What is collected
Your questions and the answers to them. Kept so your conversation is still there when you come back.
Two cookies. One holds a random token that identifies your session; the other holds which church you came in through, so your questions reach that church’s teaching. Neither holds your name, your email or an advertising identifier. Neither can be read by JavaScript or is sent to other sites, and each lasts 90 days from when it was last set — the session cookie from your first visit or your last sign-in, the church cookie from your last visit to your church’s page or your last sign-in. Signing in with Google or Microsoft also sets a third cookie that lasts only for the few minutes the sign-in takes. Separately, your browser remembers which church’s colours to show and whether you have been asked to fill in your profile; both stay on your device and are never sent to us.
Anything you volunteer about yourself. Age range, gender, race or ethnicity, which campus or service you attend, the year you started, and whether you have professed faith. Every one is optional, every one defaults to “prefer not to say”, and it cannot be stored at all without you ticking the consent box — the database physically refuses a record with no consent timestamp on it. There is no field for your name.
An email address, only if you create an account. Without one you are anonymous: your identity is the random token in your session cookie.
What you send us, if you ask for a demo. The form on our demo page emails your name, email address, church, role and message to our own inbox so that we can reply. It is not stored in Auxilium’s databases and is not added to any mailing list. Ask, and we will delete it.
What is not collected
No name is required to use Auxilium. There are no advertising trackers, no analytics pixels and no social network buttons — not Google Analytics, not anything. Auxilium loads no third-party scripts, with one exception: a sermon clip under an answer plays in YouTube’s player, and an episode with no video plays from our own storage (both below). Nothing here is sold, rented, or shared for advertising, and no profile about you is built for any purpose other than answering your questions and showing your church what its congregation is asking, as described below.
What your church can see
This is the part most people actually want to know, so it is the most specific part of this page.
Church staff can see what the congregation is asking about: how many questions came in, which topics they touched, and the questions themselves with the answers Auxilium gave — so the people who preach and care for your church know what is actually on its mind. No name is ever attached. Each person appears only as a member number, the same one for all of that person’s questions, and no screen staff can open connects that number to a person. (If you create an account, Auxilium’s own records keep your email address — and, with Google or Microsoft, your name — with it. Staff cannot see those records.)
Staff do read your words as you wrote them, though, so a question can still be recognisable from what it says. Leave out anything you would not want someone at your church to recognise.
The rest of the congregation sees less. Their shared view shows a topic only once at least three different people have asked about it, lists the passages and messages answers have been drawing on, and never shows anyone’s question. No other member can ever read what you asked.
Whose computers it passes through
Running Auxilium means passing some of what you do through a few services. They are named here rather than described as “trusted partners”.
- Anthropic. Runs the model that writes answers. Your question and the sermon passages retrieved for it are sent to be answered. Anthropic does not train models on it.
- Pinecone. Holds the searchable index of your church's teaching, and the numeric representation of a question used to search it.
- Render. Hosts the service and the databases. Your church's data lives in its own database, not a shared one.
- GitHub. Runs our nightly database backups and keeps a private copy of each for 14 days. The backups include conversations and accounts.
- Cloudflare R2. Stores documents your church's staff upload, and plays the audio of a podcast episode that has no video. Copies of the nightly backups can be kept here too — the 14 most recent.
- Sentry. Receives a technical report when something in Auxilium breaks, so we can fix it. Reports are stripped of the web request and of the values the code was working with, so your question and your details are not in them.
- YouTube. Owned by Google. When an answer includes a clip of a sermon, the clip plays in YouTube's privacy-enhanced player, which loads from Google's servers.
- Google. Sign-in, only if you choose “Continue with Google”. It happens on Google's own page — Auxilium never sees a password. Google tells us your email address and name; we tell Google nothing about you.
- Microsoft. Church staff sign in with their work account on Microsoft's own page, and Microsoft delivers the six-digit codes that let anyone sign in with just an email. No password is ever typed into Auxilium. The same service carries a demo request from our website to our own inbox.
How long it is kept
Your session cookie lasts 90 days from your first visit or your last sign-in. Conversations stay until you erase them from Your profile. Without an account, a conversation can be reached — and so erased — only from the browser that asked it, and only until that cookie expires, so erase it there first if you mean to. Volunteered demographics stay until you change or erase them. Erasing removes the records themselves rather than marking them hidden; copies in our nightly backups are replaced as newer backups are taken, and we keep only the most recent 14.
Erasing all of it
In Auxilium, open Your profile in the sidebar. It shows everything the product holds about you, lets you change any of it, and at the bottom erases the lot — profile, conversations, messages and your identity itself.
This works whether or not you ever created an account. A question you asked anonymously is still your question.
If you are in California, or elsewhere with privacy rights
You can ask what is held about you, ask for it to be corrected, and ask for it to be deleted. The profile screen above does all three immediately and without asking anyone’s permission. If you would rather someone did it for you, or you cannot reach that screen, write to the address below. We do not sell personal information or share it for cross-context behavioural advertising, and there is no such thing here to opt out of.
Children
Auxilium is built for a church’s congregation and is not directed at children under 13. If you are a parent or guardian and believe a child under 13 has used it, write to us and we will erase the record.
Changes, and how you will know
When this page changes the date at the top changes with it. Because every statement here is tied to how the software actually behaves, a change to this page means a change to the product rather than a change of mind about what we are willing to promise.
Contact
Auxilium — info@auxiliumai.app. Questions about how your own church uses what it sees are best put to your church office; questions about the software itself belong here.