What we collect
We process account email addresses, securely generated password hashes (never readable account passwords), church workspace details, bulletin content, collaborator names and emails, files you upload, optional connect-card and RSVP responses, and basic security logs. Contributors and public readers do not need an account.
How we use information
Information is used to create, save, review, deliver and publish bulletins; authenticate users; send requested notices; give the church responses it deliberately collects; report aggregate bulletin use; provide support; prevent abuse; and meet legal obligations. We do not sell personal information.
Advertising measurement
We currently keep the Google advertising-measurement tag off on this website. There is no advertising-measurement prompt because no choice is needed for a tag that does not load. The private bulletin editor and public bulletin pages remain available without it.
If we enable advertising measurement in the future, we will update this notice and show an explicit choice before loading the Google tag. The prepared consent implementation blocks the tag until a visitor accepts. We do not send bulletin content, church names, denomination or tradition choices, contributor information, account email addresses, or uploaded files as conversion data.
Optional AI and voice tools
No bulletin content is sent to an AI provider until a user invokes a tool and confirms the request. A writing or translation request may include the selected section, instructions, fact fields, bulletin title, date and tradition context; transcription sends the selected audio; an AI-assisted import may send rendered pages and extracted text from the file the user chose. The page-arrangement tool sends only structure and layout measurements—not section wording, church identity, dates, contact details or image files. Protected section types are excluded where appropriate. Provider processing is also governed by that provider’s terms. Users must not submit confidential pastoral records or information they are not permitted to process. AI output and imported candidates require human review.
Public bulletin analytics and reader tools
Published mobile bulletins record aggregate events such as views, QR opens, link clicks, PDF downloads and sponsor-section views. We do not store raw reader IP addresses, user-agent strings or destination URLs for analytics. A daily rotating keyed hash limits duplicate counts and cannot follow a reader across days. Sermon notes stay only in that reader’s browser. Optional connect-card and RSVP responses are sent to the church workspace only after consent.
Private contributor links
Contribution links are bearer credentials: anyone holding a link may be able to open its scoped task until it expires or is revoked. Links should not be forwarded or posted publicly. Organizers can revoke and reissue access.
Storage and retention
Workspace content and operational records are retained while needed to provide and secure the service. Imported source files are scheduled for deletion after 30 days, reader responses after 45 days and aggregate analytics events after 400 days. Access tokens expire and can be revoked, but related security, advertising-measurement or submission records may remain until deleted under an applicable operational or legal process. Uploaded image metadata is removed where supported.
Your choices
Workspace owners may delete reader responses in the workspace and may request access, correction, export or deletion by emailing churchbulletinsoftware@gmail.com. If advertising measurement is enabled later, you will be able to continue without it and review your choice from the footer. Some records may be retained where required for security, billing or legal compliance.
Security and children
We use encrypted transport, one-way password hashing, scoped access, hashed recovery and session tokens, and least-privilege application controls. Password recovery links expire, can be used once and invalidate older sessions when a password is changed. No online system can promise absolute security. Churches must obtain appropriate consent before publishing names or images of minors and should avoid sensitive prayer or pastoral details unless permission is documented.
Changes and contact
Material changes will be dated on this page. Questions may be sent to churchbulletinsoftware@gmail.com.