Draft — pending legal review
Privacy
Last updated 13 August 2026
This document has not been reviewed by a lawyer.
It was written to describe accurately what the software actually does, so that a lawyer has something true to work from. The places where it is incomplete are marked in the text rather than papered over. Until it is reviewed and signed, treat it as a description of the product, not as a contract.
Shuli is software a shul uses to run its own community — minyan times, announcements, chat, shiurim, giving and sponsorships. Almost everything in it belongs to a particular shul, and that shul decides who is in it. This page describes what is collected, who can see it, and the few places where something can reach the open internet.
Your shul and Shuli
Two different organisations hold your information, and they hold it for different reasons.
- Your shul decides who is a member, what is posted, who its admins are, and what it does with its own records. Its admins can see the member information described below for their own shul.
- Shuli runs the software and the servers underneath it. It does not sell your information, and it does not use it to advertise to you.
Each shul is isolated from every other shul in the database itself, not just in the app — see Security & tenancy for how.
TODO(eli): Counsel to confirm the controller / processor split between a shul and Shuli under GDPR and UK GDPR, whether a data processing agreement needs to be offered to shuls, and whether Shuli is a “service provider” for CCPA purposes. This page currently describes the intended shape and asserts no legal characterisation.
What Shuli collects
Your account. The email address (or phone number) you sign in with, and a password if you choose to set one. Sign-in codes sent by email are single-use.
Your profile. Your name and, if you upload one, a photo. Nothing else lives here — and that is deliberate, because this is the one record every member of your shul can read.
Your details, if you fill them in. A phone number and contact email; birthday and anniversary (English and Hebrew dates); a short line about yourself; whether you host Shabbos meals; and, optionally, whether you are male or female — never required, and used only so the women’s side of the shul can be addressed directly. These are visible to you and to your shul’s staff, and to nobody else, unless you switch on the shul directory yourself.
Shuli does not ask you for a home address. There is no address field for a member anywhere in the product. A shul’s office can upload its own contact list — which may include addresses it already had — and that stays a staff record inside that shul.
What you post and do. Chat messages, replies, reactions and voice notes; announcements and simcha submissions; poll votes; RSVPs and signup-sheet claims; kiddush and sponsorship requests; yahrzeits you record; and private messages to your Rav or Rebbetzin.
Giving and buying. Donations, pledges, sponsorships, seat orders and event tickets — the amount, the date, the dedication you wrote, which campaign it was for, and the Stripe reference that ties it to the payment. Your shul’s staff can see your giving history for that shul.
Notification plumbing. A push token for each device or browser you allow notifications on, and your per-shul notification preferences.
What staff write about you. Your shul’s admins can keep private notes and follow-ups about members. Those are the shul’s records, not Shuli’s, and they are not visible to other members.
And what is not collected:
- No page-view tracking, no session log, no heartbeat, no advertising or analytics profile. The “active members” figure a shul’s office sees is counted from things members actually did — posted, gave, RSVP’d — not from watching them read.
- No read receipts on announcements or chat, by design.
- No card numbers. See Payments.
- No location from your device. The coordinates the app uses for zmanim are the shul’s own, typed in once by its admin.
- In a poll the shul marked as a secret ballot, no record of who voted which way — the ballot is stored without the voter, and a poll cannot be un-secreted after it has been asked.
Who can see what
- Every member of your shul can see your name and photo, and whatever you post in a channel they are in.
- Your shul’s admins can see your contact details, your member details and your giving history for that shul.
- Your Rav or Rebbetzin can see what you send them. By default a shul’s office can see an Ask-the-Rav thread too — that is how a gabbai triages them. You can mark a thread private to the Rav before you send it, and then the office genuinely cannot read it, reply to it or reopen it.
- Nobody in another shul can see any of it. Membership is enforced by the database on every table, not by app code that could forget.
- Shuli’s operator can reach the database to run and repair the service.
TODO(eli): Decide and write down the internal rule for when Shuli staff may look at a shul’s data (support request, incident, never otherwise), and whether that access is logged. Right now the honest answer is “the operator has database access”, which is true of every hosted product but is not yet a policy.
What can become public — and only if you asked
By default a shul on Shuli is invisible to the internet. Each of the following is off until somebody deliberately turns it on.
The shul’s public page. A shul’s admin can publish its minyan times and its public announcements at a link anyone can open. Members-only posts never appear there.
The public member directory. A shul can add a “families of the kehilla” list to that page. It publishes a name and nothing else — no photo, no phone, no email, no dates, no role. Three separate yeses are required before any name appears: the feature is off for every shul until switched on, the shul must already have a public page and choose to add the directory, and you must opt in yourself. Saying your neighbours in the shul may see your name is not the same as saying the internet may; those are two different switches, and the public one only counts alongside the in-shul one.
The campaign donor ticker. If a shul runs a public campaign page and turns the ticker on, the recent gifts are shown with a display name and an amount. You choose the display name when you give, and a gift marked anonymous stores no name at all. A shul’s admin can also remove a name from the ticker after the fact.
The shul finder. The network directory lists shuls that opted into it — a neighbourhood, not a street address, and no individual people.
If you have no account
A shul can open a campaign or an event to people who are not members. If you give or buy a ticket that way, Shuli collects your name and your email address — the email is how the receipt or the ticket reaches you, because there is no account to put it in — plus the amount, any dedication, and the display name you choose. That display name may appear on the shul’s public donor ticker unless you mark the gift anonymous.
Giving as a guest does not create an account and does not add you to the shul.
Payments
Money is processed by Stripe. Each shul connects its own Stripe account, and payments settle into that account — Shuli never holds your money.
Card numbers never reach Shuli’s servers. The card fields on every payment screen are Stripe’s own, rendered inside the page; the details go straight to Stripe. What Shuli’s database stores is the amount, the currency, the status, Stripe’s reference for the payment, and — if you save a card for next time — the card brand and its last four digits.
Stripe handles your payment information under its own privacy policy and terms.
Email and notifications
Shuli sends two kinds of email: things you asked for (a sign-in code, a receipt, a ticket, a statement) and things your shul sends its members (a weekly digest, a campaign appeal, a pledge reminder). Every one of the second kind carries an unsubscribe link, and your mail client’s own one-click unsubscribe works too. Unsubscribing stops the shul’s mailings; it does not stop a receipt for something you paid for.
Push notifications go through your device or browser vendor’s push service, which needs a token to deliver them. You can turn them off per shul, per kind, or in your browser or phone settings. Every push passes the Shabbos gate before it is sent.
AI features
AI tools are off for every shul by default and stay off until a shul’s admin turns them on. When a shul does turn them on, two things can happen: audio a shul uploads for a shiur can be sent to OpenAI to be transcribed, and certain admin drafting and summarising tools send the shul’s own text to OpenAI to be rewritten. Members’ private messages and contact details are not sent anywhere for this.
No feature in Shuli answers a question of halacha. That is a permanent decision, and it is enforced by the code rather than by a guideline — there is nowhere to ask one.
TODO(eli): Before the first shul switches AI tools on, confirm the data processing terms with OpenAI (retention, training opt-out) and state them here. Right now this section says which data can leave; it does not say what happens to it afterwards, because that has not been established.
Who else touches your data
Shuli is built on other people’s services, and each of them handles some part of this:
- Supabase — the database, sign-in, and the storage that holds photos, voice notes and shiur audio.
- Vercel — hosting and delivery of the site itself.
- Stripe — payments, and the shul’s own connected account.
- Brevo — sending email.
- Your browser or phone vendor — delivering push notifications.
- OpenAI — only for a shul that has switched AI tools on, and only as described above.
TODO(eli): Name the regions data is stored and processed in, and decide whether transfers out of the EEA or the UK need standard contractual clauses. This list is the sub-processor list; formalise it, and add a way for shuls to be told when it changes.
How long it is kept
Content you post stays until it is deleted — by you where the product allows it, or by your shul’s admins, who can remove anything in their shul. Records of money are kept for as long as the shul needs them for its own accounts.
TODO(eli): Set actual retention periods, per category, and say them here: chat and voice notes, deleted messages, giving records, guest checkout records, sign-in logs, and what happens to a shul’s data after it stops using Shuli. Nothing has been decided, so nothing is claimed — this is the single biggest gap on this page.
Your choices and your rights
Whatever else the law where you live gives you, these are things you can do today, in the product:
- Change your name, photo and contact details at any time.
- Choose whether you appear in your shul’s directory, and separately whether your name may appear on a public one.
- Turn notifications off, per shul and per kind.
- Unsubscribe from a shul’s emails in one click.
- Block another member, which hides their messages from you immediately.
- Leave a shul yourself, from your own settings, without asking the office. (The one exception is a shul’s last remaining admin, who has to hand the role over first — otherwise the shul would be left with nobody who can administer it.)
Depending on where you live, you may also have the right to ask for a copy of your information, to have it corrected, to have it deleted, or to object to how it is used. Because most of it belongs to your shul, the fastest route for those is usually your shul’s admins.
TODO(eli): Decide who answers a data subject request, at what address, within what window, and how identity is verified — then build the path. There is no self-serve export or account deletion in the product today, and this page must not imply there is. Note also the CCPA requirement for a “Do Not Sell or Share” disclosure: Shuli does not sell or share personal information, and that should be stated in whatever form counsel advises.
Children
Shuli is built for a shul’s members and is used by families. A member account is created by the person themselves, or by a shul inviting them.
TODO(eli): Decide the minimum age for an account, whether shuls may create accounts for children, and what that means under COPPA and under the GDPR age of consent. Nothing in the product enforces an age today. This is a decision, not a drafting question, and it should be made before the pilot.
Changes to this page
When this page changes in substance, the date at the top changes with it.
TODO(eli): Decide how a material change is announced to shuls and members — email, in-app notice, or both — and how much notice is given.
Contact
Questions about this page, or about what a particular shul holds about you: eli@elivated.com.
TODO(eli): Replace this with the legal entity’s name, its registered postal address, and a dedicated privacy contact address. GDPR Art.13 requires the controller’s identity and contact details, and a personal email is not that. Decide too whether an EU or UK representative is required.