Privacy Policy
Church Worship Planner · Effective September 2, 2026
Church Worship Planner ("we", "us") provides worship-planning and song-management software to churches. Each church has
its own private site at
yourchurch.churchworshipplanner.com and its own separate database. This policy explains what we collect, why, and
who can see it.
We do not sell your personal information, and we do not share it for advertising. We show no ads and run no advertising or analytics trackers.
Information we collect
Information your church provides
Church leaders invite members and maintain the congregation's directory. That can include your name, email address, phone number, household or family grouping, the worship roles you serve in, and dates you are unavailable.
Information you provide
- Your password, stored only as a salted cryptographic hash. It is never stored in readable form.
- Your notification preferences, and only if you choose to receive text reminders, a mobile number you enter and confirm yourself.
- Content you create in the app: planned services, song and slide material your church uploads, and prayer requests you submit.
Information collected automatically
- Sign-in and security records: session tokens, sign-in attempts (including the originating IP address), two-factor verification codes, and devices you have marked as trusted. These exist to detect and limit unauthorized access to your church's account.
- If you turn on browser notifications, the push subscription your browser issues for that specific device.
We do not use advertising cookies. The only cookie we set is the one that keeps you signed in.
How we use your information
- To operate the app: signing you in, showing your church's schedule, and saving your work.
- To send you the service reminders you are scheduled for, over the channels you have enabled: browser notification, email, and/or text message.
- To send account email such as invitations, password resets, and two-factor codes.
- To keep the service secure, diagnose faults, and prevent abuse.
We do not use your information to build advertising profiles or to train machine-learning models.
Mobile information and text messages
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors who provide support services, such as our message delivery provider, is permitted solely to deliver the messages you asked for. All other use-case categories exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.
Text reminders are strictly optional and off by default. You must enter your own mobile number and confirm it before
any text is sent, and you can stop them at any time by replying
STOP or by turning them off in your settings. See the Text Message Program page for
the full details.
Who can see your information
- People at your church. Members can see the congregation's directory and schedule. Leaders and administrators at your church can additionally edit member records and manage accounts. Your church controls who holds those roles.
- Other churches cannot. Each church's data lives in a separate database, and no church's site can read another's.
- Us. We can access church data when necessary to operate, support, back up, or repair the service.
Service providers
We use a small number of providers to run the service. They process data only to perform their function for us, and none of them receive your information for their own marketing:
- Hosting: servers and databases that run the application.
- Email delivery: invitations, password resets, two-factor codes, and email reminders.
- Text message delivery: reminder texts, only for members who opted in.
- Encrypted off-site backup storage: nightly database backups, so a church's data survives a hardware failure.
- Browser push services: if you enable browser notifications, your browser vendor's push service delivers them to your device.
How long we keep it
- Account and church content is kept for as long as your church's account is active.
- Sign-in sessions, password-reset links, two-factor codes, and invitations expire on their own and are deleted automatically after they lapse.
- Records of reminders already sent are deleted shortly after the service they referred to.
- Backups are retained on a rolling schedule and then deleted automatically.
Security
Traffic is encrypted in transit with HTTPS. Passwords are stored only as salted hashes. Accounts support two-factor authentication, and repeated failed sign-ins are rate-limited and recorded. Each church's data is isolated in its own database. No system is perfectly secure, but we treat congregational data as sensitive and design accordingly.
Your choices
-
Notifications. Every reminder channel can be turned on or off individually in your settings,
and text reminders additionally honor
STOP. - Corrections and deletion. Your church's administrators can correct or remove your record. If you cannot reach them, contact us at the address below and we will help.
Children
The app is intended for use by adults and by minors under the direction of their church. Accounts are created only by invitation from a church leader. We do not knowingly collect information directly from children under 13 without that involvement.
Changes to this policy
We may update this policy as the service changes. The effective date at the top of the page shows when it was last revised. Material changes affecting how we handle your information will be communicated through the app or by email.
Contact
Questions about this document can be sent to cameron@churchworshipplanner.com.