Skip to content

Last updated · June 2026

Privacy.

PastSunday is a tool in the shepherd's hand, not a growth platform. We hold what we need to turn Sunday's sermon into the week's pieces, and nothing more. Here is all of it, in plain language.

Where this comes from

Your sermons, your transcripts, your drafts, your people: they belong to your church, not to a vendor's analytics stack. The Spirit forms a congregation; we just hand Sunday back to you in shapes that fit the week. So our default posture toward your data is the same as our posture toward Sunday's sermon, treat it carefully and don't make a product out of it.

What we hold

Your account: the email address you sign in with, plus a record of each sign-in (time, IP address, browser user-agent) so we can keep automated abuse out and debug a link that never arrived. Sign-in links are single-use and stored only as a hash.

Your church: its name, service times, address, and the colors, type, and logo you set for rendered images. Service times and address appear on the Saturday invitation because you put them there.

Your sermons: the audio or video you upload or link, the transcript we make from it, and every draft generated from that transcript (clips, tiles, the email, the blog draft, the study guide, the invitation). If you invite teammates, we store the email addresses you invite.

Connected accounts: if you connect a social platform so PastSunday can publish for you, we store the access tokens that platform issues. They are encrypted at rest, used only to publish what you scheduled and to read how those posts performed, and deleted when you disconnect the account.

Who processes it for us

We run on a small set of services, and each one sees only what its job requires. Fly.io hosts the app and the database. Tigris stores your uploaded media and rendered files. OpenAI transcribes your recording (Whisper). Anthropic drafts the written pieces from your transcript (Claude). Resend delivers sign-in and invite emails. Cloudflare sits in front of the site as its proxy. Under the API terms we use them on, OpenAI and Anthropic do not train their models on your sermons, and neither do we.

How long we keep it

The original recording is the biggest thing you give us, so we keep it the shortest time: about ten days after transcription, the source audio or video is deleted. Your transcript, drafts, and every rendered clip and image stay. When you delete a sermon, it leaves your workspace immediately and is held for thirty days in case the deletion was a mistake; after that the sermon, its drafts, and its files are gone for good.

What we do not do

We do not sell your data or share it with advertisers. We do not train shared models on your sermons. We do not run third-party analytics that profile you across the web: no Facebook pixels, no Google Analytics, no session replay vendors. We are not in the business of watching the people you shepherd.

Removing your data

Deleting a sermon removes it as described above. To delete your whole account and everything tied to it, email hello@pastsunday.com and we will do it. An in-app account-deletion button is coming; for now the inbox is the API.

Changes

This page will keep pace with the product. When something material changes we will note it at the top and email anyone with an account.

Questions? hello@pastsunday.com.