Privacy policy
Draft — published ahead of formal legal counsel review. It describes what the product actually does today, in plain language, but it is not a final, lawyer-reviewed policy.
Last updated: July 22, 2026
AutoPulpit is a product of Gethsemane Technologies LTD (“Gethsemane Technologies,” “we,” “us”). This policy explains what information AutoPulpit collects, how it's used, and the choices a church has over its own data.
AutoPulpit is built to run a church's operations — a website, forms, member and attendance records, follow-up workflows, and an AI assistant — from one login. That means we hold information both about the people who sign in to run the church (staff and volunteers) and about the people that church serves (members, visitors, and website guests). This policy covers both.
Who this applies to
A church or ministry that creates an AutoPulpit account is the customer. For any information a customer enters about its own members, visitors, or congregants — names, contact details, attendance, prayer requests, and so on — that customer is the data controller, and AutoPulpit acts as a data processor on its behalf. We process that data only to provide the features the customer has enabled, and only under the customer's instructions.
Information we collect
Account information (staff and volunteers)
- Name, email address, and password (stored as a salted hash, never in plain text) for email/password sign-in.
- If you choose “Continue with Google,” your name, email, and profile photo as provided by Google.
- Sign-in metadata for each session — IP address and browser/device (user agent) — used for security (detecting suspicious logins) and kept for as long as the session record exists.
Information a church enters about its own people
Depending on which apps a church has enabled, this can include:
- Member and attendance records: name, phone, email, birthday, gender, address, notes, and household/family links — including a link between a child's record and a parent or guardian's record, where a church uses AutoPulpit for children's ministry check-in.
- Form submissions: whatever a church's own form asks for — visitor cards, event registrations, volunteer sign-ups, and prayer requests submitted through a published form.
- Pastoral and sensitive content: testimonies and prayer requests, which the product lets a church mark with their own privacy level (for example, public, members-only, or pastoral-only) and consent status. We store this content as instructed by the church and don't change its visibility ourselves.
- Follow-up and pipeline notes: care-team notes on an individual, which a church can mark as team-visible, private, or pastoral-only within its own account.
- Documents and media: files a church uploads or generates (contracts, letters, reports, images, audio, and video), including any it chooses to make available via a public share link.
- Leadership directory records: name, title, department, contact info, and signature images for a church's own leadership and document-signing workflow — including for outside signers who may never create an AutoPulpit account.
- Automated message history: a log of AI-drafted follow-up messages (email, SMS, or WhatsApp) a church's workflows generate, and whether a staff member sent, edited, or discarded them before delivery.
- AI Command Center conversations: the prompts staff send to AutoPulpit's AI assistant and the responses it returns, stored per church.
Public website visitors
- If a church publishes a website through AutoPulpit, visitors to that site who submit a form or subscribe to its newsletter have that information (for example, an email address) stored for that church.
- If you try the AI website demo on autopulpit.site without an account, we keep a lightweight, anonymous session record (a device fingerprint and message count) so the demo works — this isn't tied to an identity.
Billing information
Subscription payments are handled by Stripe. We store the resulting customer and subscription IDs, but AutoPulpit never receives or stores full card numbers — that happens entirely within Stripe's systems.
Children's information
AutoPulpit does not knowingly collect information directly from children, and no child creates their own AutoPulpit account. Where a church uses features like children's ministry check-in, any information about a minor is entered by church staff or volunteers on the child's behalf and linked to a parent or guardian's own record. The church remains responsible for obtaining any consent required — from a parent, guardian, or under applicable law — before entering a minor's information into AutoPulpit.
How we use information
- To provide and operate the apps a church has enabled.
- To power AI features (drafting messages, generating website copy, answering Command Center prompts) using the content a church has stored.
- To send account-related email, like password resets and form-submission notifications.
- To secure accounts and investigate abuse or suspicious activity.
- To bill for paid subscriptions.
- To improve AutoPulpit itself — only in aggregate and only for a church that has turned on its own usage-data sharing setting; this is off unless a church opts in.
We do not sell personal information, and we do not use church data to serve ads.
Who we share information with
We use a small number of service providers to run AutoPulpit. Each only receives what it needs to do its job, and none of them may use church data for their own purposes:
- Anthropic (Claude) — powers AI drafting, website generation, and the Command Center assistant.
- Resend — delivers transactional email (password resets, form-submission alerts).
- Twilio — delivers SMS and WhatsApp messages sent from workflow automations.
- Stripe — processes subscription payments.
- Cloudflare — stores uploaded files and media (documents, images, audio, video).
- Pexels — provides stock photography when a church chooses to fill placeholder images; only a search term is sent, not personal data.
- Canva — if a church connects its own Canva account, to generate graphics in that account. Connection tokens are encrypted at rest and are only used for that church's own Canva account.
- Google — if you choose “Continue with Google” to sign in.
- Railway — hosts our servers, database, and background job infrastructure.
We may also disclose information if required by law, or to protect the rights, property, or safety of AutoPulpit, our customers, or others.
Cookies
AutoPulpit currently uses only the cookies needed to keep you signed in — including a session cookie shared across the dashboard and a church's subdomain so you stay signed in on both. We don't currently run advertising or analytics tracking on AutoPulpit. If that changes, we'll update this section first.
Security
Passwords are hashed, never stored in plain text. Tokens for connected third-party accounts (like Canva) are encrypted at rest. Traffic to AutoPulpit is encrypted in transit. No system is perfectly secure, and we can't guarantee absolute security, but we design AutoPulpit to keep church data private by default.
Data retention and deletion
A church's data belongs to that church. Disabling an app keeps its data in an archived, inactive state rather than deleting it immediately, so nothing is lost by accident. A church can request full deletion of its account and data at any time by emailing us — we'll confirm what's being deleted before we do it.
Your choices
- A church controls whether it shares aggregate usage data with us, via a setting in its own account.
- You can update your account information, or disconnect a connected third-party account (like Canva), at any time.
- You can request a copy of, or the deletion of, a church's data by contacting us below.
Changes to this policy
As AutoPulpit adds features, we'll update this page to reflect what actually happens with data, and note the date at the top. We'll email account holders about material changes.
Contact us
Questions about this policy, or about a specific church's data, can be sent to hello@autopulpit.com. AutoPulpit is a product of Gethsemane Technologies LTD.