Privacy Policy
Last updated 14 September 2026
Living Word translates live church services. That means audio from your service passes through our systems, so it matters that you know exactly what happens to it, what we keep, and for how long.
The short version
- We do not record or store your service audio. It is translated as it passes through and then it is gone.
- Transcripts are off by default. They are only kept if the host switches them on before a session.
- Listeners do not need an account and we do not learn who they are.
- Translated audio clips are deleted automatically within 24 hours.
- We do not sell personal information, and we do not use your services to train AI models.
Who this covers
Two different groups of people use this service, and we hold very different amounts of information about each.
Account holders are the churches and operators who run sessions. Listeners are the congregants who open a link or scan a code to follow along in their own language.
What we collect from account holders
- Your email address, and a sign-in identifier. If you use "Sign in with Google" we receive your email address from Google; we never receive your Google password.
- Names you choose for your workspace, rooms and sessions.
- Your settings — chosen languages, voice speed, interface language and similar preferences.
- Session records — when a session ran, how long, how many languages, and how many minutes of audio were processed. We need these to bill accurately and to show you your usage.
- Glossary and context you add — names, terms and any documents you upload to help the translation get your congregation's vocabulary right. Uploaded documents are parsed to suggest terms; that parsing happens on our own servers.
- Billing information — handled by Stripe. Card numbers go directly to Stripe and never reach us. We store only the Stripe customer reference and your plan status.
What we collect from listeners
Close to nothing. A listener joins with a room code and picks a language. There is no account, no sign-up, no name and no email address. Your language choice and text-size preference are stored in your own browser so the page remembers them next time; they are not sent to us as a profile.
We count how many people are connected to a room so the operator can see that the service is reaching people. That is a number, not a list.
Service audio, captions and transcripts
This is the part that matters most, so it is worth being exact.
Source audio is not recorded. Audio streams from the host's microphone or mixer, through our translation pipeline, and is discarded. We do not write it to disk and there is no archive of your services.
Transcripts are opt-in and off by default. A host must deliberately enable transcript saving before starting a session. If it is off, finished sentences are translated, delivered, and not retained. If it is on, the finished sentences are stored so the host can export them afterwards, and they stay until the host or the account deletes them.
Translated speech clips are generated so listeners can hear the translation. They are stored only long enough to be delivered and are deleted automatically within 24 hours by an infrastructure rule, not by a manual process.
Our diagnostic logs never contain what was said. They record identifiers, counts and timings only. This is enforced as a rule in the code, not left to habit.
AI providers and your service audio
Translating speech in real time requires specialist providers. While a session is live, your service audio and the text transcribed from it are sent to the providers listed below so they can be recognised, translated and spoken. This is the core of how the product works and it cannot be switched off while using it.
We use these providers under their business terms, which do not permit using your content to train their models. We do not grant anyone the right to train on your services.
Who else handles your data
| Provider | What they do | Where |
|---|---|---|
| Amazon Web Services | Hosting, databases, file storage, content delivery and sign-in (Cognito). Also the backup translation and speech engines (Bedrock, Transcribe, Polly) used when the primary provider is unavailable. | United States (us-west-2) |
| OpenAI | Primary speech recognition, translation and speech synthesis. Receives the service audio and the text transcribed from it while a session is live. | United States |
| Stripe | Subscription payments. Card details go directly to Stripe and are never received or stored by us. | United States |
| Optional "Sign in with Google" only. Used solely if an account holder chooses it. | United States |
Our systems run in the United States. If you are outside the United States, using the service means your information is processed there.
How long we keep things
- Service audio — not retained at all.
- Translated speech clips — deleted automatically within 24 hours.
- Transcripts — only if enabled, and then until you delete them or delete your account.
- Session and usage records — kept while your account is open, because they are the basis of billing.
- Account details — kept until you delete your account.
Your choices and rights
You can see and change your account information in the studio at any time, export a transcript from any session that saved one, and delete your account.
Deleting your account removes your workspaces, rooms, session records, preferences, saved transcripts and uploaded context. Your sign-in identity is retained in a deactivated state so the same address cannot be used to reach deleted data; write to us at TODO — privacy@yourdomain if you want that removed too.
Depending on where you live you may have additional rights — to access a copy of your information, to correct it, to object to certain processing, or to complain to a regulator. Write to TODO — privacy@yourdomain and we will respond.
Children
Accounts are for adults acting for a church or organisation, and we do not knowingly create accounts for children. Congregants of any age can listen to a translation without giving us any information about themselves, because listening requires no account. If a child's personal information has reached us some other way, tell us and we will delete it.
Security
Access to the studio requires a verified sign-in, each account can only reach its own data, and stored information is encrypted. No system is perfect; if we discover a breach affecting your information we will tell you and any regulator we are required to notify.
Changes to this policy
If we change how we handle your information we will update this page and the date at the top. For significant changes we will contact account holders directly rather than relying on you to notice.
Contact
TODO — legal entity name (e.g. "Living Word Software LLC")
TODO — registered business address
TODO — privacy@yourdomain