Legal

Security

How Churchly protects your church's content and accounts, in plain language.

Your social accounts stay yours

Churchly connects to YouTube, Facebook, Instagram and TikTok through each platform's official sign-in (OAuth). We never see or store your social-media passwords — the platforms hand Churchly a limited authorisation to publish only the content you approve. You can disconnect any platform at any time from your Churchly settings, which revokes that stored authorisation.

Encryption

Personal information and the authorisation tokens for your connected accounts are stored encrypted, and all traffic between you and Churchly is encrypted in transit (HTTPS).

Your content belongs to your church

You retain ownership of the sermons you upload and everything Churchly generates from them, and you can download it all. Deletion controls remove your content from Churchly's systems — see our Data Deletion page for how that works.

No training, no selling

We do not use your content to train third-party AI models, and we do not sell your personal information. The details are in our Privacy Policy.

Infrastructure

Churchly runs on established cloud providers — including Vercel, Render, Cloudflare and Neon — which store data on our behalf under confidentiality obligations. Access is restricted to authorised personnel.

Questions or concerns

If you have a security question, or believe you have found a vulnerability, contact support@churchly.tech.