ChurchIQ

Privacy Policy

Last updated: 14 August 2026

Draft template. This page describes what ChurchIQ actually stores and processes today, but it has not been reviewed by a lawyer. Have it checked against South Africa’s POPIA and any other law that applies to your organisation before relying on it, and fill in the placeholders (entity name, registration number, contact details) marked below.

1. Who this covers

ChurchIQ is operated by [Legal entity name], [registration number], South Africa (“ChurchIQ”, “we”, “us”). This policy explains what personal information we collect from churches (“organisations”) and their staff/volunteers who use ChurchIQ (“you”), and how we handle it, in line with South Africa’s Protection of Personal Information Act (POPIA).

2. What we collect

Account information

  • Name and email address, from either a password sign-up or Google sign-in.
  • If you enable two-factor authentication, an authenticator secret is held by our authentication provider, not by ChurchIQ directly.
  • Your role and which assembly/province/organisation it applies to.

Church records your organisation uploads

Attendance registers, giving/financial records, membership records (which can include minors, recorded by an admin — never entered by a child directly), cell group records, and event records — uploaded as spreadsheets, PDFs, Word documents, or photos by your organisation’s admins.

Conversations with the AI assistant

The questions you ask, the answers generated, and any files you attach to a question are stored so you can revisit past conversations.

Connected members-app data

If your organisation links a members-facing app, ChurchIQ can read and, for admins, propose changes to that app’s calendar and admin content, matched to your own account there by email. This is org-controlled and off by default until connected.

3. How we use it

  • To answer your questions about attendance, giving, and membership in plain language.
  • To generate charts, reports, and exports you explicitly request.
  • To enforce role-based access — e.g. giving records are only visible to treasurer-level roles and above.
  • To operate account security features (login, 2FA, role approvals).
  • To meter usage against your organisation’s monthly credit allowance.

We do not sell personal information, and we do not use your church’s data to train AI models.

4. Who we share it with

We share data only with the service providers that make ChurchIQ work:

  • Anthropic (PBC) — processes your question and relevant church data to generate the AI assistant’s answer, under Anthropic’s API terms.
  • Supabase — hosts our database (encrypted at rest, TLS in transit) and handles authentication.
  • Vercel — hosts the application and terminates TLS on every request.
  • Your connected members-app provider, only if and to the extent your organisation enables that integration.

We don’t share your data with anyone else without your consent, except where required by law.

5. Security

  • All traffic is encrypted in transit (TLS); data at rest is encrypted (AES-256) by our infrastructure providers.
  • Access to data is scoped by role and organisation at the database level (row-level security), not just in the app’s UI.
  • Optional two-factor authentication (TOTP) is available for every account.
  • Any AI-proposed change to data (e.g. a calendar event) requires a human to confirm it before anything is written.

6. How long we keep it

We retain data for as long as your organisation has an active ChurchIQ account. If your organisation closes its account, or an individual asks us to delete their personal information, contact us at [privacy contact email] and we will delete or de-identify it within a reasonable period, except where we’re required to keep it (e.g. financial records under applicable law).

7. Your rights

Under POPIA (and equivalent laws elsewhere), you can ask us to confirm what personal information we hold about you, correct it, or delete it, and you can object to certain processing. Contact [privacy contact email] to exercise any of these. If you’re not satisfied with our response, you can complain to South Africa’s Information Regulator.

8. Changes to this policy

We’ll update the date at the top of this page when this policy changes, and post material changes here before they take effect.

9. Contact

Questions about this policy or your data: [privacy contact email].

Terms of Service