This page is available in English only. The English version applies.
Privacy Policy
Last updated: October 2026
In short
- Your sermons, notes and knowledge base belong to you. Other users can't see them unless you choose to share.
- We send your prompts to AI providers only to create the content you asked for, and we don't use your content to train AI models.
- We don't sell your personal data.
- Prayer requests on your church's prayer wall are encrypted before they are stored, and in the app only the church members you share them with can read them.
- You can download a copy of your data or delete your account yourself, any time, in Settings → Privacy.
1. Introduction
GospelGen ("we", "us", or "our") helps pastors, church leaders and believers draft ministry content with AI. We know the material you bring here — sermons, prayers, pastoral notes — is personal, and we want to be plain about how it is handled. This policy explains what we collect, which services process it, and the choices you have.
2. Information We Collect
Information you give us
- Account information: your email address, password (stored hashed by our sign-in provider) and, if you add them, your name, username and photo
- Ministry details you choose to share, such as your role, church name, denomination and preferred Bible translation
- What you type into generators, the content that is generated, and anything you save or edit in your library
- Ministry Brain material: knowledge base entries, uploaded documents, your ministry profile and author personas
- Messages you send to the AI chat assistant, and posts or comments you make in the Community Hub
- Church workspace activity: your church memberships and invitations, prayer requests you post and the ones you mark as prayed for, devotionals you publish and the devotional emails you subscribe to
- Billing information, which is collected and processed by Polar (we do not store card numbers)
Information collected automatically
- Usage data such as which features you use, what you generate and how many credits you spend
- Analytics events recorded by PostHog: the pages you visit (without query strings), the buttons and links you click (without their text), your browser and device type and, when you are signed in, your account ID. We never send your name or email to PostHog, and we do not record your screen or keystrokes
- Technical logs such as IP address, browser type and timestamps, used to keep the service running and secure
3. How We Use Your Information
- To provide GospelGen: generating, saving and exporting your content
- To personalise results with your Ministry Brain when you switch it on
- To manage your account, subscription and credits
- To send service emails (for example welcome, billing and credit notices) and, if you haven't opted out, occasional updates such as a monthly recap
- To understand how the product is used so we can improve it
- To prevent fraud and abuse, and to meet legal obligations
We do not use your content to train AI models, and we do not sell your personal data.
4. Services That Process Your Data
We rely on the following providers to run GospelGen. Each one receives only what it needs for its job. AI providers process your prompts to produce a response; their handling of that data is governed by their own terms and policies.
| Provider | What for | What it receives |
|---|---|---|
| Supabase | Database, sign-in and file storage | Your account, profile, generated content, knowledge base entries, uploaded files, chat history and church workspace data (prayer request text is stored encrypted, see section 6). |
| KIE AI | AI text generation (generators, refinements and the chat assistant) and image generation | The prompts and options you submit in a generator or chat, relevant excerpts from your Ministry Brain and your selected persona when they are switched on, and the image descriptions and settings you submit. |
| OpenAI | Knowledge-base search (embeddings) | The text of knowledge base entries you add, and search queries built from your prompts and chat messages. |
| PostHog | Product analytics | Which pages you visit (the address without anything after “?” or “#”), which buttons you click (never the text you type or read), device and browser details, and your account ID when signed in. Not used when your browser sends Do Not Track or Global Privacy Control. |
| Resend | Sending email | Your email address and the content of emails we send you, such as the daily reading of a devotional you subscribed to. |
| Polar | Payments and subscriptions | Billing details and payment information, handled directly by Polar. We never see or store your full card number. |
| Sanity | Content management for our blog | Our blog articles. Your account and ministry content are not sent to Sanity. |
We may also share information with legal authorities when the law requires it, or with a successor company if GospelGen is merged or sold — in which case this policy would continue to apply to your data.
5. Community and Sharing
Content stays private to your account unless you share it. Posts, comments and anything you publish to the Community Hub can be seen by other GospelGen users, along with your public profile details: your name, username, photo and cover image, bio, website, church name, denomination and ministry role. Your location is shown on your profile unless you turn off "Show location", and your profile visibility setting controls who can open your profile page.
When you share something you generated, the post shows the title and text you share plus a few display details (such as the scripture, theme and tags) — not the private settings, notes or Ministry Brain excerpts used to create it.
Your email address, phone number, plan, credits and billing details are never visible to other users.
6. Church Prayer Wall and Devotionals
Who can read a prayer request. When you post a prayer request you choose who sees it: every member of your church, or only its owner, pastors, elders and deacons. People who leave the church stop seeing its requests. The church owner and pastors can hide a request from the wall; a hidden request stays visible to them and to you.
Anonymous requests. If you post anonymously, your name is not shown to anyone else, including your pastors. We store who wrote each request so that only you can edit or delete it, and only you see that it is yours.
Encryption. The title, text and answer note of every prayer request are encrypted by GospelGen before they reach our database (AES-256-GCM), with a key that belongs to your church. That church key is itself stored only in encrypted form, locked with a master key that is kept outside the database. Members see how many people prayed for a request, but not who.
Deleting. Deleting a request erases its text straight away. If a church is deleted, its prayer requests and its keys are deleted too. Copies in our database provider's backups expire on their normal schedule.
Devotional emails. Your church can publish a devotional plan. You only get its daily emails if you subscribe to that devotional yourself, and every email has an unsubscribe link that works without signing in. You can also turn the emails off in the app at any time.
7. Data Retention
We keep your account data for as long as your account is active. Generated content stays in your library until you delete it. Deleting an item removes it from your library straight away, and it is permanently erased from our database 30 days later, together with the images generated for it.
When you delete your account, your profile, library, Ministry Brain (including uploaded documents), chats, community posts and comments, credits, church memberships, prayer requests (including anonymous ones), prayed-for marks and devotional subscriptions are erased immediately, along with your uploaded files and the images generated for you. A church you own with no other members is deleted too, with its prayer wall. Devotionals you published to a church that continues stay with that church.
A short log of account activity (for example data downloads, church role changes and moderation actions) is kept for about 13 months to help keep accounts secure; it holds IDs and roles, never message content. Payment records held by Polar are kept as required for tax and accounting purposes. Copies in our database provider's backups expire on their normal schedule.
8. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access — ask for a copy of the personal data we hold about you
- Correction — fix inaccurate data (you can edit most profile details yourself in your profile settings)
- Deletion — ask us to delete your account and personal data
- Portability — receive your data in a machine-readable format
- Opt out — stop receiving non-essential emails
You can do most of this yourself in Settings → Privacy:
- Download my data gives you a ZIP file with your profile, library (as JSON and Markdown), Ministry Brain and uploaded documents, chats, community activity, credit history and your church activity: memberships, invitations you sent, the prayer requests you wrote (readable, anonymous ones included), which requests you prayed for, devotional subscriptions and devotionals you published.
- Delete my account permanently erases your account as described above. If you have a paid subscription, cancel it in the billing portal first; if you own a church that has other members, transfer ownership first.
- You can unsubscribe from non-essential emails, such as the monthly recap or a devotional's daily reading, with the link in any of them; it works without signing in.
For anything else, or if you can't sign in, write to privacy@gospelgen.com from the address on your account and we'll respond as quickly as we can.
9. Cookies and Local Storage
We use essential cookies to keep you signed in. PostHog uses cookies or local storage to recognise returning visitors for product analytics; it is not loaded at all when your browser sends a Do Not Track or Global Privacy Control signal. We also store small preferences in your browser, such as your language and theme. You can clear or block these in your browser settings, though signing in requires essential cookies.
10. Children's Privacy
GospelGen is not intended for anyone under 18. We do not knowingly collect personal information from children, and if we learn that we have, we will delete it.
11. Security
Data travels between your browser and our services over encrypted connections (TLS). Our database and hosting providers encrypt stored data at rest. Database access rules keep each account's content separate, so one user cannot read another user's private content or private profile details.
Prayer requests get an extra layer: GospelGen encrypts their text itself, with a key for each church, before storing it (see section 6). Everything else — your library, Ministry Brain, chats and profile — is protected by the access rules and at-rest encryption described above, not by that extra layer. No system is perfectly secure — please use a strong, unique password.
12. International Data Transfers
Several of the providers above are based in the United States, so your information may be processed in countries other than your own. We choose established providers and rely on their contractual safeguards for these transfers.
13. Changes to This Policy
We may update this policy as GospelGen changes. When we make significant changes, we will let you know by email or with a notice in the app, and we will update the "Last updated" date above.
14. Contact Us
Questions, concerns or data requests? We're glad to help: privacy@gospelgen.com