By Michael Lattis
Church leaders and staff are called to wisely administer the resources God has given them.
Stewardship, however, extends beyond managing finances. It also includes protecting information.
Caring for congregants’ personal and sensitive data is a sacred responsibility that reflects the trust members place in their church. Discretion helps safeguard not only the church but also the individuals, families, and information entrusted to its care.
As artificial intelligence (AI) becomes increasingly integrated into church operations, protecting that trust is more important than ever. Churches might use AI to assist with administration, communications, donor engagement, research, content creation, and ministry support. Whether motivated by limited staff capacity, budget constraints, or the growing visibility of AI tools, many churches are exploring how technology can help them work more efficiently.
As churches embrace these tools, leaders must balance innovation with their responsibility to protect confidential information and preserve the trust of congregants, donors, employees, and ministry partners.
Why privacy matters in churches
Churches often collect the same types of information as other organizations, including names, addresses, phone numbers, email addresses, or payment information. However, some congregants speak to pastors and deacons about deeply personal and sensitive information that might not be shared elsewhere.
In face-to-face or phone discussions with their pastors or deacons, members might discuss personal prayer requests, which can cover marital struggles, health concerns, financial hardships, counseling issues, or other confidential matters as part of their spiritual lives. This information is shared with an expectation of compassion and confidentiality and is not meant to be digitally recorded and input into AI for any reason. If a pastor or deacon is not a licensed counselor, counseling should be done on a short-term basis and then referred to a professional clinician.
Understanding how AI uses data
AI systems rely on data to generate responses. When users enter information into an AI platform, that information might be processed, stored, retained or used to train public AI models, depending on the provider’s policies.
Because many misconceptions exist about AI and privacy, church leaders should understand several common myths.
Myth #1: “If I delete a chat, the information disappears.”
Reality: According to Church & Tax Law, deleting a conversation typically removes it from your view, but it might not be immediately erased from the provider’s systems. Depending on the platform, information might remain in backup systems, security logs, or retention environments for a period before permanent deletion occurs.
Some business and enterprise platforms also maintain records for compliance, security or auditing purposes. In certain cases, data might be retained after personal identifiers have been removed. Understanding a provider’s retention and deletion policies is essential before sharing sensitive information.
Myth #2: “Free AI tools are just as secure as business platforms, which charge subscription fees.”
Reality: Security and privacy protections vary between vendors and service tiers, but free AI platforms are usually much less secure than paid platforms or service tiers. Many enterprise and business AI tools provide stronger privacy controls, administrative oversight and safeguards that help prevent customer data from being used to train free, publicly available AI models. Church and Tax Law suggests they might also offer access controls, dedicated security features and data processing agreements (contractual assurances regarding how church data is stored, accessed, protected and deleted). When evaluating AI solutions, church leaders should carefully review privacy practices and security controls rather than assuming all platforms offer the same protections.
Myth #3: “AI-generated content is always private.”
Reality: Privacy depends on the platform and its policies. Content created within an AI system might be subject to storage, retention, monitoring, and security practices established by the provider. Before using any AI solution, churches should understand how data is collected, used, stored and protected.
The 6 biggest AI privacy risks facing churches
AI can provide significant benefits, but churches should recognize and mitigate potential risks before expanding its use.
#1: Exposure of confidential congregant information
Churches staff might have access to congregants’ job or emergency contact data, and pastors are exposed to prayer requests, member support needs and crisis information, among other private matters.
#2: Disclosure of personally identifiable information
Names, addresses, phone numbers, email addresses, medical information, volunteer records, and information regarding children should be carefully protected to avoid privacy concerns and legal ramifications.
#3: Exposure of financial and donor information
Mishandling contribution records, banking information, budget documents, and donor histories can compromise both trust and financial security.
#4: Unauthorized access
Weak passwords, shared accounts, inadequate permissions, and lack of governance can allow unauthorized individuals to gain access to sensitive systems and information. Access should be restricted to those who genuinely need it to perform their responsibilities.
The proper business AI tool will keep your data from being shared outside your organization, but your church’s authorized users might be able to access any information you feed into the platform. So, be strategic and sparing about which private information you share on your business AI platform.1
#5: Exposure of personnel and security information
Human resources records, payroll information, background checks, facility security plans, and internal operational data require heightened protection and oversight.1
#6: Reputational damage
Even a single privacy incident can damage confidence in church leadership. Members who believe their information is not protected might be reluctant to share personal concerns, participate in ministry activities, or make future financial contributions.
Choosing AI tools wisely
Not all AI tools are created equal. Churches should evaluate business, enterprise or team solutions carefully before adoption. Features worth considering include:
• Clear privacy and security policies
• Data processing agreements
• Administrative controls and user permissions
• Support for data deletion requests
• Security certifications such as SOC 2 or ISO 270011
• Measures that limit the use of customer data to train public AI models
Before selecting an AI provider, consider asking the following questions:
• How is information stored and protected?
• Who can access our data?
• Do you provide a non-profit discount for churches using your business, team or enterprise platform?
Warning signs include vague privacy policies, limited transparency, lack of customer support, inadequate security information, and minimal administrative controls.1
Church staff should never enter any confidential or personally identifiable information, donor records, personnel data, counseling notes, or any other sensitive content into public AI platforms. Instead, free tools can be reserved for lower-risk activities such as general research, brainstorming, social media ideas, graphic design assistance, or editing publicly available content.
Better yet, consider using business or team AI platforms for all your church AI needs if possible. Fortunately, most major AI providers provide discounted pricing for nonprofits, so cost might not be prohibitive for most churches.
Creating an AI privacy policy for your church
One of the most effective ways to use AI responsibly is to establish a formal AI policy that guides staff, volunteers, and ministry leaders. A well-designed policy should address:
• Approved AI applications and use cases
• Information that should never be entered into AI systems
• Staff and volunteer training requirements
• Procedures for reviewing and fact-checking AI-generated content
• Password, access, and device security standards
• Roles and responsibilities for policy oversight
• Authorization requirements for AI use
• Regular review and update procedures1
Policies should be regularly communicated throughout the organization since AI technology continues to evolve rapidly.
Technology should strengthen ministry, not compromise the congregation’s confidence in their church. By exercising discretion, establishing clear policies, choosing AI platforms wisely, and maintaining strong privacy practices, churches can benefit from AI while preserving the trust that is essential to effective ministry.
1AI Privacy Checklist for Churches (2026) | AlignedAI
Michael Lattis has served as MMBB’s Director of Data & Analytics since 2015. With more than 25 years of experience with MMBB, his prior roles include Digital Application & Web Development Manager and a variety of positions spanning marketing technology and graphic design. Lattis earned a Bachelor of Science in Studio Art from New York University and an MBA from Columbia Business School.
