דלג לתוכן העיקרי

Account & Data Deletion

How to request deletion of your Rabenu account and all personal data stored with it

Last updated:

This page explains how to delete personal data held for you by Rabenu — either individual items, or your entire account and everything in it. A full description of what is stored is in the privacy policy.

1. What you can delete yourself, right now

Most personal content can be deleted immediately, without contacting us, from your personal area (sign-in required):

  • Bookmarks and highlights, together with their notes
  • Favourite excerpts, excerpt notes and tags
  • Excerpts inside a booklet, and whole booklets
  • Shared documents, knowledge-map nodes and their comments
  • Project chat messages
  • Projects and teams you own, and invite links you created
  • Playlists, audio bookmarks and favourites in the audio library

These deletions are immediate and irreversible — there is no trash.

2. Deleting your entire account, from inside the Service

Full account deletion is available in the Service itself and does not require contacting us. The deletion screen is at My account (sign-in required), also reachable from the header of your personal area. The same screen lets you download a copy of your personal data before deleting.

Deletion takes three deliberate steps:

  1. Review. An itemised list of what is about to be deleted, with the real counts from your own account, alongside a link that downloads a JSON file of the personal content you created.
  2. Typed confirmation. You must type the exact Hebrew phrase מחק את החשבון שלי (“delete my account”) — not a checkbox, not another button.
  3. Re-authentication. If the account has a password, you re-enter it. If you signed in with Google and therefore have no password, a one-time code is emailed to the account’s address and you enter that. Both the phrase and the re-authentication are checked again on the server, not only in the browser.

Once confirmed, deletion happens immediately: there is no waiting period, no way to cancel and no recycle bin. The whole purge runs as a single database transaction, so if any step of it fails your data is not deleted and the account is left intact — you can simply sign in again and try later.

One narrow exception, stated because it is true rather than because it is likely: your sign-in credentials are held by a separate identity service, and removing them is the last step before the transaction is closed. If the server were interrupted in the instant between those two events, the sign-in would already be gone while some records had not yet been committed as deleted. Nothing would be readable — there is no way to reach that data without an account — but it would still exist. If you find you can no longer sign in and want that confirmed or finished, email [email protected] and we will complete the deletion by hand.

3. If you cannot sign in

The route in §2 requires a signed-in session. If you have lost access to your account, you can request deletion by email:

  1. Email [email protected] from the email address the account was created with. Sending from the registered address is how we verify the request is yours.
  2. Use the subject line Account deletion request.
  3. State the account’s email address in the message, and mention it if you signed in with Google.
  4. Say whether you want the whole account deleted, or only certain categories of data.

Export or save anything you want to keep before sending the request — deleted content cannot be restored.

Our timeframe. [email protected] is a monitored mailbox for privacy and deletion requests. We will act on your request without undue delay and in any event within one month of receiving it — the period set by GDPR Article 12(3). In practice most deletions happen well before that. If we cannot verify that the request is yours, we will ask for a further detail before deleting anything: deleting the wrong person’s account is irreversible harm, so we would rather ask.

4. Exactly what is deleted

The purge walks every place in the database where your user id can be held — dozens of tables, not merely the content visible in the interface. When it finishes, an automatic check confirms that no record carrying your id survives anywhere; if one does, the entire deletion is rolled back rather than left half-done.

  • Your user record at the identity provider — email address, password or Google account link, name and profile picture. You will not be able to sign in again.
  • Personal reading content — bookmarks, highlights, personal notes, favourite excerpts and their notes, tags and flashcard decks.
  • Booklets (kontrasim) — booklets you created and the excerpts inside them, and excerpts you added to other people’s booklets.
  • Progress and study — reading positions, progress through learning sequences, study streaks and daily totals.
  • The audio library — playback positions, audio bookmarks, playlists and their items, favourites, listening preferences and recommendation feedback.
  • Measurement records that carry your user id — search logs (including the text of the queries you typed), listening events, popup events and daily-inspiration clicks. These are deleted outright, not merely detached from your name.
  • Notifications — the notifications generated for you. Where you appear as the actor in someone else’s notification, the link to you is severed.
  • Your presence in shared spaces — your membership in projects, teams and shared booklets, invite links you created, and your votes and emoji reactions.
  • A shared space you are the only one in — a project or team with no other member is destroyed in full, together with everything in it, including content left there by people who had already left. A booklet is destroyed only if it has no other members and holds no excerpts belonging to anyone else.

Note: deleting a note, a shared annotation or a node you created also removes the replies other people wrote on it, because they depend on it.

5. What may remain, and why

  • Content you shared in a space that still exists. If a project or team still has other members — or a booklet still has other members or other people’s excerpts in it — that space and the content you wrote in it — chat messages, shared annotations, shared documents and knowledge-map nodes — stay where they are but are detached from your name: the owner field is replaced with a single “deleted user” placeholder shared by everyone who deletes their account and unique to no one, so the content can no longer be attributed to you. The text itself remains.
  • Editorial and administrative records (only relevant if you held admin rights) — site-wide cross-references and mappings, learning sequences, system settings, the admin operations log and published share templates. The records stay as part of the site; the author name is stripped from them.
  • Data that is not identifiable. Measurement records that never carried a user id — for example browser performance metrics (page path only, with query string and fragment stripped) and aggregate per-recording totals — cannot be linked back to you and are therefore not deleted individually.
  • A record that the deletion happened. One technical row is kept: a one-way hash of the account id, how many records were removed, and the date. It contains no email address, name, IP address or content.
  • Backups. Deletion removes your data from the live service immediately. Copies may remain in operational backups for some time afterwards. We do not restore a backup in order to recover deleted account data, and a copy that remains in a backup is not returned to the live service.

Why it works this way. The choices in sections 4 and 5 are deliberate policy, not an accident of the implementation:

  • Content you shared in a space that still exists is kept and de-identified rather than deleted, so that one person leaving does not gut a conversation or a shared document belonging to other people.
  • The measurement records that carry your user id — search logs, listening events, popup events and daily-inspiration clicks — are deleted outright rather than anonymised. That means our aggregate search analytics lose those rows on every deletion, and it is the trade deliberately chosen here: privacy ahead of measurement quality. (Search logs are deleted after 90 days in any case, with or without an account deletion.)
  • There is no grace period — no few-day window in which the deletion can be undone. That is a deliberate decision: a deleted account is deleted. It is why the deletion screen shows you the itemised list first and offers a copy of your data to download.
  • Editorial and administrative records stay as part of the site with the author name stripped, so deleting an editor’s account does not delete content the site itself is built on.
  • Deleting an item also removes other people’s replies that depend on it — a reply cannot exist without the thing it replied to.

6. Data stored on your device

The Service keeps a local copy of books and chapters you viewed, display preferences, audio-player state, and a queue of actions created while offline. This lives on your device only and is not deleted by us. To remove it:

  • In a browser — clear cookies and site data for rabenu.app in your browser settings.
  • In the app — uninstall the app, or clear its app data in your device settings.

7. Third-party measurement

Aggregate usage measurement (Google Analytics) never receives your account id, so deleting your account does not affect it. You can block it with your browser or device controls.

8. Questions

For anything about data deletion: [email protected]. See also the privacy policy.

Back to home