Pulpit & Pew Privacy Policy
Last updated: July 2026
This policy describes what Pulpit & Pew ("the app," "we," "us") does with your data. It's written to match exactly what the app's code actually does — not generic boilerplate.
The short version
- If your church is on a Solo or Ministry plan (or you're using the free tier), your sermons, transcripts, audio, and generated content stay on your device. We never see them, except for the specific text you choose to send for AI generation.
- If your church is on the Whole-Church Bundle or Multi-site plan, sermon content (including audio) syncs across your church's devices through our servers, so your team can share one library. This only happens if you use the sync feature.
- We never see your payment card details — Stripe handles that entirely.
- We don't sell your data, and we don't run ads that track you.
- Right now, deleting data from our servers is a manual, request-based process, not a self-service button.
What stays only on your device
For every plan: sermon recordings, transcripts, notes, summaries, and all generated content (discussion guides, devotionals, Family Worship Guides, Church Fathers references, etc.) never leave your device unless you explicitly export/share it yourself, or your church is on a team plan and you use the sync feature (see below).
What we do see, and why
AI-generated content (text): the sermon text you're generating from is sent to our backend, which forwards it to Anthropic to produce the result. Cached for 30 days, keyed by content, not by you.
Audio transcription: raw audio is sent to our backend and passed to Cloudflare Workers AI. We cache the resulting transcript text (not the audio) for 30 days.
Team-plan sermon and audio sync: if your church is on the Whole-Church Bundle or Multi-site plan and you use sync, your sermon content and (if enabled) audio is stored on our servers so it can sync across your church's devices, for as long as your church account exists.
Account sign-in: Google Sign-In is verified directly against Google's own public keys. We receive your email, name, profile picture URL, and Google account ID. Sign in with Apple (iOS only) is verified the same way, directly against Apple's own public keys; we receive your Apple account ID and email, and your name only on the very first authorization you ever grant, never again after that. Optional settings sync covers only church name, denomination, translation, tone, audience, and plan — never sermon content.
Church billing: handled entirely by Stripe's hosted checkout. We store your email, church name, and Stripe's reference IDs — never your card details.
Congregation giving: if your church enables giving and you choose to give, the card details you enter (card number, expiry, CVC, postal code) are collected directly by Stripe's own payment screen inside the app — they go straight to Stripe and never reach our backend. The charge is made directly to your church's own Stripe account — we never hold or route your gift ourselves, and we add no fee of our own. Your church receives your gift less Stripe's own standard card-processing fee, the same as it would with any other payment processor. We store a record of the gift (amount, Stripe's reference ID, which church and member) so you can see your giving history in the app.
Church code delivery email: sent via Resend, which receives your email, church name, plan, and code.
Congregation features: published content is visible only to members who joined your specific church's code. Push notifications use OneSignal, which receives your device's push token and a church-code tag — never your name, email, or sermon content.
Optional aggregate sharing: State of the Pulpit lets you voluntarily share aggregate counts only (never names, emails, or sermon text). Off by default.
Crash and error reporting: if the app crashes or hits an unexpected error, we automatically send a report to Sentry containing only the error type, message, and stack trace — never your sermon content, never your name or email. Sentry's reports do include ordinary device diagnostics (device model, OS version, app version). Sentry is configured to discard IP addresses on receipt rather than store them. This is on for every user automatically; there is no in-app toggle to turn it off yet.
Third parties we work with
| Who | What they receive |
|---|---|
| Anthropic | Sermon text you choose to generate from |
| Cloudflare (Workers AI) | Raw audio, when you transcribe |
| Cloudflare (our infrastructure) | Everything above that reaches our servers |
| Stripe | Church plan billing email/name; giving card details go directly to Stripe, never to us |
| Resend | Recipient email, church name, plan, code |
| OneSignal | Device push token, church join-code tag |
| OAuth sign-in exchange, if you use Google Sign-In | |
| Apple | OAuth sign-in exchange, if you use Sign in with Apple (iOS only) |
| Sentry | Error type, message, stack trace, device diagnostics — never sermon content, personal profile info, or IP address (discarded on receipt) |
We do not sell your data, and we do not run third-party advertising or tracking.
How long we keep things
- AI generation and transcription caches: 30 days.
- Aggregate usage/insights submissions: about 2 years.
- Per-sermon regeneration counters: about 2 years.
- Church billing records: kept while your license is active, currently retained after cancellation too — we're working on automatic cleanup here.
- Giving records (amount, Stripe reference ID, church, member — never card details): currently kept indefinitely.
- Synced account settings and team-plan synced sermon content/audio: currently kept indefinitely, for as long as the underlying account or church code exists.
Deleting your data
Deleting data from our servers isn't yet a self-service, in-app action. To request deletion of your church's billing record, synced account settings, or team-plan-synced sermon content, contact us at contact@leodawn.org and we'll process the request manually. Uninstalling the app always deletes everything stored locally on your device immediately.
Children's privacy
Pulpit & Pew is intended for users age 13 and up — pastors, church staff, and congregation members, which in a real congregation includes teenagers, not only adults. The app isn't directed at children under 13, and we don't knowingly collect data from anyone under 13.
Changes to this policy
If we materially change what data we collect or how we use it, we'll update this page and the in-app copy together, and update the date at the top.
Contact
Questions about this policy: contact@leodawn.org
This policy is provided by Leo Dawn LLC, governed by the laws of Oklahoma.