Privacy policy
Last updated: September 1, 2026
We're a small team building software for churches. We take privacy seriously because the data flowing through our system — sermons, pastoral conversations, prayer requests — is sensitive. This page describes what we collect, where it goes, and how to delete it. It's written in plain English on purpose; if anything is unclear, email help@churchtranslator.ai.
What we collect from churches
When a church signs up, we collect: the church's display name, the admin's email address, your billing info (handled by Stripe — we never see your card number), and your language + branding choices. We also collect usage telemetry: minutes of translated audio per language, listener counts per service, latency measurements, and which capture devices are connected.
We never sell or share any of this with third-party advertisers, data brokers, or denominational organizations.
What we collect from listeners
Almost nothing. Your church's listener page asks for one thing: which language to play. We don't ask for an email, name, phone number, location, or any account. We log an anonymous session ID (random string), the IP address (used only to detect duplicate listeners + block obvious abuse), and the language they picked. None of this is shared with the church admin in a way that identifies individual listeners — admins see counts per language, never an individual person's history.
Sermon audio — the important part
Live sermon audio flows from your capture device (the Mac or Windows capture app, or the in-browser capture page) → our servers on Fly.io → our real-time translation engine → back through our servers → out to listener phones. Your church chooses the engine (Translation V1 or Translation V2). In all cases the audio does not sit in long-term storage by default — once a segment is delivered to listeners it's discarded server-side. Aggregate metrics (minute counts, latency) persist; the audio bytes themselves do not.
Our translation engines operate under enterprise API terms that state audio submitted for real-time translation is not used to train the underlying models and is retained only briefly for abuse-detection purposes before being deleted. We'll update this page if those terms change in a way that affects this.
The Mac capture app also offers optional local recording of translated audio. An operator chooses a folder on the booth Mac, and the files are written to that folder. They are not uploaded to a ChurchTranslator.AI storage bucket. Local recording is off until an operator chooses a folder and languages to record.
Who we share data with (processors)
We use the following third-party services to run the platform:
- Stripe — payment processing. Stripe handles all card data; we never see it.
- Clerk — dashboard sign-in (your admin email + password / social sign-in). Stores per-tenant metadata (which church a user belongs to) and nothing else about you.
- Fly.io — server hosting for the translation pipeline, dashboard, and listener app. Data is encrypted in transit and at rest.
- Cloudflare — edge networking, DDoS protection, and free TLS certificates for custom domains.
- Real-time translation engines — the AI providers behind our engines process sermon audio to produce the live translation: OpenAI (Translation V1) and Google (Translation V2 / Gemini). Audio is handled under enterprise no-training API terms and is not retained long-term.
- Resend — transactional email delivery (welcome, billing, and service notices to your admin email).
- Google Analytics — anonymous page-traffic statistics for this website (the marketing pages and the church admin dashboard — never the listener page). It runs in consent mode: it sets no cookies and gets only aggregated, anonymous pings unless you click "Allow" on the analytics banner. We don't send it names, emails, sermon content, or anything you type into the dashboard.
We don't use advertising networks, tracking pixels (no Facebook Pixel), or session-recording tools. The only analytics is the consent-gated Google Analytics described above, and the listener page your congregation uses has no analytics at all.
Cookies
We use cookies for sign-in sessions (Clerk session cookies) and remembering your dashboard preferences. Google Analytics sets its measurement cookie only after you click "Allow" on the analytics banner — declining (or ignoring) the banner keeps this site cookie-free beyond sign-in. The listener page uses one local-storage entry to remember the visitor's language choice across visits — nothing that travels off-device.
How to delete your data
To cancel service, open the Stripe Customer Portal from the Billing page and click Cancel. Your translation service stays live until the end of the current billing cycle. Cancellation stops the service but does not delete the church account: we retain its configuration and branding so it can be reactivated later.
To permanently delete the church account, use Delete church account in the Billing page's Danger zone. The workflow requests immediate subscription cancellation, revokes capture-app access, removes the tenant configuration, and requests removal of team sign-ins and the managed hostname. If Stripe cannot confirm a billing step, the church account is kept and the dashboard reports the failure. If an identity or DNS provider fails after local deletion, the dashboard reports the remaining cleanup for support instead of claiming complete success. Recordings saved locally by the Mac app stay in the folder your operator selected; delete those files on the Mac separately.
For individual data-subject requests (GDPR / CCPA), email help@churchtranslator.ai with the subject line "Data request". We respond within 30 days as required.
Children
The platform is sold to churches, used by adult admins. The listener page is open to anyone in the room, including children, but it collects no personal information from listeners. We don't knowingly market to or collect data from children under 13.
Security
We use industry-standard encryption (TLS 1.3 in transit, AES-256 at rest for stored data). Admin authentication is MFA-capable through Clerk. Capture-app pairing tokens are unique per device, revocable from the dashboard, and never shared across tenants. We patch infrastructure dependencies weekly. We'll notify affected churches within 72 hours of confirming any breach that exposes their data.
Updates to this policy
We'll post material changes here with a new "last updated" date and email all active tenants. Continuing to use the service after a posted change means you accept the new terms.
Contact
ChurchTranslator.AI — a product of Kulinich.Tech.
help@churchtranslator.ai
