This policy describes how Jérémy G (hereinafter “Shivim”, “we”) collects and processes your personal data when you use the service shivim.ai and the associated application.
In short. Shivim is a Torah study assistant powered by artificial intelligence. To operate, the service must retain your account (email, profile), your conversations and — if you use Ḥavruta mode — your audio/video recordings. No data is ever sold. You can export or delete your account at any time from your personal area.
1. Identity of the data controller
The controller of your data is:
- Legal name
- Jérémy G
- Legal form
- Entrepreneur individuel — micro-entreprise
- Registration
- SIRET 798 287 850 00035
- Contact email
- support@shivim.ai
- Data Protection Officer (DPO)
- dpo@shivim.ai
2. Data collected
We collect only the data necessary for the service:
2.1. When creating an account
- Email address and password (stored in an irreversible form)
- First and last name (optional)
- Preferred language
- Study tradition and level (optional, to personalise the answers)
- Single-use email verification code
2.2. When using the chat
- Your questions, the context of conversations and the answers produced by the assistant
- Files or images you attach, kept for as long as the conversation exists
- IP address used solely to enforce usage limits and combat abuse
2.3. During a Ḥavruta video session
- Session identifier and room metadata (title, date)
- If you enable recording (explicit consent required): audio and/or video stream, text transcription, automatic summary
- List of participants connected to the session
2.4. During a Premium payment
- Billing email and technical identifiers required for your subscription
- Subscription status and billing history
- No banking data is ever transmitted to or stored by Shivim: the payment is handled entirely by our payment provider on its secure pages
2.5. Security and support
- For optional two-factor authentication: phone number or secret generated by your authenticator application
- For support tickets: subject, message and minimal technical information useful for diagnosis
- For QR-code logins: technical elements needed to combat session hijacking
2.6. Kids mode (optional, under parental responsibility)
If you enable Kids Mode for your children: first name, age, avatar and a parental control code stored in an irreversible form. No other data is collected about children; Kids Mode is designed to comply with the CNIL recommendations on services aimed at minors.
2.7. Improvement logs (disabled by default)
To diagnose incidents and improve the quality of answers, we may record an anonymised sample of exchanges. This logging is disabled by default in production and can only be activated in a targeted and temporary manner for diagnostic purposes. It is never used to train artificial intelligence models.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creation and management of your account | Performance of the contract (art. 6.1.b) |
| Answering your questions and chat history | Performance of the contract |
| Ḥavruta sessions and recordings | Explicit consent (art. 6.1.a) obtained when recording starts |
| Premium payment and billing | Performance of the contract + legal obligation (accounting) |
| Authentication, fraud prevention, anti-spam | Legitimate interest (art. 6.1.f) |
| Weekly study report by email | Consent (opt-in in the settings) |
| Answers to support tickets | Performance of the contract |
| Aggregated statistics (without identification) | Legitimate interest |
4. Subprocessors and recipients
To provide the service, we rely on subprocessors grouped into categories. Each subprocessor has signed a data processing agreement (DPA) compliant with the GDPR and commits to standard contractual clauses when transfers outside the EU are necessary:
| Category | Purpose | Data concerned | Location |
|---|---|---|---|
| Paiement | Paiement, facturation et abonnements | Email de facturation, identifiants prestataire de paiement, statut d'abonnement | Union européenne ; transferts hors UE encadrés par CCT |
| Visioconférence Ḥavrouta | Visioconférence Ḥavrouta et enregistrement de séances | Identifiants de salle et de participant, flux audio/vidéo si enregistrement activé | Union européenne / États-Unis ; transferts hors UE encadrés par CCT |
| Modèles d'intelligence artificielle (réponses chat | Modèles d'intelligence artificielle (réponses chat, transcription, synthèse vocale) | Texte de votre question, contexte récent du chat, fichiers ou audio que vous fournissez | Union européenne / États-Unis ; transferts hors UE encadrés par CCT |
| Stockage des enregistrements | Stockage des enregistrements et pièces jointes | Fichiers média et transcriptions associés à votre compte | Union européenne / réseau distribué |
| Envoi des emails transactionnels (vérification | Envoi des emails transactionnels (vérification, magic link, support, rapports hebdo) | Email destinataire, contenu de l'email | Union européenne / États-Unis ; transferts hors UE encadrés par CCT |
| Sécurité du compte (2FA SMS | Sécurité du compte (2FA SMS, anti-spam, lutte contre la fraude) | Numéro de téléphone si 2FA activée, signaux navigateur agrégés | Union européenne / États-Unis ; transferts hors UE encadrés par CCT |
| Hébergement applicatif | Hébergement applicatif et base de données | Ensemble des données du compte, conversations, configurations | Union européenne |
The named list of subprocessors (provider name, exact jurisdiction, link to their privacy policy) is kept up to date internally and provided on simple request to dpo@shivim.ai. This practice aims to protect our technical setup while fully respecting your right to information in accordance with Articles 13 and 14 of the GDPR.
Your data is never sold, never transferred to data brokers and never used by Shivim to train artificial intelligence models.
5. Retention period
- Active account: for as long as you use the service. After 24 months without login, your account may be anonymised following email notification.
- Conversations: kept until you delete them; deleted within 30 days of account deletion.
- Ḥavruta recordings: kept according to your choice (by default, until manual deletion or account deletion).
- Payment data: kept for 10 years (French accounting obligation for invoices).
- Technical server logs: 30 days maximum.
- Closed support tickets: 3 years.
6. Your GDPR rights
In accordance with the GDPR, you have the following rights:
- Access: obtain a copy of the data concerning you
- Rectification: correct inaccurate data
- Erasure (“right to be forgotten”): permanent deletion on simple request
- Restriction: temporarily freeze the processing
- Portability: retrieve your conversations in a structured format (JSON)
- Objection: refuse the use of your data for legitimate interest purposes
- Withdrawal of consent: at any time for processing based on this ground
- Set directives on the fate of your data after your death
Most of these actions (export, account deletion, email unsubscription, management of recorded Ḥavrutas) are accessible directly from your My account area. For any other request, write to dpo@shivim.ai. We respond within 30 days.
If you consider that your rights are not respected, you may lodge a complaint with the CNIL (cnil.fr) or the supervisory authority of your country of residence.
7. Security
- All exchanges are encrypted in transit according to the state of the art
- Passwords are stored in an irreversible form, never in clear text
- Audio and video recordings are encrypted at rest
- Two-factor authentication is available for all accounts
- Authentication sessions expire automatically after a period of inactivity
- Our administration access is protected by strong authentication and our critical subprocessors are certified against recognised standards (ISO 27001, SOC 2 or equivalent)
8. Minors and Kids mode
The main service is intended for people aged 15 or over (the legal age of digital consent in France). Users between 13 and 15 must obtain their parents' consent before creating an account.
Kids Mode is designed for children aged 6 to 12 under the responsibility of a logged-in parent: no account is created in the child's name, no advertising is served in Kids Mode, and sensitive content is filtered. The parent controls the activation and deactivation of the mode via a PIN code.
9. Transfers outside the European Union
Some of our subprocessors may be located outside the European Union. These transfers are governed by:
- The Standard Contractual Clauses (SCC) approved by the European Commission
- The Data Privacy Framework (EU-US DPF) when the subprocessor is registered under it
- Additional technical measures: minimisation of data sent and systematic encryption in transit
Details per subprocessor (jurisdiction, applicable transfer mechanism) are provided on request to dpo@shivim.ai.
10. Cookies and trackers
Shivim uses no advertising cookies and no behavioural analytics tools. The only trackers present are strictly necessary for operation (session, language, payment). For the full details, see our Cookie Policy.
11. Changes to the policy
We may update this policy to reflect a change in the service or in the regulations. Any substantial change will be notified to you by email at the address linked to your account at least 15 days before it takes effect. The current version is always available on this page, dated at the top of the document.
A question, a doubt? Write to dpo@shivim.ai or use the contact form. We respond within 72 business hours.