Privacy Policy

Last updated: September 3, 2026

This Privacy Policy explains how AlignedAI (“we,” “us,” or “our”) collects, uses, and protects information when you use AlignedAI (the “Service”). By using the Service, you agree to this Policy.

We have written it to be specific rather than reassuring. Where we send data to someone else — including advertising and analytics companies — we name them. Where we keep something we could have thrown away, we say so.

1. Information we collect

  • Account information— your name, email, church or organization, and login details.
  • Content you provide or generate— sermons, documents, transcripts, prompts, and AI output, along with the doctrinal tradition and Bible translations you choose.
  • Meeting recordings— if you use the meeting recorder, the audio you capture and the transcript, summary, and tasks we derive from it. Other people can be recorded in a meeting you start; you are responsible for telling them and for getting whatever consent your jurisdiction requires.
  • Congregation records— if your church uses our people, groups, check-in, or giving tools, the records your church enters or imports about its own people. See section 11.
  • Connected-app data— data we access from apps you connect, only as needed to run the automations you create. See section 10.
  • Mobile number & SMS data— if you opt in to SMS, your phone number, consent record, and the messages exchanged with your assistant.
  • Support conversations— what you write to us in the app, in the feedback form, or by email to our support address, and our replies.
  • Usage data— which features you open, how many requests you send, device and browser type, and error logs. What this does not include is set out in section 4.
  • Advertising and website analytics— data collected by the third-party tags that run on our pages. Named in section 6.

2. How we use information

We use your information to provide and operate the Service, generate the content and automations you request, send the reminders, briefs, and alerts you set up (in-app and via SMS where enabled), maintain security, provide support, measure and improve the product, and comply with law.

To produce a result you asked for, we send what that request needs to the AI providers that run the Service on our behalf. They process it under contract and confidentiality obligations, only to return your result to you.

3. What we never do

  • We do not use your content to train general-purpose AI. Your sermons, documents, prompts, and outputs are not used to train, fine-tune, or improve any general-purpose AI system, ours or anyone else's.
  • We do not sell your personal information, and we do not share it with anyone for their own marketing purposes.
  • We do not target advertising using your content. Nothing you write in the app, and nothing the assistant writes back, is used to build an advertising profile or to choose which ads you see.
  • We do not read your conversations to answer support unless your report is about a conversation. See section 9.

4. How we keep usage analytics de-identified

We measure how the product is used so we can fix and improve it. That measurement is deliberately built so it cannot become a record of who wrote what.

  • Your words never enter analytics.Prompts, outputs, conversation titles, uploaded filenames, and free-text feedback notes are not written into our usage-analytics store. Where we want to know that you left a comment, we record that a comment exists — not what it said.
  • Names, email addresses, and phone numbers are stripped. Everything written into usage analytics passes through a filter that removes contact details, in the browser before it is sent and again on our servers before it is stored. Web addresses are reduced to a page path plus a short list of campaign parameters; a link to an email address or phone number is recorded only as the kind of link it was.
  • Analytics rows are counters, not content.Our request and usage counters record how many requests were made and how large they were. They do not contain your prompts or the AI's answers.
  • Internal views are pseudonymous.Our own operational view of who is currently active shows a church and an opaque short code — not a person's name, email address, or the page they are on.

Analytics rows still carry the account and church they belong to, because that is how we answer questions like “did this church ever finish setup.” What they no longer carry is anything a person wrote or any way to contact them.

5. Anonymous usage trends — and your switch

We aggregate de-identified patterns — for example, which Bible passages or sermon themes churches are working on in a given week — to refine features and to report trends back to churches generally. These reports never include your name, your church, or anything that identifies either, and we never sell them.

You choose this during setup.The switch appears at the bottom of the first screen where you pick your tradition and Bible translation. It starts on, and you can turn it off right there, or at any time afterwards in Settings → Data. For accounts created on or after September 3, 2026 it is on unless you turn it off. Accounts created before that date were never shown the switch, and we do not treat that silence as a yes: they contribute only if they turned sharing on themselves.

Turning it off stops your church's sermon topics from feeding the cross-church trends digest, and stops sermons you upload from contributing to the shared sermon-structure library. It does not switch off the operational analytics in section 4, the error logging that keeps the Service running, or the advertising and analytics tags in section 6 — each of those has its own controls, described where it appears.

6. Advertising and website analytics

Our pages — including the signed-in app and the app running inside our iOS and Android apps — load third-party tags that measure traffic and advertising. We name them here because a policy that described only our own database would be misleading:

  • Google Analytics and Google Ads— page views, referrer, approximate location from IP, and device information, used to measure traffic and the performance of our ads.
  • Meta Pixel— page views and sign-up events from your browser, used to measure the performance of our ads.
  • Meta Conversions API— when you create an account, we send Meta a one-way cryptographic hash of your email address together with your IP address and browser user-agent, so an ad click can be matched to a sign-up. We do not send your name, your church, or anything you have written.
  • Ahrefs Analytics— anonymous page-view and referrer counts for search-ranking reports, and only on our public marketing pages. It does not load on the signed-in app.

These tags see which pages you visit and when. They do not receive your prompts, your sermons, your documents, your congregation's records, or your conversations with the assistant.

You can limit them with your browser's or device's privacy controls, an ad blocker, or your Google Ad Settings and Meta ad preferences. If you would rather we did not send the sign-up event described above, email our support team and we will exclude your account.

7. The AlignedAI mobile and desktop apps

Our iOS, Android, and desktop apps present the same service as the website, so everything in this Policy applies inside them. Two points are specific to the apps:

  • What the app itself adds.If you enable notifications, we store a push token so we can deliver them, tagged with your account identifier, your church identifier, and your plan — never your email address or phone number. Microphone, camera, and photo access are used only when you invoke a feature that needs them (dictation, meeting recording, attaching a photo), and are requested at that moment.
  • What the app inherits. Because the app runs our web experience, the advertising and analytics tags in section 6 run inside it too. This Policy, not a store listing, is the authoritative description of what the app collects; where a store privacy label is less complete than this page, treat this page as correct and tell us so we can fix the label.

8. SMS messaging

If you opt in to the SMS program, we use your mobile number to send the automated and conversational texts you request from the personal assistant. Message frequency varies, and message and data rates may apply. Reply STOP to cancel or HELP for help at any time.

We do not sell or share your mobile opt-in information, phone number, or SMS consent with third parties for their own marketing purposes. SMS data is used only to operate the assistant features you have enabled and is shared with our messaging provider (Twilio) solely to deliver your messages.

9. Support conversations and automated assistance

When you contact support — in the app, through the feedback form, or by emailing our support address — we use what you send, along with your account details, to work out what went wrong and answer you. Mail sent to our support address becomes a support conversation in your account so that our reply reaches you in the same thread.

Automated systems help us handle support. An automated system reads your report, looks at your account to diagnose it, and writes a suggested reply. A person reviews that reply before it is sent, with one exception: a short message confirming that a problem you reported has been fixed may be sent to you automatically. Replies that explain, advise, or concern billing are always reviewed by a person first. You can ask to speak to a person at any point, and we will.

To diagnose a report, that system reads the account information relevant to it: your plan and usage, which apps you have connected and whether they are working, your previous support requests, and whether email is reaching you. If your report is about a conversation with the AI, it may also see the titlesof your recent conversations so it can find the one you mean — not the messages inside them. If your report is about something else, your conversations are not included at all.

Your support message and that account context are processed by our AI providers under confidentiality obligations, solely to answer you. We do not sell support content and we do not use it for advertising.

10. Connected apps

Connecting an app is always your choice, is always preceded by that provider's own consent screen, and can be undone at any time from the Connections panel. We request the narrowest set of permissions that makes the features you enabled work. Disconnecting deletes the stored tokens for that connection.

Google user data & Limited Use

When you choose to connect a Google account, AlignedAI accesses Google user data through Google APIs strictly to power the assistant and automation features you enable. This section discloses exactly what we access, how we use it, whether we share it, and how it is stored, retained, and deleted.

Data we access. Only after you connect Google and grant consent, and only for the scopes you approve:

  • Basic profile & email (openid, email, profile) — to identify the connected account.
  • Gmail (gmail.readonly, gmail.compose, gmail.send) — read recent messages to produce summaries you request, and create, read, and send drafts/emails you ask the assistant to write or send.
  • Google Calendar (calendar.readonly, calendar.events) — read your calendar to show upcoming events and daily briefs, and create, update, or delete events you ask the assistant to schedule.
  • Google Drive (drive.readonly, drive.file) — list and read files you reference so the assistant can use them, and create new Google Docs that AlignedAI itself creates (drive.file is limited to app-created files).
  • Google Contacts (contacts.readonly, contacts.other.readonly) — resolve a recipient's name to an email address when you compose a message.

How we use it. Google user data is used solely to provide the user-facing features described above, at your direction. We do not use Gmail, Calendar, Drive, or Contacts data for advertising, and we do not use it to train, fine-tune, or develop generalized AI/ML systems. Email or document content is sent to our AI providers only when needed to fulfill a specific request you make (for example, summarizing an email you asked us to read), and only transiently to return that result to you.

How we share it. We do not sell Google user data and do not share it with third parties for their own purposes. We share it only with the infrastructure and AI subprocessors that operate the Service under confidentiality obligations, solely to deliver the feature you requested, and as required by law. It is never sent to the advertising or analytics providers in section 6.

How we store & protect it.Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM and transmitted over TLS. Access is restricted by authentication and row-level data isolation so one church cannot access another's connection or data. We do not retain copies of your Gmail, Calendar, Drive, or Contacts beyond what is needed to display a result you requested.

Retention & deletion.You can disconnect a Google account at any time from the Connections panel; doing so deletes the stored tokens for that connection. You can delete your AlignedAI account and its associated data yourself from Settings → Account → Delete account — or, in the one case that screen does not handle (section 15), by emailing our support team— after which we delete your data within a reasonable period unless a longer period is required by law. You can additionally revoke AlignedAI's access from your Google Account permissions page.

Limited Use.AlignedAI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft

If you connect a Microsoft account, we request Microsoft Graph permissions for mail (Mail.ReadWrite, Mail.Send), calendar (Calendars.ReadWrite), files (Files.Read.All), and contacts (Contacts.Read) — used for the same purposes, on the same terms, and with the same limits as the Google scopes above. You can revoke access from your Microsoft account.

Church management and other services

If you connect a church management system or another third-party service, we access the records needed to run the automations and reports you set up — which can include your congregation's people, giving, and check-in data. That data is used only for your church, is never used for advertising, and is never pooled across churches.

11. Congregation records, giving, and children's data

When your church uses our people, groups, check-in, or giving tools, it enters information about its own members, visitors, and donors — names, contact details, dates of birth, attendance, and giving history. For that information your church is the controller and we are the processor: we hold and process it on your church's instructions, to provide the Service to your church. We do not use it for advertising, we do not sell it, we do not pool it across churches, and we do not use it to train AI.

Children.Children's check-in is designed for churches to run their own children's ministry, and the records a church enters can include a child's name and date of birth. We collect that information from the church, not from the child, and we process it solely on the church's behalf. Responsibility for obtaining parental consent, and for deciding what is entered and how long it is kept, rests with the church. See also section 16.

Giving.Donations are processed by our payment provider. Full card numbers are entered directly with that provider and are never sent to or stored on AlignedAI's systems; we keep the donor and donation records your church needs for receipting and reporting, plus the last four digits and expiry of a card on file.

12. How we share information

We share information only with service providers who help us run the Service, under contract and confidentiality obligations; with apps you choose to connect; with the advertising and analytics providers named in section 6, limited to what that section describes; and when required by law or to protect rights and safety. We do not sell your personal information. If AlignedAI is ever involved in a merger, acquisition, or sale of assets, we will give notice before your information becomes subject to a different policy.

The categories of provider we rely on are:

  • Hosting, database, and storage— to run the Service and store your data.
  • AI providers— to produce the results you request. Under our agreements, your content is not used to train their systems.
  • Messaging and email delivery— to deliver texts and email you have asked for.
  • Payments— to process subscriptions and donations.
  • Advertising and analytics— as named in section 6.

13. Data retention

  • Account and church content— kept while your account is active, and deleted or anonymized within 30 days of a deletion request unless a longer period is required by law.
  • Usage analytics— kept for product measurement. Because these rows are de-identified as described in section 4, they may be retained after an account closes.
  • Automation run logs— a record of the messages your automations sent, including the recipient and the message body, so your church can see what went out and whether it worked. Kept for your church's reference; deleted with the church's data.
  • Deletion records— when an account is deleted we keep a minimal audit record of the deletion, including the email address it belonged to, so we can prove the deletion happened and recognize a later sign-up with the same address.
  • Records we must keep— billing, tax, and giving records are retained for the period the law requires.

14. Security

We use industry-standard safeguards, including encryption in transit, encryption at rest for sensitive credentials, access controls, and row-level data isolation between churches. Access by our staff is limited to what is needed to operate the Service and support you. No system is perfectly secure, but we work to protect your information.

15. Your choices and your rights

  • Turn anonymous usage-trend sharing on or off during setup, or at any time in Settings → Data.
  • Opt out of SMS at any time by replying STOP or unpairing your number in settings.
  • Disconnect any connected app from your account settings.
  • Limit advertising and analytics using the controls in section 6, or ask us to exclude your account.
  • Ask for a person to handle your support request instead of an automated system, at any point in the conversation.
  • Delete your account yourself, at any time, from inside the app: Settings → Account → Delete account. You confirm by typing your own email address, and the screen names exactly what is removed before you do. Deletion is immediate and permanent, and nothing can be recovered afterwards. If you are the only person on your church, the church goes with your account — its content, its website and the address pointing at it, its church app, and every account it has connected — and the uploaded files and the search embeddings go with the database records, not just the records of them. If your church has other people on it, what is deleted is your own account, sign-in, chats, Assistant conversation, journal, saved work, books, support messages and what the assistant remembered about you; their accounts stay, and so does what you put into the church: the sermons and documents you uploaded, the images you made, the tasks and meetings you created. If your church is paying for a plan, the subscription is cancelled first. If you are the only person on your church and that church holds giving or congregation records — gifts, scheduled giving, donor details, or people in its directory — the in-app screen does not delete them: giving and tax records are kept for the period the law requires (see section 13), and a directory is personal information your church holds about other people, most of whom are not users of the Service. It names what your church holds and points you to support, who delete the church and your account by hand. Ask them for a copy of those records in the same message if you want one.
  • Request access to, a copy of, correction of, or deletion of your data, and object to or restrict certain processing. Email our support team from your account email address and we will respond within the period the law allows. Ask for a copy before you delete your account — deletion is permanent and we cannot produce one afterwards. We will not treat you differently for exercising a right.

If your church is the controller of records about you (section 11), send your request to your church — we will help them answer it.

16. Children

The Service is not directed to children under 13, and we do not knowingly allow children to create accounts or collect their personal information directly. The one exception is children's check-in, where a church enters records about children in its own ministry; we process those records on the church's behalf, as described in section 11. If you believe a child has provided us information directly, email our support team and we will delete it.

17. Changes

We may update this Policy from time to time. Material changes will be posted here with an updated date.

18. Contact

Questions about this Policy or your data? Email our support team.