Legal
Privacy Policy
Effective August 25, 2026 · Last updated August 25, 2026
In plain English
Your church's data stays yours. The AI we use only sees what you send it, never other churches' data, and never trains on it. We don't sell or share your data. You can export or delete it whenever you want. We collect the basic information needed to run the service and nothing beyond that.
Who this policy is from
This Privacy Policy explains how Andrew Chappell, an individual doing business as Cedar & Stone (“Cedar & Stone,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use our software — currently Ministry OS, Sermon OS, Steeple and Display (the “Services”).
1. Information we collect
Information you provide. Account information (name, email address, church or organization name, role, password), billing information handled by our payment processor, content you upload — documents, media, training material, sermon recordings and anything else you put into the Services (“Customer Data”) — and whatever you share when you contact us or send in-app feedback.
Information collected automatically. Usage data (pages visited, features used, session duration), device and log information (browser, operating system, IP address, timestamps, error logs), and first-party cookies for signing you in and keeping you signed in, plus basic analytics. We do not use cookies for cross-site advertising.
What we do not collect. We do not collect data about your church members from outside sources, we do not buy or sell mailing lists, and we do not track your activity outside our own Services.
2. How we use it
- To provide and operate the Services — account access, billing, support, and feature delivery.
- To power AI features. Your queries and the content needed to answer them are processed by the providers listed below.
- To improve the Services by looking at aggregate usage patterns — never by training AI models on Customer Data.
- To communicate with you about your account, security and product updates, and marketing only if you opt in.
- To comply with legal obligations and protect against fraud, abuse, or security threats.
3. AI providers and your data
Several products use third-party AI infrastructure. As of the effective date above, those providers are:
- Cerebras Systems, Inc.(Sunnyvale, CA) — primary inference for assistants, summarisation and other AI-driven features.
- Groq, Inc.(San Francisco, CA) — fallback inference when Cerebras is unavailable, and speech-to-text for sermon transcription.
- Voyage AI— generates the numerical embeddings that make your uploaded documents searchable. The text of a document is sent to Voyage when it is indexed.
When you use an AI feature, the relevant portion of your query and any content required to answer it is sent to one of these providers, processed in transit, and the response returned. These providers operate under zero-data-retention terms, meaning your content is not stored by them after the response is delivered, is not used to train their models, and is not shared with their other customers.
We may change providers from time to time and will update this Policy when we do.
4. Customer Data — ownership and use
You own your Customer Data. We hold it on your behalf, under a limited license to use it only to provide the Services to you. We do not sell it, share it with other churches, train AI models on it, or use it for advertising.
When you delete content or close your account, we remove Customer Data from active systems within 30 days. Residual copies may persist in routine backups for up to 90 additional days, after which they are permanently deleted.
5. How we share information
We share information only as needed to operate the Services:
Service providers. AI infrastructure (Cerebras, Groq, Voyage AI), payment processing (Stripe), email delivery (Resend), product analytics (PostHog), document and media storage (Cloudflare R2), databases (Neon), and hosting (Hetzner and Vercel). Each is bound by contract or terms of service restricting their use of your data.
Legal compliance. If required by law, subpoena, or legitimate legal process, we may disclose information to comply. We will give you notice unless legally prohibited.
Safety. We may disclose information if necessary to protect the rights, safety, or property of Cedar & Stone, our users, or the public.
Business transfers. If Cedar & Stone is acquired or merged, your information may transfer to the new entity, subject to the protections of this Policy.
We do not sell your information.
6. Your rights and choices
- Access your account information and Customer Data through the Services at any time.
- Update or correct your account information in your settings.
- Export your data — administrators can download uploaded documents from the app, and we will supply anything else on request within 30 days.
- Delete your account through your settings or by emailing us.
- Opt out of marketing email through the unsubscribe link. Transactional email about your account, billing and security continues unless you close the account.
If you are a California resident, the CCPA gives you additional rights, including the right to know what personal information we hold, the right to deletion, and the right not to be discriminated against for exercising those rights.
If you are in the European Economic Area or the United Kingdom, the GDPR gives you additional rights including data portability, the right to object to certain processing, and the right to complain to a supervisory authority.
To exercise any of these, email andrew@cedarandstone.io.
7. Data security
- Encryption in transit (HTTPS) for everything sent between your device and the Services.
- Encrypted storage at rest in our hosting infrastructure.
- Access controls limiting who can reach production systems.
- Routine security updates and dependency monitoring.
No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify you without undue delay and consistent with our legal obligations.
8. Children's privacy
The Services are intended for adults responsible for ministry operations. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will delete it.
Note that volunteer records uploaded by a church may include people under 18 — youth volunteers, kids ministry helpers. That data is processed under the direction of the church, on behalf of its members. Churches are responsible for obtaining appropriate consent from minors or their guardians before adding them to volunteer records.
9. International data transfers
The Services are hosted in the United States. If you access them from outside the U.S., your information will be transferred to, stored in, and processed in the U.S., where data protection laws may differ from those of your jurisdiction.
10. Retention
- Account information — kept while your account is active, deleted within 90 days of closure.
- Customer Data — kept while your account is active, deleted within 90 days of closure (30 days in active systems, up to 90 further days in routine backups).
- Billing records — kept for 7 years after closure to meet tax and accounting requirements.
- Aggregate analytics — may be kept indefinitely in de-identified form.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes we will notify you by email and update the “last updated” date above. Continued use of the Services after the update constitutes acceptance of the revised Policy.
Questions about any of this? Email andrew@cedarandstone.io.