← Back to KAHALPrivacy Policy
Effective Date: February 28, 2026
KAHAL GROUP LLC
KAHAL GROUP LLC ("KAHAL," "we," "our," or "us") operates the KAHAL mobile application and website (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the Platform.
By creating an account or using the Platform, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.
1. Information We Collect
We collect several categories of information when you use the Platform.
1.1 Account and Authentication Data
When you register, we collect your phone number (required for SMS-based one-time password verification), full name, and username. You may also provide an email address for account recovery. If you sign in with Google or Apple, we receive your name and email address from those providers. We store authentication data through Supabase Authentication.
1.2 Profile Information
You may optionally provide a profile photo, neighborhood, synagogue (shul) affiliation, community, biography, Instagram handle, personal website URL, and referral code. This information is visible to other members of your community.
1.3 User-Generated Content
We collect content you create within the Platform, including:
•Event listings, descriptions, and digital invitation cards
•Community bulletins and announcements
•Ride offers and requests (including pickup and drop-off locations)
•Meal offerings and requests
•Lost-and-found posts (including descriptions and photos)
•Babysitter profile listings and booking requests
•Business listings and vendor profiles
•Reviews and ratings you submit
•Group posts and comments
•Messages sent to other users (including forwarded content)
•Mazal Tov wishes and event comments
•Donation categories and amounts (for shul features)
1.4 Messages and Communications
Private messages between users are stored in our database. Messages are not end-to-end encrypted. Message metadata (type, forwarded content references) is also stored. AI chat conversations (messages you send to the Kahal AI assistant) are stored separately for conversation continuity.
1.5 Payment and Financial Data
Payments are processed through Stripe. We store transaction records (amount, date, purpose, recipient, anonymous preference) but do not store payment card numbers or bank account details — those are handled entirely by Stripe. If you set up payment handles (Venmo, Zelle, PayPal, Cash App usernames), those are stored on your profile. For shuls and organizations using Stripe Connect, we store the connected account identifier.
1.6 Guest and Non-User Data
Non-users may interact with the Platform without creating an account:
•Guest gift payments: We collect the guest's name, email address, optional message, and payment amount. This data is processed by Stripe and stored in our database.
•Simcha Cam anonymous photos: We assign a random guest token (UUID) stored in the device's local storage to track photo counts per guest. We collect the photographer's self-reported name and uploaded photos. No account or authentication is required.
1.7 Event and RSVP Data
We record your responses to event invitations (Going, Maybe, Mazal Tov), party size, dietary preferences, notes, RSVP history, and event view timestamps. For event hosts, we store seating assignments, budget information, vendor contacts, guest lists (including manually added guests), timeline items, checklists, accommodation details, and activity logs.
1.8 Device Permissions and Automatically Collected Data
With your explicit permission, we may access:
•Camera: To take photos for Simcha Cam, profile pictures, and content posts (via expo-camera on mobile, navigator.mediaDevices on web).
•Contacts: To import guest names from your device address book for event planning (via expo-contacts). Contact data is used only for display within the app and is not uploaded to our servers in bulk.
•Calendar: To add events to your device calendar (via expo-calendar) or generate .ics files. We do not read your existing calendar entries.
•Push Notifications: To send event updates, messages, and community activity alerts. We store your Expo Push Token in your profile to deliver notifications via the Expo Push API.
•Photo Library: To save downloaded photos to your camera roll (via expo-media-library).
You can revoke any device permission at any time through your device's Settings app.
1.9 Usage and Technical Data
We collect non-personally-identifiable data including device type, operating system version, app version, and error logs to diagnose issues and improve performance. We do not use third-party analytics SDKs. On the web platform, we use browser local storage (not tracking cookies) to persist your session, Simcha Cam guest token, and UI preferences (such as dark mode). We do not use advertising cookies or third-party tracking pixels.
1.10 Photos and Media
Photos uploaded to event galleries (Simcha Cam), profile pictures, lost-and-found posts, group posts, and business listings are stored in Supabase Storage. For Simcha Cam photos, we generate a perceptual hash (a mathematical fingerprint of the image) to detect and prevent duplicate uploads. This is not facial recognition — it compares overall image similarity only. Photo metadata includes dimensions, file size, upload timestamp, and approval status.
1.11 Moderation and Safety Data
When you report content or users, we store the report reason, content type, reported content identifier, and any action taken. We track flag counts on photos and user profiles. Rate limiting data (action counts and timestamps) is stored to prevent abuse. Blocked user relationships are stored to enforce blocking.
1.12 Social and Connection Data
We store your follow/follower relationships, family link connections (linking family member accounts), and group memberships (including your role: owner, admin, or member).
2. How We Use Your Information
We use the information we collect for the following purposes:
•Providing the Platform: To authenticate your account, display your profile, enable messaging, RSVPs, event creation, business listings, group participation, and all other core features.
•Community Features: To make your profile, posts, and listings visible to members of your community as appropriate, filtered by your community affiliation.
•Communications: To send transactional emails (email verification, password reset, event updates, RSVP notifications) via our email service provider (Resend). To deliver push notifications via the Expo Push API for event updates, messages, and community activity.
•AI Features: When you use the Kahal AI assistant, your messages are sent to the Google Gemini API for processing. We send only the content of your conversation — not your full profile, account details, or personal data — to Google Gemini. AI conversations are stored to maintain chat history within the app. You may delete your AI conversation history at any time.
•Payment Processing: To process gift payments, donations, babysitter payments, and group fund contributions through Stripe. Transaction records are maintained for your payment history.
•Content Moderation: To review reported content, enforce community standards, detect duplicate photos (via perceptual hashing), and take action on violations (hiding content, suspending accounts).
•Event Management: To facilitate hosting features including guest lists, seating charts, budgets, timelines, vendor coordination, and gift tracking.
•Safety and Security: To detect and prevent fraud, abuse, spam, and violations of our Terms of Service, including rate limiting and automated flag thresholds.
•Improving the Platform: To monitor for errors, fix bugs, and improve functionality based on aggregated, non-personally-identifiable usage data.
•Legal Compliance: To comply with applicable laws and respond to lawful requests from authorities.
3. Information We Share
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We do not share your data with data brokers or advertisers. We share your information only in the following circumstances:
With Other Users (By Design)
Certain information is visible to other community members by design. This includes your display name, username, profile photo, neighborhood, biography, social links, posts, event listings, business listings, reviews, group memberships, and follow/follower counts. Messages are visible only to conversation participants. Babysitter profiles are visible to community members browsing the directory.
Service Providers
We use the following third-party service providers who process data on our behalf:
•Supabase (Infrastructure): Our primary backend provider. All database records, authentication, file storage, and edge functions are hosted on Supabase, running on Amazon Web Services (AWS) infrastructure in the United States.
•Stripe (Payments): Processes all monetary transactions (gifts, donations, babysitter payments, group funds). Stripe collects and stores payment card details directly; we never receive or store card numbers.
•Google Gemini API (AI): When you use Kahal AI, your chat messages are transmitted to Google's Gemini API. Only conversation content is sent — not your profile, name, or account details.
•Resend (Email): Delivers transactional emails (verification, password reset, event updates). Resend receives recipient email addresses and message content.
•Expo / Expo Push Notifications (Mobile): The mobile app is built with Expo. Expo's push notification service receives your device push token to deliver notifications. Expo may collect device telemetry.
•Vercel (Web Hosting): The web platform is hosted on Vercel. Vercel may log IP addresses and request metadata.
•Apple App Store / Google Play Store (Distribution): The mobile app is distributed through app stores. Apple and Google may collect analytics and crash reports pursuant to their respective privacy policies.
Each provider's own privacy policy governs their handling of your data.
External Navigation Apps
If you tap a "Get Directions" option, we open Google Maps, Waze, or Apple Maps with only the destination address. We do not share your identity or account information with these navigation services.
Legal Requirements
We may disclose your information if required by law, court order, subpoena, or government authority, or if we believe disclosure is reasonably necessary to protect the rights, safety, or property of KAHAL, our users, or the public.
Business Transfers
If KAHAL is acquired, merged with, or sells substantially all of its assets to another entity, your information may be transferred as part of that transaction. We will notify you via in-app notice or email before your information becomes subject to a different privacy policy.
4. Cookies and Local Storage
Mobile App
The mobile app does not use cookies. We use AsyncStorage (a device-local storage mechanism) to persist your authentication session, theme preferences (light/dark mode), Simcha Cam guest tokens, recent search history, and tooltip dismissal states. This data remains on your device and is not transmitted to third parties.
Web Platform
The web platform uses browser cookies solely for authentication session management (Supabase auth tokens). We use browser localStorage to store your authentication session, Simcha Cam guest token (a random UUID for anonymous photo uploads), photographer name (for Simcha Cam), and UI preferences.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not participate in cross-site tracking or behavioral advertising.
5. Data Security
We implement reasonable technical and organizational measures to protect your personal information:
•Encrypted connections (TLS/HTTPS) for all data in transit between your device, our servers, and third-party providers
•Supabase Row Level Security (RLS) policies that restrict database access so users can only access their own data or appropriately shared community data
•Password hashing managed by Supabase Authentication (passwords are never stored in plaintext)
•Phone OTP verification for account creation and phone number changes
•Access to backend systems and administrative tools limited to authorized personnel with verified admin roles
•Rate limiting on sensitive actions (event creation, reporting, posting) to prevent abuse
•Automated content moderation thresholds (photo flags, report counts) for faster response to violations
•Perceptual hashing for photo deduplication (mathematical fingerprints, not facial recognition)
However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. If you believe your account has been compromised, please contact us immediately at support@kahal.app.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Platform's services.
Account Deletion
You can request account deletion directly within the app (Profile → Delete Account) or by emailing support@kahal.app. Upon requesting deletion:
•Your account enters a 30-day grace period during which you may cancel the deletion by logging back in.
•After 30 days, we will permanently delete or anonymize your personal data.
•We may retain certain information as required by law or for legitimate business purposes, including records of financial transactions (required for tax and accounting purposes), abuse reports, legal disputes, and audit logs.
•User-generated content (posts, reviews, event listings) may remain visible in anonymized form after account deletion to preserve community history.
•Photos you uploaded to Simcha Cam may remain in the event album at the host's discretion.
Data Export
You may request a copy of your personal data at any time through the app (Profile → Export Data) or by emailing support@kahal.app. We will provide your data in a machine-readable format within 30 days.
7. Your Privacy Rights
All Users
Regardless of your location, you have the right to:
•Access the personal information we hold about you
•Correct inaccurate personal information
•Request deletion of your personal information (subject to legal retention requirements)
•Export your personal data in a portable format
•Opt out of push notifications at any time via your device settings or in-app notification preferences
•Block other users, which prevents them from viewing your profile or contacting you
California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
•Right to Know: You may request a detailed report of the personal information we have collected, the sources, the purposes, and the third parties with whom we share it.
•Right to Delete: You may request that we delete your personal information, subject to certain exceptions (legal obligations, fraud prevention).
•Right to Opt-Out of Sale: We do not sell personal information. There is nothing to opt out of.
•Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
•Right to Correct: You may request that we correct inaccurate personal information.
To exercise these rights, email us at support@kahal.app with the subject "Privacy Request." We may need to verify your identity before responding. We will respond within 45 days as required by law.
European Economic Area, United Kingdom, and Israel Residents (GDPR)
If you are located in the EEA, UK, or Israel, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Platform, you consent to this transfer. You have the right to access, rectify, erase, restrict processing, object to processing, and port your personal data. You also have the right to lodge a complaint with your local data protection authority. Contact us at support@kahal.app to make a request.
8. Children's Privacy
The Platform is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Platform or provide any personal information.
Users between 13 and 17 must have permission from a parent or legal guardian to use the Platform.
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately at support@kahal.app and we will promptly delete such information. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information as quickly as possible.
9. Third-Party Links and Services
The Platform may contain links to third-party websites or services, including but not limited to:
•Business websites listed in directory listings
•Mapping applications (Google Maps, Waze, Apple Maps) for directions
•Payment platforms (Venmo, Zelle, PayPal, Cash App) linked via user payment handles
•Instagram profiles linked from user social links
•External event registration or donation pages
These third-party services are not operated by us, and this Privacy Policy does not apply to them. We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies before providing any personal information.
10. Push Notifications
If you grant permission, we send push notifications for:
•New messages received
•RSVP updates to your events
•New events in your community
•Babysitter booking requests and updates
•Group activity and posts
•Mazal Tov wishes received
•Moderation actions on your content
Your Expo Push Token (a device identifier for notification delivery) is stored in your profile and transmitted to Expo's push notification service when sending notifications. You can disable push notifications at any time in your device's Settings app or through in-app notification preferences (which allow per-category control). You may also enable Shabbos Do Not Disturb mode to pause notifications during Shabbat. Disabling notifications does not delete your account or data.
11. International Data Transfers
KAHAL is based in the United States, and your personal information is processed and stored in the United States via our infrastructure providers (Supabase/AWS). If you access the Platform from outside the United States, your information will be transferred to, stored in, and processed in the United States.
We rely on your consent (provided when you create an account and agree to this Privacy Policy) as the legal basis for transferring your data to the United States. By using the Platform, you acknowledge that data protection laws in the United States may differ from those in your home jurisdiction.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. When we do, we will:
•Revise the "Effective Date" at the top of this policy
•Where changes are material, notify you via in-app notification or email before the changes take effect
•Post the updated policy on the Platform
Your continued use of the Platform after any changes constitutes your acceptance of the updated policy. If you do not agree with the updated policy, you should stop using the Platform and request account deletion.
We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
KAHAL GROUP LLC
10 Laurel Avenue
Clifton, NJ 07012
Email: support@kahal.app
Phone: (347) 907-1449
We will respond to all inquiries within 30 days. For privacy-related requests, please include "Privacy Request" in the subject line of your email.