HEMY logo
© 2025 Hemy Hebrew. All rights reserved.
TermsPrivacyHelpFind a teacherAbout
    Hemy Hebrew logoBack to Home

    Privacy Policy

    Last updated: August 8, 2026

    Hemy Hebrew operates an online platform for booking, managing and practising Hebrew lessons. We respect your privacy and are committed to protecting it.

    This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights and choices you have. If you do not agree with this policy, please stop using the service.

    On this page

    1. 1. Who We Are & How to Contact Us
    2. 2. Information We Collect
    3. 3. Legal Bases for Processing
    4. 4. Google Calendar & Meet
    5. 5. AI-Assisted Learning Features
    6. 6. Payments
    7. 7. Collaborative Whiteboard
    8. 8. Cookies & Similar Technologies
    9. 9. How We Use Your Information
    10. 10. Sharing & Service Providers
    11. 11. How Long We Keep Data
    12. 12. Security
    13. 13. Your Rights & Controls
    14. 14. Children
    15. 15. International Transfers
    16. 16. Changes to This Policy
    17. 17. Contact Us

    1. Who We Are & How to Contact Us

    Hemy Hebrew ("we", "our", "us") is the controller of the personal data described in this policy. We are the owner of the database under the Israeli Privacy Protection Law, 5741-1981, and act as a data controller under the GDPR where it applies to you.

    For any privacy question, request or complaint, contact us at: office@hemy-hebrew.com

    2. Information We Collect

    • Account data — your name, email address, phone number (optional), profile picture, role (student / teacher / admin), time zone and preferred language.
    • Learning profile & progress — your level, lesson history, assigned tasks, vocabulary and game progress, achievements, and text you submit in writing exercises.
    • Scheduling data — lesson bookings (date, time, duration, status), teacher availability, blocked times, and cancellation or rescheduling records.
    • Communications — messages exchanged between students and teachers in the in-app chat, and any support requests you send us by email or WhatsApp.
    • Payment data — purchase records, credit and AI-pack balances, and, if you save a card, a payment token together with the last four digits and expiry date. We never receive or store your full card number or CVV (see section 6).
    • Google Calendar data — only if you choose to connect your Google account (see section 4).
    • AI interaction data — the text you submit to AI-assisted features such as explanations, writing feedback, vocabulary practice and text-to-speech (see section 5).
    • Whiteboard session data — real-time strokes, shapes and annotations during a lesson, which are ephemeral unless a snapshot is explicitly saved (see section 7).
    • Notification data — your notification preferences and, if you enable push notifications, your browser push subscription.
    • Technical & security logs — device and browser type, approximate location derived from IP address, timestamps, error diagnostics, and authentication and access-control events.

    We do not intentionally collect special categories of data (such as health, biometric or political data). Please do not submit such information through lessons, chat or AI features.

    3. Legal Bases for Processing

    Where the GDPR or comparable law applies, we rely on the following legal bases:

    • Performance of a contract — providing lesson booking, credits, teaching and learning features.
    • Legitimate interests — improving the service, preventing fraud and abuse, and monitoring security.
    • Consent — connecting Google Calendar, enabling push notifications, and setting non-essential cookies. You may withdraw consent at any time.
    • Legal obligations — accounting, tax and other statutory retention duties.

    4. Google Calendar & Meet

    Connecting your Google account is entirely optional. If you connect it, we request only the minimal scope needed to create, update and delete the lesson events you schedule through Hemy Hebrew. We do not read, analyse or store unrelated events from your calendar.

    • Accessed — the event IDs and Google Meet links that we create for your lessons.
    • Stored — a Google refresh token, held on infrastructure that encrypts data at rest, plus the IDs and links of the events we created.
    • Not stored — the contents, titles or attendee lists of any other calendar event.
    • Revocation — disconnect inside the app at any time, or revoke access directly from your Google Account permissions page.

    Google Account permissions

    Limited Use compliance: our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, profiling, resale, or to train generalised AI models. Google API Services User Data Policy

    5. AI-Assisted Learning Features

    Where AI-assisted features are enabled — such as Hebrew text explanations, writing feedback and vocabulary practice — the text you submit is sent to Google's AI services for processing. Our text-to-speech feature sends the words or sentences you choose to hear to Google Cloud Text-to-Speech in order to generate the audio.

    • Sent — only the content you actively submit to the feature, plus the minimum context needed to generate a useful response.
    • Not sent — your payment details, contact details, or private chat messages you did not submit to the feature.
    • Stored by us — your prompts and the generated results may be stored so you can revisit your practice history and so we can track your progress and AI credit usage.
    • Not used for model training — we do not permit your content to be used to train generalised AI models.

    AI output can be inaccurate. It is a learning aid and should not be relied on as professional, legal or medical advice. Please avoid submitting sensitive personal information to AI features.

    6. Payments

    Payments are processed by our PCI-DSS compliant payment provider. Your card details are entered directly with the provider and are never transmitted through or stored on our servers.

    • We store — a payment token issued by the provider, the last four digits of the card, and its expiry date, so you can pay again without re-entering your details.
    • We never store — your full card number, CVV or PIN.
    • We also keep — purchase records, invoices, credit balances and transaction history, as required for accounting and tax purposes.

    You can remove a saved card at any time from your account settings, which deletes the stored token.

    7. Collaborative Whiteboard

    The optional whiteboard lets lesson participants draw and add text annotations in real time. Access is limited to the teacher and the enrolled student or students in that session.

    • Ephemeral by default — strokes, shapes and text exist only in real-time storage during the active session and are deleted when the session ends.
    • Optional snapshot — an image, together with the session ID and a timestamp, is stored only if a participant explicitly saves or exports it.
    • No file uploads — the whiteboard does not accept external file uploads or arbitrary media.
    • Not collected — audio, video, or keystrokes outside the board.
    • Deletion — when you delete your account we remove, or irreversibly anonymise, any saved snapshots linked to it.

    To have an earlier snapshot removed sooner, email us with the approximate lesson date. office@hemy-hebrew.com

    8. Cookies & Similar Technologies

    We use cookies and local storage to keep you signed in, to keep the platform secure, and — only with your consent — to understand usage and measure campaigns. When you first visit, a banner lets you accept all, accept only essential, or choose per category.

    • Essential — authentication and session management, security, fraud prevention and payment processing. These are always active because the service cannot function without them.
    • Analytics — aggregate usage measurement that helps us understand how the platform is used and improve it.
    • Marketing — measuring campaign conversions and optimising our advertising. These may track activity across sites.
    • Internal tools — local storage used for internal quality-assurance and administrative enhancements.

    Your choice is stored for 180 days and you can change it at any time from the cookie preferences banner. Blocking essential cookies in your browser will prevent you from signing in.

    9. How We Use Your Information

    • Operate lesson booking, scheduling, credits and calendar synchronisation.
    • Deliver AI-assisted learning features and track your progress.
    • Process payments, manage credit balances and issue invoices.
    • Send transactional messages such as confirmations, reminders, changes and cancellations.
    • Enable communication between students and teachers.
    • Maintain platform security, detect fraud and prevent abuse.
    • Improve reliability, performance and user experience.
    • Comply with our legal, accounting and tax obligations.

    We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.

    10. Sharing & Service Providers

    We do not sell your personal data. We share it only with service providers who process it on our behalf, under contracts requiring confidentiality and appropriate safeguards:

    • Supabase — authentication and managed PostgreSQL database hosting.
    • Vercel — application hosting, content delivery and aggregate usage analytics.
    • Google — Calendar and Meet integration, AI and text-to-speech services, and Firebase/Firestore, which stores your account’s Google Calendar connection.
    • Our payment provider — PCI-DSS compliant payment processing and card tokenisation.
    • Email and messaging providers — delivery of transactional email and support conversations.

    Your teacher sees the information needed to teach you: your name, level, lesson history, assigned tasks, progress and chat messages. We may also disclose data where required by law, or to protect the safety, rights or integrity of the service and its users. If the business is ever transferred, personal data may be transferred as part of that transaction, subject to this policy.

    11. How Long We Keep Data

    • Account, learning and scheduling records — kept while your account is active, and deleted within 30 days of a verified deletion request.
    • Google OAuth tokens — deleted immediately when you disconnect or delete your account.
    • Saved payment tokens — deleted when you remove the card or delete your account.
    • Chat messages — kept while the account is active, so both participants retain their lesson history.
    • Backups and logs — rotated and purged within 90 days, unless retained longer for an active security investigation.
    • Financial and transaction records — retained for up to seven years, as required by applicable tax and accounting law.

    12. Security

    • All traffic is encrypted in transit with HTTPS/TLS, and data is encrypted at rest by our infrastructure providers.
    • Access to data is restricted by role-based access control and server-side authorisation checks on every request.
    • Card details never reach our servers — we hold only tokens issued by the payment provider.
    • Service accounts follow the principle of least privilege.
    • Authentication and access events are recorded in our server logs.

    No system can be guaranteed completely secure. If a breach affects your personal data and poses a risk to your rights, we will notify you and the relevant authorities as required by law.

    13. Your Rights & Controls

    Subject to applicable law, you have the right to:

    • Access the personal data we hold about you, and receive a copy in a machine-readable format.
    • Correct inaccurate or incomplete data — most details can be edited directly in your account settings.
    • Restrict or object to certain processing, including processing based on our legitimate interests.
    • Withdraw consent at any time, without affecting processing carried out before withdrawal.
    • Revoke Google Calendar access from within the app or from your Google Account permissions page.
    • Lodge a complaint with your supervisory authority — in Israel, the Privacy Protection Authority; in the EEA or UK, your local data protection authority.

    Delete your account and associated data — see our Data Deletion Instructions.

    To exercise any of these rights, email us from the address associated with your account. We respond within 30 days and may ask you to verify your identity first.

    14. Children

    The service is not directed to children under 13, and we do not knowingly collect their data. Where a parent or legal guardian books lessons for a minor, that adult is responsible for providing consent and for supervising the minor's use of the platform. In the EEA, users under 16 require parental consent. If we learn that we have collected data from a child without the required consent, we will delete it promptly.

    15. International Transfers

    We operate from Israel, and our service providers may process data in the European Union, the United States and other countries. Where data is transferred out of the EEA or the UK, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses. Israel benefits from a European Commission adequacy decision.

    16. Changes to This Policy

    We may update this policy from time to time. We will indicate any change by updating the "Last updated" date above, and for material changes we will give you notice in the app or by email before they take effect. Continuing to use the service after a change takes effect constitutes acceptance of the updated policy.

    17. Contact Us

    For any question about this policy, to exercise your rights, or to raise a data protection concern, contact us at: office@hemy-hebrew.com

    Terms of Service

    © 2026 Hemy Hebrew. All rights reserved.