Privacy Policy
How information is handled in the sermon archive
This notice explains what Sermon Registry collects, why it is used, which production providers support the service, and how to change your choices.
Information we collect
Sermon Registry collects information submitted through the sermon submission form and any church listing update requests. This can include sermon metadata, preacher names, church names, scripture references, tags, categories, Bible character references, takeaways, source links, YouTube URLs, and transcripts where provided.
Sermon submissions
When you submit a sermon, the information you provide is stored in the directory database. Approved submissions are published publicly and may be indexed by search engines. Submissions are reviewed before publication and may be edited, rejected, or removed at the discretion of the directory maintainer.
Published content is public
Published sermon entries and church listings are publicly accessible. Preacher names, church names, scripture references, tags, and other metadata included in published entries are visible to visitors and may be indexed by third-party search engines.
Logs and analytics
Railway application logs and Better Stack availability checks are used to operate and monitor the service. Google Analytics 4 is disabled on staging and is not loaded on the production site unless you explicitly accept analytics cookies. Analytics consent is stored for six months and can be changed at any time through Cookie Settings in the footer. Searches, transcripts, form values, email addresses, and database identifiers are not intentionally sent to Google Analytics.
Security and abuse prevention
Cloudflare Turnstile may be used on public submissions and authentication forms to distinguish legitimate use from automated abuse. Upstash Redis may be used for rate limiting. Client network addresses are validated and converted to a one-way, keyed value before rate-limit storage; raw addresses and challenge tokens are not included in application logs. Security checks may temporarily prevent a submission when the service cannot verify it safely.
Error and availability monitoring
Sentry is used for application error and performance monitoring. Request bodies, transcripts, form values, email addresses, cookies, authorisation headers, challenge tokens, and IP-related headers are removed before events are sent. Better Stack checks only public pages and health endpoints. Session replay is not used.
Accounts and transactional email
Administrative accounts are managed through Supabase. Resend may deliver transactional messages such as signup verification and password recovery through Supabase custom SMTP. These messages are not marketing email, and click/open tracking is disabled. Authentication responses are deliberately phrased so they do not confirm whether an email address has an account.
Third-party links and media
Sermon Registry links to and embeds content from external platforms such as YouTube, MapTiler, and church websites. Loading or following this content may connect your browser to those providers, which operate under their own privacy policies. Sermon Registry does not control the content or data practices of external sites.
Retention and international processing
Published directory records are retained while they remain useful to the archive. Pending and rejected submissions, moderation history, security records, and operational logs are retained only as long as reasonably needed for review, integrity, abuse prevention, and legal or operational obligations. Service providers may process data in countries outside your own jurisdiction using their contractual safeguards. You may ask for correction, removal, or more detail about retention by contacting us.
Data correction and removal requests
If you believe information published in the directory is inaccurate or should be removed, email [email protected] with details of the entry and the nature of your request.
Changes to this policy
This privacy notice may be updated as the service develops. Significant changes will be reflected on this page.
Contact
For privacy-related enquiries, email [email protected]. See also the contact page.