Privacy policy

What I do with your stuff.

last updated: july 13, 2026.

the short version

Yaniv is a free iOS app, not an ad business. Every feature is free. I don't sell your data. I don't track you across the internet. There are no advertising SDKs and no ad networks in this app. I do use one analytics tool (mixpanel) to see where people get stuck, and it never receives your name, your email, or the names on your memorial dates. You can switch it off inside the app. If you choose to send an optional "chai" (a support purchase), apple processes the payment and I never see your card.

The longer version is below, so a lawyer and an apple reviewer can both read the same words.

who i am

"yaniv," "i," and "the app" mean the yaniv iOS application and its publisher, emberlabs. you can reach me at hi@hiyaniv.app.

what you tell me directly

during onboarding and inside the app, you may share:

  • Your name (or a nickname, whatever you typed)
  • Your gender, Jewish background, relationship to Judaism
  • Your commitment level and your goals
  • Your birthdate (optional, for your Hebrew birthday)
  • Names + dates for people whose yahrzeit you want to remember (This one stays on your phone)

Everything in the first group lives in a row in my supabase database tied to your user id. You can delete it at any time from inside the app (settings · profile · delete account).

what your device shares with me

Yaniv accounts run on sign in with apple. Finishing setup means signing in, and that's what lets your profile come back if you change phones. Apple sends me a stable, app-specific user identifier and (if you allow it) your name and email address. If you used the "hide my email" option, what I actually store is the apple relay address, not your real one.

if you turn on calendar sync, the app asks for write-only access and adds the dates you picked to a separate calendar named "yaniv" on your phone. write-only means it structurally cannot read your existing events. the one exception: if you later remove synced events from inside the app, iOS requires full calendar access just to find and delete the entries yaniv itself created. calendar events live on your device and are never sent to my servers.

If you grant location access, your device sends your coordinates to Hebcal so the app can compute the right candle-lighting time for where you are. I don't store or log those coordinates on my servers. They live in memory long enough to do the lookup and then they're gone.

If you choose to send a chai (an optional support purchase that unlocks nothing), the payment is processed by apple. RevenueCat, the purchase processor I use, records the transaction under your yaniv account's random id, so your support history belongs to your account rather than to one phone. They never get your name or email, and I never receive your apple id, card number, or any other payment details. Deleting your yaniv account also deletes revenuecat's customer record.

what stays on your phone

These never leave your device. Ever.

  • Your yahrzeit list
  • Your streak history and which actions you took on which day
  • Your saved home location and the calendar events yaniv wrote

if you delete the app, this local data is gone with it. what comes back when you sign in on a new phone is your profile: your name, background, goals, birthdate, and reminder choices. what doesn't come back is everything in the list above, plus anything that's a device permission (location, notifications, calendar access), which iOS makes you grant fresh on every phone.

the third parties i use, and why

  • Supabase hosts the database that holds your profile row and serves my hand-written daily-word and parasha content.
  • RevenueCat processes the optional "send a chai" support purchases on top of apple's storekit. they see your yaniv account's random id and the purchase history attached to it, never your name or email. if you never send a chai, they hold essentially nothing about you, and when you delete your account their customer record is deleted with it.
  • Applehandles sign-in, payments, and the apple push notification service for local reminders. Apple's privacy policy governs that side.
  • Hebcalreturns Hebrew dates, candle-lighting times, and holidays. I pass location coordinates; I don't pass anything that identifies you.
  • Sefariareturns the canonical Hebrew and English of Jewish texts. I pass a reference like "exodus 13.1-10"; I don't pass anything that identifies you.

I don't use google analytics, facebook pixel, segment, amplitude, posthog, branch, adjust, appsflyer, or any advertising SDK. There are no third-party cookies, no ad networks and no beacons in this app. The one analytics tool I do use is mixpanel, described under diagnostics below.

diagnostics

Two tools, one switch. Both are off the moment you turn the diagnostics toggle off inside the app (profile · diagnostics), and neither one ever receives your name, your email, your birthdate, or the names on your memorial dates.

Sentry is anonymous crash reporting, so i can fix what breaks before it ruins your morning. crashes only: no user id, no breadcrumbs, no performance tracking.

Mixpaneltells me how the app is actually used: how many people finish setting it up, where they give up, which screens get opened. it is anonymous by design. i never call mixpanel's identify function, i never build a profile of you there, and your account id is never sent. i also switch off mixpanel's location lookup, so your events are not tagged with a city or country derived from your IP address.

Mixpanel also records a sample of app sessions (about one in ten) So I can watch where a screen confuses people. Recordings mask text and images by default, and the screens where you type your name, choose your birthdate, manage your memorial dates, or delete your account are not recorded at all. This rides the same diagnostics switch as everything else.

your rights

you can ask me at any time to (a) see a copy of what i have on you, (b) correct it, (c) delete it entirely. the in-app delete flow handles (c) on its own. for (a) and (b), email hi@hiyaniv.app and i'll respond within 30 days.

If you're in the EU / UK, you have additional rights under GDPR (lawful basis, right to portability, right to object). I lean on legitimate interest for app functionality and contract where it applies (e.g. optional purchases). You can lodge a complaint with your local data protection authority if you're unhappy with how I handled something.

If you're in california, you have rights under the CCPA. I Don't sell or share personal information.

children

Yaniv is rated 4+ on the app store. I don't knowingly collect data from anyone under 13. If you're a parent and you think your kid signed up, email me and i'll wipe their record.

how long i keep things

account data: until you delete the account or stop using the app for 24 consecutive months, whichever comes first. backups: rolling 30-day retention on the supabase side.

one honest caveat: if you ever sent a chai, apple keeps its own record of that sale under apple's policies, like any app store purchase. that record isn't mine and deleting your yaniv account can't erase it. revenuecat's copy, on the other hand, is mine to clean up, and account deletion deletes it.

changes

If I materially change what I collect or who I share it with, I'll update this page and the "last updated" date at the top. If the change is significant, i'll also surface a notice in the app the next time you open it.

← back to hiyaniv.app