Privacy policy
Last updated 11 July 2026. This policy explains what muhubiri stores about your church, your staff and your members, why, and who else touches it in the course of running the service.
1. What we store
Account data— the church's name, slug, plan, country and contact details, plus each staff member's name, email or phone number, role, and login credentials (passwords stored hashed, never in plain text).
Media— every video and audio file you upload, its transcript and translated text in each target language, generated dub audio, subtitle files, and any reference clip and consent recording used to enable voice cloning.
An audit trail of choices— every credit charge, every publish decision, every theology-gate approval, every voice-cloning consent, and other account-affecting actions are logged with a timestamp, the acting user, and the IP address the action was taken from. We keep the IP address specifically so that, if a charge, approval or consent is ever disputed, we can look at the actual record of who did what, from where, rather than relying on memory.
Giving and payment records— where giving or credit top-ups are enabled, we store the transaction reference, amount and status returned by our payment partners; we do not store full card numbers or M-Pesa PINs ourselves.
2. How we use it
To run the service you signed up for: authenticate your staff, run dubbing and hosting jobs, deliver media to your connected channels, process giving and top-ups, resolve support requests and disputes, and detect fraud or abuse of the credit system. We do not sell church or member data to third parties, and we do not use sermon content to train third-party advertising products.
3. Who processes data on our behalf
We rely on a small set of specialist infrastructure and payment providers to run muhubiri. Each only sees the data it needs to do its job:
- Amazon Web Services (AWS)— application hosting, databases and backups.
- Bunny— video storage and content-delivery streaming for your media library.
- Modal— runs the AI translation, transcription and voice generation jobs (built on the Abantu AI engines) when you dub or subtitle a sermon.
- Safaricom / M-Pesa and PesaPal— process mobile-money and card payments for giving, credit top-ups and plan billing.
- Africa's Talking— delivers SMS notifications (for example, publish confirmations and alerts) where a church has SMS enabled.
Each of these processors is contractually restricted to using the data only to provide their service to us, not for their own purposes.
4. Retention
Account and media data is kept for as long as your church account is active. Audit-trail entries (charges, approvals, consents, and the IP addresses attached to them) are kept for at least as long as the account is active and for a reasonable period afterwards, so that disputes about past charges or approvals can still be resolved. If you close your account, we delete or anonymise personal data within a reasonable period, except where we are required to keep financial records for longer by law, or where content remains published on a third-party channel (like YouTube) outside our control.
5. Your choices
Church admins can export their media and credit history from Studio at any time. Staff accounts can be removed by the church admin. To request deletion, correction, or a copy of data we hold about your church or a specific staff member, contact us using the details below — we will act on verified requests within a reasonable timeframe.
6. Security
Data is encrypted in transit (HTTPS/TLS) between your browser, our servers and every processor listed above. Passwords are stored hashed. Access to production data is restricted to the staff who need it to operate and support the service.
7. International transfer
muhubiri and its processors operate infrastructure in multiple countries (including the United States, where AWS and Modal run some services). By using muhubiri you understand that your church's data may be processed outside the country where your church is based, under the safeguards described in this policy.
8. Changes to this policy
If we change what we collect or who we share it with in a way that materially affects you, we will post an updated policy here and, where the change is significant, notify church admins by email or in-app notice.
9. Contact
Questions about this policy, or a data request: write to hello@muhubiri.com.