ChurchLibrary

Privacy Policy

Last updated: July 1, 2026

ChurchLibrary (“ChurchLibrary,” “we,” “us,” or “our”), operated by ChurchLibrary, provides a platform that lets churches and ministries upload sermon recordings and related materials, then transcribes, organizes, and makes them searchable using artificial intelligence. This Privacy Policy explains what information we collect, how we use it, who can access it, and the choices and rights you have. It applies to churchlibrary.com and app.churchlibrary.com (together, the “Service”). Our Terms of Service also apply.

The short version

  • Your content is yours.We don't claim ownership of anything you upload; we only process it to provide the Service to you.
  • You control it.You can delete content, or your whole organization's workspace, at any time, and request full deletion from our systems.
  • It's private to your organization. Other churches can never see your content. Access is limited to the people you invite, plus a small number of authorized ChurchLibrary personnel who help operate and support the Service.
  • We don't sell your data, and we don't use it to train AI models — including files you import from Google Drive.

Information we process

Account and organization information such as your name, email address, organization name, and authentication details (we support Google sign-in and one-time email codes).

Content you upload or import (“Customer Content”) — sermon audio and video, and related materials such as documents, ProPresenter files, and images, including files you choose to import from Google Drive or Dropbox.

Data we derive from your content to make it searchable — transcripts, topic tags, speaker labels, numeric embeddings used for semantic search, and, where you provide sermon video, data used to recognize and group speakers. Derived data is treated as part of your Customer Content.

Usage and technical information such as log data and how you interact with the Service, used to keep it secure, reliable, and improving.

Google Drive Data

When a customer connects Google Drive, ChurchLibrary requests access only to the files the user explicitly selects with the Google Picker (the drive.file scope) — not your entire Drive. We use that access solely to import the files you select into your ChurchLibrary workspace and process them as Customer Content.

ChurchLibrary's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not sell Google user data; we do not transfer it except as necessary to provide the Service, comply with law, or in connection with a merger or acquisition; we do not use it for advertising; and we do not use Google user data to train or improve generalized AI/ML models. We do not allow humans to read it except with your consent, for security, to comply with law, or where it has been aggregated and anonymized for internal operations.

Who can access your content

People in your organization. Customer Content is private to your organization's workspace and accessible to the members you invite, according to the roles your administrators set. Other organizations can never access your content.

ChurchLibrary personnel. A limited number of authorized staff may access Customer Content only as needed to operate, support, secure, troubleshoot, and improve the Service.

Internal analytics.We may analyze content and usage across organizations internally and in aggregate to understand trends and improve the product. This is used only by ChurchLibrary for internal product and operations purposes, is never a customer-facing feature, and never exposes one organization's content to another. Files imported from Google Drive are excluded from this internal analysis and are used only to provide the Service to your organization.

AI processing and no model training

The Service uses third-party AI providers to transcribe recordings, generate tags and summaries, create search embeddings, and answer questions about your sermons. When we send content to these providers, it is processed to deliver these features and is not used to train their or our general-purpose AI models. We do not sell your content, and we do not use your content — including Google user data — to train or improve generalized AI/ML models.

Service providers

We share information with vendors that process it on our behalf under contracts requiring appropriate confidentiality and security — including providers for cloud infrastructure and storage, database hosting, speech-to-text transcription, AI inference, email delivery, and application hosting (for example, Amazon Web Services, Google, OpenAI, Anthropic, and our hosting and email providers). We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets.

Data ownership

As between you and ChurchLibrary, your organization owns its Customer Content. You grant us only the limited rights needed to host and process that content to provide the Service, as described in our Terms of Service. We do not claim ownership of your content.

Retention and deletion

We retain Customer Content for as long as your organization maintains its account, or until you delete it. You can delete individual items or your entire workspace at any time, and request deletion of all of your organization's content by contacting us. When you delete content or request deletion, we remove it (and data derived from it) from our active systems within 30 days, and from routine encrypted backups within our normal backup rotation. We may retain limited information where required to comply with legal obligations, resolve disputes, or enforce our agreements.

Security

We use technical and organizational measures designed to protect Customer Content, including tenant isolation between organizations, encryption in transit and at rest, encrypted OAuth tokens, and access controls that limit staff access to what is necessary. No system is perfectly secure, but we work to protect your information and to promptly address issues if they arise.

People appearing in recordings; children

Sermon recordings — especially video — may include images or voices of congregants and others. Your organization is responsible for having any consents or permissions needed to upload this content and for complying with applicable laws. The Service is intended for use by organizations and their authorized adult members; it is not directed to children, and we do not knowingly collect personal information directly from children.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. Because your organization controls its workspace, please direct these requests to your organization's administrators where possible, or contact us and we will assist, including by routing the request to the relevant organization.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date and, where appropriate, notify you through the Service or by email. Your continued use of the Service after changes take effect means you accept the updated policy.

Contact

Questions about this policy can be sent to chase@vessel.org.