Privacy Policy

Mishtatef exists so your family can chip in together without arguments — not so anyone can mine your family's life. No ads, no selling data, no exceptions. Here is exactly what we collect, why, and who sees it.

Effective August 9, 2026 · version 2026-08.2

01What we collect

Account information. Your name, email address, and timezone. If you sign in with Google we receive your name, email, and profile picture from Google — never your Google password.

Circle activity. What you and your Circle create in the product: Circles and memberships, Events and their dates (including Hebrew calendar dates you add), contribution requests and your responses, chat messages, polls, reimbursement requests and receipt photos, and every ledger entry.

Payment information — the part we deliberately never hold. Bank logins and full card numbers are collected directly by our payment processor and never touch our servers. What we store is what the ledger needs: the amount, the status, which payment method was used (for example, a card’s brand and last four digits), and the processor’s reference for the transaction.

What you agreed to, and when. When you agree to these documents or to receiving things by email, we record which document, which version of it, and the date. Where you agreed in a browser we record the IP address and browser with it; where you agreed by text there is no browser to record, so the record is the message and the number it came from. That record is what makes an email count as something sent to you in writing, so we keep it for as long as we might have to show it — and we keep it after you withdraw, because the question later is what was true on the day we sent something, not what is true now.

Technical basics. Standard server logs (IP address, browser type, timestamps) kept for security and debugging. We do not use advertising trackers, we do not run ads, and we do not sell analytics about you.

A record of the service operating. We keep our own log of what happens in Mishtatef: a Circle opened, an invitation sent, a request answered, a page opened. It records the KIND of thing and the identifier of it, never the name — a Circle’s name and an Event’s title are not in it. This is our own record, on our own servers, and it is how we find out that something is broken or that people are getting stuck. It is separate from the usage measurement below, which is Google’s and which you can decline.

Usage measurement. We use Google Analytics to count how Mishtatef gets used, so we can fix what trips people up. It is deliberately limited, and the limits are enforced in our code rather than promised here:

  • It sees the KIND of page you opened — “an Event page”, “a Circle’s shared pot” — never the address of it. Your Circle’s name and the name of any Event are never sent.
  • It sees that something went wrong and which kind of thing it was, so we can rank what to fix. It never sees the message you were shown, because some of those name a person.
  • It sees that a contribution settled and for how much, so we know the product works. It never sees who it was for or what it was for.
  • It never receives your name, email address, phone number, home address, or any part of a card or bank account.
  • You are identified to it only by a scrambled code we compute from your account, which cannot be turned back into you by anyone but us.
  • Advertising features are switched off in our code and in the Google account, and there is no path in the software that can turn them on.

You can decline the first time you visit, and change your mind whenever you like under Settings → Security → Usage measurement. Declining stops the measurement everywhere, including the parts that happen on our servers rather than in your browser.

02What we use it for

  • Running the product: moving contributions, maintaining the ledger, delivering chat, sending the emails and reminders your Circle triggers.
  • Keeping Surprise Mode airtight: exclusion lists exist precisely so our servers know what to withhold from whom.
  • Dates and reminders: birthdays, anniversaries, and yahrzeits you enter are used to offer to open an Event at the right time, in your timezone.
  • Security and fraud prevention: spotting stolen accounts and abuse before money moves.
  • Legal obligations: our payment processor and partner bank require records of money movement, and we keep what the law requires.

We do not use your data to advertise to you, and we do not sell or rent it to anyone. Ever.

03Who sees what inside your Circle

Most of what you do on Mishtatef is deliberately visible to your Circle — a shared ledger only works if it is shared. The boundaries:

  • Your Circle sees the ledger, Events, chat, and — depending on the Circle’s visibility setting — your contribution amounts, percentages only, or no individual amounts at all. You can give anonymously to any single Event.
  • Organizers of a collection additionally see the response board: who has accepted, declined, or not yet answered. That list is never shown to the whole Circle.
  • An excluded honoree sees nothing. When an Event excludes someone, our servers refuse to send that person the Event’s existence, chat, ledger lines, or emails. The filtering happens server-side, before anything reaches their device, and our release tests verify it.
  • People outside your Circle see nothing about it. Circles are not public and are not indexed.

03aPeople who never signed up

Some of what we hold was typed in by somebody else. A member adding their family to a Circle types names, and sometimes an email address or a phone number, for people who have never heard of us. An Event names its honoree. A payout can be addressed to a rebbe, a kalla or a neighbour who has no account here. This section is about those people, because the rest of this policy is written to the person reading it and they are not that person.

  • What we hold is what the Circle typed: a name, and an email address or phone number if one was given. Nothing is gathered about them from anywhere else.
  • Nothing is sent to them until their invitation is. A seat on a roster is not a mailing list: no reminder, no request for money, and no announcement reaches somebody before the invitation that explains who we are.
  • A payout link collects nothing for a gift card. No form, no address, no account. If they choose a bank transfer instead, their identity details go to Stripe directly, under Stripe’s own privacy policy — they do not come to us. We keep their name, how to reach them, the amount, and whether Stripe says the account is ready.
  • They can write to us. Anyone can ask what a Circle holds about them and ask us to remove it or stop contacting them, whether or not they ever had an account. Ledger entries stay, because they are the Circle’s own financial record, but they can be de-identified the same way a closed account’s are.

04Who we share data with

Only the service providers required to run the product, each bound to use your data solely to provide their service to us:

  • Our payment processor and partner bank, to move and hold money and to meet their legal obligations (such as sanctions screening).
  • Our gift-card provider, when you choose to take a payout as a gift card: the amount and which card you picked. Nothing about you — not your name, not your email address, not your phone number. We buy the card and hand it to you ourselves. They are the card issuer, we are not, and their own privacy policy covers the card itself.
  • Our email delivery provider, to send the transactional email the product generates.
  • Our text messaging provider, to deliver every text the product sends and to receive the ones you send back. They see your mobile number and the message.
  • Our AI provider, which is Google, through its Gemini API. When you write to the assistant — in the help desk on the web, or by text — what you wrote is sent there so a reply can be generated, along with the context needed to answer it. They are bound to use it only to provide that service to us. Card numbers are never sent to it, and it cannot move money.
  • Our hosting and infrastructure providers, which store the data described above.

Beyond that, we disclose data only if the law compels it, to prevent fraud or imminent harm, or as part of a merger or acquisition — in which case this policy continues to apply to your data and we will notify you before any change takes effect.

Everything described here is stored and processed in the United States.

04bIf you set up to be paid

Contributing needs nothing but a card or a bank account. Being paid to a bank account means opening an account in your own name at Stripe, and that step collects more about you than the rest of the product does. It is the same for a member and for somebody with no account here who received a payout link.

  • Stripe collects it, not us. Legal name, date of birth, address, part of a government identifier, and your bank details go to Stripe directly, under their own privacy policy. We never receive or store them.
  • What we get back is status, not documents. Whether the account exists, whether it can receive money yet, and what is still outstanding.
  • Taking a gift card instead collects nothing. We tell the gift-card provider an amount, which brand, and our own reference number for the payout. Not your name, not your email address, not your phone number.
  • Stripe may report payments to tax authorities on a Form 1099-K where a threshold is met. We do not file those and cannot suppress them.

05Email and notifications

Mishtatef sends transactional email: invitations, contribution requests, advance notice before any recurring charge, payout approvals, and statements. Every batch is filtered through Event exclusion lists before sending, so an honoree never receives mail about their own gift. Reminders are deliberately restrained — one gentle nudge, sent by a person, not an automated chase. We do not send marketing email unless you opt in, and everything optional has an unsubscribe link.

06Text messages and your mobile number

You can run your whole Mishtatef account by text message, and you never have to. Texting is off until you give us a mobile number and tick the box asking for it — we do not text a number you merely typed into your profile, and your account works exactly the same if you never turn it on.

What we send. Account notifications and group contribution updates: a request to chip in, a code confirming your number, notice that a charge did not go through, a payout waiting on your approval. Message frequency varies based on your Circle’s activity. Message and data rates may apply. Reply STOP at any time to cancel, or HELP for help.

Mobile phone numbers and SMS consent — we do not share them, with anyone, ever. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories described in “Who we share data with” exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

What a text can do. A verified number can operate your account — check a pot, answer a request, add a payment method — so treat it like a key. No money ever moves without you confirming the exact amount in a reply, and you can remove the number from your profile at any time, which takes that ability away with it.

What we never do by text. We do not send marketing or promotional messages. We will never text you asking for a password, and the assistant you are texting cannot move money on its own — a person’s reply is what does that.

Our text messages page shows the opt-in screen itself, and the exact wording you agree to.

06aWhat the assistant remembers

The assistant you write to keeps a short notebook about you, so it does not ask the same thing every time: which Circle you usually mean, the amount you tend to give, that you write in Yiddish. Short notes, stored with your account, and never used for anything but answering you.

You can read every line of it and delete it, on the Security tab of your profile or by asking the assistant to forget. A product about your family’s money that quietly accumulates notes about you and offers no way to look is not one we would want to use either.

06bYour conversations with the assistant

We keep what you write to the assistant and what it writes back — by text message and in the help panel on the website — and we read it to make the product better. Some of that reading is done by a person; some of it is done automatically, by a program that goes through a week at a time and reports where people got stuck.

Before that program sees anything, names and phone numbers are replaced with stand-ins, so what it reports is a pattern rather than a person. Its reports are for us and are never shown to anybody else. When one of us opens a conversation to read it, that is written down, with who and when — including when the program does it.

Card numbers never reach it: if you text one, it is replaced with the last four digits before anything is stored, and a photo is deleted at the carrier without being looked at. If you close your account we delete these conversations along with the rest, on the same thirty days as §07.

07How long we keep things

The ledger is append-only and kept for as long as the Circle exists — it is the Circle’s shared financial record, and money-movement records are also retained as long as our payment processor and applicable law require (typically seven years).

If you close your account, we delete or anonymize your personal data within 30 days — your name, email address, phone number, any password, the assistant’s notebook, and your conversations with the assistant. Three things stay: ledger entries (attributed to a de-identified former member, because your family’s record of who gave what must stay intact), the record of what you agreed to and when, because its whole purpose is to say what was true on a past day, and records we are legally required to keep, which are held for the required period and then deleted.

08Security

All traffic is encrypted in transit and data is encrypted at rest. Sign-in uses one-time email links, Google, or a code by text. A password is optional and never required; where one is set, we store only a salted hash of it, and the emailed link signs that account in regardless. Access to production data is restricted to the small number of people who operate the Service, and the most sensitive material — bank credentials and card numbers — is kept out of our systems entirely by design. If a breach ever affects your data, we will tell you promptly and plainly.

09Your rights and choices

  • See and export your data: your ledger history is always visible in the product, your own giving and receiving downloads as a file from your profile, and a Circle’s ledger and an Event’s ledger each export as a spreadsheet. Ask us if you want anything we hold that those do not cover.
  • Correct it: your name, email, and timezone are editable in settings.
  • Delete it: close your account from your profile settings, or email us and a person will do it, subject only to the retention rules in section 07.
  • Object or complain: email us first — we will actually respond — and you may also complain to your local data protection authority.

We honor these rights for everyone, not only where a statute (such as the GDPR or the CCPA) requires it. We never discriminate against you for exercising them.

10Children

Mishtatef is for adults; you must be 18 to hold an account. We do not knowingly collect data from children. Events may of course be about children — a new baby, a bar mitzvah — and that information is provided by, visible to, and controlled by the adult members of your Circle.

11Changes to this policy

If we change this policy in any material way, we will email every account holder at least 14 days before the change takes effect. We will never quietly weaken the promises on this page — in particular, “no ads, no selling data” is permanent.

12Contact

Privacy questions or requests: support@mishtatef.com. For how the Service itself works, see our Terms of Service.