Legal

Privacy Policy

Last updated June 28, 2026

Shepherd is church engagement software. It connects to the tools your church already uses — Planning Center, and optionally Gmail — to help your team notice members who are drifting and follow up in time. This policy explains, in plain language, exactly what data Shepherd accesses, what it stores, and the control you have over it.

The short version

  • Shepherd never reads, searches, or sends your email. With Gmail, it only creates draft messages that your team reviews and sends.
  • From Planning Center, Shepherd reads only your member directory and check-in (attendance) records — nothing else.
  • Your church's data is isolated from every other church, and is never sold or used for advertising.
  • An admin connects Planning Center and Gmail, and you can disconnect either at any time.
  • You can ask us to delete your church's data by email.

Who this policy covers

Shepherd is used by churches. Your church — and the staff it authorizes — is the customer. Information about your members and visitors is provided by your church through its connected Planning Center account. Your church is responsible for having an appropriate basis to use that information with Shepherd and for its own commitments to its members.

Information Shepherd stores

When your church uses Shepherd, the following is stored in our database:

  • Member information synced from Planning Center: names, email addresses, member status, Planning Center identifiers, and check-in (attendance) records.
  • Engagement information Shepherd derives: visitor lifecycle (first-time, returning, established), an engagement/risk score and the reasons behind it, and follow-up status.
  • Outreach you create: AI-generated or written email/SMS drafts and a log of outreach activity.
  • Team & workspace: your church's name, staff accounts and their roles (admin, pastor, viewer), follow-up assignments, and pastoral notes.
  • Connections: the access credentials (tokens) for the Planning Center and Gmail accounts you connect, and the email address of the connected Gmail account.
  • Access requests: if you submit the “Request access” form on our site, the church name and email you enter.

Planning Center data

Shepherd connects to Planning Center only after an administrator authorizes it through Planning Center's secure sign-in (OAuth). The permission Shepherd requests is limited to People and Check-ins (the people check_ins scope).

From that, Shepherd reads members' names, email addresses, member status, and check-in / attendance records — and nothing else.

  • Shepherd's access is read-only. It cannot change or delete anything in your Planning Center account.
  • Syncing happens on demand, when your team runs it — Shepherd does not pull data continuously in the background.
  • Shepherd does not request or read other Planning Center data such as giving.

Google account & Gmail data

Connecting Gmail is optional and must be authorized by an administrator. When connected, Shepherd requests two Google permissions:

  • gmail.compose — to create email drafts in the connected Gmail account.
  • userinfo.email — to know which Gmail address is connected.

Shepherd only creates drafts. It never reads, searches, lists, or downloads your email, and it never sends email on its own. Every draft Shepherd creates lands in your Gmail Drafts folder for a person on your team to review and send. We store the connected email address and the access credentials needed to create drafts.

Shepherd's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How Shepherd uses this information

Shepherd uses the information above only to provide the service — to:

  • Score engagement and flag members who appear to be disengaging.
  • Build a prioritized outreach queue for your team.
  • Prepare outreach drafts for your team to review and send.
  • Coordinate staff follow-up (assignments, notes, status).
  • Show dashboards summarizing church health and attendance.

Shepherd does not sell your data, use it for advertising, or share it with other churches.

AI-assisted drafts and the in-app assistant

Shepherd uses a third-party AI provider, OpenRouter, to generate outreach drafts and to answer questions in the in-app assistant.

  • To generate an outreach draft, Shepherd sends the member's first name, how long it's been since they last attended, and their recent attendance count.
  • For the in-app assistant, Shepherd sends a snapshot of your members (such as names, status, attendance dates, and engagement/risk information) so it can answer your question.

This information is processed by OpenRouter to produce the response and is subject to OpenRouter's own privacy terms, which we encourage you to review. Shepherd does not use your church's data to train its own models. If no AI provider is configured, Shepherd falls back to simple, non-AI templates.

Who else processes your data

Shepherd relies on a small number of trusted providers to operate:

  • Supabase — our database and hosting provider, where the information above is stored.
  • Google — to create Gmail drafts, only if you connect Gmail.
  • Planning Center — the source your member and attendance data is synced from.
  • OpenRouter — for AI-generated drafts and assistant answers, as described above.

How your data is kept separate and secure

Each church's data is isolated. Shepherd enforces database row-level security so that staff can only ever access their own church's records — one church can never read another's. Access within your church is role-based (admin, pastor, viewer), and pastoral notes are visible only to admins and pastors.

Connection tokens are access-controlled and are never exposed to your browser or to other churches. Data is encrypted in transit (HTTPS), and our database provider encrypts data at rest. No system is perfectly secure, but we work to protect your information and limit access to it.

Keeping and deleting data

Shepherd keeps your synced and derived data for as long as your church uses Shepherd. Disconnecting Planning Center or Gmail stops future syncing and draft creation, but it does not, on its own, delete data Shepherd has already stored.

To delete your church's data, email us at shreeshkumar.lillyprabhu@gmail.com and we will process the request. Removing a staff member from a workspace ends their access but does not delete church or member data.

Your choices and control

  • An administrator can connect or disconnect Planning Center and Gmail at any time.
  • You can request deletion of your church's data by email.
  • Admins manage staff accounts and roles.
  • Because member information comes from your church, requests from individual members about their information should be directed to their church first.

Children's privacy

Shepherd is a tool for church staff and is not directed to children. Member records — which may include minors who attend the church — are provided and controlled by the church. The church is responsible for handling that information appropriately and for obtaining any permissions it needs.

Changes to this policy

We may update this policy as Shepherd evolves. When we do, we'll update the “Last updated” date above, and we'll communicate material changes to connected churches.

Contact us

Questions about this policy or your data? Email shreeshkumar.lillyprabhu@gmail.com.