Your data · version 1.1 · 14 September 2026
What we keep, who can see it, and how you leave.
Eight questions churches ask before they hand us a sermon, answered in plain words. Every answer describes what the product does today. Where something is still being built, it says so, in a tag you cannot miss.
This page is the plain-language version. The binding version is the data processing agreement and terms every church signs, and where the two differ, the signed one wins. This page is dated and versioned so you can see when an answer changed.
The eight answers
Your church's material stays your church's.
1. What do you store about our church?
The material you give us, split into small cited pieces so a draft can point back to the sermon or page it came from. The drafts and every revision of them, with who approved or sent each one back. Your settings: the name you gave your assistant, your logo, your colours, which seats you run and who approves for each.
When Planning Center is connected, your adult roster and your group names. No birthdates, no ages, no grades. There is no column for them, on purpose. For email, when that phase arrives, a record that a thread was seen and its identifiers, never the message bodies.
2. Where does it live, and who else touches it?
One database with a rule on every table that a church can only ever read its own rows. Files in a private storage bucket scoped to your church. Any credential you give us is encrypted before it is stored; there is no plaintext secret at rest.
Five providers, and no others. No advertising or analytics vendor ever sees church material.
- AnthropicDrafting. Sees the pieces of your material relevant to the draft in hand.
- SupabaseThe database and the private file bucket.
- VercelHosting. Runs the workspace and the weekly jobs.
- ResendThe email we send you: the Monday brief, your reports.
- StripeBilling. Never sees church material, only the invoice.
3. Can another church see ours?
No. The rule that keeps churches apart is enforced by the database itself, on every table that holds church data, and a test suite that tries to cross that line is run after every change to the database. That holds even when the application has a bug, which is the point of putting it there rather than in the application.
Nothing learned from your church ever improves another church's seats. Each seat is crafted from your material alone.
4. Is our material training an AI?
No. Drafts are produced through Anthropic's commercial API, and under its commercial terms the content sent to it is not used to train Anthropic's models. We do not train anything on your material either; what a seat learns about your church lives in your workspace as a crafted skill you can read and export. The provider and the retention terms are named in the agreement you sign, so you are relying on a contract rather than on this page.
5. Who on your side can see it, and when?
One operator, through a read-only console, to support you. Nobody else. Whether we receive a copy of your First-Week Report and your operational alerts is a support arrangement you choose when you start, not a default we assume.
Inside your church, the workspace owner administers the organization. Private mail, restricted financial information and sensitive material stay behind their own permissions, so administering the workspace does not mean reading everyone's inbox.
6. What about children, and giving?
Children's information is refused at the door, before it is stored, and it is guarded twice. A gate reads the language of every document you give us and refuses one that describes a child. A second gate sits where a Planning Center roster arrives and refuses any record marked as a child, carrying a school grade, or with a birthdate under eighteen, keeping nothing about a refused record. A stricter mode refuses anyone whose age cannot be proven, and we recommend it. A refused record never appears in any group.
Individual giving is never shown. Totals and aggregates only, to anyone, at any level. A filter blocks a named person beside a gift amount from ever reaching a draft, and financial material enters only through formats we have agreed with you.
7. How long do you keep it, and what happens when we leave?
While you are a customer, we keep your material, drafts and history so the seats can keep learning from them. When you leave, a full export of your material, drafts, history and crafted skills is yours, free, any time during your term and for fourteen days after it ends.
After that window your church's data is deleted from the live database within 30 days, and it ages out of our daily backups within a further 7 days, which is how long our database host keeps daily backups on the plan we run. What is true today: the workspace owner downloads the full export from inside the product, and a deletion request starts a thirty-day clock after which the workspace is removed by an automatic sweep. The request can be cancelled, and the export stays available until the sweep runs. Neither depends on a person remembering. The dates and figures on this line are confirmed in your agreement.
8. Whose is it?
Your material is yours. Giving it to us grants a licence to use it only to run your workspace, and nothing else. The platform is ours. The skill crafted from your material is yours to keep and export; we hold a licence to run it for you while you are a customer. There is no offboarding fee, and we are not going to charge you to leave.
If something goes wrong
You hear it from us first.
If we ever discover that your church's data was seen by someone it should not have been, you are told within 72 hours of our confirming it, in writing, with what happened, what was affected, and what we did. The agreement names the person who receives that notice. We would rather send an uncomfortable email than let you find out another way.
Changes to this page
Questions this page does not answer go to hello@ldw.build. If the answer changes what this page says, this page changes, with a new line above.
Before any of this matters
See what your church is already paying for.
The Staffing Report is fifteen questions and asks nothing about your data. It stays on your device.
Take the free Staffing Report