1. What we collect
Beyond the Message is sold to churches, and each church's archive is separate from every other church's. Information reaches us in three ways: you give it to us when you create an account, your church gives it to us when it adds sermons, and a small amount is generated as you use the app.
Account information
| What | Why we have it |
|---|---|
| Email address | Identifies your account, delivers password resets, and receives new-sermon notifications if you leave them on. |
| Password | Stored only as a salted hash by our authentication provider. Nobody at Beyond the Message can read your password. |
| Your church and role | Determined by the signup code your church gave you. Your role — member or staff — controls what you are allowed to see and do. |
| Notification preference | A single on/off setting for new-sermon emails, which you control in Account settings. |
Content your church provides
Church staff upload sermon material: transcripts generated from service captions, along with titles, scripture references, dates, service names, preacher names, optional video links, and their own notes. Study guides are generated from that material and stored alongside it. This content belongs to the church, not to us.
Information generated as you use the app
- Your Ask conversations. When you ask a question about a sermon, your question and the answer are saved to your account so the conversation is still there when you come back. This history is private to you — no one else, including your church's staff, can read it through the app.
- Cached answers. To avoid paying to answer the same question twice, the first question asked about a sermon and its answer are also stored in a shared cache, so the next person who asks something similar about that sermon gets the stored answer instantly. These cached entries are stored without any link to who asked — they record the sermon, the question text, and the answer, and nothing that identifies you. Follow-up questions in a conversation are never cached.
- Ordinary server logs. Our hosting provider records standard request information — IP address, timestamp, and the page or endpoint requested — as part of operating and securing the service.
Because cached questions are visible to other members of your church in the form of a stored answer, treat Ask like a question asked out loud in a group study, not a private journal. Don't put confidential personal details into a question.
2. What we don't collect
We want to be specific about this, because "we may collect" language in most privacy policies hides more than it says. Beyond the Message contains:
- No analytics or tracking SDKs, and no third-party trackers of any kind.
- No advertising, no ad identifiers, and no data sold or shared with advertisers.
- No location collection.
- No access to your contacts, photos, microphone, or camera.
- No cross-app or cross-site tracking, and no data broker relationships.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in United States state privacy laws.
3. How information is used
We use what we collect only to run the service:
- To sign you in and keep you signed in.
- To show you your church's sermon archive and its search results.
- To generate study guides and answer your questions about a sermon.
- To send the emails described in section 7.
- To keep the service secure, diagnose failures, and prevent abuse.
We do not use your content or your questions to build profiles, to market to you, or for any purpose unrelated to operating Beyond the Message for your church.
4. AI processing
Study guides and Ask answers are produced by Claude, an AI service operated by Anthropic. When a study guide is generated, the sermon transcript and any preacher notes are sent to Anthropic's API. When you ask a question, your question, the recent turns of that conversation, and the relevant sermon transcript are sent.
Anthropic processes this material to return a response and does not use inputs or outputs from its business API to train its models. Requests are sent from our servers using our own API credentials; your email address and account identifier are not included.
AI output is not authoritative. Study guides and Ask answers are generated from the sermon transcript by a language model and can be incomplete or wrong. They are a study aid, not the preached word and not pastoral counsel. Check anything that matters against scripture and against the message itself.
5. Who can see what
Access is enforced at the database level, not just hidden in the interface, and every rule is scoped to your church.
| Who | Can see |
|---|---|
| You, as a member | Published sermons from your church, their study guides, search results, and your own Ask history. Not draft sermons, not raw transcripts, and nothing from any other church. |
| Your church's staff | Everything in their own church's archive, including drafts and full transcripts, which they need in order to edit and publish. Staff cannot read any member's Ask history. |
| Other churches | Nothing. Archives are isolated from one another. |
| Us | Administrative access for support and maintenance, used only when needed to operate the service or when your church asks us for help. |
Sermon transcripts are deliberately restricted. Member search matches against transcript text without returning the transcript itself, and exported study guides and PDFs never contain the raw transcript.
6. Service providers
We use a small number of vendors to run the service. Each processes information only to provide its part of it.
| Provider | Role |
|---|---|
| Supabase | Database and authentication. Stores accounts, churches, sermons, and Ask history. |
| Vercel | Website and API hosting. |
| Anthropic | AI processing for study guides and Ask, as described in section 4. |
| Brevo | Sends transactional email — welcome messages and new-sermon notifications. |
| Apple | Distributes the iOS app. Apple provides us with aggregate, non-identifying download and crash statistics. |
These providers may store and process information in the United States and in other countries where they operate.
7. Email we send
- Account email — a welcome message when you sign up, and password reset messages when you request one. These are part of having an account and can't be turned off.
- New-sermon notifications — sent when your church publishes a message, if you have them enabled. Turn them off any time in Account settings. Notification blasts are sent blind-copied, so no recipient can see anyone else's address.
We do not send marketing email to church members, and we do not rent or sell email addresses.
8. Retention and deletion
Account information is kept while your account exists. Sermon content is kept as long as your church keeps it in the archive — that content belongs to the church, and staff can delete it at any time.
You can delete your account at any time. Deleting it permanently removes your account, your profile, and your Ask history. Full instructions and details of what is and isn't removed are on the account deletion page.
Deleted data may persist in encrypted backups for up to 30 days before those backups age out.
9. Security
- All traffic is encrypted in transit with HTTPS, and data is encrypted at rest by our database provider.
- Passwords are salted and hashed; they are never stored in readable form.
- Access rules are enforced by row-level security in the database, so a client application cannot request records it isn't entitled to.
- Privileged operations — creating accounts, deleting accounts, reading transcripts — run on our servers with credentials that are never sent to your browser or your phone.
No system is perfectly secure. If we ever discover a breach affecting your information, we will notify affected users and churches promptly.
10. Children
Beyond the Message is intended for a general audience and is not directed to children under 13. Accounts are created with a code issued by a church, and we do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact us and we will delete it.
11. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a copy of it, or object to certain processing. You can exercise most of these directly in the app — your account details and notification preference are editable in Account settings, and deletion is available on the deletion page. For anything else, email us and we will respond within 30 days.
We will not deny you service, charge you a different price, or degrade your experience for exercising any of these rights.
12. Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects how your information is used, we will notify account holders by email before it takes effect.
13. Contact
Questions about your privacy
Email hello@beyondthemessage.net and we'll get back to you within two business days. If your question is about sermon content in a specific church's archive, that church's staff may need to be involved, and we'll say so.