TL;DR: When a church management system activates AI features, your congregation’s records move through machine learning layers that did not exist in your contract a year ago. Vendor commitments vary widely, default settings on connected AI tools can route private member data into model training, and only 5 to 6 percent of churches have a written AI policy to govern any of it. The questions to ask before your next renewal are specific and answerable. We walk through them here.
Core Insights:
Data privacy is the top AI concern for 83 percent of church leaders, yet only 5 percent have a formal AI policy in place.
Pushpay’s Staq Data Lake (September 2026) and AI Involvement Summary (August 2026) are structural changes to how congregational data is consolidated and processed, not feature updates.
Planning Center’s MCP connector lets Claude and ChatGPT query your People database directly, and both providers train on conversations by default unless the church administrator changes a setting.
Vendor blog posts and actual terms of service are different documents, and only one of them is enforceable.
Five concrete questions, asked before renewal, change the conversation with any ChMS vendor from marketing language to verifiable commitments.
When a church management system activates AI features, whether that is natural-language people search, giving trend summaries, automated workflow routing, or a unified data lake, it processes congregational records through machine learning layers. According to the Barna and Pushpay State of Church Tech 2026 report, data privacy is the top concern for 83 percent of church leaders, yet only 5 percent have a formal AI policy. The practical questions that matter are narrow and answerable. Does the vendor use your data to train its models? Who has access when AI queries run? What happens to that data if your church cancels its subscription? The answers vary significantly by vendor, and the ones in writing matter more than the ones in marketing. This piece is a practical companion to our broader work on evaluating AI inside church management software.
Table of Contents
Why This Question Is Different Than It Was a Year Ago
What Actually Happens Inside a ChMS When AI Features Run
The Data Lake Question: What Pushpay’s Staq Transformation Means for Your Member Records
The MCP Connector Problem: When AI Talks Directly to Your Database
How to Read a Vendor’s AI Ethics Statement Without Getting Misled
Five Questions to Ask Before Your Next ChMS Renewal
Frequently Asked Questions
Key Takeaways
Sources and References
Where We Go From Here
Why This Question Is Different Than It Was a Year Ago
A year ago, the question of how a ChMS handled congregational data was largely a question of access permissions and storage. Today it is also a question of model training, conversational logs, and consolidated data architectures designed specifically to power AI. The shift is not theoretical. It is in the release notes. In the same six-month window, Planning Center launched a live Model Context Protocol connector to Claude Desktop and ChatGPT, and Pushpay publicly committed to a Staq Data Lake and an AI Involvement Summary feature inside its core platform. Both moves change what happens to member data in ways most administrators have not yet evaluated. Meanwhile, the 2025 State of AI in the Church Survey found that 61 percent of church leaders now use AI tools weekly or daily, up from 43 percent the prior year, while only 6 percent of ministries have any AI policy at all. The gap between adoption and governance has widened, not narrowed.
Key Point: The data-governance questions a church should ask its ChMS vendor have changed substantively in the last six months, because the products have changed substantively in the last six months.
What Actually Happens Inside a ChMS When AI Features Run
When a ChMS runs an AI feature on your congregational records, three things happen in sequence: the data is pulled from its existing tables, it is passed to a model for processing, and a result is returned to the requesting user. Where each of those steps occurs, and under whose terms of service, is the part that matters. Some vendors run AI fully inside their own infrastructure, with their own models, and never expose member data to an outside provider. Others route specific queries to a third-party model (often OpenAI, Anthropic, or a cloud-hosted equivalent) under a business agreement that limits how that provider can use the data. A few feature integrations send your data to a consumer-grade AI tool whose default settings include using conversations for model training. ChurchTechToday’s analysis of AI ethics in ministry data puts the practical implication plainly: if a church does not have clear guidelines about how AI can and cannot use members’ data, the church is effectively delegating that decision to whoever built the software it runs. That delegation is silent. It happens by default, not by choice. Permissions also behave differently than many administrators assume. Pushpay’s public AI ethics framework commits that AI operates within established permission structures, meaning a staff member who cannot see confidential pastoral notes in the standard ChMS view also cannot retrieve them through an AI query. That is the right architecture. It is also worth verifying for any vendor making AI features available, because it is not universally guaranteed.
Key Point: What happens to member data during an AI query depends on whose infrastructure runs the model, whose terms of service govern it, and whether the permission rules of the underlying ChMS still apply at the AI layer.
The Data Lake Question: What Pushpay’s Staq Transformation Means for Your Member Records
Pushpay’s Staq Transformation announcement on June 16, 2026 is the clearest current example of a vendor restructuring its data architecture to enable AI. The post commits to five platform deliverables in the next six months, two of which carry direct data-governance weight: the AI Involvement Summary, due August 2026, which generates an AI-written 45-second snapshot of a person’s ministry profile to replace what used to be a five-minute manual review, and the Staq Data Lake, due September 2026, which consolidates all ChMS and Giving data into a centralized repository designed to surface AI-driven insights. A data lake is, in plain language, a unified storage layer that holds many different categories of data (membership, giving, attendance, engagement, communications) in a form that AI features can query across all of them at once. That cross-category querying is the point. It is also the part that warrants policy. Pushpay’s Chief Product Officer described the current pain as administrators managing ChMS and Giving workflows separately because the systems do not behave as one. Merging them solves a real operational problem. It also changes what a single AI query can see. A query that previously could only touch giving records can, inside a data lake, touch membership and engagement records as well. The governance question is not whether the merge is good or bad. It is whether the church has documented, in policy and in writing, what queries are allowed to span which categories of member data, and who is authorized to run them. Churches that publish under a Pushpay contract have a narrow window to ask these questions before the data lake goes live in their tenant. The Pushpay roadmap is dated. The right time to ask is now, not after.
Key Point: A data lake changes what a single AI query can see across your congregational records, so the renewal conversation needs to address cross-category query governance, not just feature toggles.
The MCP Connector Problem: When AI Talks Directly to Your Database
Planning Center went live with a Model Context Protocol connector in March 2026 that allows users to link their People account to Claude Desktop or ChatGPT. The integration is real, the use cases are useful, and the data-governance footnote is worth reading carefully. Planning Center’s own release notes include the following: “By default, both Anthropic and OpenAI will train their models based on your conversations with them unless you change settings in your AI tool. In this case, your conversations could include personal and private information from your Planning Center account.” Planning Center strongly recommends disabling model training in AI tool settings. The recommendation is sound. The burden is also entirely on the church administrator to act on it. That detail matters because it inverts the usual assumption. Most church administrators believe their ChMS vendor controls what happens to member data inside the platform. With an MCP connector to a consumer AI tool, that assumption no longer holds. The vendor controls the connection, but the model behavior is governed by the AI provider’s terms of service for the specific account the administrator (or any staff member) is using. A staff member who uses a personal ChatGPT account with the connector enabled has, by default, routed every queried piece of member data through a model-training pipeline they did not configure. Access is scoped to each user’s existing Planning Center permissions, which is the right architecture. But access scope is a separate question from training-data scope. The first limits what a user can pull. The second governs what happens to what they pull after the model sees it.
Key Point: When an MCP connector links your ChMS to a consumer AI tool, the model-training default settings of the AI provider govern your member data, not your ChMS vendor’s policy, and that default needs to be changed deliberately before staff use the feature.
How to Read a Vendor’s AI Ethics Statement Without Getting Misled
Pushpay’s public commitment that member data and PII “remains within our secure partnership ecosystem” and is “strictly never utilized to train external foundation models” is detailed, clear, and pastoral in tone. It is also a blog post. The version of that commitment that protects a church is the one written into the terms of service that governs the contract, not the one written on the marketing site. The Lausanne Global Analysis piece on faith-based AI governance argues for an independent consortium-style certification for church AI ethics commitments, modeled on the Evangelical Council for Financial Accountability. The argument is practical: self-reported commitments are not auditable, and churches working through an evaluation lack the staff time to assess every vendor’s posture independently. Until such a body exists, the verification burden sits with the church. When we read a vendor’s AI ethics statement during an evaluation, we look for four things specifically. First, language about model training that distinguishes between external foundation models and internal model training, because those are different commitments. Second, language about data retention after cancellation, because portability commitments at contract end are often weaker than data-use commitments during the contract. Third, language about access logs and audit trails, because a commitment to permission scoping is meaningful only if it is verifiable after the fact. Fourth, language about subprocessors, because the vendor’s commitments only extend as far as their own infrastructure, and any third-party model provider has its own governing terms. A vendor whose commitments survive that read is one we trust further. A vendor whose strong language lives on the blog but not in the contract is one we ask better questions of.
Key Point: A vendor’s AI ethics blog post and its terms of service are two different documents, and only one of them is enforceable in a renewal conversation.
Five Questions to Ask Before Your Next ChMS Renewal
This list builds on the broader vendor-evaluation framework we covered in our piece on what to ask your ChMS vendor about AI before you renew and drills specifically into the data-governance layer. Each question is answerable in writing.
Does your platform use our member data to train any AI model, internal or external, and where is that commitment documented in the terms of service?
If we enable an MCP connector or any external AI integration, who owns the resulting conversation logs, and what is the retention policy on them?
What is your data portability and deletion commitment if we cancel, specifically for any data that has been processed through AI features or stored in a data lake?
Are your AI features governed by the same access permissions as the rest of the platform, and can you confirm that in writing rather than in a blog post?
Do you provide an audit trail showing what AI queries accessed which member records and when, and can our church administrators access that audit trail directly?
These five questions take a vendor conversation from general assurance to specific commitment. They also surface the gap, when there is one, between marketing language and contractual language. We have found that vendors with strong governance answer them clearly and in writing. Vendors without strong governance answer them generally, in conversation, and ask to follow up.
Key Point: Five specific questions, asked in writing before renewal, separate the vendors whose commitments are enforceable from the vendors whose commitments are aspirational.
Frequently Asked Questions
Does my ChMS vendor use congregational data to train AI models?
It depends on the vendor and on whether your church has activated any external AI integrations. Pushpay’s public commitment is that church data is not used to train external foundation models. Planning Center’s MCP connector, by contrast, routes data into Claude or ChatGPT, both of which train on conversations by default unless the administrator disables that setting. Ask in writing, and verify against the terms of service.
What is a data lake and why does it matter for member privacy?
A data lake is a unified storage layer that consolidates many categories of data, in a ChMS context typically membership, giving, attendance, and engagement records, into a single queryable repository. It matters for privacy because AI features running on a data lake can query across categories at once, where previously a query could only see one category. The governance question is what cross-category queries are permitted, and who is authorized to run them.
Are AI features inside a ChMS covered by the same permission rules as the rest of the platform?
They should be, and some vendors commit to this explicitly. Pushpay states that AI operates within established permission structures, so a staff member who cannot see confidential records in standard ChMS views also cannot retrieve them via AI query. This commitment is not universal, and it warrants verification with any vendor.
What should our church do before staff connect Planning Center to ChatGPT or Claude?
Before any staff member enables the Planning Center MCP connector on their AI tool, the church should establish a written policy that requires model-training to be disabled in the AI tool’s settings, restricts which staff are authorized to use the connector, and defines what categories of member data may be queried through it.
Does our church need a formal AI policy?
The data says yes. The 2025 State of AI in the Church Survey found that 73 percent of ministries have no AI policy in place while 61 percent of leaders use AI weekly or daily. That is a governance gap. A written policy does not have to be long. It does have to specify which AI tools are approved, what data may be processed by them, and who authorizes new use cases.
How do we verify that a vendor’s AI ethics statement is enforceable?
The blog post is not enforceable. The terms of service is. Ask the vendor where each specific commitment in their ethics statement appears in the contract that governs your account, and request that any commitment not yet in the contract be added as an addendum at renewal.
What about HIPAA if our church operates a counseling center?
The Lausanne Global Analysis piece notes that churches operating clinics or counseling centers may handle health data alongside spiritual care data, which can trigger HIPAA obligations. AI features that touch any health-related data require specific evaluation against HIPAA requirements, and that evaluation belongs in any vendor conversation before AI is enabled on that data.
What if our vendor’s answers are vague?
Vague answers are an answer. They indicate that the commitments live in marketing rather than in contract, and that the renewal conversation is the right time to ask for written specificity. We have not encountered a vendor genuinely committed to good data governance who declined to put the specifics in writing when asked directly.
Key Takeaways
Data privacy is the top AI concern for 83 percent of church leaders, while only 5 to 6 percent have a written AI policy, which means the governance gap is the headline issue, not the technology.
Pushpay’s Staq Data Lake (September 2026) and AI Involvement Summary (August 2026) are structural changes to how congregational data is consolidated and processed, and they warrant a renewal conversation before they go live in your tenant.
Planning Center’s MCP connector routes member data into Claude or ChatGPT, both of which train on conversations by default, and the burden to disable that setting sits entirely with the church administrator.
A vendor’s AI ethics blog post and its terms of service are two different documents, and only the latter governs what happens to your members’ data.
Five specific questions asked in writing at renewal (training, conversation log ownership, portability on cancellation, permission scoping, audit trails) move a vendor conversation from general assurance to enforceable commitment.
Permission scoping at the AI layer is the right architecture and should be verified, not assumed, with any vendor making AI features available on your ChMS.
A written AI policy does not have to be long, but it does need to specify which tools are approved, what data they may process, and who authorizes new use cases.
Sources and References
Pushpay, “What to Expect from Pushpay’s Staq Transformation,” June 16, 2026.
Barna Group and Pushpay, “How Church Leaders Are Using AI (And Their Top Concerns),” March 26, 2026.
ChurchTechToday, “AI Ethics and the Church’s Most Sensitive Data,” June 8, 2026.
Planning Center, “New: Connect Planning Center People to Claude or ChatGPT,” March 12, 2026.
Pushpay, “How Pushpay Builds Safe, Ethical, Ministry-Focused AI,” December 10, 2025.
Barna Group, “Four Trends Shaping Ministry Strategy This Year (State of the Church 2026),” June 2, 2026.
Lausanne Global Analysis, “How Safe is Your Congregants’ Data? Creating Ethical Guardrails for Faith-Based AI Applications,” October 27, 2025.
ChurchTechToday and Exponential AI NEXT, “2025 State of AI in the Church Survey Report,” October 15, 2025.
Where We Go From Here
The governance gap at the intersection of ChMS data and AI features is not a technology problem. It is a policy problem, and one that the next renewal window is the right time to close. The vendors are moving. The right move for a church is to ask the specific questions in writing before the architecture changes underneath the contract.
If your ministry is working through a ChMS renewal in the next twelve months, or evaluating whether to enable an AI feature already available in your platform, we would be glad to think it through with you. The work is reading the contract language carefully, mapping it against the questions in this piece, and helping you draft the policy your church needs to govern AI inside its own walls. We offer no-pressure consultations where we listen first, then share what we have learned helping ministries navigate the same questions.
For a fuller picture of how these questions fit into the broader landscape of AI inside church management software, our pillar piece is the place to start. You can also read our related work on the questions to ask your ChMS vendor about AI before you renew, how to roll out AI in church management software without breaking staff trust, and what the new wave of denominational AI statements means for your church technology decisions.



