Last updated September 27, 2026
Privacy
Engine holds a church's records so the church can run on them. This page says what that means in practice: what is stored, who else touches it, and what you can ask us to do about it.
Promo Engine is made by Engine. Everything on this page that says Engine covers Promo Engine, and the address at the end reaches the person who builds both.
Two kinds of people are described here
Staff and volunteers have an account. They chose to make one, they sign in, and they can see what is on it.
Members and guests do not have an account and mostly never will. A church holds records about them the way it always has, and Engine is where those records live. The one place a member touches Engine directly is a form their church has published.
The church decides what is kept and why. Engine keeps it on the church's behalf. If you are a member of a church that uses Engine and you want a record changed or removed, your church is the right place to ask, and they can do it. We will help them do it and we will not do it behind them.
What is stored
- Account. A name, an email address, and a password you never send to us in a readable form. Sign-in is handled by Supabase, and a new address is confirmed by a link sent to it before it can sign in.
- Church records. People, contact details, visits, pastoral notes, meetings, budgets and giving totals, forms and the answers people give to them. All of it entered by the church.
- What was done. Work assigned and finished, and a history of what happened. See the note on that history below, because it does not behave like the rest.
- Billing. Which plan a church is on and whether it is paid, and the ids Stripe uses for the church's customer and subscription. The card itself is typed on Stripe's page and never reaches Engine.
- A rate counter. A hashed value standing for whoever sent a request, a date and a count, kept seven days. It exists so one address cannot flood a church's form or run up an AI bill. The address itself is not stored.
There is no advertising in Engine, no tracking pixel, and nothing here is sold or shared with a data broker. Engine makes its money from churches paying for Engine.
Counting visits to these pages
The public pages of engine.church and promoengine.church count how many times they are opened. That is each site's front page, the product pages, the integrations page, the pricing page, and this page and the other two beside it. It is done with Cloudflare Web Analytics, which sets no cookie and puts nothing in your browser.
What it records is that a page was opened, which page, roughly which country the request came from, and what kind of browser and device asked. There is no identifier, so there is nothing to follow you between visits with and nothing to join up with anything else. We look at it to find out which pages a church reads before they sign up and which ones they leave from.
There is no counter anywhere inside Engine. Not on a dashboard, not on a person's record, not on a published form. Once you sign in, or once you open a form a church published, no third party is watching what you do. What happens in there is a church's own work, and a script that measures it would be a stranger reading over their shoulder.
What is stored in your browser
Engine sets no advertising cookie, no tracking cookie and no analytics cookie. What it keeps is your sign-in session and six small choices, all of them in your own browser, all of them things you did:
engine-theme, light or dark.engine-plain, whether the marketing on this site is switched off.engine-notice, that you closed the line at the bottom of this site telling you about this list.engine-nav, which groups in your sidebar are folded shut.engine-scope, which of an owner's two lists they were last reading.engine-slug, which church you signed into last.
Clearing your browser's storage for this site removes all six and signs you out. Nothing breaks; you pick your theme again.
Who else touches it
Engine is a small product and does not run its own data center. These are every company involved and what each one holds:
- Supabase
- The database and sign-in. Every church record lives here, in US East. This is the main one.
- Cloudflare
- Serves both sites and the app and runs the scheduled jobs. Sees requests in transit. Also counts visits to the public pages of the two sites, as described above, and to nothing inside Engine.
- Stripe
- Takes the church's payment. Holds the card, the owner's email address for receipts, and the church's name. No member's details ever reach it.
- Resend
- Sends email to staff: the link that confirms a new address, a password reset, an invitation, or a note that work landed on someone's list.
- Anthropic
- The assistant. What you type into it, and the church context the screen carries, are sent to answer the question. It is not used to train a model.
- Slack
- Only if an owner presses Add to Slack. Engine then sends a staff member a direct message naming work or a form. It never carries what anyone typed.
- Mailchimp, or Clearstream
- Only if an owner connects one, and only for a guest on a follow-up path the church has pointed at a list there. When a staff member ticks that step, Engine writes the guest's name and their email or mobile number into the church's own audience or list. That platform then asks the guest to confirm, under its own terms. Engine sends the guest nothing, never adds anyone who has asked the church not to contact them, and reads nothing back.
Text messaging is built into Engine and switched off. Nothing has been sent to a carrier and no phone number has left the database. When it is switched on, this page will say so and name the carrier before it happens.
What Engine will not do
- Engine sends nothing to your members. Not an email, not a text, not a notification. Everything Engine sends goes to a staff member with an account, about work on their own list. Reaching members is the church's job and Engine does not take it over. The one thing it does with a member's details outside itself is write a guest into the church's own mailing or texting list, when a staff member ticks that step, and the list's platform does the asking.
- Nothing sends, publishes or spends without a person pressing a button. This is a rule the product is built under, not a setting.
- Your church's records are not training data. Not for us, not for anyone we send them to.
Forms, and the one time a member types into Engine
A church can publish a form at an address anyone can open. What someone fills in goes to that church and to no one else. A form about a pastoral or prayer request is held under the same restriction as the rest of a church's pastoral records, which means most of the staff cannot read it.
The page says whose form it is before you fill it in, because a form that does not name the church asking is a form you cannot make a decision about.
A history that cannot be edited
Engine keeps a record of what happened: work marked done, a guest marked as connected, two records merged into one. That history cannot be changed or deleted by anyone, including the church's own owner and including us. It is deliberate. A pastoral record that can be quietly rewritten is not a record.
It follows that a request to remove a person's data removes their record and their details, and leaves entries saying that something was done on a date. Ask us and we will tell you exactly what would remain before you decide.
How long things are kept
Church records are kept while the church has an account, and the church decides what to remove before then. A church that stops paying can still read its records; nothing is deleted for not paying. If a church closes its account, tell us and we will delete what belongs to it. The rate counter is deleted after seven days automatically.
Children
A church that runs a kids program holds records about children, and Engine is where those records sit. Engine is not aimed at children, collects nothing from them directly, and never sends them anything. A parent or guardian who wants to know what a church holds should ask the church, and the church can show them.
Where things are
Data is stored in the United States. A church outside the United States should know that before signing up.
What you can ask for
You can ask what is held about you, ask for it to be corrected, ask for a copy, or ask for it to be removed. A church's staff can do the first three from inside Engine for anyone in their church, and answers to a form come out as a file any spreadsheet opens.
Write to contact@engine.church and we will answer.
When this changes
The date at the top of this page moves when the words do. Anything that changes what leaves Engine, or who sees it, is said here before it happens rather than after.