Seteo Privacy Policy
This Privacy Policy explains how Cinder Labs LLC ("Seteo," "we," "us," or "our") collects, uses, shares, and protects personal information when you use Seteo — our AI worship-planning service for churches, worship leaders, and their teams — including our website, web application, our iPhone and Android apps, and related services (collectively, the "Service"). Seteo helps worship leaders turn a sermon into a service plan, schedule volunteers, and deliver the set to their team — including to volunteers who never create an account and instead use a personal schedule link. Some of the information we handle is provided by an organization (a church or ministry) that uses Seteo and concerns its team members and volunteers; where a church administers a Seteo account, that organization decides who has access and how the Service is used within it. We've written this in plain language because we'd rather you actually understand it. By using the Service, you agree to the practices described here. Effective date: August 11, 2026. Last updated: September 18, 2026.
01Who This Policy Covers
This Policy applies to everyone who interacts with Seteo: the worship leaders, pastors, and administrators who set up and run a church's account; the team leads and members who are scheduled to serve; and visitors to our website. When a church or ministry creates a Seteo workspace, it acts as the account owner and controls the data within that workspace — including which volunteers are added and what information is stored about them. If you are a volunteer or team member added by your church, your church decides how Seteo is used in your community, and questions about that use are often best directed to your worship leader or administrator. Seteo provides the tools; the church directs how they're used day to day. Regardless of your role, the rights described in this Policy — including the California and other state privacy rights below — are available to you, and you can reach us directly using the contact details at the end.
02Volunteers Without Accounts: Personal Links
Many volunteers use Seteo without ever creating an account. Instead, each volunteer gets a personal link — a long, unguessable web address unique to them. Opening that link shows the volunteer their schedule and song charts and lets them respond: confirm or decline a Sunday, say which Sundays work, and record time away. Because the link is the key, anyone who has it can see and do those things as that volunteer — so don't forward it. Here's how we protect it: we never store the link itself in usable form in our database (we store a one-way cryptographic hash, plus an encrypted copy protected by a server-side key used only for support operations like re-sending your link); links automatically expire after about 180 days of non-use and renew while you keep using them; and both you and your leaders can reset the link at any time — if a page says it's you and it isn't, use the "Not you?" reset and the old link stops working immediately. Link pages are also rate-limited to slow down anyone trying to guess links. From your link page you can add or update a contact email; we use it only to send you schedule notifications — nothing else, and never marketing. What we collect about you through your link: your name and role as entered by your church, the schedule responses, availability, time-away dates and any short note you submit, your contact email if you provide one, and (if you choose to link it) your Discord user ID and username. Your church's leaders can see your responses, availability, and time away, because that's what scheduling is for. Guest links. A leader can also share one Sunday's set with someone who is not on the roster. A guest link is a long, unguessable address that shows that set's charts read-only, expires on its own after one or two weeks, and can be revoked by any leader at any time. We store only a one-way hash of the link, the set it points to, when it expires, and a total count of how many times it was opened — never who opened it or from where. Guests see your church's name, the set, and the leader's first name when the leader is driving the room. Expired links and their counts are deleted; a revoked link is kept marked for up to 30 days so the guest sees 'expired' rather than an error, then removed.
03Information We Collect
We collect the following categories of information. Account and authentication information: when your account is created, our authentication provider collects and verifies your name, email address, and password, and basic profile details so we can create and secure your account. We receive your identity and session information from our authentication provider but do not store your raw password. Church and team data: the name of your church or ministry, your role (Admin, Worship Leader, Team Lead, or Member), team and service structure, call times, assignments, and scheduling details. Volunteer information: names, roles (including roles a volunteer identifies for themselves), and contact details (such as an email address, which a volunteer can also add or update themselves from their personal link page) for the people on your worship team, typically entered by an administrator or worship leader so the team can be scheduled and notified. Volunteer email addresses are used only for schedule-related notifications — never for marketing. Availability and scheduling responses: which Sundays a volunteer says work for them, confirmations and declines, and time-away date ranges with an optional short note; this feeds the automated scheduling suggestions we show leaders. Discord information: if your church connects Discord, the server (guild) ID and name, and — through our bot — the usernames and IDs of members of that server, which we process to manage service channels; and, if a volunteer chooses to link their own Discord identity, that volunteer's Discord user ID and username only (never their messages, other servers, or Discord email). Song library and charts: song charts and lyrics your church uploads or imports, including from Planning Center if connected. Activity records: a per-church activity log of security- and scheduling-relevant events — such as personal-link resets, Discord identity links and relinks, self-identified roles, time-away submissions, and anomaly flags — visible to your church's leaders. Timezone: your church's timezone, detected from the setting-up leader's browser and editable in settings, used only for scheduling date calculations. Sermon and song content: sermon text, notes, or themes you load; the setlists, song titles, suggested keys, alternates, service plans, and edits you and your team create. Usage and device data: how you interact with the Service — pages and features used, actions taken, timestamps, browser and device type, and log and diagnostic data we use to keep the Service running and to improve it. Cookies and similar technologies: small files and identifiers used to keep you signed in, remember preferences, and understand how the Service is used (see "Cookies and Tracking" below). We do not intentionally collect special categories of data beyond what is inherent in worship planning. Sermon and worship content may reveal religious affiliation; under California law, certain account credentials are treated as sensitive personal information. We handle this information carefully and only as described here. Mobile apps: the Seteo app for iPhone and Android sends us only what you do in it — your sign-in (through our authentication provider), the personal link you open, your schedule answers, availability, time-away dates and note, roles, a contact email if you add one, and, on the Stand, the page you are on when you lead the room and any song you add live. Live room: when several devices open the same Sunday's Stand, our server relays the leader's current song and section to everyone in the room and shows a count of connected devices; followers and guests see the leader's first name, never anyone else's, and the count is a bare number computed from a random id your device sends (see 'Data Retention'). Chart annotations you draw on the Stand and your offline copy of Sunday's set are kept only on your phone; annotations are never uploaded, and the offline copy is removed when you sign out or forget a link. It contains no advertising or analytics software and does not read your location, contacts, photos, or clipboard. Sessions and links are kept in encrypted storage on the phone, excluded from device backups, and are removed when you sign out, forget a link, or delete your account. Rehearsal notes: short notes a leader attaches to a song for the team or for specific volunteers, stored with the author's first name and shown on the Stand to the people they are for; when a volunteer taps 'Got it' we record that acknowledgement so the leader can see who has read the note.
04How We Use Your Information
We use the information we collect to provide, operate, and improve the Service. Specifically, we use it to: create and secure your account and authenticate your sign-in; generate AI service plans — matching songs to sermon points, suggesting keys, and offering alternates — using the content you load; let you and your team build, edit, and view setlists and service plans; schedule volunteers and show each person their "My Sunday" call time, parts, and cues; deliver sets and notifications to your team — including sending schedule-notification and security-alert emails through our email provider, and, where your church has installed our Discord bot, creating private per-service channels in your server, managing who can see them, and posting set summaries and mentions; generate scheduling suggestions from volunteers' availability and time-away submissions; keep a per-church activity log (for example, link resets, Discord identity changes, and unusual-activity flags) that leaders can review, which we maintain in our legitimate interest in security and transparency; respond to your requests and provide support; monitor, troubleshoot, secure, and improve the Service, including analyzing usage to make Seteo faster and more useful; detect, prevent, and address fraud, abuse, and security incidents; and comply with our legal obligations and enforce our terms. We use the sermon and song content you provide to produce your service plans through our AI provider, our AI processing provider. We do not use your content to train third-party AI models, and our AI provider does not use content submitted through our business API to train its models. We do not sell your personal information, and we do not use it for cross-context behavioral advertising.
05Legal Bases for Processing
Where required by applicable law, we rely on the following legal bases to process personal information. Performance of a contract: we process account, church, team, scheduling, and content data because it is necessary to provide the Service you or your church has signed up for. Legitimate interests: we process usage, device, and log data to secure, maintain, and improve the Service, to understand how it is used, and to prevent abuse — interests we balance against your rights and expectations. Consent: where we rely on consent — for example, certain optional cookies or specific communications — you may withdraw it at any time without affecting processing that already occurred. Legal obligation: we process information where necessary to comply with applicable laws, regulations, and lawful requests. Many of these bases are most relevant under laws like the EU/UK GDPR; we describe them here for transparency even though Seteo is primarily designed for and operated in the United States.
06How We Share Information
We share personal information only as needed to run the Service, and only with the categories of recipients below. Within your church's workspace: information you and your team enter is visible to others in your workspace according to their roles — for example, an administrator can see team assignments, and a member can see their own "My Sunday" details. Service providers and subprocessors: we use a small set of trusted vendors who process information on our behalf under contracts that require them to protect it and use it only to provide services to us. These currently include: our authentication provider, for authentication and account management; our database-hosting provider, for hosting our PostgreSQL database where Service data is stored; our AI processing provider, the AI provider that generates service plans from the content you load; our transactional-email provider, which sends schedule-notification and security-alert emails on our behalf; Discord, whose platform our bot operates on — set summaries, channel structures, and member permissions live in your Discord server, and we receive your server's member usernames and IDs to manage those channels; and Planning Center, from which we import your song library (read-only) when your church connects it and until you disconnect it. Legal and safety: we may disclose information if required by law, subpoena, or legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or security issues. Business transfers: if Seteo is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy. We do NOT sell your personal information, and we do NOT "share" it for cross-context behavioral advertising as those terms are defined under California law or comparable state laws. We do not rent your information or disclose it to data brokers.
07Cookies and Tracking
We use cookies and similar technologies to operate the Service. Strictly necessary cookies keep you signed in, maintain your session, and secure your account — these are required for the Service to function. Preference cookies remember choices like display settings. We do not currently set analytics cookies. If we ever add any, we will ask for your consent where required before setting them. We do not use cookies to build advertising profiles or to track you across unrelated websites for ad targeting. You can control cookies through your browser settings, though disabling strictly necessary cookies may prevent the Service from working. Because we do not engage in cross-context behavioral advertising, we do not need to act on most advertising-related signals; where applicable law requires us to honor an opt-out preference signal such as Global Privacy Control (GPC), we treat a valid signal as a request to opt out of any "sale" or "sharing" to the extent it would otherwise apply.
08Data Retention
We keep personal information for as long as your account or your church's workspace is active and as needed to provide the Service. When you delete your account, your sign-in, profile and memberships are removed immediately; we keep only what our account-deletion page (seteoapp.com/account/delete) lists — records your church owns and another administrator still controls, billing records tax law requires, activity logs with your user reference removed, and encrypted backups that roll off within 30 days. You can delete your account at any time from the app (You → Delete account) or by writing to us; in-app deletion takes effect immediately. Sermon and song content and the service plans you create are retained within your workspace until you or your administrator delete them or close the account. Backups are retained on a rolling basis and are overwritten in the ordinary course. When we no longer need personal information, we delete it or anonymize it so it can no longer be associated with you. If you ask us to delete your information, we will do so as described in the rights sections below, subject to limited exceptions permitted by law. Live-room records: each device sends a random id so we can count connected devices; we keep only a truncated one-way hash of it, drop it about 15 seconds after the device stops streaming, ignore a room's position after six hours, and delete the room's records within 14 days of the service.
09Data Security
We take the trust churches place in us seriously and use administrative, technical, and physical safeguards designed to protect personal information. These include encryption of data in transit, access controls and role-based permissions, authentication handled by a specialized provider (our authentication provider), database hosting with a reputable provider (our database-hosting provider), monitoring and logging, and a principle of least privilege for staff access. Seteo staff may access a church's workspace only to provide support, investigate a security or billing problem, or as required by law; every such access is logged. We restrict access to personal information to those who need it to operate the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; however, we work to protect your information and to promptly address any incident. If we become aware of a breach affecting your personal information, we will notify you and any affected church as required by applicable law. We encourage you to use a strong, unique password and to keep your login credentials confidential.
10Children's Privacy
The Service is intended for users who are at least 13 years old. We do not knowingly collect personal information directly from children under 13. If you are a worship leader or administrator adding team members, you are responsible for ensuring that anyone you add meets the age requirement and that you have the appropriate authority to provide their information. If we learn that we have collected personal information from a child under 13 without proper authorization, we will delete it. If you believe a child under 13 has provided us personal information, please contact us at support@seteoapp.com so we can take appropriate action. We do not knowingly sell or share the personal information of minors under 16, and as noted above, we do not sell or share personal information at all.
11International Data Transfers
Seteo is based in the United States, and the information we collect is processed and stored in the United States and in other countries where our service providers operate. If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States and potentially other jurisdictions whose data-protection laws may differ from those of your country. Where we transfer personal information that is subject to laws requiring additional safeguards (such as the EU/UK GDPR), we rely on appropriate transfer mechanisms — for example, Standard Contractual Clauses or another lawful basis — and require our service providers to maintain adequate protections. By using the Service, you consent to the transfer of your information to the United States and other countries as described in this Policy, to the extent permitted by applicable law.
12California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this Policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"). Categories of personal information we collect: in the past 12 months we have collected (a) identifiers, such as name, email address, account ID, and IP address; (b) customer records and contact information, such as volunteer contact details, volunteer availability and time-away submissions, self-identified roles, Discord user IDs and usernames, and activity-log records; (c) internet or other electronic network activity, such as usage and log data; (d); (e) professional or role-related information, such as your role on a worship team; (f) audio, electronic, or other content you create or load, such as sermon notes, song selections, and service plans; and (g) inferences are not used to build profiles for advertising. Sources of personal information: directly from you (including through a volunteer's personal link page); from your church or its administrators and worship leaders (for example, when a volunteer is added); automatically from your devices and use of the Service; from our authentication provider; from Discord (server member usernames and IDs, and a volunteer's user ID and username if they link their identity); and from Planning Center, where your church connects it. Business or commercial purposes for collection: to provide, secure, and improve the Service; to authenticate users; to generate AI service plans; to schedule and notify volunteers; to deliver sets via Discord at your direction; to provide support; to prevent fraud and abuse; and to comply with law — as detailed in "How We Use Your Information." Categories of recipients: our service providers and subprocessors (our authentication provider, our database-hosting provider, our AI processing provider, our transactional-email provider, Discord, and Planning Center), and others as described in "How We Share Information." Sensitive personal information: account log-in credentials are treated as sensitive personal information, and sermon/worship content may reveal religious beliefs. We use sensitive personal information only to perform the Service and for other purposes permitted by the CCPA, and not for the purpose of inferring characteristics about you. Because we use sensitive personal information only for these permitted purposes, we are not required to offer, and do not offer beyond these limits, a separate right to limit. Sale and sharing: we do NOT sell personal information and do NOT "share" it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We also do not knowingly sell or share the personal information of consumers under 16 years of age. Your California rights: you have the right to know and access the specific pieces and categories of personal information we have collected, the sources, the purposes, and the categories of recipients; the right to delete personal information we have collected from you; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; and the right to limit the use and disclosure of sensitive personal information. We will not discriminate against you for exercising any of these rights — we will not deny you the Service, charge you a different price, or provide a different level of quality because you exercised your rights. How to exercise your rights: submit a request by emailing support@seteoapp.com. We will verify your request by confirming information associated with your account, such as your email address, and may ask for additional information reasonably necessary to verify your identity. We will respond within the timeframes required by law. Authorized agents: you may use an authorized agent to submit a request on your behalf; we will require written proof of the agent's authorization and may require you to verify your own identity directly with us. "Do Not Sell or Share My Personal Information": consistent with the fact that we do not sell or share personal information, we honor opt-out preference signals such as Global Privacy Control where applicable; if you wish to confirm your preference in writing, you may contact us at support@seteoapp.com.
13Other US State Privacy Rights
If you are a resident of a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others — you may have rights similar to those described in the California section, such as the right to confirm whether we process your personal information, to access it, to correct inaccuracies, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, or certain profiling. As explained throughout this Policy, we do not sell personal information and do not process it for targeted advertising or for profiling that produces legal or similarly significant effects. To exercise any available rights, contact us at support@seteoapp.com. Some of these laws also give you the right to appeal a decision we make about your request; if we deny your request and your state provides an appeal right, we will tell you how to appeal, and if your appeal is denied you may be able to contact your state attorney general. We will verify your request consistent with applicable law before responding.
14Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice — for example, by email to account administrators or through a notice in the Service. Your continued use of the Service after an update takes effect means you accept the revised Policy. We encourage you to review this page periodically so you stay informed about how we handle your information.
15Contact Us
If you have questions about this Privacy Policy or how we handle your information, or if you'd like to exercise any of your privacy rights, please reach out. You can email us at support@seteoapp.com. If you are a volunteer or team member, you may also wish to contact your church's worship leader or administrator, who manages your workspace. We read what comes in, and we'll respond as promptly as we can and within any timeframes required by law.