Privacy Policy
Last updated September 12, 2026
Churches trust Ezra with pastoral information: prayer requests, family details, background-check status, notes written in confidence. We treat that as the most sensitive data a product can hold. This page explains, in plain language, what Ezra collects, why, who can see it, and how to get it back or have it destroyed.
What we collect
Ezra stores the information your church enters to run its ministry: volunteer and guest profiles (names, contact details, availability, serving history), people directory records, schedules and assignments, tasks and follow-ups, messages your church sends through Ezra, files your staff uploads, and the audit trail of who changed what.
For your staff accounts we store the email address, name, and hashed authentication credentials managed by our authentication provider. We do not collect data from your congregation directly; your church is the data controller and Ezra processes data on your behalf.
What we never do
- We never sell your data, or anyone's data, to anyone.
- We never use your church's records to advertise to your members.
- We never use protected characteristics in scheduling suggestions, and our AI features never train on your church's data.
- Our error-monitoring pipeline scrubs names, message bodies, prayer requests, emails, and phone numbers before anything leaves our servers.
Who can see your data
Access inside your workspace follows the roles your church assigns; every table in our database enforces those permissions at the database layer, not just in the interface. Pastoral notes are restricted to roles you grant that specific permission. Volunteers who sign in see only their own serving information.
Ezra staff do not read your church's records except when you ask us to help with a specific problem, and every such access happens over audited infrastructure.
Subprocessors
Ezra runs on a small set of infrastructure providers:
- Vercel (application hosting, USA)
- Supabase (database, authentication, file storage, USA)
- Stripe (billing; card details never touch Ezra's servers)
- Resend (transactional email)
- Twilio (SMS, when your church enables texting)
- Anthropic (AI assistant; processed through Anthropic's commercial API, whose terms exclude training on customer content; Anthropic retains API inputs and outputs for up to 30 days under its standard policy, and short-lived prompt caching is enabled)
- Sentry (error monitoring, with the scrubbing described above)
Text messaging (SMS)
When your church enables texting, Ezra sends serving invitations, schedule reminders, event updates, prayer and devotional messages, and follow-up messages on the church's behalf. Congregation members and volunteers opt in by giving their phone number to their church staff, in person or on a paper form, and expressly agreeing to receive texts; church staff record that consent in Ezra, and messages are only sent to numbers with recorded consent.
- Agreeing to texts is optional and voluntary. It is never a condition of joining a serving team, attending, or receiving anything from your church, and you can fully participate without opting in.
- Mobile phone numbers and text-messaging consent are never shared with third parties or affiliates for marketing purposes.
- Message frequency varies with your involvement and your preferences: typically a few messages per month, and up to one message per day if you ask your church for daily devotionals. Message and data rates may apply.
- Reply STOP at any time to stop receiving texts; the opt-out takes effect immediately and is recorded. Reply START to resume, or HELP for help.
The full messaging program, including every opt-in path and the exact consent language, is documented at ezraos.co/sms-consent.
Your data stays yours
Owners can export the church's records at any time as a single structured bundle: every table, plus a manifest of uploaded files with their storage paths (file contents download separately). Owners can also permanently delete the entire workspace; deletion removes every record and uploaded file, is verified after it runs, and is recorded in a deletion ledger so it is always accountable.
Individual people can ask your church to erase their records. The admin tool deletes the person's volunteer, guest, and directory records with their history; their messages and the addresses they were sent to; their follow-up tasks and workflows; their uploaded files, including the stored file contents; and their identifiers from connected systems. Audit history is kept as evidence with the person's name, email, and phone replaced by a redaction, and every erasure is recorded in a ledger that stores counts and record ids — never the person's name. Two honest limits: text that merely paraphrases a person ("the new mom from Sunday") cannot be found by any exact match, so AI conversation text gets exact-match redaction plus manual review on request; and copies in encrypted database backups and provider delivery logs (email/SMS) age out on those systems' retention schedules rather than being erased instantly.
A monthly job removes message bodies and audit entries older than 24 months, and read notifications older than 6 months. Unread notifications are kept until read.
Contact
Questions, data requests, or concerns: email support@ezraos.co. We answer privacy questions from church leadership directly.