Church technology

Four Questions to Ask a Church AI Vendor Before You Sign

The question that matters is not whether an AI can read your church's records. It is whether it will do your job.

Key takeaways

  • The risk is not visibility, it is action. Churches have kept records on their members since long before computers. What is new is software that contacts people, and that is the line worth guarding.
  • Ask what it does on its own, not whether it is secure. "A human can review it" is not the same promise as "a human decides it."
  • Find out whether a real name leaves your building. Not "is our data encrypted." Specifically: what text goes to the AI company, and can that company tie it to a person.
  • Ask for the answers in writing. A vendor who cannot show you a page usually has not decided any of this. Often they have simply never been asked.
  • Four questions at the end of this post are enough to tell whether a tool helps your pastors care for people or quietly takes that work away from them.

Quick answer: What questions should a church ask an AI vendor?

Ask four things. Does it ever contact a member directly? What does it decide on its own, and what does a person decide? What text leaves your church for the AI company, and can that company tie it to a real person? And can they show you all of that written down somewhere you can hold them to it? A vendor with no page has usually not decided these questions yet.

The thing I am actually worried about

I am not worried about software that reads your church's records. Churches have kept those records forever. Before church management systems there were spreadsheets, and before spreadsheets there were logbooks and index cards and a pastor's own memory. Knowing who is sick, who has stopped coming, and who needs a visit is not surveillance. It is the job.

What I am worried about is the tool that shows up next year and offers to do the job.

An AI that texts your members. That emails them a check-in. That mobilizes a care team without a person deciding to. That, and I do not say this lightly, prays for them on the pastor's behalf. Every one of those is technically buildable today. Some of them will be built by someone who has never thought about what they are replacing, because the demo is going to look incredible and the pitch is going to be that your staff is stretched thin, which is true.

That is the tool a church should be able to spot before they sign, and most churches currently cannot. Not because pastors are naive, but because nobody has handed them the questions.

Why this is urgent now, and not in two years

Look at what is happening outside the church.

People are lonelier than they have been in a long time, and the thing they are reaching for is a screen. They are having their conversations with AI. They are taking their questions to AI. They are getting comfort from AI at two in the morning instead of from a person who knows them. The technology is good enough now that it works, in the sense that it produces something that feels like being heard.

That is the disease. A church is one of the few institutions left whose entire reason for existing is the cure.

So when a piece of church software offers to handle the relating for your pastors, understand what is being proposed. Not a time-saver. An accelerant, pointed at the exact thing your church exists to resist. C.S. Lewis wrote in The Four Loves that friendship is the least necessary of the loves and the most human, the one that has no survival value and instead gives value to survival. It is also the one that cannot be delegated. Nobody can be your friend on your behalf.

AI can absolutely help a church love people better. It can notice what a busy staff missed, organize what is scattered, and put the right information in front of the right person at the right moment. What it must never do is get between two humans who were supposed to meet.

For more on where that line sits generally, I wrote about how churches should think about using AI. This post is narrower. This is what to ask the person trying to sell you something.

The four questions

1. Does it ever contact a member directly?

Start here, because it is the cleanest test and the hardest to talk around.

Ask plainly: can this software send a text, an email, a push notification, or anything else to a person in our congregation, without a member of our staff choosing to send it? Then ask the follow-up that matters: is that a setting, or is it impossible?

A setting is not a commitment. A setting is a default that somebody can change later, usually a year after you signed, usually in a release note you did not read.

What a good answer sounds like: nothing reaches a member without a person reviewing and approving that specific message.

What a bad answer sounds like: "You can turn that off." "It only sends when it is confident." "There is a human in the loop." That last one is the one to press on, because it means almost nothing on its own.

2. What does it decide, and what does a person decide?

This is the sheepdog question. I have written before about why AI should be a sheepdog, not a shepherd: the dog watches the edges of the flock and barks. The shepherd decides what to do about it. The dog never decides that a sheep needs anything, and the dog never goes out to the sheep on its own.

So ask where the decisions actually live. Does the software flag and hand off, or does it act? When it says a person is at risk, does anything happen automatically as a result? Does that flag ever affect whether someone can serve, lead, join a group, or be considered a member in good standing?

That last one matters more than it sounds. The moment a reading about a person becomes an input to a decision about that person's standing, you have built something the church has no business operating. A flag should be an invitation for a pastor to go look. It should never be a verdict.

John Piper's title says the thing I would want a vendor to have internalized: Brothers, We Are Not Professionals. Shepherding is not managing. A tool that turns your congregation into a queue to be processed has changed the job, whatever it says on the pricing page.

What a good answer sounds like: the software surfaces, a person decides, and the flag is not wired to anything else.

What a bad answer sounds like: any description of an action that happens because of a score, with no person named in the sentence.

3. What leaves our church, and can the AI company tie it to a real person?

Most churches ask "is it secure" and stop. That is the wrong question, because the answer is always yes and it tells you nothing.

The right question is more specific: when this software asks an AI model to do something, what text goes with the request? Do our members' names go? Their phone numbers, their email addresses? The actual words our care team wrote about them? And on the other end, does the AI company keep any of it, or train on it?

Ask them to be concrete. A vendor who has thought about this can tell you exactly what fields travel and exactly what is stripped. A vendor who has not will reach for the word "encrypted," which describes how data moves, not what is in it or who can read it at the other end.

Then ask the sharpest version: if your AI provider were served a subpoena tomorrow, what would they have about my people?

What a good answer sounds like: a specific list of what is sent, a specific statement of what is removed first, and a named commitment from the AI provider about retention and training.

What a bad answer sounds like: an impressive-sounding encryption standard, "we take privacy seriously," or any sentence about security that never mentions what is actually in the request.

4. Is any of this written down where we can hold you to it?

This is the question that makes the other three durable, and it is the one almost nobody asks.

Every answer to questions one through three is a person on a sales call telling you something true about today. Written down and published, those answers become commitments that survive the salesperson leaving, the roadmap changing, and the company being acquired by someone with different ideas.

So ask for the page. Not the privacy policy, which is a legal document written to protect the vendor. A plain-language page that says what the software reads about a person, who inside your church can see it, what a member is and is not told, what crosses to the AI company, and what the vendor will never do.

If it exists, you have learned something about who you are dealing with. If it does not, you have learned something too. Usually it means they have not decided yet, because nobody made them.

What this looks like when you do it to yourself

I would not publish this list without having answered it about FlockConnect first.

We wrote our own page, at /collie-ethics. It says what our reading of a person is and is not. It says that nothing our assistant drafts reaches a member without a person reviewing and approving it, that the reading never gates membership, leadership, group placement, or serving, that we never compare your church's people against another church's, and that we never pull public data about anyone.

It also says the uncomfortable parts, because a page that only contains wins is a brochure.

It says that members do not log in and are not shown their own reading, and we explain why we think that is right rather than pretending the question does not exist. It names, specifically, the places where our system for stripping names out of AI requests can fail. And it declines to promise that sensitive information never reaches the AI, because we cannot prove that sentence and we would rather tell you exactly what can travel than say something reassuring and vague.

That last one is live work, not settled work. Names of people your church has no record of, a visitor's relative mentioned in passing, can still reach the model as written, and closing that gap is engineering we are doing now rather than a box we have ticked. I would rather you read that here than discover it later.

I am not holding FlockConnect up as the finished answer. I am saying the exercise is the point. Any vendor can do it. Most have not been asked to.

What to do with this

Print the four questions. Take them to your next demo. Ask them in that order, and pay attention less to the answers than to whether the person on the call has clearly thought about them before.

You are not being difficult. You are doing the thing a shepherd does, which is to look carefully at what is being let near the flock.

If the vendor is good, they will be glad you asked. I would be.

About the author

Michael Tribett is the founder of FlockConnect, a Church Relationship Manager that helps pastors see who is connected and who they haven't seen lately. He holds a Master of Divinity in Christian Ministry from Southeastern Baptist Theological Seminary, spent three years inside a major church management software company before building FlockConnect, and lives in Raleigh, North Carolina, where he serves as a small group leader at his local church. FlockConnect went through the Missional Labs Faith and AI Accelerator and is an official Planning Center integration partner.

Frequently asked questions

What questions should a church ask an AI vendor?

Four. Does the software ever contact a member directly, and is that impossible or merely a setting? What does it decide on its own, and what does a person decide? What text leaves your church for the AI company, and can that company tie it to a real person? And can the vendor show you those answers written down somewhere public? The fourth question is the one that makes the first three survive a change of staff or a change of owner.

Should an AI tool contact church members directly?

Not on its own, and that is the clearest line a church can draw. The distinction is who decided to send it. A pastor who reads a drafted message, edits it, and chooses to send it has done something pastoral, and the draft saved them fifteen minutes. Software that decides on its own that a member should be contacted has taken the pastoral act itself, and a member who later learns the check-in they found meaningful was sent without anyone choosing to has been given a reason to trust the church less. So ask whether unreviewed sending is impossible rather than merely switched off, because a setting is a default someone can change in a release you never read.

What does a church AI vendor send to the AI company?

It varies enormously, which is why the question has to be asked specifically rather than generally. Ask which fields travel with a request, whether member names and contact details are removed before it leaves, whether the actual words your care team wrote are included, and what the AI provider commits to about keeping or training on what it receives. A vendor who answers with the word "encrypted" has described how the data moves, not what is in it.

How can a church tell if an AI tool is doing the pastor's work?

Look for actions that happen because of a score rather than because a person decided something. If a flag about a member causes a message to send, a task to be assigned, or a status to change without a human choosing it, the software has moved from noticing to acting. Noticing is useful and worth paying for. Acting on a person's behalf is the job you called your pastors to do.

Why should a church get its AI vendor's answers in writing?

Because a spoken answer describes today and a published answer is a commitment. Salespeople move on, roadmaps change, and companies get acquired by people with different convictions. A plain-language page that states what the software reads, who can see it, what crosses to an AI company, and what the vendor will never do is something you can point back to in two years. Its absence usually means the vendor has not decided these questions rather than that they decided badly.

Is AI making church members more isolated?

The broader pattern is hard to ignore: people increasingly take their conversations, their questions, and their late-night distress to a screen rather than to another person. Church software cannot fix that by itself, but it can make it worse by handling the relating on a pastor's behalf. The useful test for any tool is whether it moves two humans closer to an actual conversation or quietly stands in for one.

Does asking these questions mean a church should avoid AI entirely?

No. AI can genuinely help a church love people better by noticing what a stretched staff missed, organizing what is scattered, and putting the right information in front of the right person at the right time. The questions exist to separate tools that hand work back to humans from tools that take it away from them. A vendor who welcomes the questions is usually building the first kind.

See who is connected, and who you haven't seen lately.

FlockConnect helps pastors know their people and act before someone slips away. Starter is one flat price for your whole church, with a 14-day no-card trial.