Living Sermon
Privacy policy
This policy explains what personal information Living Sermon collects, why, who is responsible for it, and the choices you have. It is written to meet the Protection of Personal Information Act, 2013 (POPIA).
1. Who we are
- Responsible party / operator
- Cogniz AI (Pty) Ltd, trading as Living Sermon
- Contact
- our contact form, or hello@livingsermon.online
2. Two different roles, and why it matters
Living Sermon is used in two ways, and our responsibility for personal information is different in each.
- When a church subscribes and runs its own Living Sermon, the church decides what to collect from its congregation and why. Under POPIA the church is the responsible party for its congregation's information, and we act as its operator, processing that information only on the church's instructions and only to run the service. This mainly concerns prayer requests and questions people leave (section 4).
- For our own relationship with you as a church leader or subscriber, and for people who register interest on our own site, Cogniz AI (Pty) Ltd is the responsible party. This concerns account details, billing information and enquiry details (section 5).
3. Our approach, in short
The reading experience is built to be quiet and largely anonymous. A person can walk through a sermon, sit with a phrase, ask a question, and choose what they are carrying, all without an account, without a login, and without us building a profile of them. We collect personal information only in the few specific places below, and only what is needed.
4. Information collected through a church's Living Sermon
Prayer requests
A published walk may offer an opt-in way to ask the church's prayer team to hold something. This is only ever collected if a person chooses to send it. A request may include the message a person writes, and, only where they choose to add them and tick consent, their name and a way to be contacted. A request sent without those details carries no identity at all. Prayer requests are held privately in the leader's dashboard, are never shown on the public walk, and can be deleted by the leader at any time. They are treated as personal, and in some cases special personal information (a religious or health matter), and are handled with that care.
Questions asked of a sermon
When a person uses "Ask this sermon", their question is recorded so the leader can see what people are asking and answer what the sermon could not. Questions are not tied to a person's identity. To answer a question, the text is sent to our drafting pipeline (see section 6), which replies only from what the sermon actually said. People are asked not to include personal details in a question, and should not.
Reports about assistant answers
A person can report an assistant answer as incorrect, misleading, offensive or unsafe without leaving the app. The question, displayed answer, selected reason and any optional note are stored against that sermon and emailed to the configured Living Sermon contact for human review. Reports are anonymous; an IP address is salted and hashed only for a short-lived abuse-prevention limit and is not stored with the report.
Anonymous, aggregate counts
To help a leader see what is landing, the platform keeps simple weekly tallies: how many times a phrase was touched, and which "where are you this week" options people chose. These are counts only. They do not identify anyone, set no advertising cookies, and are not shared.
5. Information we collect for our own relationship with you
- Leader and subscriber accounts. If you approve and publish sermons, you have an account with your name, email and login. You use it to review drafts and manage your own walks.
- Church enquiries. If you register interest through our site, we keep the name, church, town, email and message you send, so we can reply and talk through setup. Registering interest is not a payment step.
- Messages sent through the contact form. We keep the name, email, church or organisation, the subject you chose and the message itself, so that a person can read it and reply. It is used for that reply and nothing else: it is not added to a mailing list and it is not shared.
- Billing information. When a subscription is taken, payment is processed by Paystack (see section 6). We do not receive or store your full card details. We keep a record of the plan, the payments made, and what is needed for invoicing and accounting.
- App preferences. Followed church IDs, the selected church, cached directory details and the most recently opened sermon are stored on the device. Living Sermon does not upload this preference list to its own servers, and the app has no congregant account.
- App notifications. If a congregant chooses to follow a church, Firebase Cloud Messaging creates and processes a Firebase installation ID and subscribes the installation to that church's notification topic. Google uses that identifier to deliver messages. Living Sermon sends to a church topic; it does not hold a list of individual devices or link the identifier to a person's name.
- Technical requests. The app and embedded website necessarily send ordinary network request information such as an IP address and user agent to the website host. The public interaction routes use only salted hashes of IP addresses in short-lived abuse-prevention limits; readable IP addresses are not stored in sermon interaction records.
6. Who else processes information (operators and processors)
We use a small number of trusted services to run the platform. Each processes information only as needed to provide its part of the service:
- Website and data hosting (WordPress on managed hosting), which stores the site and its data.
- Our drafting and answering pipeline (Make.com, using an AI model), which turns a sermon into a draft and answers "Ask this sermon" questions, grounded only in the approved material.
- Email delivery, to send review notices, the weekly summary and enquiry replies.
- App notifications (Firebase Cloud Messaging, Google).
- Payments (Paystack), which processes subscription payments.
Some of these providers may process information outside South Africa. Where that happens, we take reasonable steps so the information keeps a comparable level of protection, as POPIA requires.
7. How long we keep information
- Prayer requests are kept only as long as they are useful to the person praying, and are meant to be deleted once held. A leader can delete any request at once.
- Questions, answer reports and aggregate counts are kept to support human review and show trends over time, and can be cleared on request.
- Firebase installation IDs are retained by Google until deletion is requested through Firebase; Google states that deletion from live and backup systems can take up to 180 days.
- Enquiry details are kept while a conversation is live and for a reasonable period after, then removed. Our system keeps only the most recent enquiries.
- Account and billing records are kept for as long as the subscription is active and for as long afterwards as the law requires us to keep financial records.
8. Children's information
Living Sermon in the church setting is intended for a general adult congregation and is not aimed at children. A church that knowingly collects information about a child must have the consent of a parent or guardian, as POPIA requires. If you believe a child's information has been collected without that consent, contact us and we will remove it.
9. Your rights
Under POPIA you have the right to ask what personal information is held about you, to have it corrected or deleted, to object to its processing, and to complain. Where a church is the responsible party for the information (section 2), the quickest route is that church; we will help it respond. For information we are responsible for, contact us at our contact form (or hello@livingsermon.online). You also have the right to complain to the Information Regulator of South Africa.
10. Security
We take reasonable technical and organisational steps to protect personal information, including access controls and encrypted connections. No system is perfectly secure, but we design the platform to collect little, to keep sensitive information (such as prayer requests) out of public view, and to make it easy to delete.
11. Changes to this policy
We may update this policy as the platform changes. The date at the top shows when it was last changed. Material changes will be made clear.
12. Contact and complaints
For anything about this policy, to request access or deletion, or to exercise a right above, contact the Living Sermon privacy contact through our contact form (or hello@livingsermon.online). The Information Regulator (South Africa) can be reached at inforeg@inforegulator.org.za.