Pulpit & Pew Privacy Policy

Last updated: July 2026

This policy describes what Pulpit & Pew ("the app," "we," "us") does with your data. It's written to match exactly what the app's code actually does — not generic boilerplate.

The short version

What stays only on your device

For every plan: sermon recordings, transcripts, notes, summaries, and all generated content (discussion guides, devotionals, Family Worship Guides, Church Fathers references, etc.) never leave your device unless you explicitly export/share it yourself, or your church is on a team plan and you use the sync feature (see below).

What we do see, and why

AI-generated content (text): the sermon text you're generating from is sent to our backend, which forwards it to Anthropic to produce the result. Cached for 30 days, keyed by content, not by you.

Audio transcription: raw audio is sent to our backend and passed to Cloudflare Workers AI. We cache the resulting transcript text (not the audio) for 30 days.

Team-plan sermon and audio sync: if your church is on the Whole-Church Bundle or Multi-site plan and you use sync, your sermon content and (if enabled) audio is stored on our servers so it can sync across your church's devices, for as long as your church account exists.

Account sign-in: Google Sign-In is verified directly against Google's own public keys. We receive your email, name, profile picture URL, and Google account ID. Sign in with Apple (iOS only) is verified the same way, directly against Apple's own public keys; we receive your Apple account ID and email, and your name only on the very first authorization you ever grant, never again after that. Optional settings sync covers only church name, denomination, translation, tone, audience, and plan — never sermon content.

Church billing: handled entirely by Stripe's hosted checkout. We store your email, church name, and Stripe's reference IDs — never your card details.

Congregation giving: if your church enables giving and you choose to give, the card details you enter (card number, expiry, CVC, postal code) are collected directly by Stripe's own payment screen inside the app — they go straight to Stripe and never reach our backend. The charge is made directly to your church's own Stripe account — we never hold or route your gift ourselves, and we add no fee of our own. Your church receives your gift less Stripe's own standard card-processing fee, the same as it would with any other payment processor. We store a record of the gift (amount, Stripe's reference ID, which church and member) so you can see your giving history in the app.

Church code delivery email: sent via Resend, which receives your email, church name, plan, and code.

Congregation features: published content is visible only to members who joined your specific church's code. Push notifications use OneSignal, which receives your device's push token and a church-code tag — never your name, email, or sermon content.

Optional aggregate sharing: State of the Pulpit lets you voluntarily share aggregate counts only (never names, emails, or sermon text). Off by default.

Crash and error reporting: if the app crashes or hits an unexpected error, we automatically send a report to Sentry containing only the error type, message, and stack trace — never your sermon content, never your name or email. Sentry's reports do include ordinary device diagnostics (device model, OS version, app version). Sentry is configured to discard IP addresses on receipt rather than store them. This is on for every user automatically; there is no in-app toggle to turn it off yet.

Third parties we work with

WhoWhat they receive
AnthropicSermon text you choose to generate from
Cloudflare (Workers AI)Raw audio, when you transcribe
Cloudflare (our infrastructure)Everything above that reaches our servers
StripeChurch plan billing email/name; giving card details go directly to Stripe, never to us
ResendRecipient email, church name, plan, code
OneSignalDevice push token, church join-code tag
GoogleOAuth sign-in exchange, if you use Google Sign-In
AppleOAuth sign-in exchange, if you use Sign in with Apple (iOS only)
SentryError type, message, stack trace, device diagnostics — never sermon content, personal profile info, or IP address (discarded on receipt)

We do not sell your data, and we do not run third-party advertising or tracking.

How long we keep things

Deleting your data

Deleting data from our servers isn't yet a self-service, in-app action. To request deletion of your church's billing record, synced account settings, or team-plan-synced sermon content, contact us at contact@leodawn.org and we'll process the request manually. Uninstalling the app always deletes everything stored locally on your device immediately.

Children's privacy

Pulpit & Pew is intended for users age 13 and up — pastors, church staff, and congregation members, which in a real congregation includes teenagers, not only adults. The app isn't directed at children under 13, and we don't knowingly collect data from anyone under 13.

Changes to this policy

If we materially change what data we collect or how we use it, we'll update this page and the in-app copy together, and update the date at the top.

Contact

Questions about this policy: contact@leodawn.org

This policy is provided by Leo Dawn LLC, governed by the laws of Oklahoma.