PewHQ

Privacy policy

Last updated August 16, 2026.

Who holds your information, and who to ask

PewHQ is software churches use to run their congregations. That means there are two different relationships on this page, and it matters which one you’re in:

What we collect

Information a church puts into PewHQ, which typically includes:

Information we collect to run the service: your account details via our sign-in provider, and ordinary server logs (IP address, browser, pages requested) used to keep the service working and secure.

We do not receive card numbers or bank details. Those go directly to Stripe. We see only what Stripe tells us — that a gift succeeded, for how much, and the last four digits.

What we do with it

We use it to provide the service to your church: showing you your data, sending the messages you ask us to send, producing your statements and reports, taking payment, and supporting you when you ask for help.

We do not sell your data. We do not rent it, share it for advertising, or build profiles of your members. We do not use one church’s data to benefit another, and we do not train any model on your congregation’s data.

To be precise about the limit of that promise: it covers what we do. Where a feature sends data to xAI (see below), what xAI may do with it is governed by their terms, not ours.

Our staff do not browse church data. Access happens when you ask us for support, or when we have to investigate a fault — and sensitive actions are written to an activity log your administrators can read.

Artificial intelligence

Some features send data to xAI to generate text. The most important one to know about: when you use Ask your data, up to fifty rows of your actual results — which can include names and giving amounts — are sent so the answer can be phrased in a sentence. Importing a spreadsheet sends your column headings and a few example values. The full detail, feature by feature, is on our security page.

AI never writes to your database and never moves money. If your church would rather no data reached an AI provider at all, contact us.

Who else processes your data

We use these companies to run PewHQ. Each handles only what its job requires:

We’ll update this list when it changes. Beyond these, we disclose data only when the law requires it, and we’ll tell the affected church unless we’re forbidden from doing so.

Where it’s held and how long

Your data is stored in AWS US East (N. Virginia) and is encrypted in transit and at rest. We can restore the database to any point within the last 24 hours; beyond that window there is no older copy to recover from, which is why we encourage churches to take their own exports.

We keep your data for as long as your church has an account. When a church removes a person, that person is hidden everywhere but their giving and attendance history is kept, because those are the church’s financial records — a church can ask us to erase a record outright. When a church closes its account, tell us and we’ll delete its data; otherwise we remove it within 90 days, and you can export everything before you go.

Children

PewHQ is used by churches that run children’s ministry, so records about minors are often in it — entered by the church and their parents or guardians, never collected by us directly from a child. PewHQ is not directed at children, and children do not create accounts with us. If you are a parent with a question about your child’s record, your church holds it; ask them, and we will support them in acting on your request.

Your choices

If something goes wrong

If church data is exposed in a way it shouldn’t have been, we will tell the affected churches directly and promptly, with what we know and what we’re doing about it — not a vague notice months later.

Changes and contact

If we change this policy in a way that matters, we’ll tell churches rather than quietly editing the page. Questions about this policy, or about PewHQ and your data, go to contact@cdmediainc.com, where a person reads them.