Aligned Church Privacy Policy
Last updated: September 16, 2026
This Privacy Policy explains how AlignedAI (“we,” “us,” or “our”) collects, uses, and protects information when a church uses Aligned Church(the “Service”) — the church workspace at aligned.church/church: church websites and the forms on them, giving, the congregation directory, texting members, children's check-in, automations, social publishing, and the church's own app. By using the Service, you agree to this Policy.
The account you sign in with is an AlignedAI account, and the assistant features that come with it — the chat, sermon prep, the Personal Assistant, meetings, and the AlignedAI phone and desktop apps — are covered by the AlignedAI Privacy Policy. This document covers the records your church holds through Aligned Church about other people, and the websites, texts, and app it runs through us.
We have written it to be specific rather than reassuring. Where we send data to an advertising or analytics company, or to a company that carries texts, we name it. Where we keep something we could have thrown away, we say so.
1. Information we collect
Most of the information in Aligned Church is not about the person signed in. It is about a church's members, visitors, and donors, entered by the church or submitted by those people directly. We list it by module so a church can see exactly what it is trusting us with.
- Staff accounts— the name, email address, church, and login details of each person your church gives a seat to, and which module each seat may open.
- The people directory (Manage)— the records your church enters or imports about its people: names, email addresses, phone numbers, home addresses, dates of birth, household and family links, relationships and emergency contacts, group memberships, attendance, serving schedules, milestones such as a baptism, any custom fields your church defines, saved lists, and free-text notes. A church may also record medical notesand other sensitive details it needs for pastoral care or children's ministry, and keep care cases — a summary, updates, and any assistance amount, with a confidential flag that limits which staff can open them. Those fields are kept for the church alone: they never enter usage analytics, are never used to train AI, and are never used for advertising. Every edit to a person's record is written to a change history that keeps the whole record as it was before and after the edit, medical notes included; nothing in the product deletes that history, so it lasts as long as your church's records do (section 12). To draw your church's map, the addresses in the directory are sent to Google's geocoding service and the resulting coordinates are cached against the address (section 11).
- Documents and signatures— the files your church attaches to a person's record (a signed form, custody paperwork, a scanned ID, a counselling intake), each with its name, type, and a category, held in private storage that only manager seats can open; and the documents your church sends for signature — a waiver, a media release, a membership covenant — where we keep the exact terms as they read when sent, the signer's typed name and email address, the IP address and browser they signed from, and the time, as the legal record of the signature. A person signs from a link, without an account.
- Prayer and care— the prayer requests your church records or receives: the request, who it is from or about, a category, whether it is urgent, and any answer. Every new request is read by an automated safety screen, run by one of our AI providers, that looks for one thing: a sign that the writer or the person prayed for may be in danger of harming themselves or someone else. A request the screen flags is held out of the prayer list until a staff member reads it and clears it; if the request is linked to a person, a confidential care case is opened for them and staff are notified. The screen does nothing else with the request, and if it cannot run the request is filed unflagged. The request itself is never written into the church's change history.
- Children's check-in— for each check-in, the child's name (from the directory, or typed in for a guest), the event and date, the station used, and the security code printed on the label and the pickup receipt. That code is the parent's proof at pickup. Check-in stations open from a link your church creates; the link is the only credential.
- Giving and donor records— for each donor, their name, email address, phone number, and mailing address if given, whether they asked to give anonymously, and their gifts: date, amount, fund, method, first and last gift, and lifetime total. For a scheduled gift, the arrangement and the last four digits and expiry of the card it is vaulted against. Full card and bank numbers are entered directly with our payment provider and never reach our systems. On every gift made from a browser — a one-time gift, or the setup of a scheduled one — we also record the IP address and browser user-agent it was made from, as evidence of who initiated it if the gift is ever disputed; the later charges of a scheduled gift, which we start ourselves, carry none. Nothing in the product reads them for any other purpose, and they stay with the gift for as long as it is kept (section 12). Cash and check gifts your counters record by hand are kept as batch entries: the donor or the name written on the envelope, the amount, the fund, the check number, and any note. Donors give at your church's giving page and manage their own gifts from a link we email them, both without an account. Text giving has two rails. On your church's own number, texts travel through Twilio and are logged as described under Texting. On the shared text-giving number — one number for every church, where a donor's first message is your church's keyword — messages travel through the iMessage transport we use for that line (Blooio); we keep the donor's phone number, which church the conversation is bound to, the gift in progress (amount and fund), and the link to their donor record; the messages themselves stay with the transport. No card details are ever typed into a text on either rail.
- Texting— a log of the messages sent and received in both directions with every number your church texts, and, for a number that has replied STOP or START, an opt-out or opt-in record: the number, the keyword, and when. That keyword record is the only consent record we hold; how a number first came onto your church's list is your church's own record, not something we capture. To register your church with the carriers, we also hold the business details your church enters: legal name, business type, EIN, business address, website, and a contact email and phone. See section 8.
- Email to your members— each email your church sends from Manage or through an automation: the subject, the body, who it went to, and whether each copy was sent, failed, or skipped. It goes out through the Gmail or Outlook mailbox your church connects, under that mailbox's own address, or, where we offer it, from a hosted address at our domain that your church turns on; a reply to the hosted address lands in your church's inbox in Manage, and we hold it there. Receipts, the sign-in codes we send a donor, the giving-migration notices under Giving, and Go Live announcements use your church's mailbox when one is connected and otherwise go from our own address ([email protected]) with your church's name as the sender name. A person who unsubscribes from your church's email is recorded as an address that has opted out of that church, and we skip them on every later send. Separately, one block list across all mail we deliver holds addresses that hard-bounced or reported our mail as spam; we will not send to those on any church's behalf, and the list holds the address and the reason, nothing about the church or the person.
- Your website and the forms on it— the pages, images, sermons, events, and staff profiles your church publishes, and what visitors submit through the site's forms: plan-a-visit requests, prayer requests, newsletter sign-ups, and contact messages — a name, email address, phone number, and message, plus a salted one-way hash of the visitor's IP address that we keep only to stop abuse. The pages your church shares by link collect what they ask for and no IP address: an event sign-up takes a name, an email address, the size of the party and the names in it, and the answers to any questions your church added; a group page takes a name, email address, phone number, and message. See section 7.
- Forms your church builds— a form your church designs in Manage and shares by link or places on its website collects whatever it asks: a name, email address, or phone number where the form has those fields, and the answers to any other question your church wrote. Submissions wait in a review queue; a person in your directory is matched only on an exact email address or exact name, and nothing is added to or changed on a record until a staff member accepts it. A copy of each submission is emailed to the address your church set for that form, when it set one. Like the other link pages it stores no IP address; a keyed one-way hash of the address throttles repeat submissions over ten minutes, and the counter it keeps is dropped within a week.
- Website analytics— for a published site, a page-view and page-speed log that records the page, the referring site, and a visitor code that changes every day. It stores no IP address, no cookie, and no name.
- Automations— the rules your church sets up, and a log of what each run sent: the recipient and the message body, so the church can see what went out. If a rule includes a step where the assistant writes the message, the record that triggered the run and the outputs of earlier steps are sent to our AI providers to write it, on the terms in section 3.
- Connected services— the tokens for the church-management systems, social accounts, the Gmail or Outlook mailbox your church sends member email from, and the app-store developer accounts your church connects, and the records those connections exchange. See section 10.
- Usage, device, and diagnostic data— which screens staff open, how many requests they send, device and browser type, and error logs. What this does not include is set out in section 5.
- Advertising and website analytics on aligned.church — data collected by the third-party tags that run on our own pages. Named in section 6.
2. Who is responsible for what
When your church uses Aligned Church, it enters and gathers information about its own members, visitors, and donors. For that information your church is the controller and we are the processor: we hold and process it on your church's instructions, to provide the Service to your church. We do not use it for advertising, we do not sell it, we do not pool it across churches, and we do not use it to train AI. Your church decides what is entered, who on its staff can see it, how long it is kept, and how it answers a member who asks about their record; we help it do each of those things.
Some of it arrives from the person directly.A member can update their own details, including their birthday, from the self-update link your church sends; a visitor can fill in a form on the church's website; a parent can register a child for check-in; a donor can give and manage their gifts without an account. In each case we collect that information on your church's behalf, into your church's records, and your church is still the controller of it. Where your church collects information about a child — a name and date of birth for children's check-in, for example — responsibility for obtaining parental consent, and for deciding what is entered and how long it is kept, rests with the church. See also section 15.
Responsibility for your church's own business details — its legal name, EIN, and address for carrier registration; its developer accounts for the app stores — is your church's too. We hold those only to do the thing your church asked for, and the store credentials are encrypted at rest and never shown in a browser.
3. How we use information
We use your information to provide and operate the Service, build and serve your church's website and app, deliver the texts, emails, receipts, and reports your church sends through it, run the automations your church sets up, maintain security, provide support, measure and improve the product, and comply with law.
To produce a result you asked for, we send what that request needs to the AI providers that run the Service on our behalf. They process it under contract and confidentiality obligations, only to return your result to you. The one automated pass that reads a church's record without a request from the church — the safety screen on new prayer requests in section 1 — and the support system in section 9 go to the same providers on the same terms, and so does an automation step where the assistant writes the message for a rule your church set up (section 1).
Emails and notifications we send.Besides the mail you ask for, we send product and marketing email to the address on your account: a welcome and setup series, a nudge to come back when you have been away, suggestions for parts of the Service you have not tried, offers to upgrade, and a win-back message after a plan ends. If you turned on notifications in the phone app, some of the same messages arrive as push notifications. Which ones you get, and when, is decided by how you use the Service and which plan you are on; the emails greet you by name, and two of them use your content: one, about the repurpose tools, takes its subject line from the latest sermon synced from a channel you connected and carries a short preview the assistant drafts from that title without a request from you; another names the book of the Bible your recent sermon conversations have been in. Every one carries an unsubscribe link, and using it stops all of them (a weekly series carries its own link that stops only that series). Mail that operates your account — a receipt, a sign-in link, an invitation from a colleague, a reply from support — is not marketing and keeps arriving.
4. What we never do
- We do not use your content to train general-purpose AI. Your church's records, website, messages, and the content it creates are not used to train, fine-tune, or improve any general-purpose AI system, ours or anyone else's.
- We do not sell your personal information, and we do not share it with anyone for their own marketing purposes.
- We do not target advertising using your content. Nothing you write in the app, and nothing the assistant writes back, is used to build an advertising profile or to choose which ads you see.
- We do not pool one church's records with another's. The people, donors, and messages in your church's workspace are used only for your church. We never sell or rent donor lists, and no other church can see them.
- We do not read your conversations to answer support unless your report is about a conversation. See section 9.
5. How we keep usage analytics de-identified
We measure how the product is used so we can fix and improve it. That measurement is deliberately built so it cannot become a record of who wrote what.
- Your words never enter analytics.Prompts, outputs, conversation titles, uploaded filenames, and free-text feedback notes are not written into our usage-analytics store. Where we want to know that you left a comment, we record that a comment exists — not what it said.
- Names, email addresses, and phone numbers are stripped. Everything written into usage analytics passes through a filter that removes contact details, in the browser before it is sent and again on our servers before it is stored. Web addresses are reduced to a page path plus a short list of campaign parameters; a link to an email address or phone number is recorded only as the kind of link it was.
- Analytics rows are counters, not content.Our request and usage counters record how many requests were made and how large they were. They do not contain your prompts or the AI's answers.
- Internal views are pseudonymous.Our own operational view of who is currently active shows a church and an opaque short code — not a person's name, email address, or the page they are on.
Analytics rows still carry the account and church they belong to, because that is how we answer questions like “did this church ever finish setup.” What they no longer carry is anything a person wrote or any way to contact them.
6. Advertising and website analytics
Our pages on aligned.church — including the signed-in app — load third-party tags that measure traffic and advertising. We name them here, and we name the events they receive, because a policy that described only our own database would be misleading:
- Google Analytics and Google Ads— page views, referrer, approximate location derived from your IP address, and device and browser information, used to measure traffic and the performance of our ads. When you create an account, a sign-up conversion event is sent so Google can attribute it to an ad.
- Meta Pixel— page views from your browser, plus named events: a Lead when you create an account or first sign in on the get-started page, and a StartTrial when you activate a plan. Each is used to measure the performance of our ads. The pixel sets its own cookies in your browser (
_fbp, and_fbcwhen you arrived from a Meta ad), and those identifiers travel with the events. - Meta Conversions API— when you create an account or first sign in on the get-started page, our server also sends Meta the same Lead event with a one-way cryptographic hash of your email address, your IP address, your browser user-agent, the two cookie identifiers above, and the ad click identifier if you arrived from a Meta ad, so an ad click can be matched to a sign-up. We do not send your name, your church, or anything you have written.
- Ahrefs Analytics— anonymous page-view and referrer counts for search-ranking reports, and only on our public marketing and legal pages. It does not load on the signed-in app.
These tags see which pages you visit and when, and they set and read their own cookie and device identifiers in your browser. They do not receive your church's records, its donors, the people in its directory, or the messages it sends.
This section is about aligned.church. A church's own published website is a different page on a different address, and what it loads — including the church's own analytics and ad tags — is described in section 7.
You can limit them with your browser's or device's privacy controls, an ad blocker, or your Google Ad Settings and Meta ad preferences. If you would rather we did not send the sign-up event described above, email our support team and we will exclude your account.
7. Your published website and your church's app
A website your church publishes through Aligned Church is your church's site, on your church's address, and your church is the controller of what it collects. We serve it, and we hold what it collects through us:
- Forms— a visitor who plans a visit, sends a prayer request, joins the newsletter, or writes through the contact form submits that directly to us, and it lands in your church's workspace. A submission that carries a name and an email address is matched to a person in your directory or, when nobody matches, adds them as a visitor with a note of what they sent. If your church has turned on Planning Center delivery, a plan-a-visit, newsletter, or contact submission is also sent to your church's Planning Center, where it becomes a person and, if you chose one, a card in a workflow. A prayer request is handled differently: it enters your church's prayer list — and the automated safety screen described in section 1— only if the visitor chose to share it with the prayer team; otherwise it stays in the submissions inbox alone. Prayer requests are never passed to a connected church-management system. A form your church built itself and placed on the site is the same form as in Manage and behaves as section 1 describes: its submissions wait for review and are never pushed to a connected system.
- Analytics— our own page-view and page-speed log (section 1) stores no IP address and sets no cookie. If your church adds its own Google Analytics or Meta Pixel identifiers in the site's settings, those tags load on the site under your church's accounts and terms, not ours, and what they collect is between your church and those companies. The advertising tags in section 6do not load on a church's published site.
- Giving on the site— the giving page and any giving embed are served by us and collect what section 1 describes for donors.
- Site content— the staff names, photos, and sermons your church publishes are public by your church's choice; we do not add anything to a published page that identifies a visitor.
Your church's app.The iPhone and Android app we build for a church is the church's app, published under the church's own developer accounts, and it presents the church's website. Its store listing carries the church's privacy policy, not this one. To build and submit it, we hold the App Store Connect key and the Google Play service account your church provides, encrypted at rest, and use them only to upload builds and listing details your church approved.
8. Texting your members
Aligned Church sends texts on your church's behalf, through our messaging provider (Twilio), from a number registered to your church. Carriers require a business registration for that number, so the legal name, business type, EIN, address, website, and contact details your church enters are passed to Twilio and, through it, to the carriers' registry. They are used for nothing else.
We keep a log of each message sent and received with every number your church texts, so your church can show what was said. A person can reply STOP at any time; we record the keyword and the time, honour it immediately, keep the opt-out for as long as your church texts, and will not send to that number again even if the person is imported again, until they text START themselves — which we record the same way. Those keyword records are the only consent records we hold: we do not capture how a number first came onto your church's list or whether the person agreed to be texted, so proof of that consent is your church's to keep. HELP is always answered. We do not sell or share anyone's mobile number or opt-out with third parties for their own marketing purposes. Sending texts your members did not agree to receive is against carrier rules and against our terms.
9. Support conversations and automated assistance
When you contact support — in the app, through the feedback form, or by emailing our support address — we use what you send, along with your account details, to work out what went wrong and answer you. Mail sent to our support address becomes a support conversation in your account so that our reply reaches you in the same thread.
Automated systems help us handle support. An automated system reads your report, looks at your account to diagnose it, and writes a suggested reply. A person reviews that reply before it is sent, with one exception: a short message confirming that a problem you reported has been fixed may be sent to you automatically. Replies that explain, advise, or concern billing are always reviewed by a person first. You can ask to speak to a person at any point, and we will.
To diagnose a report, that system reads the account information relevant to it: your plan and usage, which apps you have connected and whether they are working, your previous support requests, and whether email is reaching you. If your report is about a conversation with the AI, it may also see the titlesof your recent conversations so it can find the one you mean — not the messages inside them. If your report is about something else, your conversations are not included at all.
Your support message and that account context are processed by our AI providers under confidentiality obligations, solely to answer you. We do not sell support content and we do not use it for advertising.
10. Connected apps and services
Connecting an app is always your choice, is always preceded by that provider's own consent screen, and can be undone at any time from the Connections panel. We request the narrowest set of permissions that makes the features you enabled work. Disconnecting deletes the stored tokens for that connection.
Church-management systems
If your church connects a church-management system, we access the records needed to run the syncs, automations, and reports you set up — which can include your congregation's people, giving, and check-in data — and, where you ask us to, write records back to it. To draw charts and briefs without calling your system on every view, we keep a daily snapshot of a summary of that data — recent people by name and date added, recent gifts by donor name, amount, and date, attendance counts, the calendar, and service plans — refreshed once a day. Disconnecting deletes the tokens; the last snapshot stays until your church's data is deleted. That data is used only for your church, is never used for advertising, and is never pooled across churches.
Social accounts
Social publishing runs through a publishing service. Your church signs in to each social account with that network's own consent screen; we hold the connection and the posts your church schedules, and the service posts them to the accounts your church chose.
App-store accounts
The App Store Connect key and Google Play service account your church provides for its app are held as described in section 7. Removing them from the App module deletes our copy.
11. How we share information
We share information only with service providers who help us run the Service, under contract and confidentiality obligations; with apps you choose to connect; with the advertising and analytics providers named in section 6, limited to what that section describes; and when required by law or to protect rights and safety. We do not sell your personal information. If AlignedAI is ever involved in a merger, acquisition, or sale of assets, we will give notice before your information becomes subject to a different policy.
The categories of provider we rely on are:
- Hosting, database, and storage— to run the Service and store your data, including serving your church's published website on its own domain.
- AI providers— to produce the results you request, including transcribing audio you record. Under our agreements, your content is not used to train their systems.
- Messaging and email delivery— to deliver the texts, emails, and receipts your church sends. Texts go through Twilio, which also receives the business details your church registers for carrier approval (section 8); text giving on the shared line goes through Blooio, which receives the donor's number and messages (section 1). Email to members goes out through the mailbox your church connected when there is one, and otherwise through our email delivery provider — from the church's hosted address, or from our own address with your church's name on it (section 1).
- Payments— to process gifts and your plan. Card and bank details are entered with the payment provider directly and never reach our systems.
- Google Maps— to place your people on a map, the addresses in your directory are sent to Google's geocoding service and the map image is drawn by Google. See section 1.
- Apple and Google app stores— to build and submit your church's app under your church's own developer accounts, using the credentials you provide.
- Social networks and their publishing service — to post what your church schedules to the accounts it connects.
- Church-management systems you connect— to send and receive the records you ask us to sync.
- Advertising and analytics — as named in section 6.
12. Data retention
- Account and church content— kept while your account is active, and deleted or anonymized within 30 days of a deletion request unless a longer period is required by law.
- Usage analytics— kept for product measurement. Because these rows are de-identified as described in section 5, they may be retained after an account closes.
- Automation run logs— a record of the messages your automations sent, including the recipient and the message body, so your church can see what went out and whether it worked. Kept for your church's reference; deleted with the church's data.
- Text-message opt-outs— a number that replied STOP stays opted out for as long as your church texts, even if the person is imported again, because honouring it is a legal duty. The opt-out record is deleted with the church's data.
- Email unsubscribes— an address that unsubscribed from your church's email stays unsubscribed for as long as the church sends, because honouring it is a legal duty too, and is deleted with the church's data. An address that bounced or reported our mail as spam stays on our delivery block list (section 1) whether or not the church's data is deleted.
- The directory's change history— every edit to a person's record keeps the record as it was before and after, medical notes included; a person your church removes is archived rather than erased, and when two records are merged the one that was dropped survives only in that history. Nothing in the product deletes the history: it is kept for as long as your church's records exist and goes with them.
- Signed documents and uploaded files— a signed document, with the signer's IP address and browser recorded on it, is kept as the legal record of the signature for as long as your church's records exist; voiding a request marks it void and keeps it. A file attached to a person's record is kept until a staff member deletes it, which removes the file itself.
- Online gifts— the IP address and browser recorded on each gift as dispute evidence stay with the gift, and a gift is a giving record: kept for the period the law requires.
- Deletion records— when an account is deleted we keep a minimal audit record of the deletion, including the email address it belonged to, so we can prove the deletion happened and recognize a later sign-up with the same address.
- Records we must keep — billing, tax, and giving records are retained for the period the law requires. That is why the self-serve account deletion cannot remove a church that holds gifts, and why support handles it by hand.
13. Security
We use industry-standard safeguards, including encryption in transit, encryption at rest for sensitive credentials, access controls, and row-level data isolation between churches. Access by our staff is limited to what is needed to operate the Service and support you. No system is perfectly secure, but we work to protect your information.
14. Your choices and your rights
- Export your church's records yourself: Manage → Reports → “Take your records with you” produces CSVs of your people, groups, attendance, and signups, and Giving → Donations → “Export all” produces every donation.
- Stop texting a person at any time from their record; a person can stop it themselves by replying STOP.
- Stop product and marketing email at any time with the unsubscribe link at the foot of any of them; the same click stops the push notifications that ride with that program (section 3).
- Disconnect any connected app from your account settings.
- Limit advertising and analytics using the controls in section 6, or ask us to exclude your account.
- Ask for a person to handle your support request instead of an automated system, at any point in the conversation.
- Delete your account yourself, at any time, from inside the app: Settings → Account → Delete account. You confirm by typing your own email address, and the screen names exactly what is removed before you do. Deletion is immediate and permanent, and nothing can be recovered afterwards. If you are the only person on your church, the church goes with your account — its content, its website and the address pointing at it, its church app, and every account it has connected — and the uploaded files and the search embeddings go with the database records, not just the records of them. If your church has other people on it, what is deleted is your own account, sign-in, chats, Assistant conversation, journal, saved work, books, support messages and what the assistant remembered about you; their accounts stay, and so does what you put into the church: the sermons and documents you uploaded, the images you made, the tasks and meetings you created. If your church is paying for a plan, the subscription is cancelled first. If you are the only person on your church and that church holds giving or congregation records — gifts, scheduled giving, donor details, or people in its directory — the in-app screen does not delete them: giving and tax records are kept for the period the law requires (see section 12), and a directory is personal information your church holds about other people, most of whom are not users of the Service. It names what your church holds and points you to support, who delete the church and your account by hand. Ask them for a copy of those records in the same message if you want one.
- Request access to, a copy of, correction of, or deletion of your data, and object to or restrict certain processing. Email our support team from your account email address and we will respond within the period the law allows. Ask for a copy before you delete your account — deletion is permanent and we cannot produce one afterwards. We will not treat you differently for exercising a right.
If you are a member, visitor, or donor of a church that uses Aligned Church, your church is the controller of the records it holds about you (section 2). Send your request to your church — we will help them answer it — or email us and we will pass it on.
15. Children
The Service is not directed to children under 13, and we do not knowingly allow children to create accounts or collect their personal information directly. The one exception is children's check-in, where a church enters records about children in its own ministry; we process those records on the church's behalf, as described in section 1 and section 2. If you believe a child has provided us information directly, email our support team and we will delete it.
16. Changes
We may update this Policy from time to time. Material changes will be posted here with an updated date.
17. Contact
Questions about this Policy or your data? Email our support team.
For the assistant, your own account, and the AlignedAI apps, see the AlignedAI Privacy Policy. Questions about either document: our support team.