Privacy Policy

Last updated July 18, 2026

Who we are

Berean is operated by BereanHQ LLC, a Florida limited liability company (“Berean,” “we,” “us”). Berean is an intelligence and analytics layer for church leadership: it connects, with your authorization, to tools your church already uses and turns their data into dashboards and weekly briefings. For anything in this policy, contact us at hello@bereanhq.com.

Information we collect

Account information. When you create an account: your name, email address, and a password (stored only as a salted cryptographic hash — we cannot read it).

Connected-service data. When you connect a service, you authorize read-only access and we sync the minimum needed for our features: from Planning Center, weekly attendance and check-in counts, giving totals and donor counts, people counts, volunteer scheduling activity, and recent first-time guests (names and visit dates) for follow-up features; from Meta, aggregate Facebook Page and Instagram reach and engagement metrics; from Google, YouTube channel statistics and views and Google Analytics session counts; from Mailchimp, campaign send and open counts. OAuth access tokens are encrypted at rest (AES-256-GCM) before storage.

Demo requests. If you request a demo: the name, email, church, and congregation size you submit.

Cookies. We use only essential, encrypted session cookies to keep you signed in and to associate your browser with your church. No advertising cookies, no third-party tracking.

How we use information

We use your data solely to provide the service: rendering your dashboards, computing health indicators, generating your Weekly Executive Brief, and emailing it to your account holders. We do not sell, rent, or share congregational data with third parties for their own purposes, and we show no advertising.

AI-generated briefings

Your Weekly Executive Brief is drafted by an AI model (Anthropic’s Claude) from facts we compute from your synced data — aggregate weekly metrics plus limited operational details such as volunteer names with serving streaks and first-time guest names for follow-up. Under Anthropic’s commercial API terms, this data is not used to train their models.

Service providers

We rely on a small set of infrastructure providers to run Berean: Vercel (application hosting), Supabase (database), Anthropic (AI briefing generation), and Apple iCloud Mail (email delivery). Each processes data only to provide their service to us.

Google user data

Berean’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We read only YouTube and Google Analytics reporting data to display your metrics and generate your briefings; we do not transfer it except as necessary to provide these features, no humans read it except for support you request, security, or legal compliance, and we never use it for advertising.

Retention and deletion

You can disconnect any connected service at any time from the Connections page — its stored tokens are deleted immediately. To delete your account, your church’s synced data, or a demo request, email hello@bereanhq.com and we will remove it within 30 days.

Security

All traffic is encrypted in transit (TLS). OAuth tokens are additionally encrypted at rest. Application data is reachable only through restricted server-side procedures — never directly from the browser.

Children

Berean is a tool for church staff and leadership and is not directed at children under 13. Congregational records synced from your systems are controlled by your church; we process them on your behalf.

Changes

If we make material changes to this policy we will update this page and note the new date above. Questions? Write us at hello@bereanhq.com.

See your church clearly.

A 30-minute demo with your own questions in mind. No migration, no pressure.