Back to Home

Privacy Policy

Effective Date: February 27, 2026 · Version 1.0

Introduction

Bellwether ("we," "us," or "our") provides an AI-powered assistant that helps church staff query and manage their ministry data. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.

This policy applies to all users of the Bellwether application ("Service"), including church administrators, staff, and volunteers who access the Service through their organization's account.

Information We Collect

Account Information

When you create an account or are invited to an organization, we collect:

  • Name and email address — provided through our authentication provider
  • Profile information — such as your avatar, if you choose to provide one
  • Organization details — name and configuration settings for your church or ministry

Chat Data

When you use the Bellwether chat assistant, we collect and store:

  • Your messages — the questions and instructions you type
  • AI-generated responses — the answers Bellwether produces, which may reference data from your connected ministry applications
  • Session metadata — timestamps, session identifiers, and conversation structure

Chat messages are encrypted at rest using application-level encryption.

Integration Data

When your organization connects a third-party ministry application (such as a church management system, communication platform, or volunteer management tool), we collect:

Billing Information

We use Stripe to process payments. Bellwether stores your Stripe customer identifier and subscription status. We do not store credit card numbers or bank account details — Stripe handles all payment card data directly.

Usage and Diagnostic Data

We collect operational data to maintain and improve the Service:

  • Audit logs — records of data access events, tool calls, and configuration changes, including which categories of information were accessed
  • Application logs — technical metadata such as request timing, error codes, and result counts
  • Credit usage — how many AI queries your organization has used

Application logs are scrubbed to remove personally identifiable information before storage.

How We Use Your Information

We use the information we collect to:

  • Provide the Service — process your chat queries, connect to your ministry applications, and generate AI-powered responses
  • Manage your account — authenticate your identity, manage organization memberships, and enforce role-based access controls
  • Process billing — manage subscriptions, track credit usage, and process payments through Stripe
  • Maintain security — detect suspicious activity, enforce rate limits, and protect against unauthorized access
  • Support compliance — maintain audit logs for your organization's governance and accountability needs
  • Improve reliability — diagnose errors, monitor performance, and fix bugs

How AI Processing Works

We do not use your data to train AI models. We do not sell, rent, or trade your information to third parties for marketing purposes.

  1. You send a message — your question is transmitted to Bellwether's servers over an encrypted connection.
  2. Bellwether fetches relevant data — if your question requires information from a connected ministry application, Bellwether retrieves only the data needed to answer it. Your organization's data scope and field-level privacy settings control which categories of data are accessible and which fields are included or masked before AI processing.
  3. The query and data are sent to Anthropic — your message, along with the retrieved ministry data, is sent to Anthropic's Claude API to generate an answer. This data transits Anthropic's infrastructure.
  4. Anthropic returns a response — the AI-generated answer is streamed back to you through Bellwether.

What Anthropic Does and Does Not Do With Your Data

  • Anthropic does not train its AI models on data sent through its API. This is a contractual guarantee under Anthropic's API terms, not merely a policy statement.
  • Anthropic retains API logs for up to 30 days for safety monitoring and abuse prevention, after which they are deleted.
  • Anthropic does not share your data with third parties for their own purposes.

Data Minimization

Your organization's administrator can configure:

  • Which data categories the AI assistant can access (e.g., contacts, attendance, groups, services)
  • Which fields are sent to the AI versus masked (e.g., names may be included while email addresses and phone numbers are replaced with placeholders like "[email hidden]")

These controls allow your organization to limit what information reaches the AI to only what is necessary for your use case.

Third-Party Services

We use third-party services to operate Bellwether. Each service receives only the data necessary for its function:

CategoryPurposeData Involved
Anthropic (AI provider)Powers the AI chat assistantChat messages, ministry data retrieved for query answering (subject to your org's scope and masking settings)
Stripe (payment processor)Subscription billingBilling contact information, subscription status (Stripe handles payment card data directly)
Authentication providerUser identity and loginName, email address, profile data
Cloud hosting providerInfrastructure, compute, and encryption key managementAll application data is hosted on infrastructure in the United States
Database providerData storageAll application data (encrypted at infrastructure and application levels)
Observability providerPerformance monitoring and error trackingTechnical metadata (no personally identifiable information)

We name Anthropic and Stripe because they are directly relevant to how your data is processed and billed. For a complete list of all subprocessors, please contact us using the information at the bottom of this page.

When your organization connects a ministry application (such as a church management system), Bellwether accesses that application's API using OAuth credentials that your organization authorizes. Bellwether fetches data from these applications in real time and does not maintain a separate copy of your ministry records.

Data Security

Encryption and Security

  • Encryption in transit — all data transmitted between your browser, our servers, and third-party services uses TLS encryption. We enforce HSTS (HTTP Strict Transport Security) in production.
  • Encryption at rest — chat message content is encrypted at the application level. OAuth tokens for connected ministry applications are encrypted using managed encryption keys. Our database provider adds an additional layer of infrastructure-level encryption.
  • Access controls — role-based permissions (owner, admin, member) restrict who can access organization settings, manage integrations, and view audit logs.
  • Data isolation — all data queries are scoped to your organization. There is no cross-organization data access.
  • Audit logging — all data access events, tool calls, and configuration changes are logged with timestamps and user attribution. Audit logs are append-only and available to organization administrators.
  • Rate limiting — API endpoints are rate-limited to prevent abuse.
  • Security headers — we apply standard security headers including Content Security Policy, X-Frame-Options, and referrer controls.

Data Retention

Data TypeRetention Period
Chat messagesRetained while your organization's account is active; deleted upon account deletion request
Account informationRetained while your account is active; deleted upon account deletion request
Audit logsRetained for the lifetime of the organization for compliance purposes
Anthropic API logsUp to 30 days (managed by Anthropic)
Integration credentialsRetained while the integration is connected; securely deleted when disconnected
Billing recordsRetained as required by applicable tax and financial regulations

Your Rights and Choices

All Users

  • Access your data — you can view your chat history and account information within the Service
  • Delete your account — you can request deletion of your account and associated data by contacting us or through the Service. Deletion permanently removes your chat messages and personal information. Audit log entries are anonymized to preserve your organization's compliance records.
  • Export your data — organization administrators can export their organization's data, including chat history and member information, in standard formats

Organization Administrators

  • Configure data scope — control which categories of ministry data the AI can access
  • Configure field masking — choose which fields are sent to the AI and which are masked
  • Manage members — add, remove, and assign roles to organization members. When a member is removed, their chat sessions are archived and any active automated workflows are stopped.
  • View audit logs — review who accessed what data and when

Data Ownership

Your organization's data belongs to your organization. Bellwether claims no ownership rights over church data, ministry records, chat content, or any information that passes through the Service. You may export and delete your data at any time.

Data Transfers

Bellwether's infrastructure is hosted in the United States. If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States. We rely on standard contractual clauses and our service providers' data protection measures to safeguard international transfers.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Effective Date" and version number at the top of this policy
  • Notify active users through the Service or by email
  • Maintain a record of prior policy versions

Continued use of the Service after a policy update constitutes acceptance of the revised policy.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us at:

Email: hello@bellwetherapp.ai

This privacy policy is versioned. The current version is 1.0, effective February 27, 2026.