Privacy Policy

Version 2026-09-07 · Effective 2026-09-07

Mekorot is used by schools and by individual learners. This policy explains what we collect, why, and what we never do with it.

1. Who we are

Mekorot provides an adaptive interlinear Torah reader used by schools, teachers, and individual learners. This policy covers the Mekorot website and application.

2. What we collect

DataWhy we hold it
Name and email addressTo identify an account and let a teacher or administrator find a student on their roster.
Password (hashed) or Google sign-in identifierTo sign you in. Passwords are stored only as salted hashes; we never hold the plaintext.
Username, where a class signs in without email addressesSome younger classes have no school email. Those students sign in with a username issued by their teacher instead.
GradeTo pitch the reader and its grammar explanations at the right level — a grade 3 explanation is not a grade 10 one. We derive an approximate age from the grade for that purpose. We do not ask for or store a date of birth. Grade advances by one each August unless a teacher changes it.
School and class membershipTo show a teacher their own students and to scope a school administrator to their own school.
A link to a parent or guardian's account, where one existsSo a parent can see their own child's progress, and so a student who has no email can recover their sign-in through their parent.
Profile picture, if you sign in with GoogleGoogle supplies a link to your account picture, which we show on your own profile. You can sign in with an email address and password instead.
A record of accepting the Terms of Use — when, which version, and whether an adult accepted on the account's behalfTo show that the account was created with consent, which matters most for accounts belonging to minors.
Learning progress — which words are mastered or being learned, quiz answers and timingsTo adapt the reader to the learner and to show a teacher how their class is doing. This is the core function of the Service.
Basic technical logsTo keep the Service running and diagnose faults.

3. Google user data

If a teacher or administrator chooses to connect Google Classroom, we ask Google for permission to read the following, and nothing else:

Permission requestedWhat we do with it
classroom.courses.readonlyShow the list of courses you teach, so you can pick one to import.
classroom.rosters.readonlyRead the list of students in the course you picked.
classroom.profile.emailsRead those students' email addresses, which is how we match each one to the right Mekorot account, or create it if there is none.

These permissions are read-only. We never write to Google Classroom, never modify or delete anything in it, and never touch coursework or grades.

We store the roster information described above, and an encrypted Google authorisation token so that a re-import does not require signing in again. That token is encrypted at rest and can be revoked at any time by clicking Disconnect in Mekorot, or at myaccount.google.com/permissions.

Limited Use. Mekorot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as required to run the Service or to comply with law, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with law, or where the data has been aggregated and anonymised.

4. Students and children

Where a school uses Mekorot, the school decides which students are enrolled and we act on the school's instructions as its service provider. We collect from students only what is needed to run the reader and report progress to their own teachers. We do not build advertising profiles, we do not show advertising, and we do not sell student data — ever.

We hold a student's grade, and derive an approximate age from it, so that explanations are pitched at the right level for the reader. We do not ask for a date of birth, and we do not use age or grade for anything other than choosing how the material is explained.

A parent or school may ask us to delete a student's data at any time using the contact address below.

5. What we never do

6. Who can see what

A teacher sees the students in their own classes. A school administrator sees their own school. Individual learners see only themselves. Mekorot staff can access data where necessary to operate and support the Service.

7. Aggregate and anonymised reporting

We publish and share statistics about how the Service is used and how learners progress — for example, the average number of words learned over a term, or the change in reading fluency across a group. This supports research, product improvement, and reporting to partners and to current and prospective investors.

These statistics never identify anyone. Specifically:

Because these statistics identify nobody, we may keep and use them after an individual account has been deleted.

8. How long we keep it

We keep account and progress data for as long as the account exists. When a school removes a student, the account is deactivated and hidden from the school's staff, and the student can no longer sign in; the underlying record is retained so that the removal can be reversed and so a school's historical reporting stays intact.

If you ask us to erase personal data, we will do so within 30 days of the request, except where we are required to keep records to comply with law. Google authorisation tokens are deleted immediately when you click Disconnect.

9. Your choices

You may request access to, correction of, or deletion of your personal information. Students at a school should ask their teacher or school administrator, who can act on their behalf. Anyone may write to us directly at the address below.

10. Security

Data is transmitted over encrypted connections. Passwords are stored as salted hashes. Google authorisation tokens are encrypted at rest. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data we hold.

11. Changes

If we change this policy we will update the version above. Material changes affecting how we use Google user data or student data will be communicated to affected schools.

12. Contact

Questions, or requests about your data: info@mekorot.org

Terms of Use · About