Legal

Privacy Policy

Last Updated: September 7, 2026

1. Overview

ConnectCapture helps churches capture handwritten connect cards, extract contact information through OCR, store captured card records and images, and coordinate follow-up through authorized team members.

This Privacy Policy describes the types of information ConnectCapture may process, how that information may be used, and the choices and responsibilities associated with the service.

2. Information We May Collect

Account information may include user names, email addresses, church names, roles, authentication details, and subscription or billing status. For App Store subscriptions, we receive signed transaction and renewal information, product and transaction identifiers, a church-linked purchase token, and subscription dates and status. Apple processes your App Store payment details; ConnectCapture does not receive your full payment card number from Apple.

Connect card information may include uploaded connect card images and extracted information such as names, phone numbers, email addresses, mailing addresses, visit details, prayer requests, notes, and other information a person writes on a card.

Usage and technical information may include device, browser, log, diagnostic, security, and service activity data needed to operate and protect the product.

3. How Information May Be Used

Information may be used to provide the capture, OCR, review, storage, export, follow-up, account, billing, support, security, and product improvement features of ConnectCapture.

To extract contact information, uploaded connect card images are sent to our OCR provider, OpenAI, which processes the image and returns suggested fields for review by authorized church staff. Card images are transmitted to OpenAI to perform this extraction. The iOS app asks you to confirm this before uploading for AI reading; the web upload screen identifies this processing before you upload. Only upload information you are authorized to share for this purpose.

4. Sharing and Integrations

Captured information may be visible to authorized church staff within the church account based on the permissions and workflows configured by the church.

If a church enables Planning Center integrations or another third-party system, approved contact information may be sent to that service at the church's direction.

Information may also be processed by service providers that help operate ConnectCapture. These include OpenAI (card-image text extraction), Planning Center (when a church connects it and approves a sync), Stripe (web payments and subscriptions), Apple (App Store purchases and subscription verification), Resend (transactional email), Supabase (database, authentication, and file storage), Vercel (application hosting), and Cloudflare (Turnstile bot protection). Where configured, Sentry processes error diagnostics. These providers also have their own privacy practices.

On sign-in and signup pages protected by Cloudflare Turnstile, Cloudflare processes browser and connection signals, such as your IP address, browser information, connection characteristics, and the site where the challenge appears, to detect and block automated abuse. Cloudflare also uses these signals to improve Turnstile's bot detection. See Cloudflare's Turnstile Privacy Addendum for details.

Cloudflare Turnstile Privacy Addendum

5. Church Responsibilities

Each church is responsible for its own notices, permissions, access controls, retention practices, follow-up communications, and compliance obligations for the information it collects and uploads.

Churches should review card content before sharing it internally, exporting it, or sending it to another system.

6. Data Retention

ConnectCapture may retain account data, card images, extracted fields, logs, and related records for as long as needed to provide the service, comply with obligations, resolve disputes, and protect the product.

Authorized church users can delete card data using the tools described below. Deletion removes records from the live system; provider backups may retain residual copies until their retention cycle ends. Files you previously exported or contacts you synced to Planning Center are separate copies and must be managed in those destinations.

Deleting a personal account removes the sign-in account, profile, and personal service records. Church-owned cards and images remain with the team, with uploader attribution removed, unless the sole active owner explicitly deletes the workspace too. Account access ends when the deletion request is accepted. Account and file cleanup normally finishes within 48 hours, and we send a completion email. Provider failures can delay cleanup; failed work is retried.

We retain limited deletion records, including opaque account and workspace identifiers, request/completion times, and processing status, to prevent deleted accounts or purchases from being recreated by delayed requests. App Store transaction identifiers and subscription history may also be retained for purchase verification and abuse prevention after their workspace link is removed. These records do not retain the deleted profile name or contact-card content. The deletion contact email is cleared after the completion notice is sent.

Retention periods may otherwise vary based on account settings, legal obligations, operational needs, and church requests.

7. Security

ConnectCapture uses account authentication, church-scoped access controls, and restricted access to stored card images. Service providers also apply safeguards to information they process.

No online service can guarantee absolute security. Churches should limit access to authorized team members and use strong account security practices.

8. Choices and Requests

Active church members can review and correct card information. The owner can export the church's cards. Owners and authorized administrators can permanently delete an individual card and image; the owner can delete all church card data from the web account settings.

In the iOS app, open Settings → Delete account to request permanent account deletion. An owner with other active teammates transfers ownership before leaving. An owner who is the only active member can explicitly delete the account and workspace together. Apple subscriptions must be canceled separately in Apple subscription settings; account deletion does not cancel Apple billing.

Requests from individuals whose information appears on a connect card are handled by the church that collected the information, using the deletion tools above; ConnectCapture can also assist on request via the contact below.

9. Children's Information

Churches should avoid uploading information from children unless they have the rights, notices, and permissions required for their ministry context and applicable law.

Churches are responsible for determining whether additional consent, notice, retention, or access controls apply to information involving children or students.

10. Contact

For privacy questions or help with a deletion request, email hello@connectcapture.com. For requests about information written on a connect card, contact the church that collected it; we can help direct the request.

Email ConnectCapture

Support and account help