Avodah Logo Avodah
Features Pricing Terms Get Started Free

Privacy Policy

Last updated: 28 May 2026

In short: We collect only what we need to run Avodah for your church. We never sell your data. You can request access, correction, or deletion of your personal information at any time.

1. Who We Are

Avodah ("we", "us", "our") is a cloud-based church management platform operated by Avodah Software. Our platform helps churches manage rosters, people, expenses, communications, events, and more through web and mobile applications.

If you have questions about this policy or your data, contact us at:

  • Email: privacy@avodahapp.com
  • Address: Avodah Software, Newcastle Upon Tyne, United Kingdom

2. Information We Collect

2.1 Information You Provide

Category Data Purpose
Account Name, email address, password, phone number, profile photo Creating and managing your account
Profile Timezone, default church, custom attributes set by your church (e.g. birthday, gender, role) Personalising your experience and church administration
Financial Expense amounts, descriptions, categories, receipt images, bank account details (name, account number, sort code) Expense submission, approval, and reimbursement
Communications Chat messages, group messages, emoji reactions, prayer requests Enabling messaging between church members
Church Activity Roster assignments, attendance records, event participation, small group memberships, discipleship records Church operations, scheduling, and pastoral care
Assessments Responses to discipleship assessments and learning course progress Tracking growth and programme completion
Uploaded Files Profile photos, expense receipts, chat images, documents Supporting features that require file attachments

2.2 Information Collected Automatically

Category Data Purpose
Device Device name, platform (iOS/Android), push notification tokens Delivering push notifications and managing sessions
Session IP address, user agent, last activity timestamp Session management and security
Usage Feature interactions, notification read status, login timestamps Improving the service and troubleshooting

2.3 Sensitive Information

Some data processed through Avodah may be considered sensitive, including:

  • Religious information implied by church membership and participation data
  • Prayer requests that may contain personal or health-related details
  • Pastoral care notes recorded by church leaders
  • Assessment responses that may reveal personal circumstances

We process this information only to provide the church management services your church has engaged us for. Your church administrator is the data controller for this information and determines how it is used within their organisation.

3. How We Use Your Information

We use your information to:

  • Provide the service — manage accounts, enable roster scheduling, people management, expense tracking, chat, events, and all other platform features
  • Communicate with you — send push notifications, email reminders, and in-app messages related to your church activities
  • Process expenses — facilitate expense submissions, approvals, and reimbursements, including AI-assisted receipt data extraction
  • Maintain security — authenticate sessions, detect unauthorised access, manage blocked users and reports
  • Improve the platform — diagnose issues, analyse usage patterns in aggregate, and develop new features
  • Provide real-time features — deliver instant messaging, live roster updates, and notifications via WebSocket connections

4. How We Share Your Information

We do not sell, rent, or trade your personal data. We share information only in the following circumstances:

4.1 Within Your Church

Your church administrators and authorised leaders can view member data, attendance records, roster assignments, and other information necessary for church operations. The visibility of your information is determined by the roles and permissions your church has configured.

4.2 Third-Party Service Providers

We use trusted third-party services to operate the platform:

Provider Purpose Data Shared
Google Firebase Push notifications (FCM) Device tokens, notification content
Amazon Web Services File storage (S3), email delivery (SES) Uploaded files, email addresses and content
Anthropic (Claude AI) AI-powered receipt extraction and assistant features Receipt images and text for data extraction
Deepgram Audio transcription Audio content submitted for transcription
Email Providers Transactional email delivery (Postmark, Resend, or SMTP) Email addresses and message content
WhatsApp (Meta) Messaging integration (where enabled by your church) Phone numbers and message content

Each provider is bound by their own privacy policy and our data processing agreements. We only share the minimum data necessary for each service to function.

4.3 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or enforceable government request.

5. Data Storage and Security

5.1 Where We Store Data

Your data is stored on secure servers. Uploaded files may be stored locally on our servers or on Amazon S3 cloud storage. The mobile app stores authentication tokens and cached data locally on your device using secure storage.

5.2 Security Measures

  • Passwords are hashed using industry-standard algorithms (bcrypt) and never stored in plain text
  • API communication is encrypted via HTTPS/TLS
  • WebSocket connections use secure TLS encryption
  • Authentication uses token-based security (Laravel Sanctum)
  • Two-factor authentication is available for additional account protection
  • Session management allows you to view and revoke active sessions on other devices
  • Role-based access control ensures users only see data they are authorised to view
  • Multi-tenant architecture isolates each church's data from other organisations

5.3 Data Retention

We retain your personal data for as long as your account is active or as needed to provide the service. Specific retention periods:

  • Account data: Retained until you or your church administrator requests deletion
  • Chat messages: Retained for the life of the conversation unless deleted by participants
  • Expense records: Retained for a minimum of 7 years to comply with financial record-keeping requirements
  • Session logs: Automatically purged after 90 days
  • Soft-deleted records: Permanently removed within 90 days of deletion

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that we correct inaccurate or incomplete information
  • Deletion — request that we delete your personal data, subject to legal retention obligations
  • Portability — request a machine-readable copy of your data
  • Restriction — request that we restrict how we process your data
  • Objection — object to our processing of your data for certain purposes
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, contact us at privacy@avodahapp.com. We will respond within 30 days.

6.1 Account Controls

Within the app, you can:

  • Edit your profile information (name, email, timezone, photo)
  • Change your password
  • Enable or disable push notifications
  • View and revoke active sessions on other devices
  • Block other users from contacting you
  • Report inappropriate behaviour

7. Push Notifications

We use Firebase Cloud Messaging (FCM) to send push notifications to your mobile device. Notifications may include roster reminders, message alerts, expense status updates, and event notifications.

You can control push notifications by:

  • Granting or denying notification permission when prompted by the app
  • Toggling notifications in your in-app notification preferences
  • Disabling notifications in your device's system settings

Your device token is registered with our servers when you enable notifications and removed when you log out.

8. Cookies

Our web application uses cookies for:

  • Authentication — keeping you logged into the admin panel
  • Session management — maintaining your session state
  • CSRF protection — preventing cross-site request forgery attacks
  • Preferences — remembering your settings (e.g. theme, selected church)

We do not use third-party advertising or tracking cookies.

9. Admin Impersonation

Authorised administrators may have the ability to view the platform as another user ("impersonation") for the purpose of troubleshooting and support. When an administrator is impersonating your account:

  • A visible indicator is displayed in the app
  • The action is logged for audit purposes
  • It is used solely for legitimate administrative and support purposes

10. AI-Powered Features

Avodah uses artificial intelligence for specific features:

  • Receipt extraction: When you upload a receipt image for an expense, we may use AI to extract text and data (amounts, dates, descriptions) from the image. The image is sent to our AI provider (Anthropic) for processing and is not used to train AI models.

AI features are optional and only activated when you explicitly use them (e.g. uploading a receipt for extraction).

11. Children's Privacy

Avodah is not directed at children under the age of 16. We do not knowingly collect personal information from children. Church administrators may store limited information about minors (e.g. names for attendance or check-in purposes) as part of the church's operations, and the church is responsible for obtaining appropriate parental consent.

12. International Data Transfers

Your data may be processed in countries other than your own, including the United Kingdom, the European Economic Area, and the United States (where our cloud service providers operate). We ensure appropriate safeguards are in place for any international transfers, including standard contractual clauses where required.

13. Multi-Tenancy and Data Isolation

Avodah operates a multi-tenant architecture where each church's data is logically isolated. Church administrators can only access data belonging to their own organisation. If you are a member of multiple churches on the platform, each church can only see the data relevant to their organisation.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice in the app or sending you an email. Your continued use of the service after changes take effect constitutes acceptance of the revised policy.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

  • Email: privacy@avodahapp.com
  • Address: Avodah Software, Newcastle Upon Tyne, United Kingdom

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO).

Home Privacy Policy Terms of Service

© 2026 Avodah. All rights reserved.