Privacy Policy
Last updated: August 2026
KlesiaNexus, operated by [Company Legal Name] ("we," "us"), helps churches care for their people. We take the privacy of that information seriously — especially because it includes families, children, and giving. This policy explains what we collect, why, and your choices.
1. Who Controls the Data
Your church is the owner of the congregation data it enters. We process that data on your church's behalf to provide the Service. Your church is responsible for how it collects and uses its members' information, including obtaining any consents required by law.
2. Information We Collect
Account information: the name, email, church name, and web address you provide at signup.
Congregation data your church enters: member and family records, contact details, attendance, groups, serving, children's ministry information, care notes, events, and giving records.
Payment information: handled entirely by Stripe. We do not receive or store card numbers — only a reference to your subscription and its status.
Technical data: basic logs needed to operate and secure the Service.
3. How We Use Information
We use information only to provide and improve the Service:
- To operate features your church uses (records, care lists, attendance, giving, and so on).
- To send transactional messages you initiate (such as password setup or messages your church sends its members).
- To secure the Service and prevent misuse.
- To provide support and communicate about your account.
We do not sell your data, and we do not use your congregation's data for advertising.
4. Children's Information
Churches may store information about minors (for example, for children's ministry check-in and safety). We treat this data with heightened care: access is restricted by role, custody and pickup restrictions are enforced, and it is never exposed on any public page. Your church is responsible for obtaining any parental or guardian consents required by law before entering a child's information.
5. How Information Is Protected
- Each church's data is isolated so one church cannot access another's.
- Data is encrypted in transit and at rest through our infrastructure providers.
- Card data is handled solely by Stripe under its security standards; we never store it.
- Access to production systems is limited and credentials are rotated when needed.
6. Service Providers
We rely on trusted providers to run the Service, including Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (email), and Anthropic (AI features). Each processes data only as needed to provide their part of the Service.
7. Your Rights & Choices
- Export: you can export your church's data at any time.
- Deletion: you can request deletion of your account and data.
- Access & correction: you control and can correct the data your church holds.
Depending on where your members live, they may have additional rights under laws such as GDPR or CCPA; your church, as the data owner, is the first point of contact for such requests, and we will support you.
8. Data Retention
We keep your data for as long as your account is active. After cancellation, you have a reasonable period to export it before it is deleted from active systems.
9. Changes to This Policy
We may update this policy as the Service evolves and will notify you of material changes.
10. Contact
Questions about privacy? Contact us at karan@khairotech.com.
This document is a general starting point and not legal advice. Given the sensitivity of church and children's data, we recommend review by qualified counsel before relying on it.