TL;DR: Most ChMS vendors do not clearly state whether congregant data trains their AI models, and the ones that do are the exception, not the rule. The gap between concern and governance is wide: 83% of church leaders worry about AI data privacy, yet only 5% have formal guidelines in place. Knowing what to ask, where to look in the contract, and what the answer must actually say is the practical starting point for every ministry evaluating AI features right now.
What You Need to Know About ChMS AI and Congregant Data:
Some vendors explicitly prohibit training on congregant data; others do not, and the difference lives in the contract, not the demo.
Once data enters an AI training pipeline, it cannot be extracted, making upfront contractual protection the only meaningful safeguard.
Enterprise-grade AI accounts differ from consumer-tier tools in one critical way: a binding Data Processing Agreement that prohibits training on your data.
Staff informally using free consumer AI tools with congregant data is the highest-risk scenario in most churches today.
Four contract-level questions (training prohibition, subprocessor list, deletion terms, breach liability) are the minimum evaluation framework before any AI feature goes live.
The Lausanne Movement’s proposed AITAC certification framework offers a useful self-assessment benchmark today, even before the certification body is operational.
Does your church management software vendor use congregant data to train its AI models? The direct answer is: it depends on the vendor, the product tier, and specific terms buried in your contract. According to a March 2026 Barna Group survey of 1,306 church leaders, 83% of church leaders are concerned about AI data privacy, and that concern is well-founded. Some ChMS vendors explicitly commit that congregant data never trains AI models. Others have made no such commitment. And a significant number of church staff use free consumer AI tools daily that carry no contractual protections at all. The framework below helps you tell the difference.
In this guide, we walk through what ChMS vendors’ AI terms actually say about congregant data, why the distinction between consumer-grade and enterprise-grade AI matters more than most church leaders realize, and what the contract language must say before you click “enable” on any AI feature. We draw on a March 2026 Barna Group survey of 1,306 church leaders, a June 2026 legal analysis from Ward and Smith, P.A., the Lausanne Movement’s AITAC governance paper, and a current snapshot of what the four largest ChMS AI platforms (Pushpay, ACST, Tithely, and Gloo) have actually committed to in their terms. If your ministry is in the middle of a renewal decision, evaluating a new platform, or simply trying to understand what your current vendor is doing with congregant data, this is where we start. For a wider view of the category, see our overview of what ChMS vendors are actually doing with AI in 2026.
Table of Contents
Why 83% of Church Leaders Are Right to Be Concerned
The Risk Most Ministries Miss: When Congregant Data Enters an AI Training Pipeline
What Enterprise-Grade AI Actually Means for Church Data
What the ChMS Vendor Landscape Looks Like Right Now
Four Contract-Level Questions to Ask Before You Sign or Renew
What AITAC Is, and Why It Will Change How We Evaluate Vendors
Frequently Asked Questions
Key Takeaways
Sources and References
Where We Go From Here
Why 83% of Church Leaders Are Right to Be Concerned
The concern is not abstract. The same March 2026 Barna Group study found that 83% of church leaders are concerned about AI data privacy, yet only 5% of churches have formal AI guidelines in place. That means most ministries are navigating this risk without a policy, a framework, or a clear understanding of what their vendor has actually committed to.
Barna also reports that 33% of churches are currently using AI in some part of ministry operations. Put those numbers together and the picture is clear: a substantial share of churches with no policy are already in active use. The concern is correct, the governance is not catching up, and the gap between the two is where exposure accumulates.
Church data is not generic business data. Prayer requests, giving records, attendance patterns, counseling notes, and family composition information occupy a uniquely sensitive category. The Lausanne Movement’s AITAC paper makes the point sharply: data from prayer requests “could be interpreted by some AI systems as mental health indicators.” Most church leaders never consider that when they enable AI features on their ChMS.
We say this calmly because the right response is a framework, not anxiety. The concern is legitimate. What we owe ourselves is a clear way to evaluate vendors, ask the right questions, and document the answers.
Key Point: 83% of church leaders are concerned about AI data privacy, but only 5% have formal guidelines. The gap between concern and governance is where the real risk lives.
The Risk Most Ministries Miss: When Congregant Data Enters an AI Training Pipeline
When a vendor uses your ministry’s data to train an AI model, Ward and Smith, P.A. notes in a June 2026 legal analysis, “once data enters a model’s training pipeline, it may be impossible to extract.” The practical effect of training-based data use is permanent, not reversible upon request.
It helps to say plainly what AI model training means in this context. The vendor uses examples drawn from your congregants’ data to improve or build the AI’s responses. Once that happens, the data is distributed across millions of model parameters. There is no “delete congregant Jane Smith’s data from the model” option. The information has been absorbed into the system’s underlying weights.
The Lausanne paper frames the human side of this honestly: “Churches are applying AI without the necessary level of transparency or meaningful consent from their congregants.” That framing is not accusatory toward vendors. It is honest about the gap that has opened between what congregants assume and what is actually happening with their data.
There is also a security dimension. Ward and Smith identify “model inversion and data extraction attacks” as a specific category of risk. In some cases, adversaries can reverse-engineer training data from model outputs. Congregant data embedded in a training set could theoretically be extracted by third parties later, even if the original vendor never intended that exposure.
None of this appears on a vendor demo. It appears in the terms of service, the Data Processing Agreement, and the subprocessor list. Those three documents are where the question gets answered.
Key Point: Once congregant data enters an AI training pipeline, it cannot be extracted. The protection must be contractual and in place before the data ever leaves your system.
What Enterprise-Grade AI Actually Means for Church Data
The distinction between consumer-tier and enterprise-tier AI is not a marketing label. Progressive Church Media’s April 2026 analysis documents that free consumer accounts (ChatGPT free tier, free Gemini, free Claude) may use inputs to train models, provide no Data Processing Agreements, and offer no organizational controls. Enterprise accounts contractually prohibit training on customer data, provide DPAs, offer organizational access controls, and often include audit logs.
Two tiers, in plain language:
The consumer tier covers free accounts on public AI platforms. There are no contract protections. There is no DPA. There are no organizational controls. Staff using these accounts with congregant data, even informally, is the highest-risk scenario in most churches today.
The enterprise tier covers paid business accounts (ChatGPT Team or Enterprise, Microsoft 365 Copilot with Enterprise Data Protection, Claude for Work). There is a contractual prohibition on training. A DPA is in place. Organizational controls and audit logs are part of the product.
This distinction also reaches into the ChMS layer. A ChMS that has built its AI on top of consumer-tier API access, or that uses a foundation model without contractual training prohibitions at the foundation layer, may expose church data even when the ChMS vendor itself has not explicitly said “we train on your data.” The contract chain matters, not just the headline assurance.
One regulatory point belongs here. The FTC’s updated COPPA rule, effective April 22, 2026, now treats biometric identifiers as personal information and requires separate verifiable parental consent for AI training uses, with penalties up to $53,088 per violation. Churches with children’s ministry data in their ChMS should review their COPPA posture as part of any AI evaluation.
The question to ask any ChMS vendor sounds technical, but it is the right one: “Is your AI integration governed by a Data Processing Agreement with your foundation model provider that prohibits training on our data?” If the answer is yes, ask to see the documentation. If the answer is unclear, that is itself useful information.
Key Point: “Enterprise-grade AI” means a contractual prohibition on training, a Data Processing Agreement, and organizational controls. It is not just a premium price point. Ask for the DPA documentation before enabling any AI feature.
What the ChMS Vendor Landscape Looks Like Right Now
The major established ChMS vendors (Pushpay and ACST) have made explicit public commitments that congregant data is not used to train external AI models. Gloo’s terms of service, as reported by MIT Technology Review in August 2025, reserve the right to ingest health and wellness information from prayer requests and wellness assessments. That is a meaningfully different data posture.
Here is what a current reading of stated terms and independent reporting shows. We present this as a factual snapshot, not as an endorsement or an attack on any vendor.
Pushpay. AI is built as a “query builder” that interacts with a structured semantic layer, not raw congregant information. The company has stated that member data “is strictly never utilized to train external (foundation) models.” Sequential safety, accuracy, and transparency validation checks are part of the architecture, as reported by Church Tech Today in June 2026.
ACST (Realm and Ministry Platform). Ministry Platform AI, launched May 2026, explicitly commits that “congregation data queried through Ministry Platform AI is retrieved live, securely returned, and not stored or used to train AI models.” It is built on the open MCP standard. Role-based permissions, audit trails, and table-level controls are part of the launch architecture.
Tithely (TithelyAI). Public materials claim privacy and role-based access, but no formal DPA statement was located in publicly available sources as of June 2026. The product is still in pilot or early-launch phase. Church leaders evaluating Tithely should request a written DPA directly before enabling any AI feature.
Gloo. MIT Technology Review reported in August 2025 that Gloo’s terms of service reserve the right to ingest “health and wellness information” from prayer requests and wellness assessments for its data engine. Broad data enrichment partner exceptions are also present. Binding arbitration clauses limit congregant legal recourse. This is the clearest case in the current landscape where independent reporting and the terms of service diverge from what a church leader would typically expect.
Consumer AI tools used informally by staff. The highest-risk category is not any named ChMS vendor. It is church staff using free consumer AI tools with congregant data informally, with no DPA, no controls, and no policy. This is where most churches are most exposed right now, and the issue is connected to rolling out AI to church staff in a way that preserves trust.
What this snapshot is for: it helps church leaders ask better questions, not make legal determinations. The terms shift, products evolve, and vendor documentation should always be re-read at the moment of decision.
Key Point: The vendor distinctions that matter most (training prohibitions, DPA terms, subprocessor disclosures) do not appear in demo calls. They live in the contract. Request the documentation before enabling AI features.
Four Contract-Level Questions to Ask Before You Sign or Renew
Ward and Smith, P.A.’s June 2026 legal analysis identifies four non-negotiable contract provisions that every church should verify before signing any agreement with a ChMS or AI vendor: a prohibition on training on customer data, meaningful data breach indemnities, transparency on subprocessors, and deletion and portability rights at exit.
This builds on the surface-level evaluation in the five questions we recommend church leaders raise at renewal. That companion piece surfaces the questions. The four below are about what the answers must actually say.
1. “Does your contract prohibit using our congregant data to train AI models, and is that in writing?” This is the foundational question. A verbal reassurance from a sales representative is not the same as a contractual commitment. The answer must appear in the DPA or the Terms of Service, not just in a sales conversation. If a vendor cannot point to specific contract language, the commitment is not yet real.
2. “Who are your subprocessors, and what are their data training policies?” Ward and Smith call subprocessor transparency non-negotiable because a vendor can prohibit training on their own end while passing data to a foundation model provider whose terms allow training. Ask for the full subprocessor list and ask what DPA governs each subprocessor relationship. A vendor that cannot answer this question fully has not done the work yet themselves.
3. “What happens to our congregant data if we cancel?” Church Tech Today’s June 2026 piece identifies this as a critical and frequently unanswered question. The answers you want: a defined deletion timeline (30 to 60 days is reasonable), written confirmation of deletion when it happens, and a data export mechanism so you can take your data with you. Ask for this before you need it, not after.
4. “What is your liability if our data is breached through your AI systems?” Ward and Smith describe this as a “meaningful data breach indemnity.” Many vendor contracts cap liability at a low fixed dollar amount, or at the fees you have paid, which may be a small fraction of the actual harm to congregants. Ask what the vendor is prepared to stand behind in the event of a real incident.
Key Point: Ask for the Data Processing Agreement and the subprocessor list before signing or renewing. If a vendor cannot produce both, that is itself important information about their data governance maturity.
What AITAC Is, and Why It Will Change How We Evaluate Vendors
The Lausanne Movement’s October 2025 AITAC governance paper proposes an AI Trust and Accountability Consortium modeled on the ECFA: a certification body that would independently verify whether AI vendors serving churches meet a defined standard of data stewardship, transparency, and congregant consent.
A short history helps explain why this matters. Before ECFA, churches had no independent way to evaluate a ministry’s financial stewardship. Donors had to rely on the ministry’s own representations. ECFA created a third-party standard that turned trust into something verifiable. AITAC is attempting to solve the same problem for AI: turning vendor claims about data handling into something a church leader can verify without becoming a privacy lawyer.
AITAC is not yet operational, so it cannot be used as a vendor filter today. The framework it is building, however, is already useful: clear disclosures of data collection practices, plain-language explanations of data use, meaningful consent processes for congregants. Those criteria can be applied to any vendor documentation right now, even without a certification stamp.
The forward-looking guidance is straightforward. As AITAC moves from proposal to implementation, it will likely become the standard certification that discerning church leaders look for in ChMS AI vendors. This connects to broader institutional trends explored in how denominations are beginning to address AI governance at the institutional level. Asking your current vendor whether they intend to pursue AITAC certification is a reasonable part of any future renewal conversation.
Key Point: AITAC is not yet operational, but its proposed standard (independent verification of AI data stewardship, transparency, and consent practices) is the right benchmark. Church leaders can use the AITAC framework as a self-assessment tool for vendor evaluation today.
Frequently Asked Questions
Can prayer request data be used to train AI models?
It depends entirely on the vendor’s terms and architecture. The Lausanne Movement’s AITAC paper notes that prayer request data “could be interpreted by some AI systems as mental health indicators,” a consequence most church leaders do not anticipate when enabling AI features. Whether a vendor uses that data for training is governed by their DPA and terms of service, not their marketing materials. Asking specifically about unstructured text fields (prayer notes, counseling notes) is important.
What is a Data Processing Agreement, and why does my church need one?
A Data Processing Agreement is a binding contract between your church (the data controller) and the vendor (the data processor) that specifies exactly how your congregants’ data can be used, stored, and deleted. Without one, you have only the vendor’s goodwill, not a legal obligation, governing data handling. Any ChMS vendor deploying AI features should be able to provide a DPA on request. If they cannot, treat that as a significant signal about their governance maturity.
Does my church need congregant consent before using AI features in our ChMS?
For most standard AI-assisted features (giving summaries, attendance analytics, search), congregant consent is not typically required beyond your existing privacy policy disclosures, provided the vendor is not using that data for model training. The FTC’s updated COPPA rule, effective April 22, 2026, requires separate verifiable parental consent for any AI training on data from children under 13, with penalties up to $53,088 per violation. Churches with children’s ministry data in their ChMS should review their COPPA compliance posture.
What should we do if our ChMS vendor will not answer these questions directly?
Ask in writing first, since email creates a record. If the vendor still does not provide a written response on data training and DPA availability, escalate to their data privacy officer or legal contact. If written confirmation is still not forthcoming, that response is itself meaningful information about the vendor’s governance posture. At that point, we recommend involving your church’s legal counsel before renewing or enabling AI features.
Is free ChatGPT safe to use for church communications?
Free consumer-tier accounts on any major AI platform (ChatGPT free, Gemini free, Claude free) may use inputs to improve their models, provide no DPA, and offer no organizational controls. Progressive Church Media’s April 2026 analysis is clear on this point. For drafting generic communications with no congregant data included, the risk is lower. For any task that involves member names, giving records, prayer requests, or other ministry data, consumer-tier AI tools are not appropriate. Enterprise accounts with DPAs are the minimum standard.
How do we know if our ChMS vendor’s “no training” commitment is real?
Currently, we do not have an independent way to verify these commitments, since vendor statements are self-reported. The Lausanne AITAC proposal is designed to solve this through independent certification, but it is not yet operational. The practical step today is to obtain the commitment in writing in the DPA, understand what subprocessors the vendor uses, and ask whether the vendor’s foundation model provider’s own terms prohibit training on enterprise customer data. Three layers of documentation are stronger than one.
What happens to our data if we cancel our ChMS subscription?
This depends entirely on the vendor’s terms. Church Tech Today’s June 2026 piece identifies this as one of the most important and frequently unanswered questions in ChMS evaluation. We recommend asking for a specific deletion timeline (30 to 60 days is reasonable), a written confirmation of deletion when it occurs, and a data export mechanism before you need it, not after you have decided to cancel.
What is the biggest AI data risk most churches are not thinking about?
Staff using free consumer AI tools with congregant data informally, without a policy, without a DPA, and without organizational awareness. Most of the attention in this conversation focuses on what ChMS vendors are doing, which is right and important. But the largest practical exposure for most churches right now is a staff member pasting a list of prayer requests or member contact information into a free AI tool to draft a communication. A simple, clear staff AI use policy is often the most impactful first step a church can take.
Key Takeaways
83% of church leaders are concerned about AI data privacy, but only 5% have formal AI guidelines. The governance gap is where real exposure lives, not just the technology itself.
Once congregant data enters an AI training pipeline, it cannot be extracted. The protection must be contractual and verified before any AI feature is enabled.
Consumer-tier AI tools (free ChatGPT, Gemini, Claude) are not appropriate for church data. Enterprise accounts with Data Processing Agreements are the minimum standard for any use involving congregant information.
The major established ChMS vendors have made explicit “no external training” commitments, but not every vendor has. The differences live in contracts and terms of service, not in demo calls.
Four contract-level questions every church should ask: a no-training commitment in writing, a subprocessor list with their DPAs, data deletion terms at cancellation, and breach liability provisions.
AITAC, an independent AI certification body for faith contexts, is in development and will provide a future standard for vendor evaluation. Its proposed framework is a useful self-assessment template today.
A clear staff AI use policy is often the most impactful immediate step. Informal use of consumer AI tools by staff is the highest-risk scenario for most churches right now.
Sources and References
Barna Group, “Church Leaders’ AI Usage and Concerns,” March 2026. barna.com
Ward and Smith, P.A., “The Risk Landscape: Legal, Operational, and Ethical Risks in AI Vendor Engagements,” June 2026. wardandsmith.com
Lausanne Movement, “Governing AI in God’s House” (AITAC governance paper), October 2025. lausanne.org
Progressive Church Media, “Church AI Policy: What Leaders Need to Know in 2026,” April 2026. progressivechurchmedia.com
Church Tech Today, “AI Ethics and the Church’s Most Sensitive Data,” June 8, 2026. churchtechtoday.com
BusinessWire, “ACST Launches Ministry Platform AI, Bringing Secure, Ministry-Aware AI to Churches,” May 7, 2026. businesswire.com
MIT Technology Review reporting on Gloo terms of service, August 2025. technologyreview.com
FTC Updated COPPA Rule, effective April 22, 2026 (referenced via Progressive Church Media April 2026 analysis).
Where We Go From Here
Choosing the right ChMS vendor has always required careful evaluation, but the rise of AI features has added a new layer of complexity, one that lives in contracts, subprocessor agreements, and data architecture decisions most church leaders have never had to think about before. The framework matters more than any single vendor choice: ask for the documentation, read the DPA, understand the subprocessor chain, and verify the deletion terms. The vendor that welcomes those questions is usually the vendor worth working with. For a wider read on the current landscape of AI features across church management platforms, the pillar piece is the place to start.
The evidence here points in one direction: congregant data deserves the same stewardship standard we apply to everything else the church holds in trust. The practical question most ministry leaders face now is where to start, whether that is reviewing a current vendor contract, building a staff AI use policy, or evaluating a new platform. If any of those decisions are in front of your ministry, we would be glad to think it through with you. We offer no-pressure consultations where we listen first, then share what we have learned helping ministries navigate the same questions. Schedule a consultation.



