Skip to content
Sunday Notes AI
HomeSupport
Your sermons, handled plainly

Privacy policy.

Your sermon archive lives on your device. When you ask Sunday Notes AI to process a sermon, only the material needed for that feature is sent to the named service providers below.

Last updated September 25, 2026 · Madiba Labs Limited

The short version

  • No Sunday Notes account is required.
  • Recordings, transcripts, notes, summaries, scriptures, and insight cards are stored locally on your device.
  • Provider processing requires your consent. Anonymous, content-free analytics and sanitized diagnostics are described below.
  • We do not sell personal information or use it for advertising or cross-app tracking.

Information the app handles

Sermon content

When you record or import a sermon, the app may handle audio, transcripts, detected scripture references, summaries, prayers, takeaways, insight cards, titles, speaker names, and notes. Sermon content can reveal religious beliefs or worship context.

Purchases

Apple and RevenueCat process subscriptions. Sunday Notes AI receives product identifiers, entitlement status, expiration dates, and an anonymous purchase identifier so it can unlock Pro and restore purchases.

Analytics

PostHog receives anonymous feature, onboarding, and app-lifecycle events. Separately, RevenueCat may send subscription lifecycle events such as trial starts, renewals, and cancellations to PostHog under an anonymous RevenueCat identifier. We do not send sermon audio, transcripts, notes, sermon titles, advertising identifiers, your name, or your email. PostHog discards IP-based location.

ActivationPal receives the same anonymous, content-free events to measure onboarding and subscription conversion. Its events carry a random install identifier, RevenueCat's anonymous purchase identifier, device and app details (model, OS and app version, language, time zone, App Store region), and a country and city derived from your IP address. On iOS it also reads Apple's privacy-preserving AdServices attribution token to tell whether an install came from an Apple Search Ads campaign; this does not use your advertising identifier or require tracking permission. RevenueCat sends subscription lifecycle events to ActivationPal under the same anonymous purchase identifier.

Diagnostics

Sentry receives sanitized crash and error information such as app version, device model, operating system, and non-sensitive app-area tags. We configure diagnostics to exclude sermon content, file paths, API secrets, request bodies, performance traces, session replay, and identifying user data.

Where processing happens

Our thin FastAPI service coordinates processing jobs, chooses providers, and holds provider credentials, but it does not maintain a user account or cloud sermon library. For batch transcription, the device uploads audio directly to temporary Cloudflare R2 storage using presigned multipart URLs. For live scripture detection, the device connects directly to the selected transcription provider using a short-lived grant from the backend.

  • Deepgram is the primary speech-to-text provider. OpenAI and AssemblyAI may receive sermon audio when selected by the backend or used as transcription failovers, for both batch and live processing. Deepgram or OpenAI may receive selected insight-card text when you explicitly request AI narration.
  • OpenRouter receives sermon text for scripture detection, summaries, prayers, takeaways, and insight generation. OpenRouter may route a request to the selected model provider, currently including OpenAI, Anthropic, or Google. Our backend requests OpenRouter zero-data-retention routing for sermon content.
  • Cloudflare R2 temporarily holds large audio uploads while transcription runs. The backend deletes the object after the job ends, including failure paths.
  • RevenueCat and Apple handle subscription status and purchases.
  • PostHog and ActivationPal handle anonymous, content-free app analytics and may also receive anonymous subscription lifecycle events from RevenueCat. Sentry handles sanitized diagnostics.

These providers process information under their own terms and privacy policies. They are not used by Sunday Notes AI to advertise to you.

Storage and retention

Your completed archive is stored on your device. The proxy keeps a transient processing job result only until your phone collects it, plus a 15-minute retry window; an uncollected result expires after 24 hours. Temporary R2 audio is deleted when its processing job finishes. Server logs may contain operational metadata, but are designed not to contain sermon bodies or audio.

Deleting a sermon removes its local app data and media. Deleting app data or uninstalling the app removes the local archive subject to your device and platform backup settings. Sunday Notes AI has no account-based cloud archive to delete.

After a successful trial, purchase, or restore, an expired subscription receives lapsed access: completed audio, transcripts, scriptures, summaries, insight cards, and other local features remain available. Starting new provider-backed work requires confirmed Pro access. A sermon started while Pro was confirmed may finish or resume after Pro expires.

Your choices

Before the first provider-backed feature, the app asks for consent to send audio for transcription, normally to Deepgram with OpenAI or AssemblyAI available as backend-selected failovers, and to send sermon text through OpenRouter to the selected AI provider. You can withdraw that consent under Profile → Data & Privacy; new provider processing then stops. Existing locally saved sermons remain available.

The app's analytics and diagnostic events are minimized and exclude sermon content and direct identity. Apple and RevenueCat separately process subscription status, and a configured RevenueCat integration may send anonymous subscription lifecycle events to PostHog and ActivationPal.

Permissions

  • Microphone access records sermon audio.
  • Photo-library add access saves an insight card only when you choose to export it.

The app does not need your contacts, calendar, location, advertising tracking permission, or a Sunday Notes account.

Security, children, and changes

We use reasonable technical safeguards, encrypted network connections, a server-side API proxy, and short-lived processing storage. No transmission or storage method is completely secure. Do not record material you do not have permission to record or do not want processed by the providers above.

Sunday Notes AI is not directed to children. If you believe a child provided information through the app, contact us. We may update this policy as the app changes; material revisions will receive a new date here.

Contact us

For privacy questions or requests, email hello@madibalabs.com.

Need product help?
Visit Sunday Notes AI Support.
Local first.

Your long-term sermon library is on your phone, not in a Sunday Notes account. Provider processing happens only after you agree.

© 2026 Madiba Labs Limited · Sunday Notes AI