Privacy policy
Last updated: September 28, 2026
We're a small team building software for churches. We take privacy seriously because the data flowing through our system — sermons, pastoral conversations, prayer requests — is sensitive. This page describes what we collect, where it goes, and how to delete it. It's written in plain English on purpose; if anything is unclear, email help@churchtranslator.ai.
What we collect from churches
When a church signs up, we collect: the church's display name, the admin's email address, your billing info (handled by Stripe — we never see your card number), and your language + branding choices. We also collect usage telemetry: minutes of translated audio per language, listener counts per service, latency measurements, and which capture devices are connected.
We never sell or share any of this with third-party advertisers, data brokers, or denominational organizations.
What we collect from listeners
Almost nothing. Your church's listener page asks for one thing: which language to play. We don't ask for an email, name, phone number, location, or any account. We log an anonymous session ID (random string), the IP address (used only to detect duplicate listeners + block obvious abuse), and the language they picked. None of this is shared with the church admin in a way that identifies individual listeners — admins see counts per language, never an individual person's history.
Sermon audio — the important part
Live sermon audio flows from your capture device (the Mac or Windows capture app, or the in-browser capture page) → our servers on Fly.io → our real-time translation engine → back through our servers → out to listener phones. Your church chooses the engine (Translation V1, Translation V2, or Translation V3 / Studio Voice, which chains speech recognition, translation and a synthesized voice across the providers listed below). For a live service the audio does not sit in long-term storage — once a segment is delivered to listeners it's discarded server-side. Aggregate metrics (minute counts, latency) persist; the audio bytes themselves do not.
Our translation providers operate under commercial API terms under which API inputs are not used to train their models by default; each provider retains inputs briefly for abuse monitoring before deletion. We'll update this page if those terms change in a way that affects this.
Uploaded audio (Audio Dubbing) and generated tracks. If you use Audio Dubbing, the recording you upload is stored on our servers (Fly.io volume) while the job runs and, together with the dubbed tracks we generate, for 14 days afterwards so you can download the results; you can delete a job at any time, and expired jobs are deleted automatically. The audio is sent to the providers below to transcribe, translate and synthesize it. YouTube audio tracks generated from a service transcript are stored under the same rules.
Service transcripts and sermon summaries. Recording a transcript is off unless your church turns it on in the dashboard. When it is on, the caption text of each service (text only, never audio) is stored on our servers so you can read and download it, and is sent to one of the AI providers listed below to write the sermon summary. Transcripts are deleted automatically after 90 days, or sooner when you delete them.
The Mac capture app also offers optional local recording of translated audio. An operator chooses a folder on the booth Mac, and the files are written to that folder. They are not uploaded to a ChurchTranslator.AI storage bucket. Local recording is off until an operator chooses a folder and languages to record.
Who we share data with (processors)
We use the following third-party services to run the platform:
- Stripe — payment processing. Stripe handles all card data; we never see it.
- Clerk — dashboard sign-in (your admin email + password / social sign-in). Stores per-tenant metadata (which church a user belongs to) and nothing else about you.
- Fly.io — server hosting for the translation pipeline, dashboard, and listener app. Data is encrypted in transit and at rest.
- Cloudflare — edge networking, DDoS protection, and free TLS certificates for custom domains.
- Third-party AI providers — the speech recognition, translation and voice-synthesis services behind our engines (Live Interpreter, Natural Voice, Studio Voice, Steady voice, Audio Dubbing and transcript summaries) process sermon audio and text to produce the translation. Each receives only the audio or text needed for its stage, under commercial API terms that do not use inputs for model training by default, and does not retain it long-term. We may change providers as the technology improves; the current list is available on request at help@churchtranslator.ai.
- Resend — transactional email delivery (welcome, billing, and service notices to your admin email).
- Google Analytics — anonymous page-traffic statistics for this website (the marketing pages and the church admin dashboard — never the listener page). It runs in consent mode: it sets no cookies and gets only aggregated, anonymous pings unless you click "Allow" on the analytics banner. We don't send it names, emails, sermon content, or anything you type into the dashboard.
We don't use advertising networks, tracking pixels (no Facebook Pixel), or session-recording tools. The only analytics is the consent-gated Google Analytics described above, and the listener page your congregation uses has no analytics at all.
Cookies
We use cookies for sign-in sessions (Clerk session cookies) and remembering your dashboard preferences. Google Analytics sets its measurement cookie only after you click "Allow" on the analytics banner — declining (or ignoring) the banner keeps this site cookie-free beyond sign-in. The listener page uses one local-storage entry to remember the visitor's language choice across visits — nothing that travels off-device.
How to delete your data
To cancel service, open the Stripe Customer Portal from the Billing page and click Cancel. Your translation service stays live until the end of the current billing cycle. Cancellation stops the service but does not delete the church account: we retain its configuration and branding so it can be reactivated later.
To permanently delete the church account, use Delete church account in the Billing page's Danger zone. The workflow requests immediate subscription cancellation, revokes capture-app access, removes the tenant configuration, and requests removal of team sign-ins and the managed hostname. If Stripe cannot confirm a billing step, the church account is kept and the dashboard reports the failure. If an identity or DNS provider fails after local deletion, the dashboard reports the remaining cleanup for support instead of claiming complete success. Recordings saved locally by the Mac app stay in the folder your operator selected; delete those files on the Mac separately.
For individual data-subject requests (GDPR / CCPA), email help@churchtranslator.ai with the subject line "Data request". We respond within 30 days as required.
Children
The platform is sold to churches, used by adult admins. The listener page is open to anyone in the room, including children, but it collects no personal information from listeners. We don't knowingly market to or collect data from children under 13.
Security
We use industry-standard encryption (TLS 1.3 in transit, AES-256 at rest for stored data). Admin authentication is MFA-capable through Clerk. Capture-app pairing tokens are unique per device, revocable from the dashboard, and never shared across tenants. We patch infrastructure dependencies weekly. We'll notify affected churches within 72 hours of confirming any breach that exposes their data.
Updates to this policy
We'll post material changes here with a new "last updated" date and email all active tenants. Continuing to use the service after a posted change means you accept the new terms.
Contact
ChurchTranslator.AI — a product of Kulinich.Tech.
help@churchtranslator.ai