Introduction
Bellwether ("we," "us," or "our") provides an AI-powered assistant that helps church staff query and manage their ministry data. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
This policy applies to all users of the Bellwether application ("Service"), including church administrators, staff, and volunteers who access the Service through their organization's account.
Information We Collect
Account Information
When you create an account or are invited to an organization, we collect:
- Name and email address — provided through our authentication provider
- Profile information — such as your avatar, if you choose to provide one
- Organization details — name and configuration settings for your church or ministry
Chat Data
When you use the Bellwether chat assistant, we collect and store:
- Your messages — the questions and instructions you type
- AI-generated responses — the answers Bellwether produces, which may reference data from your connected ministry applications
- Session metadata — timestamps, session identifiers, and conversation structure
Chat messages are encrypted at rest using application-level encryption.
Integration Data
When your organization connects a third-party ministry application (such as a church management system, communication platform, or volunteer management tool), we collect:
Billing Information
We use Stripe to process payments. Bellwether stores your Stripe customer identifier and subscription status. We do not store credit card numbers or bank account details — Stripe handles all payment card data directly.
Usage and Diagnostic Data
We collect operational data to maintain and improve the Service:
- Audit logs — records of data access events, tool calls, and configuration changes, including which categories of information were accessed
- Application logs — technical metadata such as request timing, error codes, and result counts
- Credit usage — how many AI queries your organization has used
Application logs are scrubbed to remove personally identifiable information before storage.
How We Use Your Information
We use the information we collect to:
- Provide the Service — process your chat queries, connect to your ministry applications, and generate AI-powered responses
- Manage your account — authenticate your identity, manage organization memberships, and enforce role-based access controls
- Process billing — manage subscriptions, track credit usage, and process payments through Stripe
- Maintain security — detect suspicious activity, enforce rate limits, and protect against unauthorized access
- Support compliance — maintain audit logs for your organization's governance and accountability needs
- Improve reliability — diagnose errors, monitor performance, and fix bugs
How AI Processing Works
We do not use your data to train AI models. We do not sell, rent, or trade your information to third parties for marketing purposes.
- You send a message — your question is transmitted to Bellwether's servers over an encrypted connection.
- Bellwether fetches relevant data — if your question requires information from a connected ministry application, Bellwether retrieves only the data needed to answer it. Your organization's data scope and field-level privacy settings control which categories of data are accessible and which fields are included or masked before AI processing.
- The query and data are sent to Anthropic — your message, along with the retrieved ministry data, is sent to Anthropic's Claude API to generate an answer. This data transits Anthropic's infrastructure.
- Anthropic returns a response — the AI-generated answer is streamed back to you through Bellwether.
What Anthropic Does and Does Not Do With Your Data
- Anthropic does not train its AI models on data sent through its API. This is a contractual guarantee under Anthropic's API terms, not merely a policy statement.
- Anthropic retains API logs for up to 30 days for safety monitoring and abuse prevention, after which they are deleted.
- Anthropic does not share your data with third parties for their own purposes.
Data Minimization
Your organization's administrator can configure:
- Which data categories the AI assistant can access (e.g., contacts, attendance, groups, services)
- Which fields are sent to the AI versus masked (e.g., names may be included while email addresses and phone numbers are replaced with placeholders like "[email hidden]")
These controls allow your organization to limit what information reaches the AI to only what is necessary for your use case.
Third-Party Services
We use third-party services to operate Bellwether. Each service receives only the data necessary for its function:
| Category | Purpose | Data Involved |
|---|
| Anthropic (AI provider) | Powers the AI chat assistant | Chat messages, ministry data retrieved for query answering (subject to your org's scope and masking settings) |
| Stripe (payment processor) | Subscription billing | Billing contact information, subscription status (Stripe handles payment card data directly) |
| Authentication provider | User identity and login | Name, email address, profile data |
| Cloud hosting provider | Infrastructure, compute, and encryption key management | All application data is hosted on infrastructure in the United States |
| Database provider | Data storage | All application data (encrypted at infrastructure and application levels) |
| Observability provider | Performance monitoring and error tracking | Technical metadata (no personally identifiable information) |
We name Anthropic and Stripe because they are directly relevant to how your data is processed and billed. For a complete list of all subprocessors, please contact us using the information at the bottom of this page.
When your organization connects a ministry application (such as a church management system), Bellwether accesses that application's API using OAuth credentials that your organization authorizes. Bellwether fetches data from these applications in real time and does not maintain a separate copy of your ministry records.
Data Security
Encryption and Security
- Encryption in transit — all data transmitted between your browser, our servers, and third-party services uses TLS encryption. We enforce HSTS (HTTP Strict Transport Security) in production.
- Encryption at rest — chat message content is encrypted at the application level. OAuth tokens for connected ministry applications are encrypted using managed encryption keys. Our database provider adds an additional layer of infrastructure-level encryption.
- Access controls — role-based permissions (owner, admin, member) restrict who can access organization settings, manage integrations, and view audit logs.
- Data isolation — all data queries are scoped to your organization. There is no cross-organization data access.
- Audit logging — all data access events, tool calls, and configuration changes are logged with timestamps and user attribution. Audit logs are append-only and available to organization administrators.
- Rate limiting — API endpoints are rate-limited to prevent abuse.
- Security headers — we apply standard security headers including Content Security Policy, X-Frame-Options, and referrer controls.
Data Retention
| Data Type | Retention Period |
|---|
| Chat messages | Retained while your organization's account is active; deleted upon account deletion request |
| Account information | Retained while your account is active; deleted upon account deletion request |
| Audit logs | Retained for the lifetime of the organization for compliance purposes |
| Anthropic API logs | Up to 30 days (managed by Anthropic) |
| Integration credentials | Retained while the integration is connected; securely deleted when disconnected |
| Billing records | Retained as required by applicable tax and financial regulations |
Your Rights and Choices
All Users
- Access your data — you can view your chat history and account information within the Service
- Delete your account — you can request deletion of your account and associated data by contacting us or through the Service. Deletion permanently removes your chat messages and personal information. Audit log entries are anonymized to preserve your organization's compliance records.
- Export your data — organization administrators can export their organization's data, including chat history and member information, in standard formats
Organization Administrators
- Configure data scope — control which categories of ministry data the AI can access
- Configure field masking — choose which fields are sent to the AI and which are masked
- Manage members — add, remove, and assign roles to organization members. When a member is removed, their chat sessions are archived and any active automated workflows are stopped.
- View audit logs — review who accessed what data and when
Data Ownership
Your organization's data belongs to your organization. Bellwether claims no ownership rights over church data, ministry records, chat content, or any information that passes through the Service. You may export and delete your data at any time.
Data Transfers
Bellwether's infrastructure is hosted in the United States. If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States. We rely on standard contractual clauses and our service providers' data protection measures to safeguard international transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Effective Date" and version number at the top of this policy
- Notify active users through the Service or by email
- Maintain a record of prior policy versions
Continued use of the Service after a policy update constitutes acceptance of the revised policy.
Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us at:
Email: hello@bellwetherapp.ai
This privacy policy is versioned. The current version is 1.0, effective February 27, 2026.