ChurchLibrary is a ministry of Church of the Highlands, Inc. This Privacy Policy explains how Church of the Highlands, Inc., through ChurchLibrary ("ChurchLibrary," "we," "us," or "our"), collects, uses, discloses, and retains personal information in connection with the ChurchLibrary website, application, and related services (the "Service").
This Privacy Policy applies to information we process for our own operational purposes and explains our practices when we process information on behalf of church and ministry customers. Where a Customer controls personal information submitted through its workspace, that Customer may have separate privacy obligations and may be the appropriate party to receive an individual's privacy request.
1. Information We Collect
Account and Organization Information
We may collect names, email addresses, organization names, roles, account identifiers, authentication information, workspace permissions, and other information used to create and administer accounts. If an Authorized User signs in through Google, we may receive information made available through that authentication process, such as name, email address, and account identifier.
Customer Content
Customers may submit sermon audio or video, speaking notes, documents, images, links, and other materials. We also process transcripts, tags, summaries, embeddings, search data, and other information created from those materials. Customer Content may contain personal information about pastors, guest speakers, congregants, or other individuals, including names, voices, images, religious information, or other information contained in or inferred from the submitted content.
AI Interaction Data
We collect questions, prompts, search queries, feedback, and related responses generated when Authorized Users use AI-powered search, chat, transcription, tagging, or summarization features.
Usage, Device, and Log Information
We may automatically collect IP address, browser and device information, timestamps, pages and features used, interaction events, error and diagnostic data, security logs, and similar technical information. We may use cookies, local storage, or similar technologies to support authentication, security, preferences, analytics, and Service functionality.
Communications and Support Information
We collect information included in support requests, product feedback, surveys, and communications with us. We may also collect information about delivery or engagement with transactional or permitted marketing emails.
Billing Information
If we offer paid plans, payment information may be collected by a payment processor. We may receive limited billing and transaction information but do not necessarily receive full payment-card details.
Speaker Matching
ChurchLibrary may use facial recognition technology to identify recurring speakers within a Customer's workspace. This process may create a numerical representation of a speaker's facial features that is used only to identify and organize speakers within that workspace. ChurchLibrary does not make this information available to other Customers or use it for advertising. Customer is responsible for obtaining any consents or permissions required by applicable law before using this feature. We retain speaker-matching information only as reasonably necessary to provide the feature and otherwise handle it in accordance with this Privacy Policy.
2. How We Use Information
We use information to:
- provide, host, operate, maintain, and support the Service;
- create and administer Customer workspaces, accounts, permissions, and authentication;
- store, transcribe, convert, index, tag, summarize, embed, search, and otherwise process Customer Content at Customer's direction;
- provide AI-powered search and chat functionality;
- secure the Service, prevent fraud and abuse, investigate incidents, and enforce our agreements;
- communicate about accounts, security, support, features, onboarding, and permitted marketing;
- monitor performance, troubleshoot, conduct analytics, and improve the reliability and functionality of the Service;
- comply with law and protect our rights and the rights of others; and
- create and use Aggregated Insights as described below.
3. Processing Details
ChurchLibrary processes Customer Personal Data as necessary to provide the Service, including hosting and storing Customer Content; processing, transcribing, and organizing sermon materials; generating tags, summaries, embeddings, search results, and AI-assisted responses; administering accounts and permissions; providing support; maintaining security; and performing related Service functions.
The types of personal information processed depend on the content Customer chooses to submit and may include account information, sermon and speaking content, voice and image data, religious information, user queries, transcripts, metadata, and related information. Processing continues for the duration of Customer's use of the Service and any limited retention period permitted under the Agreement or required by law.
4. Artificial Intelligence and Model Training
We use commercial and API-based artificial-intelligence services to support transcription, tagging, summarization, search, and chat. ChurchLibrary does not use Customer Content to train or fine-tune generalized artificial-intelligence models without Customer's express authorization.
We may use user feedback, test data, technical telemetry, and error information to identify bugs, improve code, evaluate responses, and improve the Service. We may also use service providers to process Customer Content as necessary to provide the Service, subject to contractual and technical arrangements applicable to those providers.
5. Customer Workspaces and Data Isolation
Each Customer has its own workspace. The Service is designed so that Authorized Users of one Customer cannot access another Customer's Customer Content unless separately authorized by that Customer. Customer administrators control user access and permissions within their workspace.
Workspace administrators may be able to access, export, modify, or delete Customer Content and manage Authorized Users. Individuals should direct questions about a Customer's internal access decisions to that Customer.
6. Aggregated and Deidentified Information
We may create aggregated or deidentified information from use of the Service, including broad trends derived from Customer Content, such as general topic or theme patterns. We use such information internally for analytics, security, research, capacity planning, and service improvement.
We do not use Aggregated Insights to allow one Customer to access another Customer's Customer Content, and we do not disclose content-derived Aggregated Insights in a manner that reasonably identifies a particular Customer, Authorized User, speaker, or specific sermon. We do not publish or commercially disclose cross-customer content-derived trends outside our organization unless we update our practices and provide any notice or choice required by applicable law or our agreements.
7. How We Disclose Information
We may disclose information in the following circumstances:
- Service providers and subprocessors. We use providers for hosting, storage, media processing, transcription, AI services, authentication, email delivery, analytics, security, and related functions.
- Customer administrators and Authorized Users. Information may be available within a Customer workspace according to permissions set by the Customer.
- Legal and safety purposes. We may disclose information when reasonably necessary to comply with law, legal process, or government requests; protect rights or safety; investigate fraud, abuse, security incidents, or violations; or establish or defend legal claims.
- Corporate or organizational transactions. Information may be transferred in connection with an internal restructuring, transfer to a subsidiary or affiliate, merger, consolidation, financing, sale, transfer of assets, or other transaction involving all or part of ChurchLibrary, subject to applicable law.
- With consent or direction. We may disclose information when directed or authorized by the Customer or individual, or as otherwise disclosed at collection.
We do not sell Customer Content. We do not sell personal information for monetary consideration or share personal information for cross-context behavioral advertising as those concepts are commonly understood under U.S. state privacy laws.
8. Service Providers
We use third-party service providers to help operate, secure, support, and improve ChurchLibrary, including providers that support cloud hosting and storage, media processing and transcription, artificial intelligence, authentication, communications, analytics, and other technical services. These providers may process Customer Content and other information as reasonably necessary to provide their services to us, subject to applicable contractual and legal requirements.
9. Google Drive Integration
Authorized Users may select files from Google Drive for import into ChurchLibrary. ChurchLibrary uses the Google Drive drive.file permission and accesses only files the user selects or opens with ChurchLibrary, not the user's other Google Drive files.
We use information received from Google Drive only to provide the user-requested ChurchLibrary features. Our use and transfer of information received from Google Workspace APIs complies with the Google User Data Policy, including the Limited Use requirements. We do not use Google Drive information for advertising or to train or improve generalized artificial-intelligence models. Human access and transfers are limited to the circumstances permitted by Google's policies, including providing the requested Service, security, legal compliance, and access authorized by the user.
Revoking ChurchLibrary's Google access does not automatically delete files previously imported into a Customer workspace. Imported files may be deleted in accordance with the Customer's workspace controls and this Privacy Policy.
10. Data Retention and Deletion
We retain personal information and Customer Content for as long as reasonably necessary to provide the Service, maintain the Customer relationship, comply with law, resolve disputes, enforce agreements, protect security, and fulfill legitimate operational needs.
Customers may request export or deletion of workspace data through available product functionality or by contacting us. Following a valid deletion request or termination, we will delete Customer Content from active systems within a commercially reasonable period, subject to routine backup cycles, legal holds, security and audit logs, fraud-prevention records, and information we are required or permitted by law to retain.
Residual copies may remain in backups until overwritten or purged through ordinary retention cycles and generally are not restored except for disaster recovery, security, or legal purposes.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No system is completely secure, and we cannot guarantee absolute security. Customers are responsible for configuring permissions appropriately, safeguarding credentials, and promptly removing unauthorized access.
12. Customer Responsibility for Sensitive Information
Customer determines what content to submit to the Service. Customer should not upload or direct us to process confidential pastoral counseling communications, legally privileged material, protected health information, financial account credentials, government identification numbers, or other highly sensitive information unless Customer has determined that doing so is lawful, necessary, and appropriate and has provided all required notices and obtained all required permissions or consents.
Sermon content may reveal or imply religious beliefs and may contain information about identifiable individuals. Customer is responsible for evaluating its legal basis and obligations before submitting that content.
13. Privacy Rights and Requests
Depending on where an individual resides and applicable law, the individual may have rights to request access, correction, deletion, portability, or other actions concerning personal information, and may have a right to appeal certain decisions.
When we process personal information solely on behalf of a Customer, we may refer the request to that Customer or require the individual to submit the request directly to the Customer. We will assist Customers with legally required requests as described in an applicable DPA.
Requests concerning information for which ChurchLibrary is responsible may be submitted to chase@vessel.org. We may need to verify identity and authority before completing a request.
14. Children
The Service is intended for organizational use by adults and is not directed to children under 13. Authorized Users must be at least 18 unless we expressly agree otherwise in writing. Customers should not submit personal information about children unless they have determined that the submission is lawful and appropriate.
15. International Processing
ChurchLibrary is operated from the United States, and information may be processed in the United States and other locations where our service providers operate. Where required, we will use legally recognized mechanisms for cross-border transfers.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date and provide additional notice when required by applicable law or when changes materially affect our practices.
17. Transfer of ChurchLibrary
ChurchLibrary is currently operated by Church of the Highlands, Inc. If ChurchLibrary or the assets or operations associated with the Service are transferred to a subsidiary, affiliate, successor, purchaser, or other operator, information associated with the Service may be transferred as part of that transaction. The successor operator may assume the rights and obligations described in this Privacy Policy, subject to applicable law and any required notice.
18. Contact Us
Privacy questions or requests may be directed to chase@vessel.org or Church of the Highlands, Inc., 3660 Grandview Pkwy, Birmingham, AL 35243.