Privacy Policy — Qodesh
1. About This Policy
Your privacy is important to Qodesh.
This Privacy Policy explains how Qodesh collects, uses, stores, shares, protects, and deletes personal data related to the use of its platform, including its website, applications, community features, integrations, APIs, and connections made through the Model Context Protocol ("MCP").
Our goal is to present this information clearly and enable you to understand:
- what data may be processed;
- why such data is processed;
- which features use such data;
- when data may be shared;
- when information may be sent to external services;
- how long data may be retained;
- what rights you have;
- how to exercise those rights.
This Policy should be read together with the Qodesh Terms of Use.
Use of Qodesh does not, by itself, constitute general consent to any and all processing of personal data.
Personal data will be processed based on the applicable legal grounds for each specific purpose.
Where consent is required, it will be requested in an appropriate manner and may be withdrawn in accordance with applicable law.
2. Who Controls Your Data
For the purposes of Brazilian Federal Law No. 13,709/2018 — the Brazilian General Data Protection Law ("LGPD") — the controller of personal data processed by Qodesh is:
Lucas Calisto Gabriel
CPF: 169.981.617-43
General contact: lucas.gabriel@qodeshapp.com
Privacy-related contact: suporte@qodeshapp.com
3. Principles Governing Personal Data Processing
Qodesh seeks to process personal data in accordance with, among others, the following principles:
Purpose: use of data for legitimate, specific, and informed purposes.
Adequacy: use of data in a manner compatible with the context and stated purpose.
Necessity: processing only the data reasonably necessary for each purpose.
Transparency: providing clear information about our practices.
Free access: enabling individuals to obtain information regarding the processing of their data.
Data quality: adopting mechanisms intended to allow correction and updating where applicable.
Security and prevention: adopting measures intended to prevent unauthorized access, leaks, loss, or improper alteration.
Non-discrimination: personal data must not be used for unlawful or abusive discriminatory purposes.
Accountability: maintaining practices intended to demonstrate compliance with data protection rules.
4. What Data We May Process
The data we process depends on the features you actually use.
Qodesh does not necessarily collect all of the categories described below from every user.
4.1 Account and Registration Data
We may process information such as:
- name;
- email address;
- username or nickname;
- internal account identifiers;
- photograph or avatar, if provided;
- information voluntarily included in your profile;
- account preferences;
- authentication-related information;
- records related to account creation, modification, recovery, or closure.
Passwords must not be stored in plain text. Where applicable, appropriate cryptographic mechanisms will be used to protect credentials.
5. Data Related to the Use of Qodesh
When you use the Service, we may record information related to the activities necessary to provide its features.
This may include:
- texts or books accessed;
- chapters and verses viewed;
- reading progress;
- beginning and completion of readings;
- Trails accessed or created;
- progress within Trails;
- Journey and progress history;
- Favorites;
- Notes;
- comments;
- searches performed;
- Gematria calculations performed or saved;
- published content;
- community interactions;
- connections with other users;
- participation in Circles;
- Service-related preferences;
- date and time of certain activities.
This data may be used to operate features requested by the user, maintain their history, and improve their experience within the platform.
6. Notes, Favorites, and Other Private Content
Certain features allow users to store information intended primarily for their own use, such as:
- Notes;
- Favorites;
- certain Gematria calculations;
- private Trails;
- Memories;
- Journey records;
- other content identified by the interface as private.
Private content is not publicly displayed or deliberately made available to other users unless the user chooses to share it or another situation expressly described in this Policy applies.
The fact that content is classified as private does not mean that no technical processing takes place.
Qodesh may process such content when necessary to:
- store it;
- synchronize it;
- display it to the user;
- perform searches or associations requested by the user;
- create backups;
- prevent fraud or abuse;
- ensure security;
- resolve technical issues;
- comply with legal obligations;
- respond to a valid request from the data subject.
Human access to private content must be limited to what is necessary and authorized in accordance with applicable internal controls.
7. Memories
The Memories feature allows users to record events, dates, descriptions, reflections, or other personal content and associate them with elements of their study experience.
A Memory may contain:
- the date of an event;
- a description of the event;
- information about people related to the event;
- associations with Hebrew dates;
- associations with parashot;
- holidays;
- readings;
- texts;
- other calendar or library elements.
This data will be used to provide the feature requested by the user.
7.1 Third-Party Data Included in Memories
Users may occasionally write information concerning family members, friends, or other individuals.
We recommend including only information that is reasonably necessary and avoiding unnecessarily intimate or sensitive information about third parties.
When users decide to publish or share information relating to another person, they must respect that person's rights and privacy.
8. Potentially Sensitive Data
The LGPD provides special protection for certain categories of personal data, including information related to religious beliefs.
By its nature, certain activities performed within Qodesh may occasionally reveal or allow inferences regarding:
- religious beliefs;
- religious practices;
- affiliation with religious traditions;
- personal events;
- health;
- family life;
- other information of a sensitive nature.
The mere fact that an individual uses Qodesh does not mean that Qodesh attributes a particular religion or religious belief to that individual.
Whenever a processing activity involves sensitive personal data, Qodesh will observe the specific legal grounds applicable to such data.
Where consent is the appropriate legal basis, it must be requested in a specific and prominent manner for defined purposes.
Qodesh will not rely on legitimate interest as a general legal basis for processing sensitive personal data where such basis is not permitted by law.
9. Gematria
When you use Gematria tools, we may process:
- the word or expression searched;
- the characters used;
- the selected Gematria method;
- the calculated result;
- the date of the operation;
- information regarding whether the calculation was saved;
- information related to publication, where applicable.
A private calculation will remain subject to the rules applicable to private content.
If the user chooses to publish a Gematria calculation in the community, the information selected for publication may become visible to other users or, depending on the feature, to the general public.
10. Trails
When you create or use Trails, we may process:
- title;
- description;
- structure;
- related texts;
- references;
- progress;
- authorship information;
- privacy settings;
- sharing-related information.
Trails may have different levels of visibility depending on the options made available by the platform.
11. Journey and Study History
Qodesh may record study-related activities in order to provide features such as Journey, history, and progress tracking.
This may involve information such as:
- texts accessed;
- progress;
- reading percentage;
- completed readings;
- sequence of activities;
- date and time;
- relationships between different activities.
This information may be used to show users their own progress and improve progress-tracking mechanisms.
We do not automatically interpret activity levels as indicators of religiosity, spiritual merit, religious observance, or any equivalent personal characteristic.
12. Circles, Connections, and Social Features
When you use social features, we may process information such as:
- connected users;
- connection requests;
- accepted connections;
- removed connections;
- participation in Circles;
- community interactions;
- publications;
- profile information visible to other users.
The information displayed to other participants will depend on the applicable features and settings.
Qodesh will seek to provide appropriate privacy, connection, disconnection, and blocking controls according to the nature of each feature.
13. Private, Shared, and Public Content
Qodesh may use different levels of visibility.
Private
Content intended only for the user's account, without deliberate display to other users.
Shared
Content made available only to specific people, connections, groups, or Circles, depending on the feature used.
Public
Content that the user has chosen to make available to a public or community audience.
Before publishing personal or sensitive information, we recommend carefully considering the content that will be disclosed.
Information published publicly may:
- be viewed by third parties;
- be copied;
- be recorded by external mechanisms;
- be shared outside Qodesh;
- remain in caches or third-party copies even after it has been removed from the platform.
Qodesh cannot control copies lawfully or unlawfully created by third parties after information has been made public.
14. Technical Information and Logs
When you access Qodesh, certain technical data may be processed automatically.
Such data may include:
- IP address;
- date and time;
- browser;
- operating system;
- device type;
- application version;
- pages or resources accessed;
- session identifiers;
- authentication events;
- approximate origin of the request;
- error logs;
- security logs;
- diagnostic information.
These records may be used for:
- operation of the Service;
- identification of errors;
- fraud prevention;
- incident investigation;
- security;
- account protection;
- compliance with legal obligations;
- technical analysis of product performance.
15. Cookies and Similar Technologies
Qodesh may use cookies, local storage, or similar technologies.
These technologies may serve different purposes.
Strictly Necessary Cookies
They may be used for functions such as:
- authentication;
- session maintenance;
- security;
- abuse prevention;
- essential preferences.
Certain features may not function properly if these mechanisms are blocked.
Preference Cookies
These may be used to remember certain choices made by the user.
Analytics
If analytics tools are used, they may record information intended to help understand how the Service is used and identify issues or opportunities for improvement.
Qodesh will observe the appropriate legal basis and, where necessary, request consent before using optional cookies or technologies.
Where available, users may manage non-essential cookies through tools provided by the platform.
16. How We Use Personal Data
We may use personal data for the following purposes:
- To create and maintain your account using information such as your name, email address, nickname, and authentication data.
- To authenticate users and maintain account security, including protected credentials, sessions, and authentication events.
- To provide Qodesh features such as Favorites, Notes, Memories, Journey, and Trails using the data necessary to operate those features.
- To enable community interactions using profile information, publications, and other data related to interactions carried out by the user.
- To maintain platform security and prevent fraud or abuse using information such as IP addresses, logs, sessions, and security events.
- To improve the product using usage data and telemetry, where applicable.
- To provide support using identification data, messages, and information related to the issue reported.
- To send operational communications, such as messages related to the account, security, features, or operation of the Service.
- To send promotional communications where permitted by law and in accordance with applicable preferences or consent.
- To comply with legal or regulatory obligations and respond to requests from competent authorities where required.
- To exercise or defend rights using only the information necessary for each situation.
- To operate integrations and MCP features using identifiers, permissions, and the data necessary to execute requests made by the user.
The legal basis used will depend on the purpose and nature of the processing and may include performance of a contract or service, legitimate interest, consent, compliance with a legal obligation, the regular exercise of rights and, where sensitive personal data is involved, the legal grounds provided for under Article 11 of the LGPD.
17. Integration with Artificial Intelligence and MCP
Qodesh may allow users to connect their accounts to artificial intelligence assistants, applications, or other external systems through OAuth, MCP, APIs, or equivalent technologies.
This feature requires special attention because it may allow another system to access information or perform certain actions within the user's account.
18. What Happens When You Connect an AI to Qodesh
When you authorize an integration, certain technical data may be processed, including:
- identification of the connected application or service;
- account identification;
- permissions granted;
- access scopes;
- tokens or other authorization mechanisms;
- authorization date;
- revocation date;
- access records;
- calls made through the integration;
- parameters submitted;
- responses produced by Qodesh.
Qodesh must limit integration access to the permissions actually granted.
19. Scopes and Permissions
Whenever technically supported, integrations must operate according to the principle of least privilege.
This means that an integration should receive only the permissions necessary for the authorized feature.
For example, an authorization may allow an integration to:
- view Favorites;
- add Favorites;
- view Notes;
- create or edit Notes;
- view Memories;
- create or edit Memories;
- view Gematria calculations;
- publish content;
- view connections;
- create Trails.
Authorization for one particular feature must not automatically be interpreted as unrestricted authorization for all other account features.
20. Data Sent to an External Artificial Intelligence Service
When a user authorizes an artificial intelligence service or another external service to access Qodesh, information requested by that system may be transmitted in response to the integration.
This may include private content where:
- the integration is authorized to access that content; and
- the request is within the authorized scope.
Depending on the content requested, the information transmitted may constitute personal or sensitive data.
Qodesh will seek to adequately inform users of this risk before they authorize integrations capable of accessing private content.
21. Qodesh Does Not Necessarily Receive Your Entire Conversation With an AI
An MCP integration does not necessarily mean that Qodesh has access to the complete conversation between the user and the artificial intelligence provider.
Ordinarily, Qodesh receives only the information submitted by the AI client to the Qodesh server in order to execute a particular tool or request.
Depending on the implementation of the external client, such information may include:
- command;
- question;
- parameters;
- content necessary to execute the request;
- technical identifiers.
The exact operation of an external application depends on the respective provider.
22. Responsibility of Connected AI Services
When you voluntarily connect an independent service to Qodesh, that service may process information it receives according to its own terms and privacy policy.
Depending on the legal relationship and processing activity involved, the provider may act as a processor, independent controller, or in another capacity recognized under applicable law.
Before authorizing an integration, we recommend reviewing:
- who operates the service;
- which permissions are being requested;
- how the service uses data;
- whether data may be used to train models;
- how long data is retained;
- how deletion may be requested.
23. Revocation of Integrations
Users may revoke integrations through mechanisms made available by Qodesh.
Following revocation, Qodesh must prevent new authenticated requests using the revoked authorization, subject to technical events necessary to safely complete the revocation process.
Revocation within Qodesh does not automatically delete information previously transferred to an external service.
The external service's processing of such information will be governed by that provider's rules and applicable law.
24. Artificial Intelligence and Model Training
Policy adopted by Qodesh:
Qodesh does not sell users' private content for the purpose of training artificial intelligence models.
Qodesh will not deliberately use private Memories, private Notes, or other identifiable private content to train general-purpose artificial intelligence models without the user's specific, clear, and prominent authorization.
Aggregated or effectively anonymized data may be used for analysis, statistics, security, and Service improvement where such data cannot reasonably identify the data subject.
This rule concerns use performed by Qodesh itself.
If the user voluntarily sends information to an external artificial intelligence service through an integration, the processing performed by that external provider will be subject to the policies of that service.
25. Automated Decisions and Personalization
Qodesh may use automated mechanisms for functions such as:
- recommending content;
- relating texts;
- calculating progress;
- converting dates;
- relating events to calendars;
- organizing results;
- identifying relevant content;
- detecting abuse or security anomalies.
Automated results may contain errors.
Where a decision is made solely on the basis of automated processing of personal data and produces relevant effects on the interests of the data subject in circumstances covered by applicable law, the data subject may exercise the applicable rights, including requesting information regarding the criteria and procedures used and, where applicable, requesting review.
26. Data Sharing
Qodesh does not sell personal data.
Data may be shared only where necessary for the purposes described in this Policy.
This may occur with the following categories of recipients:
Infrastructure and Hosting
Providers used for servers, databases, storage, content distribution, and infrastructure.
Authentication and Security
Providers used for authentication, fraud protection, monitoring, or security.
Email and Communications
Providers used to send operational messages or other authorized communications.
Monitoring and Observability
Tools used to detect errors, downtime, performance issues, or incidents.
Analytics
Providers used to understand how the platform is used, where applicable.
Artificial Intelligence Services or Applications Chosen by the User
Where the user connects an external service and authorizes the sharing of information.
Public Authorities
Where required by law, court order, or a legally valid government request.
Professional Advisors
Lawyers, auditors, or other professionals where necessary for the defense of rights, compliance, or legitimate operations.
27. Register of Service Providers and Subprocessors
To increase transparency, Qodesh must maintain an up-to-date list of the main service providers that process personal data on behalf of or in connection with the platform.
Where applicable, this list should identify:
- provider name;
- purpose;
- service category;
- categories of data involved;
- countries in which data may be processed;
- provider's role;
- mechanism used for international data transfers, where applicable.
Current list:
Neon: https://neon.com/
Google Cloud: https://cloud.google.com/
28. International Data Transfers
Some service providers used by Qodesh may maintain infrastructure in other countries.
As a result, personal data may be transferred to or processed outside Brazil.
Such transfers will not be performed solely on the basis that the user has generically "accepted" this Policy.
Where an international data transfer is subject to the LGPD, Qodesh will adopt an appropriate legal basis and one of the mechanisms recognized under applicable law and regulations.
Depending on the circumstances, these mechanisms may include:
- adequacy decisions;
- standard contractual clauses approved by the Brazilian National Data Protection Authority (ANPD);
- recognized equivalent clauses;
- approved binding corporate rules;
- specifically approved contractual clauses;
- other mechanisms permitted under the LGPD.
Qodesh will seek to limit international transfers to the minimum necessary to achieve their intended purpose.
More detailed information about providers, countries, and transfer mechanisms may be made available in Qodesh's public list of service providers.
29. Data Retention
Personal data will not be retained indefinitely without a legitimate purpose.
The retention period may vary depending on:
- the nature of the data;
- the feature used;
- the duration of the account;
- user expectations;
- security requirements;
- legal obligations;
- the need to defend rights;
- fraud prevention;
- applicable limitation periods.
In general:
Account Data
May be retained while the account remains active and subsequently for the period necessary to comply with legal obligations or exercise rights.
Private Content
May be retained for as long as necessary to provide the relevant feature or until deleted by the user, subject to legally permitted retention and temporary backup copies.
Public Content
May remain available for as long as it is published.
Following removal, certain information may remain temporarily in backups or technical logs, or where a legal basis exists for its retention.
Integration Tokens
Will be retained for the period necessary to maintain the authorization and must cease to permit new access after revocation.
Security Logs
May be retained for the period necessary for security, investigation, compliance with legal obligations, and the exercise of rights.
Support and Privacy Requests
May be retained to document the handling of requests and compliance with obligations.
Qodesh must internally maintain a retention schedule defining the periods applicable to the main categories of data.
30. Account Deletion
When a user requests account deletion, Qodesh will initiate procedures intended to delete or anonymize associated data, except where retention is permitted or required by law.
Such circumstances may include:
- compliance with a legal obligation;
- regular exercise of rights;
- prevention and investigation of fraud;
- security;
- compliance with a court order;
- other situations provided for by law.
Previously published public content may require specific treatment.
Where there is a legitimate justification for retaining such content, Qodesh will assess measures such as dissociation, anonymization, or limited preservation, depending on the nature of the content and applicable law.
Data may also temporarily remain in backups until the normal backup replacement cycle is completed.
31. Security
Qodesh adopts technical and organizational measures intended to protect personal data against:
- unauthorized access;
- loss;
- destruction;
- improper alteration;
- unauthorized disclosure;
- inappropriate use.
Depending on the nature of the system and the risks involved, these measures may include:
- access controls;
- segregation of permissions;
- credential protection;
- appropriate encryption;
- security logs;
- backups;
- monitoring;
- system updates;
- privilege limitation;
- provider reviews;
- authentication mechanisms;
- incident response procedures.
No system connected to the internet can guarantee zero risk.
This does not reduce Qodesh's responsibility to adopt appropriate security and preventive measures as required by law.
32. Security Incidents
If an incident involving personal data occurs, Qodesh will assess:
- the nature of the incident;
- the data involved;
- affected data subjects;
- potential misuse;
- potential consequences;
- relevant risk or harm;
- available mitigation measures.
Where required by applicable law or regulation, Qodesh will notify the Brazilian National Data Protection Authority (ANPD) and affected data subjects within the applicable time limits.
Qodesh may also adopt measures such as:
- blocking access;
- revoking credentials;
- resetting sessions;
- correcting vulnerabilities;
- conducting technical investigations;
- preserving evidence;
- issuing preventive notifications.
33. Data Subject Rights
Under applicable law, you may have rights relating to your personal data.
These may include:
- confirmation of whether processing exists;
- access to personal data;
- correction of incomplete, inaccurate, or outdated data;
- anonymization of unnecessary or excessive data;
- blocking of unnecessary, excessive, or unlawfully processed data;
- deletion where provided by law;
- data portability, subject to applicable regulation;
- information regarding entities with which data has been shared;
- information regarding the possibility of refusing consent and the consequences of doing so;
- withdrawal of consent;
- deletion of data processed on the basis of consent, where applicable;
- objection to processing carried out in violation of the LGPD;
- rights relating to automated decisions in circumstances provided by law.
You may also file a complaint or petition with the ANPD and other competent authorities in accordance with applicable law.
34. How to Exercise Your Rights
Requests may be submitted to:
suporte@qodeshapp.com
To protect your account, we may request information reasonably necessary to confirm your identity before responding to certain requests.
We will not request more information than necessary for such verification.
The legitimate exercise of privacy rights will be provided free of charge where required by applicable law.
35. Children and Adolescents
Qodesh is intended exclusively for individuals who are 18 years of age or older.
Account creation and use of authenticated Qodesh features are permitted only for users who meet this age requirement.
During the registration process, Qodesh may require users to confirm that they are 18 years of age or older and may adopt additional age assurance or age-signaling mechanisms where necessary or appropriate, taking into account applicable law, guidance from competent authorities, risks associated with the Service, and available technologies.
Whenever possible, Qodesh will seek to apply the principle of data minimization by using mechanisms capable of confirming compliance with the age requirement without collecting additional personal information beyond what is necessary for that purpose.
The declaration of legal age made during registration may be recorded for the purposes of documenting the account creation process, security, and compliance.
Qodesh may prevent account creation, restrict access, suspend, or terminate an account if it identifies or has reasonable grounds to conclude that the account holder is under 18 years of age, subject to applicable law.
If Qodesh becomes aware that personal data relating to a child or adolescent has been processed as a result of the unauthorized creation or use of an account, it may take appropriate measures to restrict access and delete or limit the processing of such data, except where retention is necessary or permitted by law, including for security, fraud prevention, compliance with legal obligations, or the regular exercise of rights.
Any data processed exclusively for age assurance purposes will not be used for purposes incompatible with that objective.
Establishing a minimum age of 18 does not exclude any legal obligations that may apply to Qodesh if the Service is considered, under applicable law, to be directed at or likely to be accessed by children or adolescents. In such circumstances, Qodesh will adopt any additional measures required by law and by competent authorities.
36. Information About Third Parties Provided by Users
You may enter information relating to other individuals into Qodesh, particularly in Notes, Memories, Trails, comments, or community content.
When doing so, we recommend considering:
- whether the information truly needs to be included;
- whether it should remain private;
- whether disclosure could harm the person concerned;
- whether it involves sensitive information;
- whether you have a legitimate basis for sharing it.
Qodesh may remove or restrict content where necessary to protect third-party rights or comply with applicable law.
37. Anonymized Data and Statistics
Qodesh may generate statistics and aggregated information for purposes such as:
- understanding general usage patterns;
- evaluating performance;
- planning new features;
- identifying issues;
- conducting internal analysis.
Where information is effectively anonymized so that it cannot reasonably be associated with a natural person, it will cease to be treated as personal data within the limits established by applicable law.
Pseudonymization and anonymization are different concepts.
Data that is merely pseudonymized may continue to constitute personal data.
38. Sale or Commercialization of Personal Data
Qodesh does not sell databases containing users' personal data.
Qodesh does not commercialize Memories, private Notes, reading history, or individual religious information for advertisers.
If the business model changes in a way that creates a new and relevant purpose for personal data processing, this Policy must be updated and the necessary legal mechanisms must be implemented before the new purpose is introduced.
39. Advertising
Qodesh must not use sensitive personal data for behavioral advertising.
If advertising features are introduced in the future, they must undergo a specific privacy and transparency assessment before implementation.
Children and adolescents will be subject to the additional protections established by applicable law.
40. External Links and Services
Qodesh may contain links to external websites, libraries, or services.
Once you leave an environment controlled by Qodesh, data processing carried out by the external service will be subject to that third party's own practices.
This Policy does not automatically apply to third-party services.
41. Change of Corporate Control
If Qodesh becomes involved in a corporate transaction, reorganization, investment, acquisition, merger, or transfer of assets, personal data may form part of the assets or operations involved.
In such cases, processing will remain subject to applicable law, and appropriate measures will be adopted to preserve data subject rights.
Material changes to the identity of the controller or to the purposes of processing will be communicated where required.
42. Government and Judicial Requests
Qodesh may disclose personal data where required by:
- law;
- court order;
- a competent authority;
- another legally valid obligation.
Whenever legally permitted and appropriate, Qodesh will seek to limit disclosure to the data strictly necessary to comply with the valid request.
43. Changes to This Policy
This Policy may be updated to reflect:
- changes in legislation;
- new features;
- infrastructure changes;
- new service providers;
- new integrations;
- significant changes in how data is processed.
The update date will be indicated at the beginning of the document.
Material changes may be communicated via Qodesh, by email, or through another appropriate channel.
When a new purpose legally requires consent, simply continuing to use the platform will not serve as a substitute for obtaining new, valid consent.
44. Contact
For questions regarding privacy, data protection, or the exercise of rights:
suporte@qodeshapp.com
Qodesh — The text at the center, the sources all around.