Privacy Policy
Last Updated: September 30, 2026
1. Introduction
Welcome to Communicate! We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, disclose, and protect your information when you use our services.
Who We Are
Communicate is operated by Communicate, LLC, 128 NW Jayellen Ave., Burleson, TX 76028, United States (“Communicate,” “we,” “us,” or “our”).
Our Role and Your Church's Role
Communicate is used by churches. Who is responsible for your information depends on the kind of information:
- Church content: Each church controls the content it puts into Communicate, such as campaigns, communications, calendars, uploaded files, and Church Voice. For that content, the church is the controller and Communicate is a processor acting on the church's instructions. If your information appears in a church's content and you have questions or want to exercise your rights, please contact that church. We will help the church respond.
- Account data: Communicate is the controller of account data, such as team member logins, billing records, and product analytics.
A data processing agreement for church content is available on request at [FILL IN: privacy email].
By using Communicate, you agree to the terms of this Privacy Policy. If you do not agree with any part of this Privacy Policy, you should discontinue use of the app and services.
We encourage you to review this Privacy Policy regularly to stay informed about how we handle your personal data.
2. Information We Collect
We collect various types of information to provide and improve our services. The types of information we collect include:
2.1 Personal Information
We collect personal information when you sign up for an account, interact with the app, or subscribe to a paid plan. This includes:
- Account Information: Name, email address, church name, and user role within the organization.
- Multi-User Access: Churches can invite additional users and assign each one a role (Owner, Admin, Manager, Editor, or Viewer). Each role has different permissions, and some users can be limited to specific campuses or categories.
- Account Owner Responsibility: The account owner is fully responsible for managing invited users. Communicate is not responsible for any actions taken by invited users, including data modification, deletion, or sharing of information outside the platform.
- Login Credentials: Email and password (passwords are stored securely and never in plain text).
- Profile Data: Profile picture (if uploaded), contact preferences, and optional phone number.
- Payment Information: When your church subscribes to a paid plan, we collect billing details. Payments are processed by Stripe, and we do not store full payment card details on our servers.
2.2 Usage Data
We collect information about how users interact with Communicate, including:
- App Interaction Data: Features used, campaigns and communications created, templates and categories set up.
- Feedback and Surveys: User-submitted feedback, survey responses, and suggestions to improve our services.
- AI Usage Records: If your church uses AI Features, a record of each AI request (see Section 12).
2.3 Technical Information
To ensure platform security and optimize performance, we collect technical data, including:
- Device Information: IP addresses, browser types, operating systems, and device identifiers.
- Cookies and Tracking Technologies: We use cookies to monitor activity, store preferences, and enhance user experience. For more details, see the Cookies and Tracking Technologies section below.
2.4 Church Content
When your team uses Communicate, it stores the content your church creates, such as campaigns, communications, calendars, templates, uploaded images and files, and Church Voice settings. We process church content as a processor on your church's behalf (see Section 1).
2.5 Our Marketing Website
Our marketing website (communicate.app) is separate from the Communicate app and uses its own providers:
- Hosting and server logs: The website is hosted on Cloudflare Pages (Cloudflare, Inc.). Cloudflare processes server logs, including IP addresses, to deliver and secure the website. The Communicate app itself is hosted on Vercel.
- Analytics and marketing tools: The website uses Google Analytics, Google Tag Manager, Google Ads conversion tracking, the Meta (Facebook) Pixel, and MailerLite. These load only after you accept the matching category (Analytics or Marketing) in our cookie banner, and you can change your choice at any time. Details are in our Cookie & Privacy Policy.
- Email: If you subscribe to the "Do This" weekly email, we store your email address with Resend, which sends the email. Resend also delivers contact form and partner application submissions to our team.
3. Legal Basis for Data Processing
For users in the European Economic Area (EEA) and United Kingdom (UK), our legal basis for processing personal data depends on the information collected and the context in which it is processed, in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the UK GDPR.
We process personal data based on the following legal grounds:
- Church Instructions (Church Content): When we process church content, including content sent to AI Features, we do so as a processor on the church's instructions. The church, as controller, is responsible for having a legal basis for its own content.
- Contract Necessity: When processing data is required to provide our services, including account creation, authentication, and feature access. This includes the internal user and church IDs sent with AI requests.
- Legitimate Interests: When data is used to improve our platform, conduct analytics, enhance security, or communicate with users about service updates. This includes AI usage records and abuse monitoring (to apply usage allowances, keep the service secure, and prevent misuse) and the record of a church turning AI Features on or off (as evidence of the church's instruction).
- User Consent: When users opt in to marketing emails, accept non-essential cookies, or provide feedback. When a church turns on AI Features, that is the church's instruction to us as its processor, not consent under GDPR from the individuals whose information may appear in its content.
- Legal Obligations: When we are required to process and retain data to comply with applicable laws, regulations, or legal processes.
If you have any questions about the legal basis under which we process your data or wish to exercise your GDPR rights, you can contact us at [email protected].
4. How We Use Your Information
We collect and process personal data for the following purposes:
4.1 To Provide and Improve Our Services
- Operate, maintain, and improve Communicate to ensure the platform functions correctly.
- Personalize the user experience based on account preferences and past interactions.
- Troubleshoot technical issues and provide customer support.
- Provide optional AI Features when your church turns them on and a team member asks for a draft (see Section 12).
4.2 To Communicate with You
- Send account-related notifications, including security alerts, feature updates, and administrative messages.
- Respond to inquiries, feedback, and support requests.
- Users consent to receive essential service-related communications when signing up.
4.3 To Analyze and Enhance the App
- Track usage patterns and monitor system performance.
- Identify trends and optimize existing features.
- Develop and test new features based on feedback and engagement data.
4.4 To Ensure Security
- Authenticate users and prevent unauthorized access.
- Detect and prevent fraud, abuse, and security breaches.
- Monitor login activity and device data to protect user accounts.
4.5 For Marketing and Promotions
- With user consent, we may send promotional materials, feature announcements, and special offers.
- Users can opt out of marketing emails at any time by clicking the "unsubscribe" link in the email or adjusting their preferences in their account settings.
If you have any questions regarding how your data is used, please contact us at [email protected].
5. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information. However, we may share your data in the following circumstances:
5.1 With Service Providers
We work with third-party service providers (subprocessors) to help operate and improve Communicate. These providers may process your data only as necessary to perform the services we request:
- Supabase – database, sign-in, and file storage.
- Vercel – application hosting, and the AI Gateway that routes AI requests.
- OpenAI – AI text generation for AI Features (see Section 12).
- Resend – transactional email, such as notifications and account emails.
- PostHog – product analytics, to understand how the app is used and improve it.
- Stripe – payments. Stripe acts as a separate data controller for your billing information. Your payment data is subject to Stripe’s own privacy policy and terms of service.
Our current list, with each provider's purpose and location, is on our Subprocessors page. We notify account Owners by email at least 30 days before adding or replacing a subprocessor, and churches may object during that time.
All third-party providers are contractually obligated to keep your data confidential and use it only for the specified purposes, and we have a data processing agreement in place with each subprocessor listed above.
Our marketing website uses separate providers, described in Section 2.5.
5.2 For Legal Reasons
We may disclose user data if required by law, regulation, or legal process, such as:
- Complying with court orders, subpoenas, or legal investigations.
- Enforcing our Terms of Service or protecting the security of our platform.
- User Actions & Data Loss: Communicate is not liable for any loss, corruption, or unauthorized sharing of data caused by an invited user within an account. The account owner is responsible for managing users and ensuring that only trusted individuals are granted access.
- Preventing fraud, illegal activities, or security threats.
5.3 During a Business Transfer
If Communicate undergoes a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify users of any change in ownership before such a transfer occurs.
If you have questions about how your data is shared, you can contact us at [email protected].
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
6.1 Retention Periods
- Account Information: Retained as long as the account remains active. Deleted upon user request or after prolonged inactivity.
If an account is paused (rather than canceled), we will retain data indefinitely unless the user requests deletion or we apply a data retention policy after prolonged inactivity. - Church Content: Retained until the church deletes it or its account is deleted.
- Usage Data & Analytics: Stored for up to 24 months for platform improvement, unless anonymized for longer-term analysis.
- AI Usage Records: Kept while the church's account is active and deleted when the account is deleted. They do not contain prompts, Church Voice content, or generated text (see Section 12 for all AI-related retention).
- Customer Support & Communication Records: Retained for up to 12 months to assist with inquiries and issue resolution.
- Payment Information: Financial transaction records are retained for a minimum of 7 years in compliance with tax and accounting regulations.
6.2 Data Deletion Requests
Users may request deletion of their personal data under the Right to Erasure (Right to be Forgotten) by contacting us at [email protected]. Upon verification of the request, we will:
- Delete personal information unless required for legal or operational purposes.
- Data Ownership for Multi-User Accounts: If multiple users have been invited to an account, the church, acting through its account Owner, retains full ownership of all data. If an invited user leaves the account, they do not have rights to export or retain account data unless explicitly granted permission by the account owner.
- Anonymize retained data where full deletion is not feasible (e.g., aggregated analytics).
6.3 Legal & Compliance Retention
In some cases, we may retain certain information for compliance purposes, including:
- To comply with legal obligations (e.g., tax, audit, and regulatory reporting).
- To resolve disputes or enforce our agreements.
- To prevent fraud and abuse on the platform.
If you have questions about data retention, please contact us at [email protected].
7. Cookies and Tracking Technologies
Under GDPR, users in the EEA and UK have the right to explicitly opt in to non-essential cookies. Upon visiting our marketing website, users will be presented with a cookie consent banner allowing them to accept, reject, or customize cookie preferences. This banner does not currently appear in the Communicate app (see Section 7.2).
We use cookies and similar tracking technologies to enhance user experience, improve performance, and analyze app usage.
7.1 Types of Cookies We Use
- Session Cookies: These are temporary cookies that help with authentication and user experience while using the app. They are deleted when you close your browser.
- Analytics Cookies: We use cookies to collect information on how users interact with Communicate. This helps us understand user behavior, optimize features, and improve functionality.
7.2 Third-Party Tracking
In the Communicate app, we use product analytics provided by PostHog, Inc. to help us understand how the product is used and improve it. PostHog records pages viewed, page exits, and clicks in the app. Analytics are anonymous: we do not link analytics data to your name or email address. PostHog uses a first-party cookie and browser local storage (ph_<project-key>_posthog), and the data is processed in the United States.
To opt out of app analytics today, you can block or delete cookies and local storage for the Communicate app in your browser settings. You can also email us at [email protected] with questions about your analytics data.
On our marketing website, we use Google Analytics and marketing tools, loaded only after cookie-banner consent (see Section 2.5). These tools may collect information such as:
- The pages you visit.
- How long you stay on a page.
- Browser and device information.
For the full list of cookies and similar technologies, see our Cookie & Privacy Policy.
7.3 Managing Cookies
You can control or disable cookies through your browser settings. However, please note that disabling certain cookies may affect the functionality of Communicate.
In accordance with GDPR, you may also withdraw your consent to marketing website cookies at any time by adjusting your preferences in our Cookie Settings page, accessible through the footer of our website.
Most browsers allow you to:
- Block or delete cookies through privacy settings.
- Opt out of analytics tracking by installing browser add-ons like the Google Analytics Opt-Out Add-on.
8. Your Data Rights
Depending on your location, you may have certain rights regarding your personal data. These rights may include:
8.1 Access and Correction
- You can request access to the personal information we hold about you.
- If any of your information is inaccurate or incomplete, you may request a correction.
8.2 Data Deletion
- You can request the deletion of your personal data, subject to exceptions required by law (e.g., financial records for compliance).
- Once deleted, some data may remain in backup archives for a limited time before being fully removed.
8.3 Opt-Out of Marketing Communications
- Users may opt out of marketing emails at any time by clicking the "unsubscribe" link in any email or adjusting preferences in their account settings.
- Even if you opt out of marketing emails, we may still send important service-related messages (such as security updates).
8.4 Data Portability (Applicable where required by law)
- You may request a copy of your personal data in a structured, commonly used format.
8.5 How to Exercise Your Rights
To submit a request regarding your data, please contact us at [email protected]. We will respond within the timeframes required by applicable laws, including within 30 days for GDPR-related requests. You may also lodge a complaint with your local Data Protection Authority (DPA) if you are not satisfied with our response.
If your request falls under the General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA), additional rights may apply, and we will process your request accordingly.
9. Data Security
We take data security seriously and implement industry-standard measures to protect your personal information from unauthorized access, loss, misuse, or alteration.
9.1 Encryption & Secure Data Transmission
- All user data is encrypted in transit and at rest using SSL/TLS and AES-256 encryption where applicable.
- Passwords are hashed and stored securely to prevent unauthorized access.
9.2 Two-Factor Authentication (2FA)
- To enhance security, Communicate offers two-factor authentication (2FA) for user accounts.
- Users are encouraged to enable 2FA to protect against unauthorized logins.
9.3 Access Control & Internal Safeguards
- User data is accessible only to authorized personnel who require access for operational purposes.
- Internal access is strictly controlled and monitored for security compliance.
9.4 Security Breach Notification
In the event of a data breach, we will:
- Notify affected users without undue delay, and within 72 hours when required under GDPR.
- Investigate the incident and take immediate action to contain the breach.
- Notify affected users via email or in-app notification if their data is compromised.
- Comply with applicable legal requirements for breach disclosure and mitigation.
While we follow best security practices, no system is completely secure. If you suspect a security issue with your account, please contact us at [email protected] immediately.
10. Third-Party Links
Communicate may contain links to third-party websites or services that are not operated or controlled by us. These external services may have their own privacy policies and practices.
We are not responsible for the content, policies, or practices of any third-party websites or services. Clicking on a third-party link means you will be subject to their policies, not ours.
We encourage users to review the privacy policies of any third-party services they interact with to understand how their information may be collected and used.
11. Children's Privacy
Communicate is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13.
If we become aware that we have inadvertently collected personal information from a child under 13, we will:
- Delete the information immediately from our records.
- Take appropriate steps to prevent further collection.
If you believe that a child has provided us with personal data, please contact us at [email protected] so we can take the necessary actions.
12. AI Features and Your Data
This section explains how Communicate's optional AI Features handle data. It is written to stand on its own so we can update it without changing the rest of this policy. For step-by-step product details, see AI Copy Generation. The rules for using AI Features are in Section 15 of our Terms of Service.
12.1 Overview
- Optional and off by default. AI Features are available on the Plus plan and are off for every church until an Owner or Admin turns them on and accepts the AI terms on behalf of the church.
- Only when someone asks. Even when AI Features are on, data is sent to our AI providers only when a team member clicks Generate, or when an Owner or Admin saves Church Voice. Nothing is sent in the background.
- Our role. For church content sent to AI Features, the church is the controller and Communicate is a processor acting on the church's instructions (see Section 1).
12.2 Our AI Providers
- Vercel, Inc. (AI Gateway) routes AI requests to the AI model provider.
- OpenAI generates the draft text and the Church Voice profile.
Requests go from Communicate's servers, through Vercel AI Gateway, to OpenAI, using Communicate's own OpenAI account. Nothing is sent from your browser directly to an AI provider. The AI model we use may change over time.
12.3 What We Send
When a team member clicks Generate:
- Your church's Church Voice profile: a summary Communicate creates from your Church Voice settings (tone, writing style, and preferred and prohibited words).
- The campaign being written for: title, description, target audience, category, tags, planning and event dates and times, registration and content links, internal notes, and any existing copy.
- Or the communication being written for: title, status, date, existing copy, channel type, template name, and copy from its linked campaign.
- Any instructions or feedback the team member types into the AI window.
- Generation settings, such as length and emoji and hashtag preferences.
When an Owner or Admin saves Church Voice (to build the voice profile):
- The Church Voice settings as entered: the Voice & Tone description, language guidelines ("don't say / use instead"), and writing examples (for example, pasted emails, social posts, or announcements).
With every request:
- Random internal IDs for the church and the user (not names or email addresses), used for cost tracking and to trace misuse.
- A label for the feature being used (for example, "campaign copy").
12.4 What We Don't Send
- Team members' names, email addresses, passwords, or roles.
- Contact lists, recipients, subscribers, or audience member records.
- Billing or payment information.
- Other churches' data. Every request is limited to the requesting church's own data.
- Images and uploaded files.
Automatic removal and its limits. Before sending, Communicate replaces email addresses and phone numbers found in campaign and communication fields with placeholders. This has limits:
- It covers only email addresses and phone numbers. Names and other personal details in text are not removed.
- It does not currently apply to Church Voice writing examples or to instructions and feedback typed into the AI window.
Please don't enter sensitive personal information into campaign or communication fields you generate from, Church Voice, or AI instructions. This includes prayer requests, health information, family matters, counseling or pastoral care matters, and anything that reveals a specific person's religious beliefs.
12.5 What Comes Back
Our AI provider returns draft text (two options per request) or, for Church Voice, the voice profile summary. Drafts are shown to the team member and are saved in Communicate only if they choose to use one.
12.6 How Long AI Data Is Kept
Communicate:
- We do not store the requests sent to AI providers or the drafts that come back, unless a team member saves a draft into a campaign or communication.
- We store a usage record for each request: church, user, feature, model, success or error, token counts, estimated cost, and response time. We use it to apply usage allowances, track costs, and provide support. Usage records do not contain prompts, Church Voice content, or generated text. We keep them while your church's account is active and delete them when the account is deleted.
- We store your church's Church Voice settings and voice profile until your church edits them or its account is deleted.
- We keep the record of your church turning AI Features on or off (who, when, and which terms version) for as long as the account exists, as evidence of your church's instruction.
Vercel AI Gateway:
- Does not keep the content of requests or responses after the request is complete.
- Keeps request details (model, provider, token usage, cost, duration, and status) in logs for about 30 days.
OpenAI:
- May keep requests and responses for up to 30 days to monitor for abuse and misuse, and then deletes them.
- May keep them longer where required by law (for example, under a legal hold).
- We have turned off every optional data retention and sharing setting available in our OpenAI account. We do not have a zero-data-retention agreement with OpenAI, so the up-to-30-day retention above applies.
12.7 AI Training
- Communicate does not train any AI models on your church's content.
- OpenAI does not use data sent through its API to train its models by default, and we have not opted in to sharing data with OpenAI for training.
- Vercel does not train on requests.
12.8 Turning AI Features Off
An Owner or Admin can turn AI Features off at any time in Admin Console → Church Profile → AI Features. This immediately stops all AI requests for the whole church.
- Turning AI Features off does not delete your Church Voice settings or voice profile. An Owner or Admin can edit them at any time, and they are deleted when your church's account is deleted.
- When your church's account is deleted, its Church Voice settings, voice profile, AI settings, AI usage records, and on/off record are deleted with it.
- Data already sent to OpenAI remains subject to OpenAI's retention described above (up to 30 days, or longer if required by law).
12.9 Security and Access
- AI requests are made only from Communicate's servers. Our AI credentials are never exposed to browsers.
- The voice profile is internal. It is never shown to any user and is used only to write drafts.
- Church Voice settings are visible to team members who can access your church's account settings.
13. International Data Transfers
Communicate is based in the United States. Our app providers (Supabase, Vercel, Resend, OpenAI, and PostHog) process data in the United States, and AI requests are processed in the United States.
When we transfer personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States, we rely on appropriate safeguards:
- Vercel and Stripe are certified under the EU–U.S. Data Privacy Framework, including the UK Extension and the Swiss–U.S. Data Privacy Framework.
- OpenAI transfers from the EEA and Switzerland rely on the Standard Contractual Clauses in OpenAI's Data Processing Addendum (EEA and Swiss data is handled by OpenAI Ireland Limited). Transfers from the UK rely on the UK Addendum to those clauses.
- Supabase, Resend, and PostHog transfers rely on the Standard Contractual Clauses in their data processing agreements.
Our Subprocessors page lists each provider's location and safeguard.
EU and UK representatives.
EU representative: [FILL IN: name, address, contact]
UK representative: [FILL IN: name, address, contact]
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When significant changes are made, we will notify users through one or more of the following methods:
- Posting the updated Privacy Policy on our website.
- Sending an email notification to registered users.
- Displaying an in-app notice about the update.
We encourage users to review this Privacy Policy periodically to stay informed about how we protect and use their information. The "Last Updated" date at the top of this document will indicate the most recent changes.
If you continue to use Communicate after an update takes effect, you agree to the revised Privacy Policy. If you do not agree with the changes, you should discontinue use of the platform.
If we materially change how AI Features handle data (Section 12), AI Features pause for your church until an Owner or Admin accepts the updated terms in the app. Changes to our list of subprocessors are posted on our Subprocessors page and do not change the date of this policy.
15. Contact Us
If you have any questions about this Privacy Policy, need support, or wish to exercise your data rights, you can contact us at:
📧 Email: [email protected]
📬 Mail: Communicate, LLC, 128 NW Jayellen Ave., Burleson, TX 76028, United States
We aim to respond to inquiries in a timely manner, but response times may vary depending on the nature of the request.