Data Processing Agreement
For business and church customers who need a written data processing agreement with Verse Copilot
Last updated: August 31, 2026
This Data Processing Agreement ("DPA") is part of the Terms of Service between Verse Copilot LLC, an Indiana limited liability company ("Verse Copilot," "we," "us"), and the customer organization that signs it ("Customer," "you"). If this DPA and the Terms of Service conflict on the handling of personal information, this DPA controls; on everything else, the Terms of Service control. To request a signed copy, email support@versecopilot.net.
1. Definitions and roles
"Customer Content" means the presentations, slides, song lyrics, sermon notes, images, scans, service audio, transcripts, and other content you create, upload, or record through the Service.
"Personal Information" means information that identifies, relates to, or could reasonably be linked with an identifiable person, as defined by the privacy laws that apply to you.
"Sub-processor" means a third party we engage to process Personal Information in order to provide the Service.
Roles. The two of us handle two different kinds of information differently, and this DPA says so plainly rather than using one label for both:
- For Customer Content, we act on your instructions. You decide what to record, what to scan, and what to put on screen. We process it to give you the result you asked for. In the language of privacy law, you are the controller (or "business") and we are the processor (or "service provider").
- For account, billing, security, and product-usage information, we act for ourselves. We decide to keep an account record, to bill you, to detect abuse, and to measure which features are used so we can improve the product. For that information we are the controller, and our Privacy Policy describes what we do.
2. Subject matter and duration
We process Personal Information for as long as your subscription is active, plus the wind-down periods described in §10 and in Terms of Service §§7 and 9. This DPA lasts as long as we process Personal Information for you.
3. Nature and purpose of processing
We process Customer Content only to:
- provide the features you use — putting scripture and slides on screen, recognizing scripture from live audio, turning notes and scans into slides, and syncing between your devices;
- keep the Service secure and working, including diagnosing failures;
- support you when you ask for help; and
- comply with the law.
What we do not do, per Terms of Service §7: we do not sell Customer Content, do not use it for advertising, do not make it public, do not use it to identify people by their voice, and do not create devotionals, clips, books, or similar products from it.
4. Types of personal data and data subjects
Data subjects: your staff and volunteers who hold accounts; the pastors, worship leaders, guests, and members of your congregation whose voices may be captured when you turn the microphone on; people named in notes or documents you scan.
Categories of Personal Information:
| Category | Examples |
|---|---|
| Account and identity | name, email address, sign-in method, role, which computers are on your account |
| Billing | plan, billing contact, transaction history. Card numbers go to our payment processor, not to us |
| Service audio and transcripts | recorded service audio, its transcript, and the log of what the app detected |
| Content you create or upload | slides, song lyrics, sermon notes, images, scans of bulletins and handwritten notes |
| Product usage | which features were used, app version, device and screen information, error and crash reports, and the scripture reference and translation shown on screen. Attributed to your organization; we do not send an individual user identifier |
| Support | your messages to us and our replies |
| Church location | your church's approximate location — city, state, ZIP, country, and map coordinates — worked out at account setup from the internet address you connected from, your church's name, and (if you gave us one) your church's website. We keep the result, not the internet address |
| Trial anti-abuse signals | to prevent repeated free trials and bulk or automated sign-ups: the account email and its domain, the church's name and general area, a scrambled (hashed) form of the network subnet a connection came from (not the IP address itself), a scrambled per-computer identifier, and — if one is on the account — a hashed phone number and its line type. Kept for the life of the account and deleted when the account is deleted |
Sensitive information. Worship-service audio and sermon transcripts can reveal religious beliefs, and may contain prayer requests or other personal matters. Several state privacy laws treat that as sensitive. We handle it accordingly: it is stored privately, is never sold, is never used for advertising, and is never used to identify anyone by their voice.
5. Our obligations as processor
We will:
- process Customer Content only for the purposes in §3 and on your documented instructions — your use of the Service is an instruction;
- tell you if we believe an instruction requires us to break the law;
- require our staff who can access Customer Content to be bound by confidentiality;
- limit access to Customer Content to the staff who need it to run and support the Service;
- maintain the security measures in §8;
- assist you, at your cost where the assistance is substantial, in responding to the requests of the people described in §4 and in meeting your own security, breach-notification, and assessment obligations; and
- delete or return Customer Content as described in §10.
6. Sub-processors
You authorize us to use the sub-processors listed in the Sub-processor Annex to this DPA.
Before we add a new sub-processor that processes Customer Content, we will give you at least 30 days' notice by email to your account's billing contact. If you reasonably object to a new sub-processor on data-protection grounds, tell us within that window and we'll work with you to find an alternative. If we can't, you may cancel the affected part of the Service and we'll refund any prepaid, unused fees for it. This refund applies despite anything to the contrary in the Terms of Service.
We remain responsible to you for our sub-processors' performance of these obligations.
7. Rights of individuals
If someone asks you for access to, correction of, or deletion of their Personal Information, and it sits in our systems, we'll help you respond. You can reach us at support@versecopilot.net. If someone contacts us directly about information we process for you, we will refer them to you rather than acting on it ourselves, unless the law requires otherwise.
8. Security measures
We maintain the following measures:
- Encryption in transit — connections to our services use TLS.
- Encryption at rest — Customer Content stored in our cloud storage and databases is encrypted at rest by the cloud platform.
- Private storage — service recordings are stored in a private, non-public cloud storage bucket; access is limited to administrators and is granted through time-limited signed links.
- Access control — administrative access is limited to named personnel and requires multi-factor authentication.
- Payment isolation — we never receive or store full payment card numbers; our payment processor handles them.
- No voice identification — we do not build voiceprints, voice embeddings, or speaker-identification systems (Terms of Service §9).
- Logging — we keep operational logs and do not log the text of scripture, sermons, lyrics, or transcripts in them.
9. Breach notification
If we become aware of a security breach that compromises Customer Content, we will notify you without undue delay and in any event within 72 hours of confirming it. Our notice will describe what we know, what we are doing about it, and what we recommend you do. We'll keep you updated as we learn more.
10. Return and deletion of data
When your subscription ends, you can export the content you created through the app. After that:
- Content stored on your own computers stays on your computers; we never touch it.
- Content on our servers is deleted as described in Terms of Service §§7 and 9 — the operational license ends when you delete content or your account closes.
- Service recordings associated with your account are kept for as long as your account is active, and you can have them deleted sooner at any time by emailing support@versecopilot.net from your account owner's address. We confirm the number of recorded sessions and the dates with you before deleting, and confirm again when it's done. Deletion is permanent.
- Our free-trial fraud-prevention record (the "Trial anti-abuse signals" category in §4) is kept as security history for the life of the account and is deleted when the account is deleted. It holds only scrambled identifiers plus the church name, email, general area, and the check result.
- We may keep information the law requires us to keep, such as billing and tax records, and copies in backups until those backups age out on their normal cycle.
11. Audit
On request, no more than once a year, we will provide the information reasonably needed to show we are meeting this DPA — including a written description of our security measures and answers to a reasonable security questionnaire.
12. International transfers
The Service is operated from the United States and Customer Content is stored and processed in the United States. This DPA is offered for customers in the United States. If you are subject to the GDPR or UK GDPR, contact us before signing — we will need to agree the appropriate transfer mechanism and additional terms first.
13. Term and termination
This DPA takes effect when signed and ends when we stop processing Personal Information for you, after which §10 applies.
14. Contact and signature
Questions or requests under this DPA: support@versecopilot.net.
Verse Copilot LLC · [signature block] · Customer · [signature block]
Sub-processor Annex
The companies below process content you put into the product, on our behalf, so we can run the Service. Each entry lists what the company does for us and what it receives.
| Sub-processor | What it does for us | What it receives | Where it runs |
|---|---|---|---|
| Google LLC — Google Cloud Platform and Firebase (Cloud Run, Cloud Storage, Firestore, BigQuery, Firebase Authentication) | Hosts our servers, stores your account and content, stores service recordings, handles sign-in, and holds product-usage data | Account data, sign-in identity (including Sign in with Google / Sign in with Apple), all content stored on our servers including recordings and transcripts, product-usage events | United States |
| Soniox, Inc. — speech recognition | Converts live service audio into text in real time so the app can follow along | Raw service audio, plus a fixed list of Bible book names sent to improve recognition. No church, user, or session identifier is sent | United States |
| xAI Corp. — Grok models | Resolves ambiguous spoken scripture references, and designs slides from sermon notes | Rolling transcript excerpts (roughly the last 30 seconds, and up to about 2 minutes for ambiguous references); sermon-note text submitted to the slide feature | United States |
| Google LLC — Gemini Developer API (separate terms from Google Cloud above) | Reads photos of bulletins and handwritten sermon notes, and helps split song lyrics into slides | Photographs and scans you take in the companion app; song lyric text | United States |
| OpenAI, L.L.C. | Backup provider for the slide-design feature when the primary is unavailable; powers our in-product support chat | Sermon-note text; support-chat messages | United States |
| American Bible Society — API.Bible | Supplies licensed scripture text, and receives the licence-compliance usage reporting their terms require | Scripture references only (book, chapter, verse, translation), sent server-to-server; and, when a licensed translation is displayed, a record of the passage shown plus a persistent per-installation device identifier and a per-launch session identifier | United States |
| ipwhois.io — ipwho.is IP geolocation | Turns the internet address your computer connects from into an approximate city-level location, once, when your church's account is set up | The IP address of that connection, and nothing else. No account, church, or user identifier is sent. We store the approximate location it returns, not the IP address | Global |
| Google LLC — Google Maps Platform (Places API) | Finds your church's published address so the approximate location above can be made accurate | Your church's name and the approximate area from the step above | United States |
| Stripe, Inc. | Processes payments and subscriptions | Billing contact, plan, and transaction data. Card details go directly to Stripe — we never receive or store the full card number | United States |
| Resend — email delivery | Sends account, invitation, verification, and receipt emails | Recipient email address and the content of that email | United States |
| Cloudflare, Inc. — Turnstile | Checks that sign-in, comment, and chat requests come from a real person, not a bot | IP address and browser signals at the moment of the check | Global |
| Google LLC — Perspective API | Screens support-chat messages for abusive content | The text of the message being screened | United States |
| Functional Software, Inc. (Sentry) | Collects backend error reports so we can fix failures | Error details and stack traces, which can incidentally include request context | United States |
Website visitors. versecopilot.net uses no advertising, session-recording, or cross-site tracking providers. Visits are counted with Cloudflare Web Analytics, which is cookieless and receives no Customer Content and no visitor identifier. Nothing of the kind is present in the desktop or mobile apps. See our Cookie Policy.