1. Who we are
SermonTrack is software that helps a church track every service on its schedule from the recording through to publication on YouTube, and publish the result as a podcast feed and a public sermon archive.
SermonTrack is operated by Surface Collective Corporation of 1 Park Pt. Apt 1128, Brooklyn, NY 11218 (“SermonTrack”, “we”, “us”). We are the data controller for the information described in this policy, except where we act as a processor for a church customer as described in section 2.
This policy covers the SermonTrack website at sermontrack.io and the hosted SermonTrack application we provide to churches. It does not cover a copy of the software you host yourself — see section 13.
2. Information we collect
Information you give us directly
- Pilot and contact enquiries. Your name, email address, church name, role, the number of services you record, an optional link to your YouTube channel, and anything you write in the message box.
- Account information. The email addresses of the people you give access to, and the role (admin or editor) you assign each of them. SermonTrack signs people in with one-time email links — we do not store passwords, because there aren’t any.
- Billing information. If you subscribe to a paid plan, our payment processor collects and holds your card details. We receive only the billing contact, plan, invoice history and payment status — never full card numbers.
Church content you put into the app
This is the substance of the service: your service schedule, sermon records (title, date, speaker, series, scripture, notes, internal status), uploaded sermon audio, thumbnail images and background art, transcripts, AI drafts, and your podcast and archive settings. We handle this content on your church’s behalf and under your instructions. We do not use it for our own purposes, and we do not publish any of it — the public archive and podcast feed are off until you turn them on, and even then they expose only the fields you have chosen to publish, never internal notes or workflow status.
Information from accounts you connect
Only if you choose to connect them, and only the scopes listed in section 4 and section 5. Nothing is connected by default.
Information collected automatically
- Service logs. Ordinary server logs — IP address, timestamp, request path, status code, user agent — kept for security, debugging and abuse prevention.
- An audit trail. The app records who changed what and when inside your own instance, so a church team can answer “who edited this?”. It is visible to your admins.
- Usage metering. If you are on a plan that includes AI or transcription, we count requests, tokens, transcribed minutes and cost per month so we can show you your allowance and bill correctly. This counts volume, not content.
The marketing website itself sets no analytics or advertising cookies — see section 11.
3. How we use it
| What | Why | Lawful basis (UK/EU) |
|---|---|---|
| Pilot and contact enquiries | To reply to you and set up a trial instance | Legitimate interests; steps prior to a contract |
| Account information | To sign people in and enforce roles | Performance of a contract |
| Church content | To provide the tracker, podcast, archive and backups you asked for | Performance of a contract |
| Connected account data | To perform the specific action you connected the account for | Consent, given at the point of connection |
| Service logs | Security, debugging, abuse prevention | Legitimate interests |
| Usage metering | To show and enforce plan allowances, and to bill | Performance of a contract |
| Billing information | To take payment and meet tax and accounting duties | Contract; legal obligation |
We do not use your information for advertising, we do not sell or rent it, and we do not build profiles of your congregation.
4. Google user data
Connecting a Google account is optional. If you never connect one, SermonTrack still tracks your schedule, composes your titles and descriptions, and publishes your podcast and archive — you just do the YouTube step and your backups by hand.
4.1 What we ask for, and why
| Scope | What we do with it |
|---|---|
https://www.googleapis.com/auth/youtube.force-ssl |
Read only, in practice. We use it to (a) list the videos on your own channel’s uploads playlist so the tracker can reconcile what is actually published against your service schedule, and (b) list and download the caption track of a video on your channel so a sermon can have a searchable transcript. SermonTrack never uploads, edits, deletes, or changes the privacy of any video, playlist, comment or channel setting. Google does not offer a narrower scope that permits downloading caption content, which is the only reason this scope is requested rather than a read-only one. |
https://www.googleapis.com/auth/drive.file |
Only if you turn on Google Drive backups. This scope grants access solely to files SermonTrack itself creates — it writes your backup archives into a single folder and deletes old archives according to the retention you set. It cannot see, read, or touch any other file in your Drive. |
4.2 What we store
- OAuth tokens. The access and refresh tokens Google issues, held encrypted at rest and used only to make the calls above on your behalf.
- Channel metadata. Your channel ID, the uploads playlist ID, and, for videos we match to a sermon, the video ID, title, publication date and thumbnail URL.
- Caption text you choose to fetch, stored as the sermon’s transcript so it can be searched, and cached briefly to avoid repeat API calls.
- Backup archives written to your own Drive. We do not keep a copy of what we put in your Drive.
4.3 Sharing and transfer
We do not transfer Google user data to anyone, except: (a) the infrastructure providers who host the service on our behalf under contract (section 7); (b) where you explicitly direct it, such as transcript text you send to a transcription or AI provider by using an AI feature; and (c) where the law requires it. We never transfer it for advertising, credit assessment, resale, or model training.
Limited Use. SermonTrack’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.4 Revoking access
You can disconnect Google at any time from Settings › Connections inside the app, which deletes the stored tokens immediately. You can also revoke SermonTrack’s access from your Google Account at myaccount.google.com/permissions. Revoking access stops reconciliation and Drive backups; everything already in your tracker stays where it is.
SermonTrack uses YouTube API Services. Your use of it is also governed by the YouTube Terms of Service, and Google’s handling of your data by the Google Privacy Policy.
5. Microsoft and Dropbox
Both are optional and exist only to store your backup archives in a cloud drive you already have. Each is requested with the narrowest scope the provider offers:
- Microsoft OneDrive —
Files.ReadWrite.AppFolderandoffline_access. Access is confined to SermonTrack’s own application folder; the rest of your OneDrive is invisible to us. - Dropbox —
files.content.write, scoped to the app folder Dropbox creates for SermonTrack.
We store the OAuth tokens (encrypted) and nothing else from these accounts. Disconnect from Settings › Connections, or from the provider’s own security settings, at any time.
6. AI features
AI drafting, clip finding and transcription are optional and are only ever invoked when someone on your team asks for them. When they are used:
- The relevant text or audio — a sermon’s details, its transcript, or an uploaded audio file — is sent to our AI subprocessors (currently Anthropic for text and OpenAI for speech-to-text) purely to produce that result.
- Our agreements with those providers prohibit using your content to train their models, and they retain it only briefly for abuse monitoring, if at all.
- Nothing an AI produces is published automatically. Drafts appear in the app for a person to edit, accept or discard.
- If you supply your own Anthropic or OpenAI key, requests go to your own account under your own terms with those providers, and we do not meter them.
8. Storage, security and location
Each church runs on its own isolated instance with its own data directory — your content is not mixed into a shared database with other churches. We use HTTPS everywhere, encrypt credentials and OAuth tokens at rest, apply a strict content security policy, and keep an audit trail of changes. Access to production systems is limited to the people who need it.
Our servers and backups are located in the United States. If you are in the UK or EEA and your data is processed elsewhere, we rely on the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator we are required to notify, without undue delay.
9. Retention and deletion
| What | How long |
|---|---|
| Church content (sermons, audio, transcripts, settings) | For as long as your account is active, then 30 days after it closes — during which you can still export it |
| OAuth tokens | Until you disconnect the account, or the account closes |
| Pilot and contact enquiries | Up to 24 months from your last message |
| Service logs | Up to 90 days |
| Usage metering records | Up to 24 months, for billing history |
| Invoices and accounting records | As long as tax law requires (typically 6–7 years) |
| Backup archives held by us | Rolling, per your configured retention; deleted copies age out within 35 days |
You can export your entire archive as a single file from inside the app at any time, and ask us to delete your instance early by writing to us.
10. Your rights and choices
Depending on where you live you may have the right to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; and to withdraw consent you have given. To exercise any of these, email privacy@sermontrack.io. We will respond within 30 days and will not discriminate against you for asking.
If we hold information about you because your church put it into SermonTrack, we will normally refer your request to your church, who decides what happens to it — and we will help them carry it out.
UK and EEA users may complain to their data protection authority (in the UK, the Information Commissioner’s Office). We would rather you told us first, so we can fix it.
12. Children
SermonTrack is a tool for church staff and volunteers and is not directed at children under 16. We do not knowingly collect personal information from children. Sermon content that happens to mention or depict young people is church content, handled as described in section 2 — please follow your own safeguarding policy about what you publish.
13. Self-hosted installations
SermonTrack can be run on your own server. In that case the software stores everything on your infrastructure, connects directly to whichever APIs you configure with your own credentials, and sends us nothing. This policy does not apply to a self-hosted instance; your church is the controller for all of it.
14. Changes to this policy
We will update this page when our practices change, and change the “last updated” date above. If a change materially affects how we handle your information, we will email account admins at least 14 days before it takes effect. Previous versions are available on request.
15. Contact us
Privacy questions, requests, and complaints:
privacy@sermontrack.io.
Anything else: hello@sermontrack.io.
Postal: Surface Collective Corporation, 1 Park Pt. Apt 1128, Brooklyn, NY 11218.