Mishtatef exists so your family can chip in together without arguments — not so anyone can mine your family's life. No ads, no selling data, no exceptions. Here is exactly what we collect, why, and who sees it.
Effective August 9, 2026 · version 2026-08.2
Account information. Your name, email address, and timezone. If you sign in with Google we receive your name, email, and profile picture from Google — never your Google password.
Circle activity. What you and your Circle create in the product: Circles and memberships, Events and their dates (including Hebrew calendar dates you add), contribution requests and your responses, chat messages, polls, reimbursement requests and receipt photos, and every ledger entry.
Payment information — the part we deliberately never hold. Bank logins and full card numbers are collected directly by our payment processor and never touch our servers. What we store is what the ledger needs: the amount, the status, which payment method was used (for example, a card’s brand and last four digits), and the processor’s reference for the transaction.
What you agreed to, and when. When you agree to these documents or to receiving things by email, we record which document, which version of it, and the date. Where you agreed in a browser we record the IP address and browser with it; where you agreed by text there is no browser to record, so the record is the message and the number it came from. That record is what makes an email count as something sent to you in writing, so we keep it for as long as we might have to show it — and we keep it after you withdraw, because the question later is what was true on the day we sent something, not what is true now.
Technical basics. Standard server logs (IP address, browser type, timestamps) kept for security and debugging. We do not use advertising trackers, we do not run ads, and we do not sell analytics about you.
A record of the service operating. We keep our own log of what happens in Mishtatef: a Circle opened, an invitation sent, a request answered, a page opened. It records the KIND of thing and the identifier of it, never the name — a Circle’s name and an Event’s title are not in it. This is our own record, on our own servers, and it is how we find out that something is broken or that people are getting stuck. It is separate from the usage measurement below, which is Google’s and which you can decline.
Usage measurement. We use Google Analytics to count how Mishtatef gets used, so we can fix what trips people up. It is deliberately limited, and the limits are enforced in our code rather than promised here:
You can decline the first time you visit, and change your mind whenever you like under Settings → Security → Usage measurement. Declining stops the measurement everywhere, including the parts that happen on our servers rather than in your browser.
We do not use your data to advertise to you, and we do not sell or rent it to anyone. Ever.
Most of what you do on Mishtatef is deliberately visible to your Circle — a shared ledger only works if it is shared. The boundaries:
Some of what we hold was typed in by somebody else. A member adding their family to a Circle types names, and sometimes an email address or a phone number, for people who have never heard of us. An Event names its honoree. A payout can be addressed to a rebbe, a kalla or a neighbour who has no account here. This section is about those people, because the rest of this policy is written to the person reading it and they are not that person.
Only the service providers required to run the product, each bound to use your data solely to provide their service to us:
Beyond that, we disclose data only if the law compels it, to prevent fraud or imminent harm, or as part of a merger or acquisition — in which case this policy continues to apply to your data and we will notify you before any change takes effect.
Everything described here is stored and processed in the United States.
Contributing needs nothing but a card or a bank account. Being paid to a bank account means opening an account in your own name at Stripe, and that step collects more about you than the rest of the product does. It is the same for a member and for somebody with no account here who received a payout link.
Mishtatef sends transactional email: invitations, contribution requests, advance notice before any recurring charge, payout approvals, and statements. Every batch is filtered through Event exclusion lists before sending, so an honoree never receives mail about their own gift. Reminders are deliberately restrained — one gentle nudge, sent by a person, not an automated chase. We do not send marketing email unless you opt in, and everything optional has an unsubscribe link.
You can run your whole Mishtatef account by text message, and you never have to. Texting is off until you give us a mobile number and tick the box asking for it — we do not text a number you merely typed into your profile, and your account works exactly the same if you never turn it on.
What we send. Account notifications and group contribution updates: a request to chip in, a code confirming your number, notice that a charge did not go through, a payout waiting on your approval. Message frequency varies based on your Circle’s activity. Message and data rates may apply. Reply STOP at any time to cancel, or HELP for help.
Mobile phone numbers and SMS consent — we do not share them, with anyone, ever. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories described in “Who we share data with” exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
What a text can do. A verified number can operate your account — check a pot, answer a request, add a payment method — so treat it like a key. No money ever moves without you confirming the exact amount in a reply, and you can remove the number from your profile at any time, which takes that ability away with it.
What we never do by text. We do not send marketing or promotional messages. We will never text you asking for a password, and the assistant you are texting cannot move money on its own — a person’s reply is what does that.
Our text messages page shows the opt-in screen itself, and the exact wording you agree to.
The assistant you write to keeps a short notebook about you, so it does not ask the same thing every time: which Circle you usually mean, the amount you tend to give, that you write in Yiddish. Short notes, stored with your account, and never used for anything but answering you.
You can read every line of it and delete it, on the Security tab of your profile or by asking the assistant to forget. A product about your family’s money that quietly accumulates notes about you and offers no way to look is not one we would want to use either.
We keep what you write to the assistant and what it writes back — by text message and in the help panel on the website — and we read it to make the product better. Some of that reading is done by a person; some of it is done automatically, by a program that goes through a week at a time and reports where people got stuck.
Before that program sees anything, names and phone numbers are replaced with stand-ins, so what it reports is a pattern rather than a person. Its reports are for us and are never shown to anybody else. When one of us opens a conversation to read it, that is written down, with who and when — including when the program does it.
Card numbers never reach it: if you text one, it is replaced with the last four digits before anything is stored, and a photo is deleted at the carrier without being looked at. If you close your account we delete these conversations along with the rest, on the same thirty days as §07.
The ledger is append-only and kept for as long as the Circle exists — it is the Circle’s shared financial record, and money-movement records are also retained as long as our payment processor and applicable law require (typically seven years).
If you close your account, we delete or anonymize your personal data within 30 days — your name, email address, phone number, any password, the assistant’s notebook, and your conversations with the assistant. Three things stay: ledger entries (attributed to a de-identified former member, because your family’s record of who gave what must stay intact), the record of what you agreed to and when, because its whole purpose is to say what was true on a past day, and records we are legally required to keep, which are held for the required period and then deleted.
All traffic is encrypted in transit and data is encrypted at rest. Sign-in uses one-time email links, Google, or a code by text. A password is optional and never required; where one is set, we store only a salted hash of it, and the emailed link signs that account in regardless. Access to production data is restricted to the small number of people who operate the Service, and the most sensitive material — bank credentials and card numbers — is kept out of our systems entirely by design. If a breach ever affects your data, we will tell you promptly and plainly.
We honor these rights for everyone, not only where a statute (such as the GDPR or the CCPA) requires it. We never discriminate against you for exercising them.
Mishtatef is for adults; you must be 18 to hold an account. We do not knowingly collect data from children. Events may of course be about children — a new baby, a bar mitzvah — and that information is provided by, visible to, and controlled by the adult members of your Circle.
If we change this policy in any material way, we will email every account holder at least 14 days before the change takes effect. We will never quietly weaken the promises on this page — in particular, “no ads, no selling data” is permanent.
Privacy questions or requests: support@mishtatef.com. For how the Service itself works, see our Terms of Service.