Privacy Policy
Last updated: May 24, 2026
1. Introduction
This Privacy Policy explains how BeEzrat HaShem, Inc. (“we,” “us,” or “our”) collects, uses, and shares information about you when you use BH Live (the “Service”). By using the Service you consent to the practices described here.
2. Information We Collect
Account information. When you create an account we collect your email address, name, and authentication identifiers from the sign-in provider you choose (Google, Apple, email, etc.).
Phone number. If you opt in to phone verification or WhatsApp, we collect your phone number and verification status. This is used to authenticate you, prevent abuse, and (if enabled) send / receive WhatsApp messages.
Chat content. Questions you submit and answers returned by the Service are stored against your account so you can revisit past conversations. Source citations attached to answers are stored alongside them.
Payment information. If you subscribe, your payment details are collected and stored by Stripe. We never see or store your full card number; we only receive metadata such as the last four digits, brand, subscription status, and billing period.
Usage data. We log technical information such as IP address, browser type, device identifiers, referring URL, pages viewed, and timestamps. We also use cookies and similar technologies for session management and analytics.
Analytics and support. We use PostHog for product analytics and Intercom for customer support. These tools may set cookies and collect interaction events (clicks, page views) tied to your account.
3. How We Use Information
We use information to:
- Operate, maintain, and improve the Service;
- Generate AI answers (your question is sent to Anthropic and AWS Bedrock; see Section 5);
- Synthesize audio replies via ElevenLabs when you play an answer aloud;
- Authenticate you and protect your account against fraud and abuse;
- Process payments and manage subscriptions via Stripe;
- Send transactional emails (receipts, account notices, digests you have subscribed to);
- Communicate via WhatsApp if you opt in;
- Understand how the Service is used so we can prioritise improvements (PostHog, Intercom);
- Comply with legal obligations and enforce our Terms.
4. Legal Bases (EEA / UK Users)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
- Contract. To provide the Service you signed up for, including processing your subscription.
- Legitimate interests. To secure the Service, prevent fraud, and improve quality.
- Consent. For optional features such as WhatsApp messaging, marketing emails, and non-essential cookies. You can withdraw consent at any time.
- Legal obligation. When required by law.
5. Sharing with Third Parties
We share information with the providers listed below only to the extent needed to deliver the Service. We do not sell your personal information.
- Stripe — payment processing and subscription billing.
- Anthropic — language-model inference (your question text is sent for generation).
- AWS (Bedrock, S3, KMS) — knowledge-base retrieval and infrastructure hosting.
- ElevenLabs — text-to-speech for voice playback of answers.
- Vercel and Heroku — hosting and edge delivery.
- PlanetScale / Upstash — database and chat-history storage.
- Resend — transactional email delivery.
- WhatsApp / Meta — messaging channel (only if you opt in).
- PostHog and Intercom — product analytics and customer support.
We may also share information if required by law, to respond to lawful requests, to protect the rights or safety of users or the public, or in connection with a merger, acquisition, or asset transfer (in which case the receiving party will be bound by this Policy).
6. Data Retention
We retain your account information for as long as your account is active. Chat history is retained for as long as your account exists so you can revisit past conversations; you can delete individual chats at any time. Payment records are retained as required by tax and accounting law (typically seven years). When you delete your account, we delete or anonymise personal information within 30 days, except where retention is required by law or for legitimate business purposes.
7. Security
We use industry-standard safeguards including TLS in transit, encryption at rest (KMS) for Bedrock sessions, access controls, and regular security review. No system is perfectly secure; you use the Service at your own risk and should choose a strong password and protect your devices.
8. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, restrict or object to certain processing, or withdraw consent. To exercise any of these rights, contact us at the address in Section 12. We will respond within the timeframe required by applicable law.
California residents (CCPA/CPRA). You have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell personal information.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us and we will delete it.
10. International Transfers
We are based in the United States and our service providers operate primarily in the US. If you are accessing the Service from outside the US, your information will be transferred to and processed in the US, which may have different data-protection laws than your country.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date above reflects the most recent change. Material changes will be communicated through the Service or by email. Continued use of the Service after a change constitutes acceptance.
12. Contact
Questions, requests, or concerns? Contact us at contact@beezrathashem.org.
BeEzrat HaShem, Inc.
EIN: 81-2041082 (US 501(c)(3) non-profit)