Skip to content
Your Data, Protected

Privacy Policy

How we protect your data and respect your privacy

Last updated: September 25, 2026

We treat your data as sacred trust. Churches are places of vulnerability, confession, and care. The information shared through our platform deserves the highest standard of protection. This policy explains exactly how we honor that trust.

1. Who We Are

ChurchWiseAI LTD (“we,” “our,” or “ChurchWiseAI”) is a company incorporated in Ontario, Canada. We build AI-powered tools for churches and ministries, including:

  • ChurchWiseAI Voice Agent — an AI phone assistant for churches
  • ChurchWiseAI Chatbot — an AI care agent embedded on church websites
  • SermonWise AI (sermonwise.ai) — AI sermon outline generation
  • PewSearch (pewsearch.com) — a church directory serving the United States and Canada
  • IllustrateTheWord (illustratetheword.com) — sermon illustration library for pastors

This Privacy Policy applies to all of these services and any related websites, applications, and communications. As a Canadian company, we are governed primarily by the Personal Information Protection and Electronic Documents Act (PIPEDA). We also comply with applicable US state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA), Canada's Anti-Spam Legislation (CASL), and the US Children's Online Privacy Protection Act (COPPA).

Our designated Privacy Officer is responsible for our compliance with this policy and can be reached at privacy@churchwiseai.com.

2. What We Collect

We collect only the information necessary to provide our services. Under PIPEDA, we are required to identify the purposes for collection before or at the time we collect personal information. Below is a complete inventory of the categories of information we collect.

2.1 Account Information

  • Name, email address, phone number, and church affiliation provided during registration or onboarding.
  • Church profile information: church name, denomination, address, website, service times, and staff names/titles.
  • Team member roles and permissions within the ChurchWiseAI admin dashboard.

2.2 Voice Call Data

  • Call recordings — only when a church administrator has turned recording on. It is off by default, so most churches have no call audio stored with us at all.
  • Call transcripts generated by speech-to-text processing.
  • AI-generated call summaries, including detected prayer requests, visitor contacts, and callback requests.
  • Caller phone number, call duration, and call metadata.

2.3 Chat Data

  • Conversation logs between website visitors and the AI chatbot.
  • Contact information voluntarily shared by visitors during chat (name, email, phone).
  • AI-generated conversation summaries and detected care needs.

2.4 Sensitive Data — Prayer Requests and Pastoral Care Content

This information is classified as sensitive personal information under PIPEDA and US state privacy laws. It receives our highest level of protection.

  • Prayer requests submitted through the voice agent or chatbot, including those marked as confidential.
  • Pastoral care conversations, including disclosures about health conditions, grief, marital issues, addiction, mental health, and other deeply personal matters.
  • Religious beliefs and theological preferences expressed during conversations.

We require express consent for the collection and use of sensitive data. This data is accessible only to authorized pastoral roles within the church's admin dashboard, never to general staff or volunteers.

2.5 Church Knowledge Base Content

  • FAQs, documents, and information uploaded by church administrators to train their AI agents.
  • Custom persona settings, theological lens selections, and response tone preferences.

2.6 Sermon Generation Data

  • Sermon prompts, topics, scripture references, and theological preferences submitted through SermonWise AI.
  • Generated sermon outlines, small group guides, and derivative content.

2.7 Church Directory Data

  • Public church listing information on PewSearch: church name, address, phone number, denomination, service times, and website.
  • Premium Page content uploaded by churches that have claimed their listing.

2.8 Payment Data

  • Payment processing is handled entirely by Stripe. We never store, see, or have access to full credit card numbers.
  • We retain billing contact information (name, email, billing address) and transaction records (amount, date, plan) for accounting and tax compliance.
  • Billing practices: Cancel anytime, no contract. No refunds on current billing period. Chat plans include a 14-day trial; voice and bundle plans do not. See the Terms of Service section 11 for full billing and cancellation details.

2.9 Usage Data

  • Feature usage metrics, page views, and service performance data.
  • Device and browser information: browser type, operating system, screen resolution, and IP address.
  • On our own websites: the pages you visit, the links and buttons you click, how you arrived (for example the referring site, campaign tags such as utm_source, and ad click identifiers from Google or Meta), and, where session replay is enabled, a recording of how you moved through the page. When you are signed in, this activity is linked to your account ID and email address.

2.10 Cookies and Tracking Technologies

We use essential cookies to keep you signed in and to remember your cookie choice. On our own websites we also use analytics tools (PostHog and Google Analytics) and advertising measurement tools (Google Ads and the Meta Pixel), which set their own cookies and browser storage. These run unless you decline them using the cookie banner. They are never used on the church websites we host for our customers. See Section 14 for exactly what each one does and how to turn them off.

3. How We Use Your Information

Under PIPEDA, we must identify the purpose for collecting personal information before or at the time of collection. We use your information for the following specific purposes:

3.1 Providing Our Services

  • Operating and delivering AI voice agent, chatbot, sermon generation, directory, and illustration services.
  • Processing voice calls, generating transcripts, and creating AI summaries.
  • Responding to visitor questions using your church's knowledge base and configured theological lens.
  • Capturing and routing prayer requests, visitor contacts, and callback requests to the appropriate church staff.

3.2 Improving AI Quality and Accuracy

  • Analyzing conversation patterns (in aggregate, not individually) to improve AI response quality.
  • Refining our theological lens system to better serve diverse Christian traditions.
  • We do NOT use your church's data to train third-party AI models. See Section 6.

3.3 Transactional Communications

  • Sending welcome emails, magic-link authentication emails, and password resets.
  • Delivering notification emails when the AI detects prayer requests, visitor contacts, or care needs.
  • Sending billing confirmations, subscription updates, and service alerts.

3.4 Processing Payments

  • Processing subscription payments, upgrades, and cancellations through Stripe.
  • Maintaining billing records as required by Canadian and US tax law.

3.5 Safety and Abuse Prevention

  • Detecting threats of violence, self-harm, or abuse through our moderation system.
  • Enforcing rate limits and blocking abusive users to protect churches and their congregations.
  • Providing crisis referral resources (988 Suicide & Crisis Lifeline, Crisis Text Line) when the AI detects potential crisis language.

3.6 Analytics and Advertising Measurement

  • Generating aggregate usage statistics (e.g., average conversations per church per month) to improve our products and report on overall platform health.
  • Understanding how visitors use our own websites (which pages they view, what they click, where they drop off) using PostHog and Google Analytics. This is not anonymous: when you are signed in, it is linked to your account.
  • Measuring whether our advertising works: recording which ad or campaign brought you to us, and telling Google and Meta when an ad visit led to a sign-up or purchase. See Section 14.

5. Who We Share With

We do not sell, rent, or trade your personal information. Ever. For the purposes of the CCPA/CPRA, we do not “sell” personal information. Our own websites use the Meta Pixel and Google Ads to measure our advertising, which California law may treat as “sharing” for cross-context behavioral advertising. You can stop the in-browser tools by declining cookies in our cookie banner (see Section 14), and you can ask us about or object to any other use by emailing privacy@churchwiseai.com. Prayer requests, pastoral conversations, call data, and chat content are never sent to advertising platforms.

We share data only with the following trusted service providers (“sub-processors”) who are contractually obligated to protect your data and use it solely to provide their services to us:

ProviderPurposeData Shared
StripePayment processingBilling contact info, payment method (handled by Stripe directly)
SupabaseDatabase hosting (US)All stored data (encrypted at rest)
TwilioPhone numbers, voice calls, and SMS (older phone lines)Phone numbers, call audio, call metadata, SMS content
CartesiaText-to-speech (the voice agent's voice)AI-generated response text
OpenAIProduct support assistant; search vectors for knowledge base lookup; fallback for some church chat replies and chat tools when Anthropic is unavailableProduct-question chat text; chat questions and knowledge base text (to build search vectors); during a fallback, the visitor's message and church context
AnthropicAI processing (church chat assistant, voice agent, call summaries, sermon generation)Chat messages, call transcripts, system prompts, knowledge base context, sermon prompts
Google (Gemini)AI processing (voice agent and call-summary fallback); text-to-speech on Punjabi- and Urdu-language phone linesConversation transcripts, system prompts; the voice agent's response text on those lines
TelnyxPhone numbers and call routing (newer phone lines)Phone numbers, call signaling, call metadata
LiveKitReal-time call audio transport and voice agent hostingCall audio, call signaling
DeepgramSpeech-to-text on voice calls (and backup text-to-speech)Call audio; response text when used as the backup voice
AssemblyAIBackup speech-to-text if Deepgram is unavailableCall audio
Sarvam AISpeech-to-text for Punjabi-language calls onlyCall audio on phone lines set up for Punjabi
ResendTransactional email deliveryRecipient email, notification content
VercelWeb application hostingHTTP request logs, visitor IP addresses
Cal.comAppointment schedulingName, email, appointment time, reason (when visitor books via AI)
PostHogProduct analytics and session replay on our own websites (US)Pages viewed, clicks, campaign tags, device/browser info, IP address; account ID and email when signed in
Google (Analytics & Ads)Website analytics and ad conversion measurementPages viewed, device/browser info, IP address, Google ad click IDs, purchase value (with a one-way hashed identifier, never your email)
Meta (Facebook)Ad conversion measurement (Meta Pixel and Conversions API)Pages viewed, Meta cookie and click IDs, IP address; on purchase, a hashed (SHA-256) email and purchase value

If we add a new sub-processor that will handle personal information, we will update this policy and notify active customers at least 30 days before the new processor begins handling data.

5.1 Legal Disclosures

We may disclose personal information if required by law, including in response to court orders, subpoenas, or lawful government requests. We may also disclose information to protect the safety of our users or the public, or to enforce our Terms of Service.

5.2 Business Transfers

If ChurchWiseAI is acquired, merged, or sells substantially all of its assets, your personal information may be transferred to the successor entity. We will notify you by email and by a prominent notice on our website at least 30 days before such a transfer, and your information will remain subject to this Privacy Policy until a new policy is accepted.

6. AI-Specific Data Practices

Because our core services are powered by artificial intelligence, we want to be especially transparent about how your data interacts with AI systems.

6.1 What Data Goes to AI Providers

  • Chat conversations: The visitor's messages and the AI's prior responses are sent to Anthropic (Claude) for response generation on the chat assistant that churches place on their websites. Your church's system prompt (persona, tone, theological lens) and relevant knowledge base excerpts are included for context. To find those excerpts, the visitor's question is converted into a search vector using OpenAI. If Anthropic is unavailable, some short chat replies and chat tools (such as devotionals and lesson plans) fall back to OpenAI, which then receives the visitor's message and the same church context.
  • Product questions: The support assistant that answers questions about our own products (on churchwiseai.com and our other product websites) sends your messages to OpenAI.
  • Voice conversations: The caller's transcribed speech is sent to Anthropic (Claude) for response generation, along with your church's system prompt and relevant knowledge base excerpts. If Anthropic does not respond in time, the same request goes to Google (Gemini) instead. After the call, the transcript is summarized by Anthropic, with Google as the fallback.
  • Sermon generation: Your sermon prompts, selected scripture, theological lens, and any source material you provide are sent to Anthropic (Claude) for content generation.
  • We minimize the personal information sent to AI providers. When possible, we send conversation content without caller names or phone numbers.

6.2 AI Provider Data Retention

  • OpenAI: Retains API data for up to 30 days for abuse monitoring, then deletes it. API data is not used to train OpenAI models.
  • Anthropic: Retains API data for up to 30 days for safety monitoring, then deletes it. API data is not used to train Anthropic models.
  • Google (Gemini): Used only as a fallback for the voice agent and for call summaries, when Anthropic does not respond in time.
  • OpenAI and Anthropic operate under Data Processing Agreements (DPAs) that contractually prohibit using our data for model training.

6.3 Our AI Data Commitments

  • No third-party training: We do NOT use your church's data to train third-party AI models.
  • Church data isolation: Each church operates in complete isolation. Church A's knowledge base, conversations, and settings are never visible to Church B's AI agent. There is no mechanism for cross-church data leakage.
  • AI accuracy disclaimer: AI-generated content (sermon outlines, chatbot responses, voice agent responses) may contain inaccuracies. Churches should review AI-generated content before using it in ministry contexts.
  • Shared public content: Our shared content library (sermon illustrations, Bible references) contains publicly available, non-sensitive material and is accessible to all churches as a common resource.

7. Call Transcription and Recording

These are two different things, and it is worth separating them, because what happens on almost every call is transcription, not recording.

Transcription is the normal practice. Calls handled by the voice assistant are transcribed to text so church staff can follow up, and the assistant discloses this on the call: it tells the caller the call may be transcribed and reviewed by authorized church staff.

Audio recording is a separate feature, and it is off by default. A church administrator can turn it on. It is not enabled on customer lines as standard, and a church that has never turned it on has no call audio stored with us. When it is enabled, the practices below apply:

  • Disclosure: the caller is told at the start of the call that the call may be recorded, in addition to the transcription disclosure above.
  • Consent mechanism: By continuing the call after the disclosure, the caller consents to recording. Callers who do not wish to be recorded may hang up and contact the church through alternative means (email, web chat, or visiting in person). Canadian law permits a participant in a conversation to record it, but privacy law separately requires the purpose to be made known, which is why the disclosure is given rather than relied upon implicitly.
  • Retention: Call recordings are retained for 90 days, then automatically and permanently deleted. Call transcripts and AI summaries are retained for 1 year.
  • Access: Church administrators and office administrators can access recordings for their own church only. No other roles can access call recordings.
  • Caller access: Any caller may request access to their own recording by contacting us at privacy@churchwiseai.com with identifying details (approximate date, time, and phone number used).
  • Deletion requests: Callers may request deletion of their recording at any time. We will fulfill deletion requests within 5 business days.

8. Facebook Pages and Social Posting

Some of our products (ShareWiseAI and the social-posting tools in our dashboards) let you connect a Facebook Page so we can publish posts you write, to the Page you choose. This section covers exactly what we get from Facebook (Meta Platforms) and what we do with it.

What we receive when you connect

  • The list of Facebook Pages you manage (each Page's id, name, username, profile picture and follower count), so you can pick one. We keep only the Page you choose.
  • An access token for that Page, plus a Facebook login token and your Facebook user id for our app, which we need to keep the connection working and to honour deletion requests.
  • For posts published through us: the post's id and link, and engagement numbers (such as reactions, comments and shares) so your dashboard can show how a post did.

What we do with it

  • We publish a post to your chosen Page only when you press Post (or schedule it yourself). We never post on our own, and never to a Page you did not choose.
  • We show you your connected Page, your post history and its engagement numbers.
  • We do not sell Facebook data, use it for advertising, share it with other customers, or read your personal profile, friends or messages.

Storage, retention and deletion

  • Tokens are stored encrypted (AES-256-GCM) and are never shown in your browser.
  • We keep the connection until you disconnect it. Clicking Disconnect in your dashboard deletes the stored Page connection and its tokens immediately.
  • You can also remove our app in your Facebook settings (Settings & privacy → Settings → Business integrations or Apps and websites). Facebook then notifies us automatically, and we delete every Facebook connection made by your Facebook account.
  • Or email privacy@churchwiseai.com and we will delete it for you.

9. Data Retention

Under PIPEDA, personal information must be retained only as long as necessary to fulfill the purposes for which it was collected. The following table sets out our retention schedule:

Data TypeRetention PeriodNotes
Call recordings90 daysOff by default. Where enabled, cleared by a scheduled daily job.
Call transcripts & AI summaries1 yearChurch admin can request earlier deletion
Chat conversation logs1 yearChurch admin can request earlier deletion
Prayer requestsDuration of subscription + 90 daysChurch admin can delete individually at any time
Visitor contactsDuration of subscription + 90 daysUsed for ongoing pastoral follow-up
Account dataDuration of subscription + 90 days90-day grace period allows reactivation
Sermon contentDuration of subscription + 90 daysUsers can export before cancellation
Billing records7 yearsRequired by Canadian and US tax law
Usage analytics2 yearsAggregated metrics retained indefinitely. Website analytics held by PostHog, Google, and Meta follow those providers' retention settings.
Moderation violation logs2 yearsRequired for abuse pattern detection
Breach notification records24 months minimumRequired by PIPEDA

After the retention period, data is permanently deleted or anonymized so that it can no longer identify any individual. Deletion is irreversible. If you cancel your subscription, your data is preserved in a read-only state for 90 days to allow reactivation, after which it is permanently deleted and a confirmation email is sent.

10. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption in transit: All data is transmitted over TLS 1.2 or higher (HTTPS). WebSocket connections for the voice agent use WSS (WebSocket Secure). HTTP requests are automatically redirected to HTTPS.
  • Encryption at rest: All stored data is encrypted using AES-256 encryption via our database provider (Supabase on AWS infrastructure).
  • SOC 2-compliant providers: Our primary infrastructure providers (Supabase, Stripe, Vercel, OpenAI, Anthropic, Twilio) maintain SOC 2 Type II certifications.
  • Role-based access controls (RBAC): Church data is protected by a 7-role permission system. Sensitive pastoral data is restricted to authorized pastoral roles. Financial data is restricted to admin and treasurer roles. Access is enforced at the API level, not just in the user interface.
  • Audit logging: All data access is logged with timestamps, user identifiers, and actions performed. Moderation events are permanently logged.
  • No local storage of church data: Church data is not stored on ChurchWiseAI employee devices or local machines.
  • Regular security reviews: We conduct periodic security assessments and vulnerability reviews.

While we implement robust security measures, no system is 100% secure. We commit to notifying you promptly of any data breach that may affect your personal information (see Section 17).

11. Your Rights

Under PIPEDA, the CCPA/CPRA, and other applicable privacy laws, you have the following rights regarding your personal information:

  • Right to Access — You may request a copy of all personal information we hold about you or your church. We will respond within 30 days of your request (as required by PIPEDA) and provide the information in a commonly used electronic format.
  • Right to Correction — You may request correction of any inaccurate or incomplete personal information. You can update most information directly through your admin dashboard.
  • Right to Deletion — You may request that we delete your account and all associated personal information. We will comply within 30 days, except where we have a legal obligation to retain certain records (e.g., billing records for tax compliance).
  • Right to Data Portability — You may request an export of your data in a standard machine-readable format (CSV or JSON). This includes conversations, prayer requests, visitor contacts, knowledge base content, and sermon content.
  • Right to Withdraw Consent — You may withdraw your consent for any data processing at any time. Some features may become unavailable if consent is withdrawn.
  • Right to Know (CCPA) — California residents may request that we disclose what categories of personal information we have collected, the purposes for collection, and the categories of third parties with whom we share it.
  • Right to Opt-Out of Sale (CCPA) — We do not sell personal information. However, for CCPA compliance, we affirm your right to opt out of any future sale, should our practices ever change.
  • Right to Non-Discrimination — We will not discriminate against you for exercising any of your privacy rights. You will not receive different pricing, a different quality of service, or any penalty for making a privacy request.

How to Exercise Your Rights

To exercise any of these rights, contact our Privacy Officer at:

We may verify your identity before processing your request. For church-level requests, we will confirm that the request comes from an authorized administrator.

Right to Complain

If you believe we have not handled your personal information properly, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC):

Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
Phone: 1-800-282-1376
Website: www.priv.gc.ca

12. Children's Privacy

Our services are designed for church leaders, ministry staff, adult volunteers, and adult congregation members. Our services are not intended for use by children under the age of 13.

  • We do not knowingly collect personal information directly from children under 13 without verified parental consent.
  • If a child under 13 interacts with a church's voice agent or chatbot, the church is responsible for ensuring appropriate parental consent and COPPA compliance for their congregation.
  • Voice recordings of children (including voiceprints, which are covered under COPPA) are subject to the same protections and should not be collected without parental awareness.
  • If we discover that we have inadvertently collected personal information from a child under 13 without proper consent, we will delete it promptly.

If you are a parent or guardian and believe your child has provided personal information through one of our services, please contact us at privacy@churchwiseai.com and we will delete it immediately.

13. International Data Transfers

ChurchWiseAI is incorporated in Ontario, Canada, and serves churches in both Canada and the United States. Your data may be processed and stored in both countries.

  • Primary database: Hosted in the United States (Supabase on AWS).
  • AI processing: Performed in the United States (Anthropic, OpenAI, Google).
  • Voice infrastructure: Telnyx, Twilio, LiveKit, Deepgram, AssemblyAI, and Cartesia operate primarily from the United States. Google Cloud Text-to-Speech, used for the voice on Punjabi- and Urdu-language lines, is a Google service operated from multiple regions. Sarvam AI, used only for Punjabi-language calls, is based in India.
  • Web hosting: Vercel operates a global CDN with edge functions in multiple regions.

We ensure adequate data protection for all cross-border transfers through:

  • Data Processing Agreements (DPAs) with all sub-processors.
  • Contractual obligations requiring equivalent data protection standards.
  • Technical safeguards including encryption at rest and in transit.

By using our services, you consent to the transfer and processing of your data in the United States and Canada. You may request more information about specific safeguards by contacting our Privacy Officer.

14. Cookies and Tracking Technologies

This section describes the cookies and browser storage (“localStorage”) used on churchwiseai.com and our related product websites (such as sermonwise.ai, sharewiseai.com, wiseaiagency.com, funeralwiseai.com, and veterinarywiseai.com). They fall into three groups.

14.1 Essential

  • Sign-in cookies: Secure, same-site cookies set by our authentication provider (Supabase) that keep you signed in to your dashboard or account.
  • Security and account cookies: A cookie that remembers which account you are working in (kept for up to one year) and a signed sign-in hand-off cookie between our pages (kept for 12 hours).
  • Your cookie choice: A localStorage entry named cookie-consent that remembers whether you clicked Accept or Decline.
  • Preferences: Small localStorage entries that remember interface choices (for example, a dismissed banner or a collapsed menu).

These are needed for the site to work and are not affected by your cookie choice.

14.2 Analytics

  • PostHog (product analytics and session replay). Records the pages you view, the links and buttons you click (including their text), when you leave a page, campaign tags in the address (utm_*), and your device, browser, and IP address. It stores a random visitor ID in a cookie and in localStorage. When you sign in, we link this activity to your account ID and email address. PostHog may also record a replay of how you moved through a page; text you type into form fields is masked by default and is not captured in the replay. We also send a small number of events from our servers to PostHog (for example, when a subscription is completed).
  • Google Analytics 4. Records the pages you view and key actions (such as starting a checkout, signing up, or sending an enquiry), with device, browser, and approximate location. It sets Google Analytics cookies (such as _ga). It is not loaded on the church admin, business, and realtor dashboards, but it does run on other signed-in areas such as the SermonWise and ShareWise apps. When a purchase is completed, our server tells Google Analytics the purchase value, using a one-way hashed identifier rather than your email address.

14.3 Advertising and Attribution

  • Google Ads. Shares the Google tag above and sets Google Ads cookies (such as _gcl_au) so that, when you arrive from one of our Google ads, a later sign-up or purchase can be credited to that ad.
  • Meta Pixel (Facebook/Instagram). Records page views and sets Meta cookies (_fbp, and _fbc when you arrive from a Meta ad). When a purchase is completed, our server also sends Meta the purchase value, those Meta identifiers, and your email address in hashed (SHA-256) form through Meta's Conversions API, so Meta can match the purchase to an ad.
  • Our own attribution cookies (cwa_attr_first and cwa_attr_last). When you arrive through a link with campaign tags or an ad click ID (gclid, wbraid, gbraid, fbclid), we store those values, your landing page, and the referring site for 90 days. If you then sign up, buy, or send us an enquiry, they are saved with that record so we know which campaign brought you.

We do not use these tools on the church websites we host for our customers, on our outreach preview pages, or on wisedatingprep.com. Prayer requests, pastoral conversations, call data, and chat content are never sent to analytics or advertising platforms.

14.4 Your Choices

  • These tools run by default. Analytics and advertising cookies start when you first visit and continue unless you decline them. Our banner is a notice with an opt-out, not a request for opt-in consent.
  • To decline: click Decline in the cookie banner at the bottom of the page. From then on, PostHog, Google Analytics, Google Ads, the Meta Pixel, and our attribution cookies stop collecting in that browser. The change takes full effect from the next page you load. Declining does not delete cookies that were already set; to remove them, clear this site's cookies and site data in your browser settings.
  • To change your mind: there is no settings page for this yet. Clear this site's cookies and site data in your browser. The banner will then appear again and you can make a new choice.
  • Where the banner does not appear: your choice is saved separately for each website, and the banner is not currently shown on some of our product websites (including sermonwise.ai, sharewiseai.com, wiseaiagency.com, funeralwiseai.com, and veterinarywiseai.com). On those sites, you can block these tools with your browser's tracking protection or a content blocker, or email privacy@churchwiseai.com and we will help.
  • Purchase reporting to Google and Meta happens on our servers after checkout, so declining in the banner does not stop it. If you have questions or objections about it, email privacy@churchwiseai.com.
  • We do not currently respond to browser “Do Not Track” or Global Privacy Control signals automatically.

15. Email Communications (CASL Compliance)

As a Canadian company, we comply with Canada's Anti-Spam Legislation (CASL) for all email communications.

14.1 Transactional Emails (No Consent Required)

The following emails are sent as part of providing our services and do not require opt-in consent under CASL. They will always identify ChurchWiseAI as the sender and include contact information:

  • Account verification and magic-link authentication emails
  • Payment confirmations and billing receipts
  • Service notifications (prayer request alerts, visitor contact alerts, threat alerts)
  • Subscription status changes and renewal reminders
  • Security alerts and password reset emails
  • Privacy policy or terms of service updates

14.2 Marketing Emails (Express Consent Required)

Marketing and promotional emails (newsletters, product announcements, feature highlights) are sent only with your express opt-in consent. We log the date, time, source, and manner of your consent as required by CASL.

  • You can unsubscribe from marketing emails at any time using the unsubscribe link in any email.
  • We process unsubscribe requests within 10 business days (CASL requirement).
  • Unsubscribing from marketing emails does not affect transactional emails.

16. Automated Decision-Making

Our platform uses AI-powered moderation to detect abuse patterns including spam, harassment, threats of violence, self-harm language, and misuse of the chatbot or voice agent. If abuse is detected, access may be automatically restricted through a graduated escalation system (warning, cooldown, temporary block, permanent block).

If you believe your access has been restricted in error, you may appeal by contacting support@churchwiseai.com. All appeals are reviewed by a human within 48 hours. We do not use automated decision-making for any other purpose (such as pricing, eligibility, or content filtering).

17. Breach Notification

Under PIPEDA, we are required to notify affected individuals and the Office of the Privacy Commissioner of Canada (OPC) of any breach of security safeguards involving personal information that creates a “real risk of significant harm.”

  • Notification to individuals: We will notify affected individuals as soon as feasible after confirming a qualifying breach. Notification will include a description of what happened, what data was affected, what we have done in response, and recommended steps for the affected individual.
  • Notification to the OPC: We will report qualifying breaches to the OPC as required by PIPEDA.
  • Notification to churches: For breaches involving church data, the church administrator will hear from us directly (personal communication from ChurchWiseAI leadership, not a generic email).
  • Breach record: We maintain a log of all breaches (including those that do not meet the notification threshold) for a minimum of 24 months, as required by PIPEDA.
  • Our commitment: We will over-notify rather than under-notify. If there is any doubt about whether a church's data was affected, we will notify them. Affected parties will always hear from us before hearing from anyone else.

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features.

  • We will provide at least 30 days' notice before any material change takes effect.
  • Notice will be provided by email to the address on file and by a prominent notice on our website.
  • The “Last Updated” date at the top of this policy indicates when it was most recently revised.
  • Your continued use of our services after the effective date of a revised policy constitutes acceptance. For material changes affecting your rights, we may require explicit acknowledgment before you can continue using our services.

Questions about your privacy?

Contact our Privacy Officer — we're here to help.

Privacy Officer

ChurchWiseAI LTD

125 Concession Street

Ingersoll, ON, Canada N5C 1G2

We typically respond to privacy inquiries within 2 business days and will fully address your request within 30 days, as required by PIPEDA.