Church Media Kit Privacy Policy

Version:
August 26th, 2026
Effective Date:
August 26th, 2026

1. Scope, operator, and accountability

This Privacy Policy explains how Hekima Solutions Inc. ("Hekima," "we," "us," or "our") collects, uses, discloses, and retains personal information in connection with the Church Media Kit service (the "Service") at https://churchmediakit.com. Hekima's mailing address is 7915 152A Ave NW, Edmonton, Alberta T5C 3A1, Canada.

Hekima has designated a Privacy Officer role accountable for this Policy. Privacy inquiries, requests, and complaints should be directed to privacy@churchmediakit.com.

This Policy covers personal information Hekima collects through the Service. It does not cover a customer organization's own website, ministry activities, or communications made outside the Service, and it does not cover third-party services Customer connects except as described in Section 7.

2. Information collected directly from you

  • Account and organization information — name, email, phone, avatar, organization/church profile, and role.
  • Preferences and settings — language, timezone, posting defaults, and notification preferences.
  • Sermon source information — the YouTube video URL Customer submits and the ownership/rights attestation described in the Terms of Service.
  • Uploaded media — logos, brand assets, and other files Customer uploads.
  • Generation inputs — prompts, instructions, and settings Customer provides for a generation request.
  • Generated content — drafts, edited content, kit metadata, and design data Customer creates or edits in Studio.
  • Support communications — messages Customer sends to support@churchmediakit.com or privacy@churchmediakit.com.
  • Connected-destination choices — which social destinations Customer connects and selects for publication.

3. Information collected automatically

  • Strictly necessary session cookies issued by Supabase Auth to keep Customer signed in.
  • Request and security metadata (such as IP address, device/browser information, and request logs) processed by Cloudflare and Supabase as part of operating and securing the Service.
  • Application events, errors, and logs generated by using the Service. Essential server and background Supabase failure telemetry is sent to PostHog even when optional browser tracking is declined. It contains only fixed component, subsystem-area, request-method, runtime, HTTP-status, and status-class categories under a static anonymous service identity, with geo-IP enrichment disabled; it excludes Customer Material, account identifiers, request or response bodies, error messages, URLs, paths, queries, headers, keys, and SQL. When an authenticated Customer declines optional browser measurement, a bounded browser application-error event may still identify that Customer in PostHog using the Customer's Supabase account ID, email address, and display name so Hekima can diagnose the failure. It excludes error content and is never sent to Google Tag Manager.
  • Site analytics and advertising — Google Tag Manager loads across public and Studio pages by default unless you decline tracking or a supported browser privacy signal is present. Loading the container sends Google technical request information such as your IP address and browser information. Configured tags, including Meta Pixel, can collect page information and advertising identifiers to measure visits and advertising performance.
  • Site and Studio product measurement and replay — when PostHog is configured and tracking is enabled, bounded page categories, named Studio features, workflow actions and outcomes, and an in-memory session pseudonym. For an authenticated Customer, PostHog also receives the Customer's stable Supabase account ID, email address, and display name so product events and replays can be associated with that Customer. Product events exclude Customer Material, church identifiers, raw URLs, query strings, referrers, error messages, filenames, and page text. Session replays may show rendered page and Studio design content to help diagnose failures; they mask every input value, block file and hidden inputs, strip URL queries and fragments from replay URLs and serialized URL attributes, and exclude console logs, network headers and bodies, and canvas capture.
  • Payment status received from Stripe (see Section 4) and stored to reflect subscription state.
  • Publication attempts and provider identifiers — status, timestamps, and identifiers returned when content is sent to a connected destination.

The analytics and advertising described above runs by default before an undecided visitor chooses. You can select Essential only or turn it off in Cookie preferences. A saved decline stops optional browser analytics, advertising, product events, and replay; it does not stop the bounded authenticated browser application-error event described above. Global Privacy Control and Do Not Track stop browser measurement, including that event. Necessary storage remains active for essential service and authentication. Both runtimes cover public and Studio pages; PostHog requires its own configuration. This measurement does not authorize reuse of Customer Material for model training, evaluation, product-improvement datasets, or marketing content.

4. Information received from third parties

  • Stripe — subscription and payment status (such as active, past-due, or canceled) and transaction records. Stripe collects payment card details directly; Hekima does not receive or store full card numbers.
  • YouTube — publicly available video metadata (title, description, thumbnail) and caption/transcript data for a URL Customer submits.
  • Pexels — metadata about a photo Customer selects from stock-photo search (such as photographer credit and source URL).
  • Meta — account/destination identifiers, display names, avatar URLs, and publication status when Customer connects and uses a Meta destination.

5. Purposes for processing

Hekima processes personal information to: create and administer Customer's account; deliver the Service, including AI-assisted generation, Studio editing, export, and publication; process billing through Stripe; provide support; secure the Service and prevent fraud or abuse; comply with legal obligations; and send transactional communications necessary to operate the account. Optional product-news or marketing communications are a separate purpose that Hekima does not currently pursue (Section 14).

6. AI data flow (OpenAI)

For a generation request, Hekima sends OpenAI the sermon context, transcript excerpts, prompts, and generation settings relevant to that request, using OpenAI's Responses API configured with store: false. This configuration is intended to limit OpenAI-side persistence of the request. It is not a claim of zero data retention or that OpenAI performs no abuse-monitoring review of the request; those are OpenAI's own policies and are not eliminated by this configuration. Hekima does not use Customer Material sent to OpenAI, or received back from OpenAI, to train Hekima's own models, and does not authorize OpenAI to use it for training without OpenAI's own applicable no-training default and Hekima's separate contractual controls. Hekima does not use Customer Material for model training, evaluation, or product-improvement datasets without Customer's separate, explicit, revocable consent (see the Terms of Service, Section 4).

7. Subprocessors

Hekima uses the following subprocessors to operate the Service:

SubprocessorCategoryPurpose
SupabaseDatabase, authenticationHosts account data, sermon and generation records, file metadata, and application data; provides sign-in.
OpenAIAI processingGenerates and revises content drafts from submitted sermon material (Section 6).
StripePaymentsProcesses subscription billing and payment status.
CloudflareNetwork, private object storage, publication dispatch, observabilityStores uploaded and generated files in private R2 buckets, operates publication workers, and provides application observability with sampled logs.
MetaSocial publishing and advertising measurementReceives Customer-approved social content for publishing. Its Pixel, managed through GTM when tracking is enabled, can receive page information, advertising identifiers, and configured events for advertising measurement.
PexelsStock mediaProvides stock photo search results and licensed images.
Google Tag ManagerSite analytics and advertising tag managementLoads across public and Studio pages when tracking is enabled; receives the container request and manages configured analytics and advertising tags.
PostHogProduct measurement, session replay, and essential error monitoringReceives bounded page categories, named feature use, workflow outcomes, and an in-memory session pseudonym when optional tracking is enabled. For authenticated Customers, it also receives the stable Supabase account ID, email address, and display name to associate product events and replay. Consented replay may show rendered page and Studio design content while masking inputs, blocking file and hidden inputs, stripping URL queries/fragments from replay URLs and serialized URL attributes, and excluding console logs, network headers/bodies, and canvas capture. It also receives consent-independent, anonymous, bounded server Supabase failure categories and bounded authenticated browser application errors needed to operate and repair the Service. Browser error events contain no error content and are not sent to Google Tag Manager.

Hekima's policy is to give at least 30 days' notice of a change to this subprocessor list, subject to an urgent security replacement.

8. International processing

Hekima uses Cloudflare R2's Eastern North America location hint for application files. That hint is a best-effort placement preference, not a Canadian data-residency guarantee. Hekima and the subprocessors listed in Section 7 may process personal information outside Canada, including in the United States, as necessary to provide the Service. Cross-border processing may make information subject to access requests under the laws of the country where a provider operates. If Customer has a question about cross-border processing, contact privacy@churchmediakit.com.

9. Storage and security

By design, all files created or retained by the Service, including source uploads, account assets, generated media, and publication assets, are stored in private Cloudflare R2 buckets. Development and production use separate buckets. Direct browser uploads and provider reads use short-lived signed access; the signed URL is a temporary bearer credential and is not stored as the file record. Hekima stores an immutable object key and provider-neutral metadata in its database. Connected-destination OAuth credentials are stored encrypted. Hekima applies least-privilege access controls for staff and systems that can access Customer content. No storage or transmission method is completely risk-free, and this Policy does not claim absolute security, a specific certification, or a specific compliance badge.

10. Retention matrix

Data categoryRetention
Account, profile, and billing ledgerRetained while the account is active and during the 12-month post-cancellation read-only period (Terms of Service, Section 7).
Generation jobs, inputs, and outputs; uploads; generated mediaRetained while the account is active or read-only; database-driven retention and deletion rules remove the corresponding private R2 objects when due, subject to deletion on request (Section 11).
Publication snapshotsFull-resolution rendered publication media for 30 days after successful publication; thereafter, a lightweight history record (metadata, links, checksums, compressed thumbnail).
Connected-destination (OAuth) credentialsRetained while the connection is active; removed when the Church Media Kit account is deleted.
Routine application/product logs30 days.
Security and authentication logs90 days.
Support records24 months.
Breach and incident records24 months.
Billing, tax, and other legally required records6 years, or longer if required by law.
Backups after active deletionAn additional 35 days after active deletion completes, absent a legal hold or statutory requirement.

Retention may be extended for material subject to a documented legal hold, security investigation, or statutory retention rule.

11. Deletion and provider boundaries

Customer may request deletion in-app (Settings) or by emailing privacy@churchmediakit.com; see Data Deletion for instructions. Hekima's deletion policy commitment, being implemented as a durable, retryable process, is to complete an active-account deletion request within 30 calendar days (subject to a documented legal hold, security investigation, or other lawful exception) and to expire backup copies within an additional 35 days, removing database records, private R2 source and working objects, derived assets, credentials. Hekima does not yet operate an automated provider-deletion workflow for account-linked measurement records already sent to PostHog; those provider-held copies remain subject to PostHog's applicable retention and deletion process.

Provider-held content. Deleting your Church Media Kit account removes locally stored Meta connection credentials from Church Media Kit. It does not itself revoke authorization in Meta. It does not delete or unpublish posts already published to Meta. Church Media Kit does not currently provide a separate control to disconnect an individual Meta destination. To remove an already-published post, Customer must use Meta's own controls. See Data Deletion for step-by-step instructions.

12. Access, correction, withdrawal, and complaints

Customer may request access to, correction of, or deletion of its personal information, or withdraw a consent it has given, by emailing privacy@churchmediakit.com. Hekima's policy is to acknowledge a verifiable request within 5 business days and complete it within 30 calendar days, subject to a documented legal hold or other lawful exception. Withdrawing a consent may limit or end the corresponding functionality; it does not affect processing that already occurred lawfully before withdrawal.

If Customer is not satisfied with Hekima's response, Customer may escalate to the applicable privacy regulator, including the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca), depending on which law applies to the request.

13. Cookies

Church Media Kit uses strictly necessary session cookies and similar storage, including Supabase Auth session cookies, to keep Customer signed in and provide essential service functions. Optional analytics and advertising through Google Tag Manager and PostHog runs by default until you decline. The banner remains visible until you make a choice; a default setting is not recorded as your express acceptance. Saved declines and unavailable preference storage keep optional tracking off. Global Privacy Control and Do Not Track also stop the bounded authenticated browser application-error event.

The app stores your allow or decline preference in browser local storage and honors existing declines. PostHog stores its SDK preference marker and, for authenticated Customers, receives the Customer's stable Supabase account ID, email address, and display name. Cookies, identifiers, and collection by Google Tag Manager tags depend on the configured tags, including Meta Pixel. Google analytics storage, advertising storage, advertising user data, and advertising personalization are enabled while tracking is allowed and denied when it is declined. The app does not explicitly send Customer Material or account details into the tag data layer.

You can turn analytics and advertising off from the public footer or Studio Settings. Withdrawal reloads the current page to stop loaded tags and also applies in other open tabs. Withdrawal does not undo information already sent. Changes to measurement practices require updated disclosures and applicable privacy review.

14. Communications

Hekima sends transactional communications necessary to operate the account — such as sign-up confirmation, password reset, billing, security, and publication-status messages. Church Media Kit does not currently send marketing or newsletter email. Before Hekima enables any marketing communication, it will implement the consent, sender-identification, and unsubscribe controls Canada's Anti-Spam Legislation (CASL) requires and obtain Customer's separate consent.

15. Eligibility

The Service is offered globally to organization/church accounts whose accepting owner is at least 18 years old and authorized to act for the organization, subject to applicable law and location-specific payment or feature availability. See the Terms of Service, Section 2. Church Media Kit is not directed to children, and Customer is responsible for ensuring any personal information about a minor that appears in Customer Material is included only as necessary and with appropriate authority.

16. Business transfers and legal disclosures

Hekima may disclose personal information where required by law, subpoena, or valid legal process; to protect the rights, property, or safety of Hekima, its customers, or others; or in connection with a corporate transaction such as a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards and, where lawful, notice.

17. Customer and Hekima roles

For Customer Material Customer submits to the Service (such as sermon content, transcripts, and generated drafts), Hekima acts as a service processor on Customer's instructions, under the licence terms in the Terms of Service. For account administration, billing, security and fraud prevention, and legal compliance, Hekima determines its own purposes and means of processing. Where a customer-specific Data Processing Addendum or Security Addendum is required, it is addressed separately from this Policy.

18. Geographic scope

Church Media Kit permits account creation globally, subject to applicable law and location-specific payment or feature availability (Section 15). Rights described in this Policy may vary depending on which province, state, or country's law applies to Customer's account.

19. Policy changes

Hekima may update this Policy. Hekima maintains a version archive and will state the current version and Effective Date at the top of this document. A material change to the purposes or risks of processing will be accompanied by notice and, where the change requires it, an opportunity for Customer to provide renewed consent before the change applies, consistent with the Terms of Service, Section 13.