Privacy Policy

Last updated: January 2026

Quick Navigation

Information We Collect Cookies and Tracking How We Use Information AI Data Processing Meta Platform Data Data Sharing Data Security Church-Specific Protections Your Rights Data Deletion Requests Contact Us

Our Commitment to Your Privacy

EvangelOS is a product of EvangelOS, Inc. At EvangelOS, we understand that churches handle deeply personal and sensitive information about their members and community. We are committed to protecting your privacy and the privacy of your congregation members with the highest standards of data protection. This Privacy Policy explains how we collect, use, protect, and share information when you use our church management platform.

For Churches: We recognize the sacred trust placed in us when handling congregation data. We treat all member information with the same confidentiality and care that churches themselves provide.

Information We Collect

Church Administrative Information

  • Church organization details (name, address, denomination, tax ID)
  • Administrator and staff contact information
  • Subscription and billing information
  • Church size, attendance, and organizational structure

Member and Visitor Information

  • Personal details (names, addresses, phone numbers, email addresses)
  • Family relationships and household information
  • Attendance records and participation in church activities
  • Giving records and financial contributions
  • Volunteer service records and ministry involvement
  • Prayer requests and pastoral care notes (when permitted by church policy)
  • Event registrations and participation history

Google Calendar Integration & Limited Use Disclosure

EvangelOS accesses your Google Calendar data solely to synchronize your ministry events and does not share this data with third parties. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Usage and Technical Information

  • Login activity and system usage patterns
  • Device information and IP addresses
  • Browser type and operating system
  • Feature usage and system performance data

Precise Location Data

To enable features like our "Geofence Check-In Reminders," our mobile application will request access to your device's precise location (geocoordinates).

This location monitoring is processed on your device by your mobile operating system (iOS or Android). Our servers do not receive or track your continuous location. We only receive a one-time trigger from your app after your device determines you have entered a pre-defined event area (a "geofence").

Your Privacy: Location processing happens entirely on your device. We never receive or store your real-time location. We only know when you've arrived at a church event location you're registered for.

Device Information and Push Notification Tokens

To send you notifications, such as check-in reminders or other ministry updates, we collect:

  • A unique push notification token (also called a "device token") generated by your mobile device
  • Your device type (e.g., "iOS" or "Android") to ensure we can send notifications successfully to your specific device

Crash Reports and Diagnostic Data

To identify and fix technical issues and improve the stability of our mobile application, we may collect crash reports and diagnostic information when the app encounters an error. This data may include:

  • Device model, operating system version, and app version
  • Error logs and stack traces at the time of a crash
  • App state information (such as which screen was active when the error occurred)
  • Performance metrics such as memory usage and load times

Crash and diagnostic data is used solely for engineering and quality purposes — to reproduce issues, prioritize fixes, and improve app reliability. It is never used for advertising or shared with third parties for marketing purposes.

Your Choice: Crash and diagnostic data collection is optional. You can enable or disable it at any time in the app under You > Prefs. If you opt out, no crash or performance data will be transmitted from your device.

How We Use Your Information

Platform Services

  • Provide church management tools and features
  • Process and manage member information as directed by your church
  • Generate reports and analytics for church leadership
  • Facilitate communication between church staff and members
  • Process donations and manage giving records
  • Send service notifications and platform updates
  • Power AI-assisted features including Smart Workflows and Proactive Outreach suggestions based on member engagement patterns

Account Management

  • Manage subscriptions and billing
  • Provide customer support and technical assistance
  • Ensure system security and prevent unauthorized access
  • Comply with legal obligations and church governance requirements

To Provide Location-Based Services and Notifications

We use the location data access you grant, in combination with your device token, to provide specific features:

  • Geofence Check-In Reminders: We use your on-device location access to determine when you have arrived at a church event location. When your device enters the event's geofence during the designated check-in time, it notifies our server.
  • Send Timely Notifications: If you are registered for the event and have not yet checked in, our server will use your stored push notification token to send a reminder to your device, allowing you to check in quickly.
  • Prevent Unnecessary Notifications: We maintain a log when a check-in reminder has been successfully sent for a specific event. This is done to prevent sending you duplicate or "spammy" notifications for the same event.
Important: We only use member information as directed by your church administration. We do not use congregation data for marketing, advertising, or any purpose unrelated to providing our church management services.

AI Data Processing

EvangelOS uses artificial intelligence to help churches work smarter — from automating routine administrative tasks to surfacing insights about congregational engagement. This section explains exactly how AI is used, what data it touches, and the protections we have in place.

What Data Is Processed by AI

To deliver AI-powered features, certain member and church data may be transmitted to and analyzed by our AI models. This includes:

  • Attendance records and participation patterns
  • Member engagement history (event check-ins, group activity, volunteer involvement)
  • Communication histories (message open rates, outreach interactions)
  • Giving records and financial contribution trends

Purpose of AI Processing

EvangelOS is not merely a system of record — it is designed to be a system of action. AI processing enables us to:

  • Automate routine administrative tasks — such as scheduling follow-ups, generating giving statements, and managing event logistics
  • Personalize member communication workflows — by suggesting timely outreach to members who may be disengaging or who have recently joined
  • Provide predictive analytics on congregational trends — such as attendance forecasting, giving pattern analysis, and ministry health indicators
  • Power Smart Workflows — automated sequences triggered by member behavior (e.g., initiating a New Member Pathway after a first-time visit)
  • Surface Proactive Outreach Tasks — AI-generated recommendations for pastoral follow-up based on member activity patterns

Subprocessor Boundaries — AI Model Restrictions

EvangelOS uses OpenAI and Google (Gemini) as AI model providers. We take your data's sanctity seriously and have implemented strict contractual boundaries with both providers:

  • No model training on your data: OpenAI and Google are contractually prohibited from using any data transmitted through EvangelOS to train, fine-tune, or improve their public foundational models.
  • Purpose limitation: Church data is transmitted to these providers solely to facilitate the specific EvangelOS features you have enabled — for no other purpose.
  • Confidentiality obligations: Both providers are bound by data processing agreements that require them to treat your church's data as confidential and to process it only under our documented instructions.

Human Oversight — AI as an Assistive Tool

All AI-generated suggestions within EvangelOS are strictly assistive. The platform is designed so that human ministry leaders retain full oversight and final authority over every action taken.

  • AI may suggest that a pastor follow up with a disengaged member — but no outreach is sent without a staff member reviewing and approving it
  • AI may recommend enrolling a first-time visitor in a New Member Pathway — but a church administrator must confirm that action
  • AI-generated content drafts are always presented for human review before sending
  • No automated decisions with legal or similarly significant effects are made solely by AI within EvangelOS
Our Commitment: EvangelOS AI never autonomously acts on member data. Every AI recommendation requires a human to review and approve it before any action is taken. Ministry leaders remain in control at all times.

Your AI Opt-Out Rights

You have meaningful choices about how AI processes data within EvangelOS:

  • Church Administrators can disable specific AI-powered features (such as Smart Workflows or Proactive Outreach Tasks) at any time through the platform's settings. Disabling a feature stops that data from being sent to AI models for that purpose.
  • Individual Members may contact their church administrator to request that their personal data be excluded from AI-driven workflows. Churches can flag individual member records to opt out of AI-based processing.
  • GDPR-Covered Individuals have the right to object to automated processing under Article 21 of the GDPR. To exercise this right, contact us at privacy@evangelos.app.

Meta Platform Data (Facebook & Instagram Integration)

EvangelOS offers an optional integration that allows churches to connect their Facebook Pages and Instagram Business accounts in order to publish content and view engagement analytics directly from the platform. This section describes exactly how we handle data obtained through Meta's Graph API in compliance with Meta's Platform Terms and Data Use Policy.

Scope: This section applies only to churches that choose to connect a Facebook Page or Instagram Business account to EvangelOS. If you have not connected a Meta account, no Meta Platform data is collected.

What Meta Data We Collect

When a church administrator authorizes the Facebook/Instagram integration, we collect the following data from Meta's Graph API:

  • Page identifiers: Facebook Page IDs and Page names associated with the connected church account
  • Page metadata: Page category, follower counts, and public Page details
  • Page access tokens: Long-lived tokens that authorize EvangelOS to act on behalf of the connected Page
  • Instagram Business account IDs: The Instagram Business or Creator account linked to the connected Facebook Page
  • Post content: Text, images, and media associated with posts published through EvangelOS to the connected Page or Instagram account
  • Post insights and engagement metrics: Reach, impressions, reactions, comments, and shares on posts published via EvangelOS
  • Connecting administrator profile: The name and profile picture of the Facebook user who authorized the integration, used solely for display within EvangelOS

Why We Collect It

We collect this data solely to enable churches to manage their social media presence through EvangelOS — specifically to publish content to their own Facebook Pages and Instagram Business accounts, and to display engagement analytics to authorized church staff within the platform. We do not use Meta Platform data for advertising, profiling, or any purpose beyond delivering this feature to the church that authorized the connection.

Where We Store It

  • Database: Meta Platform data is stored in Cloud SQL (PostgreSQL) hosted on Google Cloud Platform (GCP), encrypted at rest using AES-256
  • Access tokens: Facebook Page access tokens are encrypted at the application layer before being written to the database, using the same encryption scheme applied to other third-party integration credentials within EvangelOS
  • Transmission: All data is transmitted over TLS-encrypted connections
  • Geographic location: Data is stored in GCP data centers in the United States

How Long We Retain It

  • Meta Platform data is retained for the lifetime of the active Facebook/Instagram integration connection
  • When a church administrator disconnects the integration (via Settings → Integrations), all associated Meta Platform data — including Page tokens, account IDs, and cached engagement metrics — is deleted within 30 days
  • When a church account is deleted from EvangelOS, all Meta Platform data is deleted within 30 days of account closure
  • Published post content that has been pushed to Facebook/Instagram remains on those platforms under the church's own account and is governed by Meta's own policies; EvangelOS does not retain copies of published post content beyond what is needed to display post history within the platform

Who We Share It With

Meta Platform data is never sold, never shared with other churches, and never used for advertising. It is shared only with the following sub-processors strictly as necessary to operate the integration:

  • Google Cloud Platform (GCP): Cloud infrastructure and database hosting
  • No other sub-processors receive Meta Platform data

All sub-processors are bound by data processing agreements and are contractually prohibited from using this data for any purpose other than operating the services we have engaged them for.

Your Rights Regarding Meta Data

  • Disconnect: Church administrators can disconnect the Facebook/Instagram integration at any time via Settings → Integrations. Disconnecting immediately revokes EvangelOS's ability to act on the Page and queues all associated Meta data for deletion within 30 days
  • Request deletion: To request immediate deletion of Meta Platform data associated with your account, contact us at privacy@evangelos.app
  • Revoke via Facebook: You may also revoke EvangelOS's access to your Facebook account at any time through your Facebook account settings under Settings & Privacy → Settings → Apps and Websites. Revoking access there will trigger our data deletion process automatically
Meta Platform Terms Compliance: Our use of data obtained through Meta's Graph API is governed by Meta's Platform Terms. We do not use Meta Platform data to build profiles on individuals, retarget users, or for any purpose beyond the specific church social publishing and analytics features described above.

When We Share Information

We do not sell, rent, or share your congregation's personal information with third parties, except in these limited circumstances:

Authorized Church Access

  • With church staff and volunteers as authorized by your church leadership
  • With other members as configured in your church's privacy settings
  • For church-approved communications and activities

Service Providers (Sub-Processors)

We work with a limited set of authorized sub-processors to operate EvangelOS. All are bound by data processing agreements and may only process data as directed by us. A full list of our authorized sub-processors, including their purpose and data location, is maintained on our Security page.

Data is never sold to third parties and is never shared with other churches or organizations on the platform.

Legal Requirements

  • When required by law, court order, or legal process
  • To protect the safety and security of individuals
  • To prevent fraud or unauthorized system access

Data Security

We implement industry-leading security measures to protect your church's information:

Technical Safeguards

  • 256-bit SSL encryption for all data transmission
  • AES-256 encryption for data at rest
  • Multi-factor authentication for administrative access
  • Regular security audits and penetration testing
  • Automated backup systems with geographic redundancy

Access Controls

  • Role-based access controls within your church system
  • Regular access reviews and permission audits
  • Secure data centers with 24/7 monitoring
  • Employee background checks and confidentiality training

Incident Response

  • 24/7 security monitoring and threat detection
  • Immediate notification protocols for security incidents
  • Detailed incident response and recovery procedures
  • Cooperation with law enforcement when necessary

Church-Specific Privacy Protections

Pastoral Confidentiality

We respect the sacred nature of pastoral relationships and confidential communications. Churches can designate certain information as confidential, accessible only to authorized pastoral staff.

Member Privacy Controls

  • Members can control visibility of their personal information
  • Options to restrict access to contact details and family information
  • Ability to opt-out of directory listings and communications
  • Special protections for sensitive situations (divorce, domestic issues, etc.)

Children's Privacy

  • Enhanced protections for information about minors
  • Parental consent requirements for children's data collection
  • Secure handling of children's ministry and youth group information
  • Background check management with appropriate access controls

Financial Privacy

  • Giving records accessible only to authorized financial staff
  • Anonymous giving options when requested
  • Secure processing of all financial transactions
  • Compliance with IRS regulations for charitable giving

Your Privacy Rights

For Church Members

  • Access: Request to see what personal information we have about you
  • Correction: Request corrections to inaccurate personal information
  • Deletion: Request deletion of your personal information (subject to church record-keeping needs)
  • Portability: Request a copy of your personal information in a portable format
  • Objection: Object to certain uses of your personal information

For Church Administrators

  • Full control over member data access and privacy settings
  • Ability to export all church data at any time
  • Right to delete church account and associated data
  • Access to detailed activity logs and audit trails

Location Services

You can opt-out of geofence-based features, including automatic check-in reminders, at any time by disabling location services for the EvangelOS application.

  • iOS: Go to Settings → Privacy → Location Services → EvangelOS and select "Never"
  • Android: Go to Settings → Location → App permissions → EvangelOS and select "Don't allow"

If you disable location services, the geofence check-in reminder feature will not function, and you will not receive automatic check-in reminders upon arrival at events.

Push Notifications

You can disable all push notifications from EvangelOS at any time through your mobile device's settings menu.

  • iOS: Go to Settings → Notifications → EvangelOS and turn off "Allow Notifications"
  • Android: Go to Settings → Apps → EvangelOS → Notifications and turn off notifications

This will stop all notifications from our app, including check-in reminders, ministry announcements, and other updates.

SMS & Text Messaging Privacy

We respect your privacy. Your mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. This includes text messaging originator opt-in data and consent, which will not be shared with any third parties.

Important: By providing your phone number, you agree to our SMS Terms and Privacy Policy. Your consent to receive SMS messages is not a condition of any purchase or service.
Note: Some privacy rights may be limited by legitimate church interests, legal requirements, or the need to maintain accurate records for church governance and compliance purposes.

International Privacy Compliance

GDPR Compliance (European Union)

For churches and members in the European Union, we comply with the General Data Protection Regulation (GDPR), including:

  • Legal basis for processing personal data (legitimate interests, consent, contract performance)
  • Data minimization and purpose limitation principles
  • Enhanced rights for EU data subjects
  • Data breach notification requirements
  • Appointment of Data Protection Officer for EU operations

CCPA Compliance (California)

For California residents, the California Consumer Privacy Act (CCPA) provides specific rights regarding personal information:

  • Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell.
  • Right to Delete: You have the right to request the deletion of your personal information collected or maintained by us.
  • Right to Opt-Out: You have the right to opt-out of the sale of your personal information. Note: EvangelOS does not sell personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

Other International Frameworks

  • CCPA compliance for California residents
  • PIPEDA compliance for Canadian churches
  • Adherence to applicable local privacy laws

Data Retention

We retain personal information for as long as necessary to provide our services and as required by law:

  • Active Church Data: Retained while your church maintains an active subscription
  • Financial Records: Retained for 7 years for tax and compliance purposes
  • System Logs: Retained for 90 days for security and troubleshooting
  • Backup Data: Automatically deleted from backups after 30 days of account closure
  • Meta Platform Data (Facebook/Instagram): Retained for the lifetime of the active integration connection. Upon disconnection or account deletion, all Meta Platform data (Page tokens, account IDs, engagement metrics) is permanently deleted within 30 days
  • Google Calendar Integration Data: Retained for the lifetime of the active integration connection and deleted within 30 days of disconnection

Churches can request earlier deletion of specific data, subject to legal and operational requirements.

Data Deletion Requests

You have the right to request deletion of your personal data from EvangelOS at any time. We honor deletion requests through the following methods:

In-App Deletion

  • Disconnect a social integration: Navigate to Settings → Integrations and disconnect your Facebook Page or Instagram account. This queues all associated Meta Platform data for deletion within 30 days
  • Delete your church account: Church administrators can initiate a full account deletion from the platform settings, which removes all church and member data within 30 days

Meta Platform Data Deletion Callback

In accordance with Meta's Platform Terms, EvangelOS supports Meta's Data Deletion Request callback. When a user removes the EvangelOS app from their Facebook account (via Facebook Settings → Apps and Websites), Meta will send an automatic deletion request to our systems. We will process this request and delete all associated Meta Platform data within 30 days.

Data Deletion Request URL: Meta's deletion callbacks are processed at our secure endpoint. To verify or follow up on a deletion request, contact us at privacy@evangelos.app with the subject line "Meta Data Deletion Request" and include the confirmation code provided by Facebook.

Manual Deletion Requests

To request deletion of any personal data not covered by in-app options, contact our Privacy Team:

  • Email: privacy@evangelos.app
  • Include your name, organization, and description of the data you want deleted
  • We will confirm receipt within 5 business days and complete the deletion within 30 days
Note: Some data may be retained beyond your deletion request where we are required to do so by law (e.g., financial records for tax compliance) or where retention is necessary for legitimate dispute resolution. We will inform you of any such exceptions at the time of your request.

Cookies and Tracking Technologies

On this marketing website, we use Cookiebot to record and manage your privacy choices. Strictly necessary technologies support core site functions and consent records. With your permission, analytics technologies help us understand site usage, and marketing or support technologies enable HubSpot and the Intercom support messenger.

  • Google Analytics 4: measures visits and interactions when you allow Analytics cookies.
  • HubSpot: supports marketing measurement when you allow Marketing cookies.
  • Intercom: provides the website support messenger when you allow Marketing cookies.

We do not load these optional services until the relevant consent is available. You can withdraw or change consent at any time using Privacy Choices. When consent is withdrawn, we stop applicable services and Cookiebot removes cookies it can identify and control. Vendor retention periods and the current cookie inventory appear below.

We honor Global Privacy Control signals through Cookiebot where applicable. A recognized signal is treated as an instruction not to enable nonessential tracking unless you make a different affirmative choice.

Updates to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will:

  • Notify church administrators via email and in-app notifications
  • Post the updated policy on our website with the revision date
  • Provide a summary of material changes
  • Allow reasonable time for review before changes take effect

Contact Us About Privacy

If you have questions about this Privacy Policy, want to exercise your privacy rights, or need to report a privacy concern, please contact us:

Privacy Team

Email: privacy@evangelos.app

Mail: EvangelOS Privacy Team
70380 Highway 21 Suite 2 #116, Covington, LA 70433

For EU Data Protection Inquiries:

Data Protection Officer: dpo@evangelos.app
Response time: Within 30 days as required by GDPR

Emergency Security Issues:

Security Team: security@evangelos.app

Effective Date

This Privacy Policy is effective as of January 2026.

Previous versions are available upon request for transparency and record-keeping purposes.