Trellis · Updated September 18, 2026
This policy explains what Trellis stores about people, why, who can see it, and how to ask for it to be corrected or removed. Trellis is a platform that churches use to run small groups, giving, communications and serving. Each church is responsible for the records in its own account; Trellis holds them on the church’s behalf and uses them for nothing else.
Who this covers
Three kinds of people appear in Trellis. Staff and leaders sign in and use it: administrators, pastors, office staff, group leaders, coaches, and directors of serving areas. Members, prospects, volunteers and donors are the people the church cares for; most never sign in, and their information is entered by staff and leaders, or comes from what they themselves give, sign up for, or answer. Visitors use the public pages: a church’s giving page, or the link at the foot of an email.
What we store
About everyone who signs in: your sign-in email address, your name, your roles, and anything you add to your profile: a preferred email for church communication, phone number, address, birthday, neighborhood, pronouns, a line about yourself, and an emergency contact’s name, relationship and phone. The emergency contact is seen only by you and the church staff. We keep the time you last signed in and what you did in the app (see the audit log below).
Living Room, for small groups: for members and prospects, name, phone, email, address, birthday, household and neighborhood; when they joined and whether they are active; attendance week by week, including a reason when one is given, and the names of guests who came; notes leaders write to remember conversations; prayer requests and whether they were followed up; and for prospects, how they heard about the group, who is following up, and a log of contact. Children may be named as part of a household so a leader knows a family.
Giving: for each gift, the amount, date, fund, method and status; the donor’s name and email as given at checkout or on a check; whether a receipt was sent; and, for recurring gifts, the schedule and its status. Card and bank details are entered on Stripe’s pages and never reach Trellis; Trellis keeps only Stripe’s reference numbers. Gifts can be matched to a person’s record so the church can prepare year-end statements.
Communications: the messages the church sends, who they went to, and what happened to each one: sent, delivered, opened, bounced, failed, or marked as spam by the recipient. Opens are reported by the recipient’s mail program when it loads the message and are not always accurate. When someone unsubscribes, the date is recorded and they are not emailed again. A person’s record also notes when the church gathered consent for text messages, where it did so, and if they opted out; Trellis does not itself send text messages today.
Serving: for each volunteer, what they said they’re interested in, when they’re available, relevant skills and background, how they came to the church, notes for the office, the date a background check was completed if the church records one, and which areas they serve in. For each service or event, who was asked to serve, whether they said yes or no, a note they left, and whether a reminder was sent.
The write-up after a meeting: a leader may write a paragraph about how a group meeting went. Trellis keeps it as the meeting’s record. If the church has turned on Silas, a paid add-on to Living Room, and has the setting on, Trellis sends the paragraph with the group’s roster names to Anthropic’s Claude model (called Silas in the app), which proposes attendance marks, guests, notes and prayer requests for the leader to check before anything is saved. Anthropic does not train on this data and keeps it only briefly for abuse monitoring under its API terms. Nothing is saved from the reading until the leader confirms it. Silas also reads, on the same terms and under the same switch: a serving director’s write-up of a service or event, with the day’s rosters and schedule, to propose who served, who missed, notes, tasks and seats for next time; what a new volunteer said about their interests, availability and skills, with the church’s list of serving areas, to suggest where they fit; the leader guide the church has filed on its shelf for a week, together with the meeting’s passage, to draft discussion questions; and a one-line brief for a message template, with the church’s name, its groups pastor’s name and its existing templates, to draft or tighten the template’s wording. In each case a person checks the proposal before anything is written, and the drafted questions are saved only if the leader puts them in the plan.
About the church: its name, time zone, pastor’s contact details, logo, group names and meeting times, series plans, serving areas and positions, funds, and the files staff and leaders put on the shelf. For billing, the modules it has on, the subscription’s status and dates, and Stripe’s reference numbers. The church’s card details are held by Stripe, not Trellis.
The audit log: every change to a church’s records is logged with who made it, when, and what changed. Administrators can read the log for their church. It exists so the church can answer “who changed this?” and so mistakes can be undone.
Technical records: the services below keep standard server logs, which include IP addresses and request times, for a limited period to keep the service running and secure. Trellis itself has no analytics, no advertising and no tracking pixels on its pages. The one exception is the open tracking in church emails described above.
Where it comes from
Staff and leaders type most of it in, usually from what a person shares with their church. Some churches first load their people from an existing directory or spreadsheet. Donors give their name and email at checkout. Volunteers may sign themselves up from their own page. Members are not asked to create accounts unless the church invites them.
Why we hold it
To do the church’s work: to know who is in a group and who came, to notice when someone has gone quiet and reach out, to pray for people and remember what they shared, to help a newcomer find a group, to take gifts and account for them, to tell people what is happening, to schedule volunteers and remind them, and to let the church staff support their leaders. Trellis does not sell information, use it for advertising, build profiles across churches, or share it with anyone for their own purposes.
Who can see it
Access follows the role the church gives you, and every role sees one church only.
- A group’s leaders see that group: its people, attendance, notes, prayer requests, prospects and shelf.
- A serving area’s directors see the volunteers in that area and the schedule for it.
- Volunteers see their own asks and answers on their own page, and nothing about anyone else.
- Staff see every group, every person, every area and every message. Finance sees gifts, donors and statements. Communications sees lists and messages.
- Administrators see everything for their church, manage roles, and can read the audit log.
- Members do not see the app unless invited. Their group leader or the church office is the person to ask about what is recorded.
These limits are enforced by the database itself, not just by the screens you see. A leader who edits a web address to point at another group, or another church, gets nothing back. Details are in the security policy.
Who processes it for us
Trellis is a web app and a database. Four services handle data on the church’s behalf, under their own security commitments:
- Supabase stores the database and uploaded files and handles sign-in, in its US East (Ohio) region.
- Vercel serves the app to your browser and runs the scheduled job that sends serving reminders.
- Stripe takes gifts on the church’s own connected account and bills the church for Trellis. It sees the donor’s name, email and payment details, and the church’s billing details.
- Anthropic reads what Silas is asked to read, when the church has paid for Silas and has it on: a leader’s or director’s write-up with the roster names it needs, a volunteer’s own words with the church’s serving areas, a leader guide from the shelf with a meeting’s passage, or a brief for a message template with the church’s existing templates. It returns the proposal and nothing else. A church that has not turned Silas on sends nothing to Anthropic.
- Resend delivers email: sign-in links, church messages, serving reminders. It sees each recipient’s address and the message, and reports back delivery, opens and bounces.
Stripe’s and Resend’s own privacy policies apply to what they hold.
Cookies and storage on your device
When you sign in, your browser keeps a session token so you stay signed in. It is stored in your browser only and is removed when you sign out. There are no advertising or tracking cookies. Stripe’s checkout pages set their own cookies for fraud prevention.
How long we keep it
Records stay as long as the church uses Trellis. When a group is removed, its people, attendance, notes, prayer requests, prospects and shelf files are deleted with it. Turning a module off keeps its records so it can be turned back on. A leader who stops leading loses access; their profile can be removed on request. When a church closes its account, its records are deleted after ninety days, sooner on request; gifts and invoices stay in the church’s own Stripe account. Email delivery logs are kept only as long as Resend keeps them.
Your choices
Anyone can ask the church to see what is recorded about them, to correct it, or to remove it. Ask your group leader, the church office, or the contact the church lists on its pages. Trellis will help a church answer such a request, and if you cannot reach the church, write to nadirmims@sgmtllc.com. The church will remove information unless it has a genuine need to keep it, such as a giving record required for tax purposes. People who sign in can edit their own profile from “Your profile”. Anyone can stop church email with the link at the foot of any message. A donor who signs in can change or stop a recurring gift from “Your giving”; anyone else can ask the church, which can stop it from Giving.
Children
Trellis is used by adults. A child’s name may appear as part of a household so that a leader knows a family, but leaders should not record contact details, notes or prayer requests about a child beyond what the parents have shared for the group’s care. Parents can ask for anything about their child to be removed.
Changes
If this policy changes in a way that affects you, the date at the top changes and each church’s administrators are told. The current version is always at this address.
Questions
Write to nadirmims@sgmtllc.com.