Kehilah Privacy Policy
Last updated: June 3, 2026
Kehilah (“we,” “us”) is operated by Kehilah LLC. This Privacy Policy explains what data we collect, how we use it, and the choices you have. We try to collect as little as possible.
1. What we collect
- Account data — when you sign in, we receive your email and (if available) display name and profile photo from your sign-in provider (Google, Apple, or email).
- Creator-claim data — if you claim a creator profile, we associate that profile with your account.
- Connected channel data — if you connect Instagram, TikTok, YouTube, X, an RSS feed, or a podcast feed to your creator profile, we collect public content from that source (see Section 4).
- Messages — if you send or receive direct messages on Kehilah, we store the message content and any attachments you upload (see Section 5).
- Preferences — your follows, saved items, and feed filters.
- Usage data — basic device and app data needed to operate the Service (crash logs, page load events). We do not sell this data.
2. What we do not collect
We do not collect contacts, location, microphone, camera, or browsing history outside Kehilah. We do not run third-party ad trackers. We do not access private messages on connected platforms, your followers list, or any private content on those platforms.
3. How we use your data
To run the Service: sign you in, display your claimed creator profile, sync content from your connected channels, deliver direct messages you choose to send, personalize your feed based on the filters and follows you choose, sync your preferences across devices, and improve reliability.
4. Connected channels (Instagram, TikTok, YouTube, X, RSS, podcasts)
When you connect an external channel to your creator profile, Kehilah retrieves and stores public content from that channel so we can display it on your Kehilah profile and in the Kehilah feed.
When you connect Instagram via Meta's “Instagram API with Instagram Login,” we request a single scope: instagram_business_basic. With this scope we access:
- Your Instagram username, account ID, and account type
- Your public media (photos, videos, captions, timestamps, permalinks)
We do not access: direct messages, your followers or following list, ads data, insights, comments management, or the ability to publish on your behalf.
We store this data in our database (Google Firebase / Firestore) and refresh it periodically while your connection is active. You can disconnect Instagram at any time from your Kehilah account page, or by revoking Kehilah's access in Instagram → Settings → Apps and websites. When you disconnect, we stop syncing new content and, within 30 days, delete the Instagram content and tokens we stored.
TikTok
When you connect TikTok, you authorize Kehilah through TikTok's official OAuth login. We access your public profile information (username, display name, avatar) and your public videos (titles, thumbnails, timestamps, and links). We do not access: direct messages, your followers or following list, ads or analytics data, or the ability to post on your behalf.
We store this data in Google Firebase / Firestore and refresh it periodically while your connection is active. You can disconnect TikTok at any time from your Kehilah account page, or by revoking Kehilah's access in your TikTok settings. When you disconnect, we stop syncing new content and, within 30 days, delete the TikTok content and tokens we stored. TikTok users may also request deletion of their data via our Data Deletion page.
YouTube, X, RSS, and podcast feeds
We retrieve publicly available metadata and content (titles, descriptions, thumbnails, episode files, publish dates, permalinks) from public profiles, handles, or feed URLs that you or an administrator provide. We do not use private YouTube data or OAuth scopes for these sources.
5. Direct messages
Kehilah lets registered users message claimed creators, and lets creators message back. When you send a message, we store its text and any image or video attachments so we can deliver and display the conversation. You can delete your own messages, and deleting your account removes your messages from Kehilah's database within 30 days. Messages are visible to the participants of a conversation, and to Kehilah staff only where necessary to operate the Service, respond to a report, or comply with law.
6. Third-party platforms
When you play a video or podcast inside Kehilah, the underlying platform (e.g. YouTube, TikTok, podcast host, Instagram) may collect data per its own privacy policy. Kehilah does not control that data collection.
7. Storage & security
Your data is stored with Google Firebase (Authentication, Firestore, Cloud Functions, Storage) in Google Cloud data centers. We follow industry-standard security practices, including encryption in transit (HTTPS) and at rest. No system is perfectly secure.
8. Data retention & deletion
We retain account data for as long as your account is active. You can delete your account from Settings; this removes your profile, follows, saved items, messages, and any creator profile you've claimed, along with all connected-channel content and tokens, from Kehilah's database within 30 days. You can also request deletion at hello@kehilah.co or via our Data Deletion page.
9. Your choices
- Edit your filters and follows at any time.
- Disconnect any connected channel from your account page.
- Hide individual items from your profile and the feed.
- Delete your own direct messages.
- Delete your account or any connected channel; revoke Instagram access at Instagram → Settings → Apps and websites, or TikTok access in your TikTok settings.
- Email hello@kehilah.co with any data request.
10. Children
Kehilah is not directed to children under 13. If you believe a child has provided us data, contact us and we will delete it.
11. Changes
We may update this Policy as the Service evolves. Material changes will be noted by updating the date above and, where appropriate, by in-app notice.
12. Contact
Kehilah LLC — chaim@kehilah.co