Privacy Policy

Last updated: 8/10/2026

Who we are

Disciplo (“Disciplo”, “we”) (a DBA of MEKS GROUP LLC) provides church management software. Our contact address is 9097 Suttersmill Cove E, Cordova, TN 38016 and you can reach us at support@getdisciplo.com.

Controller and processor

Each church that uses Disciplo decides what information it records about its own people and why. In data-protection terms that church is the controller of that information, and Disciplo is a processor acting on its instructions. If you are a member of a congregation and want to see, correct or delete your information, please contact your church directly — they control it, and they have tools inside Disciplo to action your request.

What we store

On behalf of a church, Disciplo stores the information that church enters: names and contact details, household relationships, attendance records, group and ministry membership, giving records, pastoral notes and care records, messages sent and received, and any files the church uploads. For the church’s own staff accounts we also store an email address and authentication details.

Why we store it

Solely to provide the service to the church: to let its staff record and find information, communicate with their congregation, and produce their own reports. We do not sell personal information, and we do not use a church’s congregational data to train models or for advertising.

How we measure use of the product

Separately from the information a church records about its congregation, we keep a record of how church staff use Disciplo itself: when someone signs in, which screens they open, their role, and the IP address and browser of the sign-in. We use it to work out which parts of the product need improving and which churches need help getting started.

What this record deliberately does not contain: which member, donation or note was opened, or anything typed into a search box. Screens are stored in the form “/people/[id]” — the shape of the page, never the record. We do not track congregants using the member portal, the check-in pages or the giving pages at all.

Staff are identified in this record by a random key rather than by name or email. Sign-in IP addresses are deleted after 90 days; only the country is kept after that.

Sub-processors

We use these providers to deliver the service: Supabase (database and file storage), Hostinger (application hosting), Resend (email delivery), Telnyx, Infobip and/or Twilio (text and WhatsApp delivery), Stripe (payments and donations), and Anthropic (optional AI drafting, only where a church has enabled it).

Where data is held

ca-central-1

How long we keep it

We keep a church’s information for as long as their account is active. When an account closes we delete it after 30 days. Some records — notably donation records — may be kept longer where the church has its own legal obligation to retain them.

Your rights

Depending on where you live you may have rights to access, correct, delete, or export your information, and to object to certain processing. Because your church is the controller, please contact them first. Disciplo provides them with built-in tools to export their data and to permanently anonymise an individual’s record on request.

Security

Access is controlled per church and per role, enforced in the database itself rather than only in the interface. Data is encrypted in transit and at rest. Two-factor authentication is available to every church.

Contact

Questions about this policy: policy@getdisciplo.com.