Cartha for Churches Privacy Policy
Cartha for Churches Privacy Policy
Privacy leaders cannot weaken. The staff app helps leaders see whole-church patterns and respond to information a person intentionally shared. It does not turn private member life into a leader dashboard.Who is responsible and how to contact us
This Privacy Policy applies to Cartha for Churches (Android package ai.cartha.church), provided by Cartha AI, Inc. Contact support@cartha.com for privacy questions or requests. The policy text for this staff app is provided on this page; no sign-in or additional navigation is required.
What the staff app uses
Cartha for Churches uses your Cartha account, church-admin role, and church workspace configuration to provide the staff product. Live church data remains in the existing Cartha service boundary; the mobile app does not create a second copy of a church database.
- Name, email address, and account identifier for sign-in and access.
- Church membership and admin authorization.
- Congregation-wide Scripture and sermon aggregates.
- Care content a member intentionally shared with church leaders. This can include religious beliefs and health information when a person chooses to include them in a prayer or care request.
- Staff workflow actions such as assign, respond, and reopen.
What leaders cannot see
Leaders cannot use this product to open a member’s reading history, assessment, giving activity, private AI conversation, or private reflection. Congregation metrics remain hidden below the minimum cohort. Prayer content is never scored, themed, summarized, or added to aggregate reports.
Tracking and advertising
The standalone church staff app contains no advertising, attribution, cross-app tracking, or third-party analytics SDK. System services may provide ordinary store download and crash information under Apple or Google’s own terms.
How information is used and shared
We use account and church-role information to authenticate you and enforce workspace access. We use shared care content and staff actions to deliver the care workflow, and aggregate information to provide the congregation and sermon dashboards. Security and operational information supports service reliability and abuse prevention. We do not sell personal information or share it with advertisers.
Information intentionally shared with church leaders is available to authorized leaders for that care workflow. Service providers, including Amazon Web Services for hosting and account infrastructure, process information to operate Cartha. If you choose Google or Apple sign-in, that provider processes sign-in under its own policy and supplies the account information needed to authenticate you. Apple and Google also operate their app stores.
We may disclose information when required by valid legal process, to protect people or the service, or as part of a business transfer subject to applicable privacy protections. The staff app does not send prayer content to AI for scoring, summaries, or themes.
Security and international processing
The app communicates with Cartha over HTTPS. Sign-in tokens use the device’s protected credential storage, and access to live church workspaces is checked by Cartha’s servers. Our hosting and service providers may process information in the United States or other countries where they operate. No system is completely secure; do not share passwords, access codes, or private member records in support email.
Data retention and account deletion
We retain account and workspace information while needed to provide the service and fulfill the purposes described here. Retention can also depend on security, legal, and recordkeeping obligations. Deleting the app alone does not delete your account or server data.
To delete your whole Cartha account, open Control in the app, choose Delete Cartha account, read the warning, type DELETE, and confirm. If you cannot access the app, email support@cartha.com from your account email with the subject “Cartha account deletion request.” We verify ownership before acting. Deletion removes deletable account data across Cartha products and ends church-admin access. Narrowly required security, transaction, legal, or consent records may be retained and restricted from ordinary product use.
Your choices and privacy rights
Congregation impact reporting uses opted-in adult participation and minimum-cohort protections, not individual member activity reports. Members can revoke participation through their Cartha church controls. Depending on your location, you may request access, correction, deletion, a copy of your data, or withdrawal of consent, and may complain to your local data protection authority. Email support@cartha.com to make a request. We may verify your identity without requesting your password.
Children and changes to this policy
Cartha for Churches is a church-staff product, not an app directed at children. Minors are excluded from congregation impact reporting. We update this page when the staff app’s data practices change and display the effective date below. Other Cartha experiences are described in the general Cartha Privacy Policy; the staff-app disclosures above can be read in full without following that link.
Effective September 3, 2026 · Contact: support@cartha.com