לחםLechem
Sign in

Privacy

What this website holds about you, and what it does not.

A public privacy-policy page is required before Lechem can be listed on Google Play. This page is that address.

Last updated
3 August 2026
Applies to
The Lechem Android app (app.lechem) and lechem.app

The short version

Lechem is built to work with the phone in airplane mode. Your brachos, your davening, your learning, your names, your resolutions — all of it is written to storage on your phone and stays there.

There is no account required to use it, no advertising, no tracking, and no analytics of any kind: the app contains no code that reports what you do.

Two things send information about you off the phone, and neither of them ever happens on its own. Sending a feedback report — only when you tap Send. And signing in — only when you tap Continue with Google, Continue with Microsoft, or type an email address and a password. Signing in is optional; every part of the app works without it.

Both are described in full below, because they are the places where the "everything stays on your phone" sentence stops being completely true, and a privacy policy that buried them would be worthless.

And here is what we do not have. We do not know what you daven, what you counted, or whose name is on your list, because none of it has ever reached us — the two places on the server that would hold such a record hold no rows at all, and the log that records everything is forbidden by the database itself from ever containing what you practised. What you tap is written on your own phone. It does not sync between your phones yet, and this page will not pretend otherwise.

What this website does with your data

The policy above covers the app and this website together. These are the website-specific details, true of the code that serves this page today.

  • One cookie of our own: your language.

    Choosing English, Hebrew or Yiddish stores that one word in a cookie named lechem_lang so the page opens in your language, and reads right-to-left when it should. It holds nothing else.

  • Signing in is optional, and it is a real account — not a tracker.

    The public pages need no account at all. If you do sign in, the account system sets its own session cookie so the site knows it is you on the next page. What it then holds about you is your name and your email address, plus any feedback report you sent — signing in does not pull anything off your phone, because the sync described in section 2.4 above has never carried a record.

  • No analytics, no advertising, no third-party trackers.

    There is no measurement script, no advertising code and no social pixel on any Lechem page. Nothing about your visit is sold, shared or sent to anyone.

  • Your practice is not on this website.

    What you counted, what you davened, the names you keep — none of that reaches this site. It lives on your phone. The engine that would one day carry it here is designed and not built, and when it is, this page changes in the same breath.

  • The most private screens never leave the device — by design, everywhere.

    A small set of the most personal screens in the app is device-local by rule, in every version of Lechem. They are not listed on this website, not linked from it, and no part of this site can reach them.

  • This website is not where a child signs up.

    Signing in here is self-serve: the first time you use Google or Microsoft, your account is created. So this page says plainly that it is not built for a child. A profile the app is running as a child is refused sign-in by code, not by a setting a child could change. Family accounts, parental controls and a child’s safe corner are designed and are gated behind a children’s-privacy review before any of it ships publicly.

The full policy

The policy below was written against the build that actually exists, section by section, and it covers the Android app and this website together — one policy, not two.

1. What stays on your phone, always

All of the following is stored locally on your device. Nothing here is collected by us, sent on a timer, or used for advertising, analytics or profiling of any kind — the app contains no code that does those things at all. The only thing that can carry any of it off the phone is a feedback report you deliberately send, and section 2.1 sets out exactly what such a report contains.

Two ways a report can carry it, and both are visible to you before you send. Some of these are sent as fields in their own right — they are marked below. And a report can include an automatic picture of the screen you were on, so whatever was on that screen at that moment is in the picture, whether or not it is a field the report collects. Nothing forces you to send the picture: the app shows you the whole report, picture included, before you tap Send, and you can remove it. The strictly private screens are the exception with no exception — they are never photographed at all.

  • Your bracha count and everything behind it — what you counted, when, on which day. Never sent as a field.
  • Your davening, your learning, your Chitas and Shnayim Mikra progress. Never sent as a field.
  • The names you daven for, refuah names, yahrtzeits, kevarim tefillos, your kabbalos. Never sent as a field.
  • 🩸 Your minhag, nusach, edah, and the city you chose for zmanim. Sent as a field in a feedback report: your edah/nusach and the city name you set are included in one, and the app shows you both on the send screen before you tap Send. Your coordinates are never sent; only the city name you chose.
  • 🩸 Your profiles and any family or child profiles set up on the phone. Sent as a field in a feedback report: the name on the profile that filed it, its profile identifier and your account number are included, and the app shows you all three before you tap Send. A child’s name is never included, from any field.
  • Everything on the screens the app treats as strictly private (the cycle and mikvah sections). These are held to an additional rule with no exception at all: they are never photographed by the app, never named in a report, and never included in any transmission for any reason. A report filed from one of those screens carries none of the identifying fields above.

The cycle and mikvah records, stated plainly. Google Play classes menstrual cycle tracking as a health feature regardless of why an app does it, and this app declares it as one. So it is set out here rather than left to be inferred. What the app records is the dates you enter yourself — nothing is measured, sensed or imported, and no other app or device supplies them. What it does with them is arithmetic under halacha: it counts the days and tells you what the count means for vestos and for mikvah timing. It does not diagnose, does not track fertility, and is not a means of preventing or planning a pregnancy — for anything about your health, ask a doctor, and for any question of halacha, ask your Rav. Where the records live is this phone, in the app’s own store, and nowhere else: no account behind them, no server copy, and no sync — nothing carries them anywhere on its own. How long they are kept is entirely up to you — they stay until you delete them or uninstall the app, and there is no expiry, no archive and no backup that outlives either. Who else can read them is nobody unless you choose otherwise — not us, not a third party, not the two Android backup channels, and not a feedback report, which is held to the additional rule above with no exception at all. There is exactly one way these records leave the phone, and it is your hand: inside that section, Copy and Download file put them where you point them — to your Rav, your husband, a parent, or nobody. The app never does it for you, never on a timer, and never anywhere you did not choose; and what you do with the copy after that is between you and the person you gave it to.

If you uninstall the app, this data is deleted with it. It is also kept out of both of Android’s backup channels — Google cloud backup, and the phone-to-phone transfer that runs when you set up a new device. Three settings control this and all three are set against copying: the app opts out of backup entirely, and it additionally ships two rules files that exclude every one of its stores by name. 🩸 Those two rules files were added on 1 August 2026, and they are a repair rather than a formality: on some manufacturers’ phones the opt-out flag alone closes cloud backup but does NOT close device-to-device transfer, so until that date the phone-to-phone channel was not in fact shut. It is shut now, and it is shut by the rules files rather than by the flag alone. (android:allowBackup="false" — the app opts out of Android’s automatic backup entirely, plus all-exclude dataExtractionRules and fullBackupContent — so this data does not land in a Google account, or on a new phone, without you asking). If you signed in, see section 6 — the account itself is the one thing an uninstall does not remove.

2. What leaves the phone

There are exactly seven pieces of code in Lechem that are permitted to use the network. This is enforced by an automated build gate, not by good intentions: they are named in an allow-list, and a build in which any other file contains a network call is refused and never produced. Adding one more is a deliberate, recorded decision — it cannot happen quietly. Each of them is described below, and between them they account for every byte this app can send or fetch.

  • One sends a feedback report you chose to send (section 2.1).
  • Three fetch files and send nothing about you: the app-version check, the content check, and the language-pack download (section 2.2).
  • One signs you in, if you choose to sign in (section 2.3).
  • One is the sync transport, which is built and not switched on (section 2.4).
  • One is the developer’s own message channel, which the server refuses to anybody else (section 2.5).

2.1 Sending a feedback report — the only path that sends your own records

When you tap Send on a feedback report, the report is uploaded. It contains:

Always: what you wrote, and any notes you pinned on a picture; the screen you were on, and the name of the last thing you tapped on it; the app version, your language, your screen size, your device model and browser identification string, the time, and your time zone. Plus two facts about the phone, so a report can be understood rather than guessed at: whether the microphone was refused (included only when it was, so a report with no words reads as a silenced one rather than an empty one), and whether the phone was online when you filed it.

Any media you attached or recorded: screenshots (including automatic screenshots of the screen you came from), screen recordings, and voice recordings — which will contain your voice, and anything audible around you while recording. If you attach a file that is already on your phone — a picture, a video or an audio file — then the file’s name travels with it, as file names do. Names of children set up on the phone are removed from it first.

Unless the report was filed from a strictly private screen: who filed it — the name on the profile, the profile identifier, your account number, your edah/nusach, and the city you have set for zmanim.

If the report is filed from a strictly private screen (cycle / mikvah), those identifying fields are not included at all — not blanked, not replaced with "unknown", simply absent — and no picture of that screen is taken.

When a child's profile files a report, the child's name is deliberately not included. The report says only that a child filed it, on which profile, and on whose account.

Reports are sent to a server operated for OOretz on Supabase infrastructure, and are readable only by the developer, who uses them to fix the app. They are not sold, not shared with advertisers, and not used to build a profile of you. The app shows you, on the send screen and before you send, exactly what the report will carry.

Nothing is ever sent automatically. There is no timer, no background upload and no "anonymous usage statistics". If you never tap Send, no report about you ever leaves the phone.

2.2 Checking for updates and content packs — sends nothing about you

Three parts of the app make simple download requests to fetch files:

  • a check for whether a newer version of the app exists (it only tells you; it never downloads or installs anything);
  • a check for updated content;
  • downloading a language pack.

These are ordinary downloads. They carry no identifier, no account, no usage data and no contents of your phone. As with any request to any website, the server necessarily sees the network address (IP) the request came from and the time — that is unavoidable in how the internet works, and we mention it rather than pretend otherwise.

2.3 Signing in — live, optional, and it sends the address you sign in with

Lechem has a working sign-in. The app’s first screen offers it — Continue with Google, with "Not now" beside it — and there is a fuller sign-in card on the Settings & Account screen. It is an offer, not a gate: "Not now" takes you straight into the app, nothing you count, daven or learn is behind a login, and the app keeps your records on the phone whether you ever sign in or not.

There are three ways in, and two of them are other companies. Continue with Google, Continue with Microsoft, or an email address and password. The two buttons open a Google or a Microsoft sign-in page in a separate browser tab — not inside the app, because both companies refuse to accept a password typed into an app’s own window. On that page you are dealing with Google or with Microsoft under their privacy policies, not with us; when you finish, they hand our authentication server the fact that you signed in, and your email address. If you use the email-and-password route instead, your address and password are sent over HTTPS to that same authentication server, which is hosted on Supabase infrastructure and operated for OOretz.

What is kept. Your account identifier and your email address are held on the server. Google and Microsoft may also pass across the name on the account you signed in with. On the phone, only the session tokens are stored — your password is never written anywhere on the device; it is handed to the server once and forgotten, and signing out removes the tokens.

Signing in creates an account if you did not have one. Completing a Google or Microsoft sign-in brings an account into existence on our authentication server. That is worth stating plainly, because it is the one action in this app that leaves something behind which uninstalling the app does not remove. See section 6 for how to have it deleted.

Signing in does not move your practice. It puts a name on what is already on this phone. Nothing is uploaded and nothing is downloaded by the act of signing in — the sync that would do that is described in the next section and is not switched on.

Who may not sign in, by design. A child’s profile cannot get an account — children stay local, under a parent — and a phone that has been lent out under a guest seal cannot authenticate either.

2.4 Syncing your practice to another device — built, not switched on

Signing in is the first half of an optional sync: your practice following you to another phone and to the web. The second half is not switched on. No sync data is transmitted by this version — the app checks whether an account and a household exist and stops before contacting the sync server at all.

And nothing has ever arrived, which is a different claim and a stronger one. The tables that would hold a synced record were created, and they are empty: the table of merged records holds no rows, the journal that would feed it holds no rows, and no phone has ever registered itself for sync. Separately, the server keeps an audit log of everything that happens to it — and that log is forbidden by the database itself from ever containing what you practised. It is not a setting, and no account or administrator can turn it off.

Where this is going, stated as intent and not as fact: the owner has ruled that Lechem should become an app where the database is the record and nothing depends on one phone surviving. That work has not begun. This section will be rewritten when it does, and until then it describes the build you can install today.

When it is switched on it will be optional, it will be announced in the app, and this policy will be updated before it carries a single byte. At that point the data it would carry is your practice records — the things listed in section 1 — sent to your own account so that your other device can read them.

Two things about that day are worth writing down now rather than later. Your cycle and mikvah records are never included, and cannot be: they are refused by name in three independent places in the code, not merely left off a list. And the names on the phone — including children’s names and the names of people you daven for — are part of what would sync, because they are part of your record. Nothing carries them today.

2.5 The developer’s own message channel — refused to everybody else

The seventh piece of code with network access exists for one person: it carries the developer’s own working notes to his own phone, so that messages written for him on a computer reach him when he is not at it. It is described here rather than left out, because a policy that names six of seven network paths is not a complete policy.

It sends nothing about you and cannot read anything on your phone. If you are signed in, the app asks the server once, when it starts, whether this account is allowed that channel; for anyone who is not the developer the server answers no and nothing further is requested. That question carries your sign-in token and, as with any request to any website, the server sees the network address (IP) it came from and the time. If you are not signed in, the question is never asked at all.

3. Permissions, and what each is really for

The app does not request background location, does not read your contacts, does not read your photos or files, and does not read your calendar.

PermissionWhat it is forDoes it send anything?
Internet / network accessThe three downloads above, sending a feedback report you chose to send, and signing in if you choose toOnly as described in section 2
CameraReading an ingredients label. The text is recognised on the device; the picture is not uploadedNo
Location (approximate and precise)Zmanim, candle lighting and the parsha for where you actually are; and noticing you have left the place where you ate, so it can ask whether to bentch — which, in this version, happens only while the app is on screen (see the withdrawn row below)No — your coordinates are used on the device and are not transmitted. The city name you set is included in a feedback report if you send one
MicrophoneTwo things: recording a voice note or narrating a screen recording inside feedback; and the one screen you can speak to instead of tapping, which either uses the phone’s own speech recognition or records a short voice note kept on the phoneOnly inside a feedback report you send. What you say to the app on the voice screen stays on the phone
NotificationsReminders you asked for — zmanim, candle lightingNo
Exact alarmsSo a candle-lighting reminder arrives at the right minute, not "roughly"No
Foreground service (location) — WITHDRAWN, not requested by this versionThis permission would have kept the "did you leave where you ate?" question working while the app is not on screen. It was withdrawn on 27 July 2026 and this version does not ask for it: the question now works only while the app is on screen. The feature is parked rather than abandoned, and if it returns, this policy is updated in the same releaseNo — and the app does not hold the location foreground-service permission at all
Foreground service (generic)Lechem itself runs no foreground service. This permission is present only because a standard Android background-work library the app is built on (AndroidX WorkManager) declares it, and Android merges a library’s permissions into the app’s. No code in Lechem starts a foreground serviceNo
Run at startupSo the home-screen widget is correct about Shabbos after you restart the phoneNo

4. Children

Lechem is built so that a child can use it — the pictures do the talking and nothing is asked of a child that a child should not be asked. A child’s name and details stay on the phone. If a report is sent from a child’s profile, the child’s name is not included.

Specifically: a child’s profile cannot sign in, cannot get an account, and cannot attach or send a picture, a video or a voice recording to us at all. A child’s name is removed from every part of a report before it is sent — from the words, from the details, from the label of the button that was tapped, and from the name of any file attached.

One thing a parent should know. Those protections work on text. If you, as the adult using the phone, send a feedback report while you are looking at the children’s screen, the report includes an automatic picture of that screen — and a name printed on that screen will be in the picture. Nothing forces you to send it: the app shows you exactly what the report will carry before you tap Send, and you can remove the picture.

Lechem does not knowingly collect personal information from children. If you believe a report was sent that contains a child’s personal information, contact us and it will be deleted.

5. Third parties

  • Supabase hosts the storage, the endpoint that receives feedback reports, the authentication server that checks a sign-in, and — in future — sync. They act as a processor for us, on our instructions.
  • Google is one of the two identity providers behind "Continue with Google". If you use that button, you sign in on Google’s own page, under Google’s privacy policy, and Google tells our authentication server that you signed in and what your email address is. If you never tap that button, Google is not involved in your sign-in at all.
  • Microsoft is the other, behind "Continue with Microsoft", on exactly the same terms.
  • Google Play services supplies the on-device text-recognition model used by the ingredients label reader; the model is downloaded to the device by Google Play, and the recognition itself happens on the phone. No photograph is uploaded.
  • There are no advertising networks, no analytics SDKs, and no social-media SDKs in this app.

6. Your choices

  • Don’t want anything to leave the phone at all? Don’t send a feedback report and don’t sign in. Everything else works with the phone offline.
  • Want a report deleted after you sent it? Contact us with the ticket number the app showed you.
  • Signed in and want to stop? Sign out on the Settings & Account screen. The session tokens are removed from the phone.
  • Want everything on the phone gone? Uninstall the app. Local data goes with it, and it is not sitting in a Google backup or waiting in a phone-to-phone transfer — see section 1 for how both channels are held shut, and since when.
  • Want your account gone too? Uninstalling does not remove it — signing in created a record on our authentication server, and that record outlives the app on your phone. You can delete it yourself, at https://lechem.app/delete (the same page is at ooretz.space/lechem/delete, and it is linked in the footer of every page on this site). Sign in there and the page shows you your own answer before anything is armed. It always deletes your Lechem membership and every feedback report you filed — the words, the pictures, the screen recordings and the voice notes with them. It deletes the account itself only if you hold nothing in any other OOretz service; if something else is holding it open, the page names what, and your Lechem data goes regardless.
  • The app can start you on that road: Settings carries a row called "Delete my account" which opens that same page. It opens it in a browser rather than doing it inside the app, because the act requires you to be signed in where the server can check it — the page is readable by anybody, but nothing on it can be armed without a session we validated ourselves. And if you have lost access and cannot sign in to use the page at all, write to us by the contact route in section 7 — but know that we will not delete an account on the strength of a message alone, because a message is not proof that the account is yours.

7. How long each of these is kept

What is collected is described above. This section says how long each of those things is kept, which is a separate question and is answered here in full.

  • What stays on your phone — kept for as long as the app is installed. Nothing expires and nothing is removed on a timer: your count, your davening, your learning, the names you daven for and your kabbalos are yours to keep or clear. Uninstalling deletes all of it with the app, and it is not left behind in either Android backup channel — see section 1 for how both are held shut, and since when.
  • Feedback reports — kept until they are deleted, with no automatic expiry. A report is held so the problem you raised can actually be worked on and answered, which is why there is no fixed window. You can end that at any time: contact us with the ticket number the app showed you, or delete every report you have ever filed at once from https://lechem.app/delete — the words, the pictures, the screen recordings and the voice notes go with them.
  • Your account, if you signed in — this is the one thing an uninstall does not remove. Signing in creates a record on our authentication server, and it is kept until you delete it yourself at https://lechem.app/delete. That page always removes your Lechem membership and all of your feedback reports; it removes the account itself only where nothing in another OOretz service is still holding it open, and it names what is holding it when that happens.
  • Syncing your practice between devices — built and not switched on (section 2.4), so nothing is being held on any server for it. If that changes, this policy is updated in the app before the first byte moves.

Nothing about you is retained for advertising, analytics, profiling or resale — not for a short period and not for a long one — because none of it is collected in the first place.

9. Changes

If this policy changes in a way that affects what leaves your phone, the change will be announced in the app before it takes effect — not merely posted here.

That promise has been broken once, and it is written here rather than quietly repaired. Sign-in shipped, and for a period this page went on telling readers that the sign-in server was not enabled. It was corrected across late July and early August 2026, and the corrections are stated inside the sections themselves — §2.3 and §3 both say what they used to say — so that anyone who read the older text can see exactly what changed.

8. Contact

No monitored email address has been published for Lechem yet, and this page will not print one until it exists.

The two things this section is for — asking for a report to be deleted, and reporting a child's data — still have a route that reaches a person today: the feedback button in the corner of this page. It needs no account, it files a numbered Lechem ticket, and it is read. How to reach us.

OOretz, Inc.

How to reach the people who make Lechem.