Privacy Policy

Effective 16 September 2026 · Last updated 16 September 2026

1. Who we are

MinistryAI is a nonprofit corporation recognized as tax-exempt under Section 501(c)(3) of the Internal Revenue Code, EIN 41-4049715, with a mailing address at Studio City, CA 91604, United States. In this policy, "MinistryAI," "we," "us" and "our" mean that organization.

We build AI tools for churches and seminaries. People bring real questions, struggles and prayer requests to those tools. This policy explains what we do with what they share, and what we will not do with it.

2. What this policy covers

This policy covers ministry-ai.org and the MinistryAI platform, including Cornerstone Bible Study, Shepherd Studio, and any other workspace we operate.

It does not cover a church's own website, email, or other systems, and it does not cover what a church does with information after it leaves our platform. Your church's own privacy practices are its own.

3. Information we collect

Information you give us

  • Account information — your name, email address, and, where a workspace is organization-based, the church or organization you belong to and your role in it.
  • Requests to join or to open a workspace — the details you submit on our sign-in page, such as an administrator's name and email, a church's name, address and contact information, and a pastor's name and email.
  • What you write in the platform — questions you ask, study notes, journal entries, prayer requests, feedback on teaching, and anything else you type or upload.
  • Correspondence — messages you send to us by email.

Information your church gives us

  • The church's corpus — doctrine, liturgy, approved sermons, curriculum and other teaching materials the church chooses to have ingested so its workspace answers from its own teaching.
  • Membership and role information — who should have access to the workspace and at what level.

Information collected automatically

  • Technical and usage data — IP address, browser and device type, pages viewed, and timestamps, used to operate and secure the service.
  • Authentication records — sign-in events recorded by our identity provider.

We do not buy personal information from data brokers, and we do not build advertising profiles.

4. Member privacy tiers

Where a workspace offers them, you choose how a submission is handled at the moment you submit it:

  • Fully anonymous Identifying details are stripped and the submission contributes only to aggregate patterns. Leadership sees themes, not individuals.
  • Confidential pastoral routing The submission goes to a designated pastoral care provider with your identity intact and is excluded from aggregate analysis.
  • Identified but sanitized A specific pastor sees who you are; a sanitized version informs broader pastoral awareness.
  • Full transparency For non-sensitive matters, you may choose full visibility to your leadership.

An honest limit. Anonymization reduces risk; it does not eliminate it. A submission that describes a situation in enough detail may still identify the person who wrote it, however the record is labelled. Please use the tier that matches how sensitive the matter really is.

5. How we use information

  • To provide the service — answering questions from your church's corpus, with citations, and routing submissions according to the tier you chose.
  • To create and secure accounts, and to authenticate sign-in.
  • To respond to requests to join a study or to open a church workspace.
  • To support, maintain, debug and improve the platform.
  • To protect people — for example, where someone appears to be at risk of serious harm, the system is designed to step back and point them to a pastor or care-team member.
  • To meet legal and tax obligations that apply to a United States nonprofit.

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use what members write to advertise anything to them.

6. AI models and your content

MinistryAI is model-agnostic: the platform can be configured to run on different underlying AI models, some operated by third-party providers. When you ask a question, the text of that question and relevant excerpts from your church's corpus are sent to the configured model so it can produce an answer.

  • We contract with model providers on terms that prohibit using your content to train their models.
  • Your church's corpus is not pooled with any other church's, and answers in your workspace draw only on materials your church approved.
  • We never sell your content, and we do not use it to train models for anyone outside your church's workspace.

If you would like to know which model provider is configured for your workspace, ask your church's administrator or write to us.

7. When we share information

We share personal information only in these circumstances:

  • With your church's designated leadership, according to the privacy tier you chose for each submission.
  • With service providers who host, secure and operate the platform on our behalf — including cloud hosting, identity and authentication, and AI model providers — under contracts that limit them to providing those services.
  • Where the law requires it, or to respond to a valid legal process. Where we are permitted to tell you, we will.
  • To prevent serious harm to you or another person.
  • In an organizational change, such as a merger with or transfer of our programs to another nonprofit — in which case the successor is bound by this policy until it gives you notice of a change.

8. Your church's role

For organization-based workspaces such as Shepherd Studio, your church decides who has access, what materials are ingested, and how pastoral oversight works. In data-protection terms, the church is the controller of that workspace's data and MinistryAI processes it on the church's instructions.

This matters in practice: your church's designated leaders can see what the tier you chose permits them to see. If you want to know exactly who at your church can see what, ask your church — and we will help them answer.

9. How long we keep information

  • Account information — while your account is active, and for up to 12 months after it is closed.
  • What you write in the platform — while your account is active, unless you or your church delete it sooner.
  • Aggregate, de-identified patterns — may be kept indefinitely, because they are no longer tied to an individual.
  • Technical logs — typically 90 days, longer where needed to investigate a security incident.
  • Records we must keep by law — for as long as the law requires.

When a church ends its use of MinistryAI, we will return or delete its workspace data at its direction.

10. Security

Each church's workspace and corpus are kept isolated from every other church's. Access is controlled through an identity provider with role-based permissions, connections are encrypted in transit, and data is encrypted at rest. Access by our staff is limited to those who need it to operate or support the service.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as the law requires.

11. Your rights and choices

Depending on where you live, you may have the right to:

  • know what personal information we hold about you and get a copy of it;
  • correct information that is wrong;
  • delete your information;
  • limit or object to certain processing;
  • withdraw consent you previously gave; and
  • not be discriminated against for exercising any of these rights.

California residents have these rights under the California Consumer Privacy Act as amended by the CPRA. We do not sell or share personal information as those terms are defined there.

To exercise a right, write to admin@ministry-ai.org. We will verify your request and respond within the time the law allows. If your information sits in a church's workspace, we will work with that church to carry out your request.

12. Children and youth ministry

MinistryAI is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has an account, write to us and we will delete it.

Where a church uses MinistryAI in youth ministry with participants aged 13 to 17, the church is responsible for obtaining any parental consent its own policy or applicable law requires before giving a minor access. We will support churches in setting that up.

13. International users

We operate from the United States, and information we hold is processed there and in other countries where our service providers operate. If you are in the European Economic Area, the United Kingdom, Korea or another jurisdiction with data-transfer rules, we rely on appropriate safeguards — such as standard contractual clauses — for those transfers.

14. Cookies

Our public website uses no advertising or analytics cookies. The platform uses cookies that are strictly necessary to keep you signed in and to keep your session secure. We do not use cookies to track you across other websites.

15. Changes to this policy

We will update this policy as the platform develops. When a change is material, we will post the new version here with a new effective date, and give notice in the platform or by email before it takes effect.

16. How to reach us

Questions, requests and complaints about privacy go to admin@ministry-ai.org, or by post to MinistryAI, Studio City, CA 91604, United States.

If you are not satisfied with our response, you may have the right to complain to your local data-protection authority.