare sees your IP address and some signals about your browser in order to judge whether you are a person. Unlike Google reCAPTCHA it sets no tracking cookie and does not follow you between sites.

If it cannot run — because you block it, or because Cloudflare is having a bad day — your message still sends. We would rather take some spam than be unreachable by someone whose browser it does not get along with. We do keep a note of whether the check ran, alongside the message.

Your email address is used to reply to you. It is not added to any mailing list, because we do not have one.

The Kavua app

What stays on your device and is never sent to us

The great majority of what the app remembers is stored in your browser's own storage on your device. We never receive it, and it is gone if you clear the app's data:

  • Your place in each sefer — where you were up to, per shiur.
  • Every display setting: font choice, text size, nikud and taamim, page layout, split-pane and column positions, brightness, auto-hiding header, pinch zoom.
  • Which commentaries and translations you have chosen to show, and which tab you last had open.
  • Your calendar setting — whether you follow the Eretz Yisroel or chutz la'aretz parsha cycle.
  • The Torah text itself, downloaded ahead of time so that the app works with no connection.
  • Birthday dates you enter for the Tehillim kapitlach — yours and your family's. These are used only to work out which kapitel to show, and only on your device. Our servers reject these fields outright rather than storing them.

What is sent to us only if you sign in

Signing in is optional and exists so that one setting can follow you between devices. If you never sign in, we hold no account for you at all.

Sign-in is through Google. We request only the openid and email scopes — we deliberately do not request access to your Google profile, contacts, or anything else. From it we store:

  • The identifier Google uses for your account.
  • Your email address.
  • Your name and profile picture URL, but only when Google supplies them — with the profile scope withheld, often it does not.
  • The time you last signed in.
  • A sign-in token for your device, which expires after a year.

Beyond that, the only thing your account holds is your Chalukas HaShas selection — which masechta and which perakim you have taken — together with two display preferences about whose kapitlach are shown. That is the entire contents of a Unity account. Your reading positions and display settings are not part of it.

If you previously used Kavua through a community portal account, we also keep a record linking your new account to it, so your existing selection carries over. That record holds an opaque numeric identifier and the email address the match was made on.

Analytics in the app

The Kavua app uses Google Analytics 4 to record which parts of it are used — which buttons are tapped, on which screen, in which shiur. It's the only measurement we have, and we use it to see which parts are worth keeping.

Google Analytics sets its own cookies, and receives your IP address, approximate location derived from it, and device and browser details. It is governed by Google's privacy policy. We do not send it your email address, your name, your account identifier, or the text you are learning.

Blocking analytics doesn't affect the app. Everything keeps working.

Other sites the app draws on

Using these features means the site named sees your IP address, as it would if you visited it directly:

Google Fonts
Two typefaces used in the reader are loaded from Google's font service.
Sefaria
The app asks Sefaria's public calendar API which portions fall on a given date.
Amazon S3 and Google Drive
The Dvar Malchus booklet is a PDF hosted on Amazon S3. When our own converter cannot render it, the app falls back to displaying it through Google's document viewer.
Chabad.org
Some shiurim offer a link out to the corresponding page on Chabad.org. Nothing is sent until you follow the link.

Our own servers

When the app fetches text or a page image from api.unitythroughtorah.org, that request appears in the same fourteen-day access logs described above. We do not keep a record of which texts an individual has read.

Licensed seforim

Some seforim are published by others and licensed to us rather than freely available. This is not yet available to anyone; the section describes how it will work when it is, so that nothing about it arrives unannounced.

We do not sell them and we take no payment. The purchase happens on the publisher's own website, under their terms and with their payment provider. They then tell us which sefer to unlock for you. We never see your card details, your billing address, or anything else you gave them — only that an order was placed and what it entitles you to.

What we store is an entitlement record: which sefer, and an order reference so a repeated message from the publisher cannot grant the same thing twice. The text itself is delivered encrypted and decrypted on your device.

We do not report your reading back to the publisher. They learn that you bought a sefer, because you bought it from them; they do not learn whether or when you opened it.

What we never collect

We do not ask for and do not receive your location, your contacts, your photos, your microphone or camera, your health data, or any advertising identifier. We have no advertising and no ad networks. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Who else sees your information

We do not sell or rent personal information to anyone. It is shared only with the service providers named in this policy — Cloudflare and Google — each doing a specific job described above, and only when we are legally required to disclose something.

Our servers and the service providers named above operate in more than one country, and Cloudflare in particular serves requests from wherever is nearest to you. Using our software therefore means your information may be processed outside the country you are in.

Your choices and your rights

You can ask us what we hold about you, correct it, or delete it. Depending on where you live these may be legal rights; either way we do it.

  • Delete your account. Use the account deletion page, which lists exactly what is removed and the little that may be kept. Write from the address you signed in with. Requests are handled by a person, not automatically, and we confirm by email when it is done.
  • Clear what is on your device. Clearing the app's storage in your browser, or deleting the app, removes everything in the first list above. None of it is on our servers to begin with.
  • Stop signing in. Signing out revokes that device's token. The app keeps working.

Requests go to the support form, which is where all our correspondence starts. We do not publish an email address, because a published one is scraped and buried in spam, and yours would be the message we lost.

Children

Our software is for Torah study and is suitable at any age, but it is not directed at children under 13 and we do not knowingly collect personal information from them. A Unity account requires a Google account, which has its own age requirements. If you believe a child has given us information, tell us through the support form and we will delete it.

How long we keep things

Your account and synced settings
Until you delete the account. We do not expire inactive accounts, because an account that has sat untouched for a year is usually somebody who will come back to it.
Sign-in tokens
One year from the sign-in that issued them, or until you sign out on that device — whichever is first.
Server access logs
Fourteen days. They rotate daily and are then deleted.
Support messages
Kept while we deal with them and afterwards as a record of the correspondence, so a follow-up months later has context. Deleted on request.
Everything on your device
Until you clear the app's storage or delete the app. None of it is on our servers to expire.

Security

All traffic is encrypted in transit. Sign-in tokens expire after a year, and each device holds its own so that revoking one does not sign you out elsewhere. Purchased text is stored encrypted, with the keys held separately from the text itself, so neither a copy of the database nor a copy of the files is readable on its own.

No system is completely secure, and we won't claim otherwise.

Changes to this policy

If we change what we collect we'll update this page and change the date at the top. If it's a significant change we'll say so in the app rather than expecting you to check back here.

Contact

Questions about this policy, or about anything we hold, go through the support form — choose A privacy question as the topic. A person reads it.