Privacy Policy
Last updated: July 9, 2026
Am-Echad ("we", "our", "the app") is a community safety network for Jewish communities. Anyone can create an account to receive real-time safety alerts; posting reports and other full-member features are unlocked with an invitation code. This Privacy Policy explains what we collect, how we use it, and the choices you have. We've designed the product with privacy first; most fields are optional, and the rest are kept only as long as they are needed to serve you.
What we collect
Account & identity
- Phone number: used once during sign-up to send a one-time verification code (via Twilio Verify). After you complete sign-up, we keep only an HMAC-SHA256 hash of the number on your account row — the plaintext phone is discarded.
- Nickname & region (optional): shown in comments, mentions, and chat headers. You may leave them blank, edit, or remove them at any time from the More tab.
- Device-bound public key: created during biometric set-up so we can verify future sign-ins. The private key never leaves your device's secure enclave.
Location
- Home location (when you enable location): stored as a single GPS point and a personal notification radius. Used only to fan out geofenced alerts to people near a reported incident — never shared with other members.
- Background location (only if you grant "Always" permission): amehad is a real-time safety app, so with your permission it updates your latest location in the background — even when the app is closed — so that alerts about a protest or danger can reach you before you walk into it while you are on the move. We keep only your single latest point (no location history or trail), use it solely to decide which nearby alerts to send you, and never share it with other members. You can decline background access and still use the app with foreground-only location, or turn location off entirely in your device settings at any time.
- Incident location: latitude/longitude of an incident you report. Visible to other members on the map.
Notifications
- Push token: an opaque Expo Push token used to deliver alerts to your device. Cleared automatically when you uninstall the app.
- Quiet hours (optional): the time window in which non-critical notifications are muted. Stored as two hours plus your IANA time zone — never the contents of any message.
Content you create
- Incident reports: title, description, category, severity, photos, and location. The description is encrypted at rest with AES-256-GCM. Photos you attach are uploaded to Cloudinary or Cloudflare R2.
- Comments & replies: body text and optional photos on incidents you participate in. Encrypted at rest, same scheme as descriptions.
- Direct messages: 1:1 chat messages between members. Encrypted at rest. Note: Am-Echad currently operates server-side encryption — the server can decrypt to relay and store. We do not currently use end-to-end encryption.
- Verifications & likes: an opaque token identifying you as the verifier or liker. We do not display who specifically verified or liked a report; we only show the count.
Contacts (Android & iOS)
When you tap "Pick from contacts" while inviting a friend, we read your address book on-device only to render the picker UI. The contacts list is never sent to our servers. Once you pick a contact, only the chosen phone number is sent to generate the invitation.
Camera & photos
Used only to attach photos to incident reports or comments when you choose to. Photos go directly from your device to our hosting provider (Cloudinary / R2) — we never see your full photo library.
Diagnostic data
We use Sentry to capture crash reports and unhandled errors so we can fix them. Sentry payloads are scrubbed of any message bodies, descriptions, and contact details.
What we do with it
- Verify your phone number at sign-up, and — for full members — validate the invitation code that unlocks posting.
- Deliver alerts and advisories that are relevant to your location and notification window.
- Show your reports, comments, and chats to the people you intend.
- Enforce our community rules — soft-deleting content that violates them, suspending accounts when needed.
- Operate, maintain, and improve the service.
Who we share it with
We do not sell your data. We share the minimum necessary with the following service providers, all bound by data-processing agreements:
- Twilio — sends the SMS verification code (receives the phone number for that one transaction).
- Expo Push (Anthropic-unrelated) — relays push messages to your device (receives the push token and notification body).
- Cloudinary & Cloudflare R2 — store photos you attach to reports or comments.
- Sentry — captures crash and error reports.
- Our CRM provider — if you choose to provide your name and email during sign-up and agree to be contacted, we send those details (with your phone number) to our customer relationship management (CRM) provider so we can reach you about your membership. This is optional, tied to the consent checkbox on the profile screen, and kept separate from your in-app activity — it is never shown to other members.
- Fly.io, Supabase, Upstash — host the API, Postgres database, and Redis. Data lives in their managed infrastructure under our account.
We also share data when legally required (court orders, valid subpoenas) or to protect the safety of our community members.
Retention
- Incident reports auto-delete after 180 days unless flagged for ongoing review.
- Plaintext phone numbers are wiped after biometric setup completes (typically within minutes of account creation).
- Push tokens are cleared automatically when the app is uninstalled or reinstalled.
- Direct messages and comments persist until you delete them or close your account.
Your rights
You can, at any time:
- Update or remove your nickname, region, or home location from the More tab.
- Delete any comment or chat message you authored. Soft-deleted rows display as "[deleted]" but the body is replaced with a tombstone marker so threads don't break.
- Disable notifications, quiet hours, or location sharing in your device settings.
- Request export or full deletion of your account and all associated content by emailing privacy@am-echad.app. We will respond within 30 days.
Security
- All traffic is over TLS 1.2 or higher.
- Sensitive content fields (incident descriptions, comment bodies, message bodies) are encrypted at rest with AES-256-GCM using a server-managed key.
- Phone numbers are stored as HMAC-SHA256 hashes after sign-up, not as plaintext.
- Passwordless auth: biometric sign-in uses a device-bound ECDSA P-256 keypair; the private key never leaves your device's secure enclave.
Children
Am-Echad is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has registered, contact privacy@am-echad.app and we will delete the account.
International transfers
Our backend operates from data centers in the United States (Fly.io, primarily IAD region). If you use Am-Echad from outside the US — including Israel — your data may be transferred to and processed in the US under standard contractual clauses with our providers.
Changes to this policy
We will update this page when our practices change and bump the "Last updated" date at the top. For material changes, we will also notify you in the app.
Contact
Questions, requests, or concerns? privacy@am-echad.app.