Privacy Policy
Last updated June 2026
Epimely is pastoral-care software for churches, built and operated by Stuart Technologies. Churches use it to document the people they care for and the care they provide. Because that work involves sensitive personal and spiritual information, privacy is not a feature we added — it is how the product is built. This policy explains what we collect, how it is protected, and who can see it.
Who owns the data
The church is the owner and controller of the records it puts into Epimely. We process that data on the church's behalf, to provide and operate the service. We do not sell personal data, we do not use it to train advertising or third-party models, and we do not share it between churches. Every record belongs to exactly one church and is isolated from every other church on the platform.
What we collect
- Account information — the name, email address, and role of each staff member or volunteer a church invites, and a securely hashed password.
- People records — the members, visitors, and households a church chooses to track: names, contact details, family relationships, group membership, and milestones such as baptisms, anniversaries, and bereavements.
- Care records — care and prayer requests, visit and contact notes (including SOAP-structured and author-private notes), tasks, and follow-ups. This is the most sensitive class of data in the system and is treated accordingly.
- Imported data — records a church imports from Planning Center Online (one-way) or from a CSV file it uploads.
- Operational data — an audit log of who accessed personal information and when, plus standard technical logs needed to run and secure the service.
How it is protected — encryption at rest
Sensitive fields are encrypted in the database using AES-256-GCM, an authenticated encryption standard. We use envelope encryption: each church has its own data-encryption key, and that key is itself wrapped by a separate master key. The contents of care and prayer requests, requester email addresses and phone numbers, and intake answers are sealed this way — they are never stored as readable plain text. Because the auth tag is verified on every read, tampered ciphertext fails to decrypt rather than returning corrupted data.
Who can see what — default-deny
Most church software pours every member's life into one shared database where any staff login can read it all. Epimely works the opposite way. Signing in grants almost nothing on its own. Access to each record is decided individually — by a person's role, by whether a record is assigned to them, and by explicit, recorded access grants. Confidential requests are visible only to pastors and above and are sealed at the database, so they do not even appear in anyone else's list. Staff who triage incoming requests can see them with names, emails, and phone numbers redacted to initials. Even an administrator works day-to-day with limited scope and must step into organization-wide access deliberately, through a short, re-authenticated, fully logged window.
The audit log
Reads of personal information, reads of care notes, changes to a person's status or flags, access grants, and administrative elevations are written to a tamper-evident, hash-chained audit log. Each entry is linked to the one before it, so the record of who saw what — and when — cannot be quietly altered after the fact. A church's administrators can review this log.
Retention and deletion
We keep a church's data for as long as it maintains an account, so that pastoral history stays intact. A church can delete individual records at any time, and can ask us to delete its account and the data associated with it. When an account is closed, we delete its data on a reasonable schedule, except where we are required to retain something to meet a legal obligation. Backups are encrypted and cycle out over time.
Sub-processors
We use a small number of infrastructure providers to host and operate Epimely, and Planning Center Online when a church chooses to connect it for one-way import. We do not share personal data with advertisers or data brokers. A church that requires a formal list of sub-processors or a data-processing addendum can request one from us.
Your choices
People recorded in Epimely should direct privacy requests — to see, correct, or remove their information — to the church that holds their record, since the church owns and controls that data. We support churches in honoring those requests. If you administer a church account, you can manage your own profile, export your data, and request account deletion from within the app.
Contact
Questions about this policy or about how your church's data is handled can be sent to [email protected]. See also our Terms of Service and Security pages.