rebbe.dev Privacy policy
Back to rebbe.dev

Privacy at rebbe.dev

A clear account of your information.

Jewish questions can be personal. This policy explains what rebbe.dev processes, why it is used, who helps process it, and what choices you have.

Effective and last updated

Share thoughtfully.

Do not include identifying details, account numbers, or sensitive facts about yourself or another person unless they are necessary to your question. AI services are not a confidential relationship like one with your lawyer, doctor, therapist, or rabbi.

01

Scope and operator

This policy applies to the rebbe.dev website, conversational application, weekly d'var Torah, sponsorship flow, and related administration. In this policy, “rebbe.dev,” “we,” and “us” refer to the operator of this service.

This policy does not govern websites or services operated independently by our providers. Their own notices apply when they process information for their services.

02

Information we process

We process information you give us, information created while the service operates, and limited information supplied by service providers.

Account and profile

WorkOS user ID, email address, first and last name, account role, credit balance, Jewish background or denomination, and the optional free-text context you save in your profile. rebbe.dev does not receive your WorkOS password.

Questions and responses

Your questions, recent conversation history, assistant responses, conversation titles, source references, feedback, and timestamps. What you write may reveal religious beliefs, health information, emotional circumstances, relationships, or other sensitive information.

Response and safety context

The system may infer question type, emotional tone, vulnerability, crisis indicators, need for human referral, cited sources, token use, and performance data. These signals help shape and operate the response. They are not medical diagnoses and are not guaranteed to receive real-time human review.

Transactions and dedications

Stripe customer and payment-intent identifiers, purchase amount, package or sponsorship tier, credits, status, and timestamps. A sponsorship also includes its dedication text, dedication type, parsha, and Hebrew year.

Usage, device, and security

A browser-generated session identifier, event type and event data, page path, referrer, user agent, IP address, request timing, guest-use count, rate-limit and abuse signals, and a shortened fingerprint derived from request headers.

Operations records

Text-to-speech event status and text length, error messages and stack traces, up to 500 characters of a failed question in some error records, admin actions, and other records needed to troubleshoot and protect the service.

03

How we use information

  • Authenticate you, maintain your account, restore conversation history, and manage credits.
  • Generate source-aware responses, apply your optional profile context, and maintain a multi-turn conversation.
  • Identify safety or human-referral signals and support authorized review. The service does not promise continuous monitoring or emergency response.
  • Process purchases and sponsorships, prevent duplicate fulfillment, and keep accounting records.
  • Publish completed sponsorship dedication text with the relevant weekly d'var Torah.
  • Provide optional audio playback, receive message feedback, troubleshoot failures, measure service use, and improve reliability.
  • Prevent fraud, enforce limits, secure the service, comply with law, and protect users, the public, and rebbe.dev.

04

AI and text-to-speech processing

To answer a question, rebbe.dev sends the current message and may send recent conversation history, optional denomination and profile context, retrieved source excerpts, and system-created pastoral, halachic, ethical, or safety context through a configured AI gateway. The current software supports Vercel AI Gateway or OpenRouter, which routes requests to a selected model provider.

Different model providers may have different logging, retention, review, and model-training practices. The provider can change with service configuration. Review the applicable gateway and model provider terms before including information you would not want an external AI provider to process.

If you choose Speak, the assistant response text is sent to ElevenLabs to create audio. rebbe.dev does not record your voice or use your microphone for this feature.

05

How information is disclosed

We disclose information only for the purposes described here:

  • Authentication: WorkOS provides sign-in and identity services.
  • AI response processing: a configured gateway, such as Vercel AI Gateway or OpenRouter, and the downstream model provider process question and context data.
  • Audio: ElevenLabs processes assistant text only when you request speech.
  • Payments: Stripe processes payment details and receives customer, transaction, and purchase metadata. Stripe-hosted fields keep full card numbers outside the rebbe.dev server.
  • Hosting and storage: Vercel and configured database or infrastructure providers process application, network, and stored data needed to run the service.
  • Authorized administrators: admins may review users, conversations, feedback, inferred safety signals, errors, purchases, sponsorships, analytics, and audit records for operations, moderation, and safety.
  • Legal and safety needs: information may be disclosed when reasonably necessary to comply with law, respond to valid legal process, investigate abuse or fraud, or protect rights and safety.

Public dedications

When a sponsorship is completed, its dedication text and type are displayed publicly with the relevant d'var Torah. Do not name someone or reveal health or other sensitive information without their permission.

The current application code has no advertising-network or data-broker integration. The service-provider disclosures described above are used to operate the product.

06

Cookies and browser storage

Item Purpose Typical duration
session Keeps a signed-in session and contains basic identity fields. It is signed and HttpOnly, but its payload is not encrypted. 24 hours
OAuth state and popup cookies Protect the sign-in return flow and restore the correct window. 10 minutes
guest_chats_used Enforces the guest-use allowance. 30 days
Session storage Holds an analytics session ID, page-session flag, a draft during sign-in, and a dismissed calendar notice. Usually until the browser tab or session closes
rebbe-theme Remembers system, light, or dark appearance on this browser. Until you change or clear it

The conversational application sends first-party analytics when it loads and records session, path, referrer, device, and event data. The current product does not provide an in-app analytics opt-out. Browser controls can clear or block storage, but doing so may sign you out, remove a draft or preference, or affect guest limits.

07

Retention and deletion

Stored account, conversation, profile, feedback, analytics, text-to-speech, error, payment, sponsorship, and admin records do not currently have an automatic expiration schedule in the application. We retain them while reasonably needed to provide and secure the service, keep transaction and audit records, resolve disputes, meet legal obligations, and maintain legitimate operational records.

You can delete an individual conversation in the application. That removes the conversation, its messages, and associated message feedback from the active database. It may not remove separate error excerpts, text-to-speech or analytics records, payment records, admin logs, provider logs, or backups. Those records can remain for operational, security, accounting, legal, or provider-retention reasons.

Guest abuse-prevention state is designed to clear after roughly 24 hours of inactivity when cleanup runs. Cookie and browser-storage durations are listed above. Provider and hosting logs follow their own schedules.

08

Security

rebbe.dev uses measures such as HTTPS in production, signed HttpOnly and SameSite session cookies, OAuth state checks, rate and request-size limits, role-protected admin routes, ownership-scoped conversation reads and deletes, Stripe webhook signature verification, and TLS-required hosted database connections.

No internet service or storage method is perfectly secure. The session cookie is signed to detect tampering but contains readable identity fields if someone gains access to the cookie value. Do not use rebbe.dev for secrets or emergencies.

09

Your choices and privacy rights

  • Leave optional denomination and profile context blank, or edit them in Settings.
  • Delete individual conversations from your signed-in history.
  • Do not use Speak if you do not want assistant text sent to ElevenLabs.
  • Do not sponsor a d'var Torah if you do not want dedication text made public.
  • Clear cookies, local storage, or session storage through your browser, understanding that some features may reset.

Depending on where you live, you may have rights to ask for access, correction, deletion, or a portable copy of personal information, or to object to or restrict certain processing. You may also have a right to appeal a denied request or contact your local privacy regulator. We may need to verify your identity and may retain information where an exception applies.

The current product does not provide self-service account-wide export or deletion. Send a request using the contact information below. We will not discriminate against you for exercising a privacy right that applies to you.

10

Children

rebbe.dev is intended for adults and is not directed to children under 13. We do not knowingly solicit personal information from children under 13. If you believe a child has provided personal information, contact us so the situation can be reviewed and appropriate action taken.

11

International processing

Service providers may process information in the United States and other countries, as described in their notices. Privacy protections and government-access rules can differ from those where you live.

12

Changes to this policy

We may update this policy when the product, providers, or legal requirements change. The effective date at the top will be revised. If a change materially affects how existing personal information is used, we will provide additional notice when required.

13

Contact

The current application does not publish a dedicated privacy-request address. Until one is designated, use the project’s security-reporting channel below to request private contact. Do not put personal information in a public GitHub issue.

Private contact Open a private GitHub report