Privacy Policy — Jewish Ground-Truth Intelligence (J-GTI) API by TATEH
Effective 2 October 2026 · served at https://api.tateh.org/privacy
This policy covers the J-GTI API at https://api.tateh.org: the REST API (/v1), the MCP server (/mcp), the account page (/account) and the support form (/support).
What we receive
- The question. These are the parameters of each call: search words, a place name or address, a location or coordinates, dates.
- Your API key, if you send one. We check it and do not keep it.
- Your email address, if you create an account. Sign-in is handled by Supabase Auth, which keeps the address and sends the sign-in link.
- What you write in the support form, and a reply address if you give one.
- Your IP address, which is part of every network connection.
What we keep
One record per call (the usage ledger). It holds:
- the time;
- the tool or endpoint;
- REST or MCP;
- the response status and error code;
- latency;
- whether a live re-check ran;
- an estimated cost;
- a request id and a trace id;
- the key's id and the account it belongs to.
It never holds the key itself, the text of your question, your location, your IP address or any chat content.
Calls without a key (the anonymous MCP beta). The per-client rate limit is counted against the IP address in memory only, for at most a few minutes. The ledger keeps only a one-way keyed hash of it, which cannot be turned back into the address.
Keys. We store a keyed hash of each key, never the key itself, together with its prefix, plan, status and dates.
Accounts. We store the email address and the account id, the keys of the account, and daily and monthly call counts.
Support messages. We store the text and the reply address you gave.
Why
To answer your calls, to prevent abuse, to enforce rate limits and daily or monthly allowances, to measure cost and reliability, and to answer support messages.
What we do not do
We do not sell data. We do not use your questions to train models. We do not build advertising profiles. Answers contain no tracking.
Who else processes data
- Railway hosts the service.
- Supabase hosts the database and handles account sign-in.
- Cloudflare may carry traffic.
We share call records with no one else unless the law requires it.
Retention
- Usage ledger: 13 months, then deleted automatically.
- Keys: kept while active. Revoked keys are kept 90 days, then deleted.
- Accounts: kept until you ask us to delete them through the support form.
- Support messages: 24 months.
The facts in our answers
Answers are built from public sources, and each one is named with a link and a date:
- certifying agencies' own lists;
- businesses' own websites and menus;
- public government registers;
- open map data;
- organisations' own event feeds;
- astronomical calculation (for Shabbat, holiday and zmanim times).
AI is never a source.
Children
The service is not directed at children under 13.
Your choices
You can revoke your keys yourself at https://api.tateh.org/account. To have your account and its records deleted, write through https://api.tateh.org/support.
Changes
Material changes are announced at https://api.tateh.org/changelog at least 14 days before they take effect.