Skip to content

Acceptable use

Acceptable use policy

Churches on ChurchOS share infrastructure and a reputation. This is what may not be done with it, and what happens when it is.

Legal review required

This is a draft. It was written by the team that builds ChurchOS and has not been reviewed by a lawyer, has not taken effect, and does not yet bind anybody. It is published so that a church can see what we intend to commit to before we ask them to agree to anything.

No church is being asked to accept these terms today, because ChurchOS cannot currently take payment from anybody. Nothing here is legal advice, and a church that needs certainty should take its own.

Draft version
Draft 1
Drafted
2026-08-01
Effective date
Not in force
No version of this document has taken effect.

1.Who this applies to

This policy applies to every church using ChurchOS, everyone the church grants access to, and anyone using a website a church publishes at mychurchos.app or through ChurchOS.

It forms part of the terms of service.

2.What must not be published or stored

A church controls its own content and ChurchOS does not review it in advance. The following are not permitted regardless.

  • Anything unlawful, or that infringes somebody else's copyright, trademark or other rights — including reproducing a Bible translation or song lyrics without the licence that permits it.
  • Material that sexualises a child, or any depiction of child abuse.
  • Content that incites violence against a person or a group, or that harasses or threatens an identifiable person.
  • Deliberately false statements about an identifiable person or organisation.
  • Malware, phishing pages, or anything designed to deceive a visitor into giving up credentials or money.

3.What must not be done to the platform

These protect every other church on the same infrastructure.

  • Attempting to reach another church's data, or probing whether you can.
  • Attempting to escalate a permission you were not granted, or to use an account that is not yours.
  • Automated scraping, load testing or traffic that degrades the service for others.
  • Reselling access to ChurchOS, or operating it on behalf of an organisation that is not the church that holds the account.
  • Circumventing a rate limit, an authentication check or an audit record.

4.Congregation data

A church holds records about people who trusted the church. That trust does not transfer to every use the software makes possible.

  • Records must be used for the church's own ministry, not sold, rented or passed to a third party for their marketing.
  • Pastoral notes are for pastoral care. Using the notes feature to record something a person would be harmed by is a misuse of it, whatever the visibility setting says.
  • Bulk messaging must respect the wishes of the people receiving it.
  • ChurchOS has no children's module and must not be used as a child-safeguarding system or an authorised-pickup register.

5.Email and messaging

ChurchOS sends transactional email — address verification and similar — from its own domain, and the deliverability of that domain is shared by every church on the platform.

Using ChurchOS to send unsolicited bulk email, or messaging addresses that were not given to the church, damages that shared reputation and is not permitted.

6.Security research

A genuine vulnerability report is welcome and will not be treated as a breach of this policy. Write to hello@mychurchos.app with enough detail to reproduce the issue, give us a reasonable opportunity to fix it before publishing, and do not access, alter or retain any church's data while investigating.

Testing against your own church's account is fine. Testing against another church's is not, and the row-level security this platform rests on means a successful attempt is a serious incident rather than a curiosity.

7.Reporting a problem

Report anything on this list to hello@mychurchos.app. Say what you saw and where, and include an address if the content is on a published church site.

A report about content on a particular church's site is normally raised with that church first, unless the content is of a kind that has to be acted on immediately.

8.What happens after a report

Proportionate to what was found, and not automatic.

  • Most cases start with a conversation with the church and a request to put it right.
  • Specific content may be removed or a published site taken down where it plainly breaches this policy.
  • Access may be suspended where a church will not act, or immediately where the material is illegal or people are at risk.
  • Material depicting child abuse is removed immediately and reported to the appropriate authority.
  • A church whose access is suspended will be told why and, unless the law prevents it, will be able to obtain a copy of its data.

9.Open items this draft cannot answer

For review alongside the terms of service.

  • The jurisdiction whose reporting obligations apply, and to which authority.
  • Whether a formal notice-and-takedown procedure with a right of appeal is required.
  • Notice periods before suspension, and who inside ChurchOS may authorise an immediate one.
  • Whether a published vulnerability-disclosure safe harbour should be offered, and on what terms.

Questions about this document

Write to hello@mychurchos.app. A church evaluating ChurchOS is welcome to send this draft to its own advisers, and we would rather hear an objection now than after somebody has relied on it.