Privacy Policy
What we collect, why, how long we keep it, and how we delete it — in plain language.
The question we get most
Sermon audio and captions are not stored on our servers. Audio flows from the operator's PC straight to the engine; captions vanish once delivered. See the Data Handling page
1. If you sign up or contact us
Information we receive when a church or organization signs up or contacts us.
| Organization, contact name, email, phone, region | Account identity and contact |
| Password | Never stored in plain text — only as an irreversible hash (scrypt) |
| Google account ID | Only if you use Google sign-in. We never receive your Google password |
| Your inquiry text | To reply and keep context. We never overwrite it later |
| Notes (title, role, preferred channel, availability) | So we don't start over when your volunteer changes |
| Payment records (amount, time, plan) | Billing, receipts, refunds. We never receive or store card numbers — Stripe handles payment directly |
2. If you view captions
- ·We collect no name, phone, or email. No login is required.
- ·One thing only: a random string stored in your phone's browser. It identifies no one — it exists so a refresh isn't counted twice. Deleted after 90 days. If your browser blocks storage, we don't count at all.
3. Audio and captions
- ·Audio never passes through our servers. It streams from the operator's browser straight to the interpretation engine, and is not stored.
- ·Captions are not stored by default. They pass through server memory to reach phones and screens, then are gone. The one exception: when the organizer turns on 'Record sermon' in the console, finalized captions are stored and used only to keep that organization's own spellings (names, program titles) consistent next time. Deleted after 90 days. Visible only to that organization and our staff.
- ·When interpretation misbehaves and auto-recovers, we log only the diagnostic numbers (repeat count, detected language code). No caption text is recorded.
- ·See our Data Handling page for details — written so you can hand it to your church board as is.
4. How we use it
- ·Providing the service — accounts, sessions, access codes
- ·Billing, payment, and refunds
- ·Replying to you and technical support
- ·Finding and preventing failures — so a dropout gets fixed before next Sunday
- ·Service notices — renewal, remaining hours, how-to
- ·We do not sell your information, nor share it with third parties for advertising.
5. Third-party services we use
We rely on the following. Each provider's own policy also applies.
| Google (Gemini API) | Live interpretation. Audio passes through and is gone |
| Google Analytics · Ads | Site analytics and ad performance. No names, emails, or phone numbers are sent |
| Google sign-in | Account identifier and email |
| Stripe | Payments. Only Stripe sees card numbers |
| Resend | Sending email |
| Twilio | Text messages — only to those who opted in |
| Neon · Fly.io | Database and server hosting |
6. Where it is stored
- ·Our servers and database are in the United States. If you use the service from Korea or elsewhere, your information is transferred to and processed in the US.
7. How long we keep it
| Account information | Until you delete your account |
| Payment records | As required by tax and accounting law |
| Usage records | Kept after contract end for billing verification |
| Inquiries and notes | 3 years from last contact |
| Caption view counts | Auto-deleted after 90 days |
| Recorded captions (opt-in only) | Auto-deleted after 90 days · learned spellings until the organization removes them |
| Incident logs | 1 year |
| Message history | Sent: 3 years · Blocked: 180 days |
8. Your right to deletion
- ·Email us and we'll take care of it after verification. Here is exactly what we do.
- ·We erase everything that identifies a person — name, email, phone, notes. The transaction facts remain (when a contract ran, what was paid): tax law requires it, and without them neither of us could verify anything later. After erasure, those records can no longer be tied to you.
- ·California residents have the right to know what we hold, to request deletion, and to request correction. We will never treat you differently for exercising these rights.
9. Opting out
- ·Email — use the unsubscribe link, or just reply to us
- ·Text — reply `STOP` and it stops immediately
- ·Essential service notices (outages, billing, renewal) may still be sent.
10. Children
- ·We do not direct our service to children and do not collect information from them. The caption view opens with no login and no personal information, so even if a viewer is a child, we learn nothing about them.
11. How we protect it
- ·All traffic is encrypted (HTTPS).
- ·Passwords are stored only as irreversible hashes.
- ·Operator sign-in links are stored only as hashes and are single-use.
- ·Admin screens are restricted to our own accounts, and changes are logged.
- ·That said, no method of transmission or storage is perfectly secure. We protect your data reasonably, but cannot guarantee absolute security.
12. Changes to this policy
- ·We post changes here with a new effective date. Material changes are also emailed to account holders.
Contact
Send any privacy request to:
ok@sotonis.com
SORiGiO
Effective 2026-09-01





