You’re considering trusting us with your congregation’s contact details and your church’s giving. Here is exactly how that works, in plain terms — including the parts we haven’t built yet.
Every record belongs to one church. That isn’t enforced by remembering to add a filter in the right place — it’s enforced by PostgreSQL row-level security on every one of the seventy-odd tables that hold church data, with FORCE set so the rule applies even to the account that owns the database. Each request opens a transaction that declares which church it is acting for, and the database refuses to return anything else for the life of that transaction.
Practically: if we wrote a bug tomorrow that forgot to filter by church, the database would return nothing rather than another church’s people.
Your database runs on Neon in Amazon’s US East (N. Virginia) region, and the application runs on Vercel. Everything travels over HTTPS and is encrypted at rest by the hosting providers.
On backups, we’d rather give you the real number than a comfortable one: we can rewind the database to any point within the last 24 hours. That covers the common disaster — a bad import, a mistaken bulk delete, something noticed the same day. It does not cover a problem you only discover a week later. So if you are about to do something drastic, take an export first (it’s one click), and keep your own copy of anything you couldn’t bear to lose. We are working on a longer window and will say so here when it changes.
Online giving runs through Stripe’s own hosted checkout. Card details are entered on Stripe’s page, not ours, and never pass through PewHQ.
More than that: your gifts never pass through us either. Each church connects its own Stripe account, and charges are created directly on that account. Payouts go from Stripe to your bank. We are not a middleman holding your offering, and we could not withhold it if we wanted to.
Several features use an AI model from xAI: asking questions about your data, drafting sermon slides, drafting follow-up messages and social posts, generating website copy, and matching columns when you import a spreadsheet. Being specific about what that means:
If you would rather no church data reached an AI provider at all, tell us — the features are separable and we would rather know than assume.
Every list can be exported to CSV, and there’s a one-click download of everything as a zip, plus an accounting export for your bookkeeper. No support ticket, no waiting period, no export fee. If you leave, you leave with your data.
Removing a person hides them everywhere but deliberately keeps their giving and attendance history, because those are your financial records and a deletion shouldn’t silently alter last year’s totals. Ask us if you need a record removed outright.
Running PewHQ means these companies handle some of your data:
We would rather you hear this from us than discover it:
If your church has a question this page doesn’t answer — or you want a specific claim here demonstrated rather than asserted — email contact@cdmediainc.com. A real person reads it.