Legal

Privacy Policy

Last updated 26 September 2026

Sermon Guides turns your church's public sermon streams into sermon pages, clips and social posts, and emails them to you. This page describes exactly what we store, why we store it, and how to get rid of it.

What we collect

Account details — your email address and the sermon link you submit when you sign up; your church's name, which we take from that sermon's channel or you enter yourself; and your first name, last name, role at your church and church Facebook page link if you add them in your settings. If you sign in with Google, Google shares your name, email address, profile picture and Google account identifier with us; we keep your name, email address and identifier.

Channel details — the YouTube channel or Facebook page link you connect, its public name, handle and picture, and public metadata about the videos on it (title, description, publication date, duration and link).

Sermon content — the audio and video of the streams we process, the transcript we generate from them, and the pages, clips and posts we produce.

Operational records — sign-in times, the IP address and browser of each signed-in session, processing status, email delivery status, and error diagnostics. We keep these to run, secure and debug the service.

Site analytics — we use Google Analytics to count visits to this website: which pages are viewed, roughly where from, and on what kind of device. Sign-in and confirmation links are removed from what it receives.

We do not collect payment card details; we do not process payments on this site.

Why we process it

To create your account and sign you in, to detect and download your new sermons, to generate your sermon page and its clips and posts, to email them to you on your chosen schedule, and to keep the service secure and working. We do not sell your data, and we do not use your sermon content to train our own models.

Who we share it with

We use a small number of processors, each for one job: speech-to-text and language model providers (Groq, OpenAI and Google Gemini, and TypeSafe for some features) to produce transcripts, written guides and clip choices, Cloudflare, which carries traffic to our servers, an object storage provider to host finished clips and images, an email provider to deliver your emails, Google Analytics to count site visits, a network provider that relays downloads of your public sermon videos, Google Fonts for the typefaces on this website (it receives your IP address when a page loads), a hosting provider for this website (Vercel), a hosting provider for the servers that run the processing, and a managed database provider that stores your account and sermon data. Each receives only what that job requires.

Anything you publish — your sermon page, its clips and its quote graphics — is public by design, because that is the point of it. Source video, audio and raw transcripts are never published. A video you upload directly is held at an unguessable address and deleted as soon as we have downloaded it for processing. If it never becomes a sermon, or its download fails, it stays there until you delete that sermon or ask us to close your account.

How long we keep it

Source video, audio and transcripts are deleted automatically, normally about a week after processing (a clean-up runs after each sermon and every night, and removes source files older than 7 days); we do not keep a permanent copy of your stream. Generated pages, clips and posts are kept while your account is open. Delete a sermon and its page, clips and posts are removed straight away; its source files are deleted on the same weekly schedule. Ask us to close your account (see Deleting your data) and we delete your account data and generated content, with source files following on that schedule. Session records (including IP address and browser) are deleted 30 days after the session expires; processing and email delivery records lose your address after 180 days. An address that signs up with a sermon link but never confirms it is deleted after 7 days.

Your choices

You can disconnect a channel at any time, which stops us finding new sermons on it; a sermon already being processed, or one that failed and is retried, may still finish. You can unsubscribe from sermon emails (the weekly email and new-sermon notices) with the unsubscribe link in any of those emails; account emails such as sign-in codes will still reach you. You can request a copy or deletion of your data by emailing us from your account address.

Because we act on public streams from a channel you control, please make sure you have the right to the content you connect.

Accounts you connect

When you connect a Facebook Page, its linked Instagram account, or your YouTube channel, you sign in on that platform and it gives us an access token, which we store encrypted. We never see your password. What we do with it:

Facebook: list the Pages you manage so you can pick yours; read that Page's videos and live broadcasts (title, date, length) to find each new sermon; check once a day that the connection still works; check which permissions it has before we post; find the Instagram account linked to the Page; and publish or schedule the clips and graphics you ask us to post, and record each post's link.

Instagram: publish the clips and graphics you ask us to post, then read back each post's link.

YouTube: read your channel's name, ID and picture so you can see which channel is connected, and upload the clips you ask us to post.

We never read your messages or your followers, and we never post anything you did not ask for.

Sermon Guides's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. For YouTube we request two permissions: to upload videos, and to view your YouTube account, used only as described above. Uploads go through the YouTube API Services, and the Google Privacy Policy applies to them.

What we receive from Google — the access token and your channel's name, ID and picture — is used only for the features above. We do not share it with any third party (including the transcription and language model providers listed above), we do not use it for advertising, we do not sell it, and we do not use it to train AI models. The token is encrypted at rest on our servers and is deleted when you disconnect.

Deleting your data

Disconnect an account: in your dashboard under Connections, choose Disconnect. We delete the stored token straight away. You can also remove our access from the platform itself: Facebook Settings → Business Integrations, or your Google Account → Security → Third-party connections.

Delete everything: email volodymyr@sermonguides.com from your account address. We delete your account, connected-account tokens, uploads and generated content, and confirm by email; source video, audio and transcripts follow on the weekly schedule described above. Our own database backups that still contain it expire within 30 days; our database provider also keeps short-term recovery copies, which expire under its own retention schedule. Posts already published to your own pages stay there; delete them on the platform.

Security

You sign in with a one-time code sent to your email; codes are stored only in hashed form and expire after 15 minutes. Traffic is encrypted in transit. Access to your content is scoped to your church account.

This document describes how the product actually works today. It has not been reviewed by a lawyer — have counsel review it before launch, particularly if you take churches outside the United States.