AI in the Church
AI and Data Privacy in the Small Church: What Happens to Your Members’ Information When You Use AI Tools
The data privacy question most small churches have not asked, and need to.
By Brent Lacy
A pastor sits down to prepare a response to a difficult situation in his congregation. He types the details into an AI tool: the member’s name, the situation, the history, the family dynamics. He asks for help drafting a sensitive letter. The AI produces something helpful. He edits it, sends it, and moves on.
What he did not consider: that information may now live on a server he does not control, potentially used to train future AI models, potentially accessible to people he never intended to share it with. He did not read the terms of service. Most people do not. But the terms of service are where the data privacy story actually lives.
This is not a hypothetical. It is happening in small churches every week, in churches where well-meaning pastors and volunteers are using powerful tools without understanding what those tools do with the information they receive. The consequences range from minor to serious, and the difference between those outcomes is almost entirely determined by what you type into the tool.
What AI Tools Actually Do with Your Data
The specifics vary by tool and change over time, but the general pattern is consistent: free consumer AI tools are free because your data has value to the company that built them.
ChatGPT (OpenAI): According to OpenAI’s Data Controls FAQ, the free tier of ChatGPT uses your conversations to train its models by default. You can opt out by going to Settings, then Data Controls, and turning off “Improve the model for everyone.” This setting syncs across devices. If you have not done this, your conversations, including anything you have typed about your congregation, may have been used to train the model. The ChatGPT Team plan ($30/user/month) and Enterprise plan include contractual commitments not to use your data for training.
Google Gemini: Google’s consumer AI tools have similar data practices. Conversations may be reviewed by human reviewers and used to improve Google’s AI systems. Google Workspace accounts with Gemini for Business include stronger privacy protections.
Microsoft Copilot: The free consumer version of Copilot has data practices similar to other consumer tools. Microsoft 365 Copilot, available through business subscriptions, includes enterprise-grade privacy protections and does not use your data to train foundation models.
The pattern is consistent: consumer free tiers have weaker privacy protections. Enterprise and business plans have stronger ones. For a church using AI only for general administrative content with no member-specific information, the free tier with training disabled may be sufficient. For a church that handles significant sensitive data, the investment in a business plan is worth evaluating.
What Information Should Never Enter an AI Tool
Be specific with your staff and volunteers about what is off-limits. Vague guidelines produce inconsistent behavior. Specific guidelines produce consistent behavior. Here is a concrete list that you can share directly with your team.
Member names combined with personal situations. “John Smith is going through a divorce and struggling with his faith” is not appropriate input for a consumer AI tool. Neither is “our deacon’s wife has been diagnosed with cancer.” The combination of identity and sensitive information is what creates the risk. General questions, “how should a pastor respond when a member is going through a divorce?”, are lower risk because they do not identify anyone.
Counseling notes or summaries. Even anonymized versions can be re-identified in small communities where details are distinctive. If you are summarizing a counseling situation to get AI help drafting a response, you are sharing that situation with a third party. The fact that you removed the name does not necessarily make it anonymous.
Giving records or financial information. Who gives what is among the most sensitive information a church holds. It should never enter a consumer AI tool under any circumstances. This includes aggregate information that could identify individuals in a small church context.
Personnel matters. Staff conflicts, performance issues, compensation discussions, and termination situations are confidential. They do not belong in an AI tool. This is true even if you are asking for general advice, because the specific details you provide to get useful advice are the details that create the privacy risk.
Prayer requests that identify individuals. “Please pray for our member who is battling cancer” is appropriate for a bulletin. “Sarah Jones, 47, diagnosed with stage 3 breast cancer, struggling with her faith and her marriage” is not appropriate for an AI tool. The level of detail that makes a prayer request feel personal is exactly the level of detail that creates a privacy risk.
Anything shared in confidence. If someone told you something privately, it stays private. That includes keeping it out of AI tools. The pastoral relationship is built on confidentiality. Violating that confidentiality, even accidentally, even with good intentions, damages the trust that makes pastoral ministry possible.
What Is Safe to Use AI For
The data privacy concern does not mean AI is off-limits for church use. It means you need to be thoughtful about what you put into it. These uses are generally low-risk because they involve no member-specific sensitive information.
- Drafting general communications: bulletins, announcements, event descriptions, social media posts with no member-specific information
- Sermon research: background on biblical passages, historical context, cross-references, theological summaries from different traditions
- Brainstorming: sermon series ideas, event themes, outreach approaches, volunteer appreciation ideas, small group curriculum topics
- Administrative templates: policy documents, volunteer agreements, meeting agendas, job descriptions, welcome letters for new members
- General educational content: Sunday school lesson outlines on general topics, newsletter articles about faith and life, small group discussion questions on non-sensitive topics
The pattern is consistent: AI is appropriate for general, non-personal content. It is not appropriate for anything involving specific people and their private situations. When in doubt, ask yourself: does this prompt contain information that belongs to someone else? If yes, remove it before submitting.
Practical Steps for Your Church
Step 1: Audit Your Current Practices Today
Before you write a policy, find out what is actually happening. Ask your staff and key volunteers: “What AI tools are you currently using, and what are you putting into them?” The answers may surprise you. Most people have not thought carefully about data privacy in this context, not because they are careless, but because no one has raised the question. Raise it now, before a problem occurs rather than after.
Step 2: Disable Training on All Church Accounts
For any AI tool your church uses, go into the account settings and disable model training. For ChatGPT, this is Settings, then Data Controls, then turn off “Improve the model for everyone.” This takes two minutes and should be done today. If you have multiple staff members using AI tools, make sure each of them does this on their own accounts.
Step 3: Add a Data Privacy Section to Your AI Policy
Your church AI policy should explicitly state what information may and may not be entered into AI tools. Make it specific enough that a volunteer with no technology background can follow it without having to make judgment calls. Our Church AI Policy Guide includes a data privacy section you can adapt directly. The policy should also specify which AI tools are approved for church use, not because other tools are necessarily worse, but because having a defined list makes it easier to ensure that everyone is using tools with appropriate settings.
Step 4: Train Your Staff and Volunteers
The data privacy risk in most small churches does not come from the pastor. It comes from well-meaning volunteers who do not know the rules because no one has told them. A fifteen-minute conversation at your next volunteer meeting, covering what AI tools are, what they do with data, and what is off-limits, prevents most problems. Make it concrete. Give examples. Ask if anyone has questions. The volunteer who understands why member information should not go into an AI tool will make better decisions than the volunteer who just knows the rule.
Step 5: Consider Whether a Paid Plan Is Worth It
For a church that handles significant sensitive data, a counseling ministry, a recovery program, a foster care support group, the investment in a business-tier AI plan with stronger privacy protections is worth evaluating. ChatGPT Team at $30 per user per month includes a contractual commitment not to use your data for training. For a church with two or three staff members using AI regularly, that is $60-90 per month. Whether that cost is justified depends on how much sensitive data your church handles and how much risk you are willing to accept.
A Note on Temporary Chats
ChatGPT offers a “Temporary Chat” mode that does not save conversations to your history and deletes them from OpenAI’s systems after 30 days. These chats are not used to train models. For situations where you need to discuss something sensitive but cannot avoid including some identifying details, Temporary Chat mode reduces the risk. It does not eliminate it entirely, since the conversation still passes through OpenAI’s servers, but it is a meaningful improvement over standard chat mode for sensitive content.
The better practice is still to avoid entering sensitive information at all. But if you find yourself in a situation where you need AI assistance with something that touches on sensitive territory, Temporary Chat mode is the safer option.
Related Resources on MinistryPlace
- AI Governance and the Church: What Every Small Church Needs to Know
- AI, Children, and Foster Care: What Every Ministry Worker Needs to Know About Data Privacy
- Guidelines for Ministry Work with Minors: AI and Data
- AI in the Small Church: What Every Pastor Needs to Know Before Writing a Policy
- Church AI Policy Template: Free Download and Complete Guide
Frequently Asked Questions
Is it safe to use ChatGPT for church communications?
It depends entirely on what you type into it. General writing assistance is generally low risk. Typing member names, personal situations, counseling content, or financial information is not safe. ChatGPT’s free tier uses conversations to train its models by default. Go to Settings, then Data Controls, and turn off “Improve the model for everyone” right now if you have not already done so.
What information should never go into an AI tool?
Member names combined with personal situations, counseling notes or summaries, giving records or financial information, personnel matters, prayer requests that identify individuals by name, and any information shared with you in confidence. The principle: if the information is sensitive and belongs to someone else, it does not go into a consumer AI tool.
What is the difference between consumer and enterprise AI tools for churches?
Consumer AI tools like the free tier of ChatGPT may use your conversations to train their models. Enterprise or team plans typically include contractual commitments not to use your data for training. ChatGPT Team costs $30 per user per month and includes a no-training commitment. For a church that handles significant sensitive data, the difference matters.
What should a church’s data privacy policy for AI include?
At minimum: a list of information categories that may never be entered into AI tools, a requirement that all staff and volunteers complete a brief training before using AI tools for church purposes, a designation of which AI tools are approved for church use, and a process for reporting concerns. See our free Church AI Policy Template for a ready-to-use starting point.
The Pastoral Dimension of Data Privacy
Data privacy in a church context is not just a legal or technical issue. It is a pastoral one. The information that flows through a church, the prayer requests, the counseling conversations, the giving records, the personnel matters, is information that people have shared in the context of a covenant community. They shared it because they trusted the church. Violating that trust, even accidentally, even with good intentions, is a pastoral failure, not just a policy failure.
This is why the data privacy conversation in a church context needs to be grounded in theology, not just in risk management. The question is not just “what are the legal consequences of sharing this information?” The question is “what does it mean for a covenant community to handle the information its members share in trust?” The answer to that question is more demanding than any privacy law, and it applies even in jurisdictions where churches have significant legal exemptions from data protection requirements.
A church that handles its members’ information with genuine care, that treats every piece of sensitive information as a sacred trust rather than a data point, is a church that is living out its theology. A church that handles information carelessly, that feeds member situations into AI tools without thinking about what it means to do so, is a church that is not living out its theology, regardless of whether it has technically violated any law.
Building a Data-Conscious Culture
The goal is not just a data privacy policy. It is a data-conscious culture, a culture in which every person who handles information on behalf of the church understands that they are handling something sacred and acts accordingly.
Building that culture requires more than a policy document. It requires ongoing conversation, regular reminders, and consistent modeling by leadership. Here are three practices that small churches have found effective.
The “would I say this out loud?” test. Before entering any information into an AI tool, ask: would I say this out loud in a public setting? If the answer is no, it does not go into the AI tool. This test is simple enough that volunteers can apply it without consulting a policy document.
Regular reminders at volunteer meetings. Once a quarter, spend five minutes at your volunteer meeting reminding people of the data privacy guidelines. Not as a lecture, but as a brief, practical reminder: “Just a reminder that member names and personal situations don’t go into AI tools. If you’re ever unsure, ask me.” Repetition builds culture.
Modeling by the pastor. When the pastor talks about how they use AI, they should explicitly mention what they do not put into it. “I use AI to help with the bulletin and sermon research, but I never put member information into it.” That kind of explicit modeling gives volunteers a clear picture of what the standard looks like in practice.
A data-conscious culture is not built in a single meeting. It is built over time, through consistent practice and consistent conversation. The church that invests in building that culture is the church that will handle the next AI tool, and the one after that, with the same care it handles this one.
The Stewardship Dimension of Data Privacy
Churches talk a great deal about financial stewardship. They talk much less about data stewardship, even though the information a church holds is in many ways more sensitive than its finances. A church’s financial records reveal how much people give. Its pastoral records reveal who people are, what they struggle with, what they fear, what they hope for. That information is entrusted to the church in the context of a covenant community. Stewarding it well is not just a legal obligation. It is a theological one.
The concept of stewardship in Scripture is not limited to money. It encompasses everything that has been entrusted to us. “It is required of stewards that they be found faithful” (1 Corinthians 4:2). The information your congregation shares with you has been entrusted to you. Feeding it into an AI tool without thinking carefully about what that means is not faithful stewardship. It is carelessness dressed up as efficiency.
This framing, data privacy as stewardship rather than just compliance, changes the conversation in a useful way. It moves the question from “what are we legally required to do?” to “what does faithfulness require of us?” The answer to the second question is more demanding than the answer to the first, and it applies even in jurisdictions where churches have significant legal exemptions from data protection requirements.
A church that handles its members’ information with genuine care, that treats every piece of sensitive information as a sacred trust rather than a data point, is a church that is living out its theology. That kind of faithfulness in small things, in the unglamorous work of data hygiene and privacy policy, is itself a form of ministry. It is the kind of ministry that your congregation will never see or thank you for, but that protects them in ways they will be grateful for if they ever find out how carefully you handled their information.
Build that culture of data stewardship now, before a problem forces it. The church that handles data well because it believes in faithful stewardship is in a much better position than the church that handles data well because it got caught handling it poorly.
Protect Your Congregation’s Data
The MinistryPlace Church AI Policy Template includes a complete data privacy section, plain language, ready to adapt for your church in a single board meeting.