Yossi
Privacy Policy

Privacy that respects the way you wrap.

This policy explains what information Yossi collects, where it goes, and the choices you have when you use the app to share daily wraps, prayer, and community.

Effective July 29, 2026

What this policy covers

Yossi is operated by Joseph Kline. It is intended for people age 13 and older who want to share tefillin wraps, prayer, and encouragement with friends and family. This policy applies to the Yossi iOS app and services that support it.

In short: content you choose to post or send is processed to provide the social features you requested. Saved sunset places and reminder settings are currently kept on your device by the app and are not sent to Supabase by the current implementation unless you separately attach a location to a post.

Information we collect

Account and profile information

When you create or use an account, Yossi may process your email address, password authentication result, display name, username, profile photo, bio, public/private account setting, and the account identifier assigned to you. Usernames are searchable by signed-in users so people can find friends.

Apple and Google sign-in

You may authenticate through Apple or Google. Yossi receives the identity information and token claims needed to create or sign in to your Supabase account, such as a provider account identifier, email when provided, and display information when provided by the provider. Yossi does not receive or store your Apple or Google password. Apple and Google process information under their own privacy policies.

Content you create

Yossi processes the content you choose to create, including tefillin photos, captions, comments, likes, tags, prayer or refuah shelema requests, direct and group messages, shared-post references, reports, blocks, hides, and other content or actions associated with your account. The current database schema also supports video media, although the current daily-wrap composer is photo-only.

Location attached to a post

If you choose to attach a location to a post, Yossi sends and stores the city or location label and may send and store precise latitude and longitude coordinates. This information is optional and is shown according to the post and account visibility rules described below.

Permissions and device data

The app can request access to the camera and photo library so you can capture or select a wrap. It can request Core Location access and use Apple MapKit or geocoding to search for cities and calculate sunset times. It can request notification permission to schedule wrap and sunset reminders through Apple UserNotifications.

In the current app, saved sunset locations, current-location sunset calculations, notification preferences, and reminder schedules are stored locally on the device. The current code does not upload those local sunset locations or current coordinates to Supabase. A location you deliberately attach to a post is different: that post location is sent to and stored by Supabase.

How we use information

  • To create accounts, authenticate you, maintain your profile, and keep you signed in.
  • To display feeds, profiles, posts, comments, likes, tags, prayer requests, and messages according to your choices and the app’s access rules.
  • To store and deliver photos and other post media you choose to upload.
  • To send in-app or device notifications that you enable, including daily wrap reminders, sunset reminders, and friend-post notifications.
  • To operate reporting, hiding, blocking, follow/friend, moderation, and account-safety features.
  • To troubleshoot, protect the service, prevent abuse, and respond to support or deletion requests.

How your content is shared

Yossi uses account and post visibility rules. A public account’s public posts are intended to be visible to other people using Yossi. A private account’s posts are intended to be visible only to friends. Friend-only prayer requests are intended for friends. Messages are available to the members of their one-to-one or group conversation. You can also share a post inside a message.

People who can view content may be able to copy, screenshot, or otherwise retain it. No online sharing setting can prevent that completely. You can report or block accounts and can hide posts for your own view.

Profile photos: the current implementation stores profile images in a public Supabase Storage bucket. Do not upload a profile photo that you do not want publicly accessible. Post media is stored in a private bucket and the app requests time-limited signed URLs to display it.

Supabase, storage, and security

Yossi uses Supabase for authentication, its database, storage, and the server-side APIs used by the app. Post images are stored in the private post-images bucket and are displayed through signed URLs. Profile images are currently in the public profile-images bucket, as described above.

The database has row-level security policies and access checks for profiles, posts, messages, prayer notes, moderation records, and social relationships. We use these controls to limit access, but no transmission or storage system is guaranteed to be completely secure. Supabase and other service infrastructure may process ordinary technical information needed to deliver and protect the service.

Yossi does not put service-role keys, provider client secrets, or other private credentials in the public policy page or the iOS app’s user-facing experience.

Retention and deletion

We keep account, profile, and user-generated content while it is needed to provide the service or until you delete it, archive it, or request deletion. An archived post is removed from ordinary profile/feed views but can remain available in your archive until deleted. Active prayer notes are designed to expire after 24 hours; after expiry they are excluded from active-note queries, but the current schema does not promise immediate physical deletion of the underlying database row.

The app includes an account-deletion action that requests deletion of your Supabase account and related database records. Current storage cleanup is not guaranteed to cascade for every uploaded object, so contact us at yossi.tefillin@gmail.com if you want us to verify removal of remaining media or other information. Backups or security logs may retain limited copies for a period under the provider’s operational practices.

Your choices and rights

  • Choose whether your account is public or private and choose whether to attach a location to a post.
  • Allow or deny camera, photo-library, location, and notification permissions in iOS Settings.
  • Edit your profile, delete or archive posts, remove comments where available, and manage follows/friends.
  • Hide posts, block accounts, report content or accounts, and request account or data deletion.
  • Ask us to access, correct, or delete personal information associated with your account by emailing us.

Depending on where you live, you may have additional privacy rights. We will respond to a verifiable request as required by applicable law. We may need to verify that the request is connected to the account owner.

Reporting, blocking, and safety

When you report or block someone, Yossi processes the report, account identifiers, relevant post or message references, and any explanation you submit to provide safety and moderation tools. Reports may be reviewed by the operator or service providers supporting Yossi. Blocking and hiding controls are intended to affect what you see and who can interact with you, but they cannot remove information someone has already copied outside Yossi.

Children

Yossi is intended for users age 13 and older and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child under 13 has provided information, contact us so we can investigate and take appropriate steps.

Advertising and analytics

Our audit of the current Xcode project, Swift package configuration, and app source found no advertising SDK or analytics-tracking SDK/configuration. We do not sell personal information. This statement applies to the audited build and should be re-checked if new SDKs, vendors, advertising, analytics, or monetization features are added.

Changes to this policy

We may update this policy when Yossi’s features, data practices, or legal obligations change. We will post the updated version at this URL and update the effective date. Your continued use of Yossi after an update means the updated policy applies to future use.

Contact

For privacy questions, access or deletion requests, or concerns about this policy, contact:

Joseph Kline
yossi.tefillin@gmail.com