Information you provide
A draft may include a deceased person’s name and dates, service and parish details, reading and music choices, participant names, a portrait, obituary or remembrance text, acknowledgments, reception information, parish questions, and an optional recovery email. If collaboration is used, it may also include a contributor’s name and email, the organizer notification email, role-specific suggestions, and submission status. A verified-email account also includes the account email, organization name, workspace role, subscription status, sign-in and session records, and the projects associated with that workspace. Do not add sensitive information that is unnecessary for the program. A cause of death is never required.
How private drafts and task links work
The site uses a secure session and private access tokens stored only in hashed form. Ordinary resume and view-only links are single-use. A private organizer link sent after a contributor submits work opens the complete editable draft and may be reopened only while that specific submission awaits review, before the link expires or is revoked. Treat every organizer link like a password and do not forward it unless you intend to grant full draft access. Contributor links are narrower: a music director, priest or presider, or family member sees only limited service context and the fields assigned to that role. Their submission remains a separate suggestion until the organizer approves it. The organizer may revoke a task link. Draft, task, and review pages are private application pages and are marked noindex.
Optional memorial share page
A memorial share page is not created automatically. The organizer must deliberately enable it and may revoke it. It is unlisted and marked noindex, but it is protected by a bearer link rather than an account sign-in: anyone who receives or forwards the complete link may open the page. Do not publish sensitive information there. The page expires when its link is revoked or when the associated project reaches the applicable deletion or retention deadline. Search engines are asked not to index it, but no noindex instruction can guarantee that a copied link or its contents will never be disclosed elsewhere.
How verified workspace accounts work
Parish, funeral-home, and coordinator access begins with a single-use, time-limited sign-in link sent to the submitted email address. Using that link verifies control of the address and creates or opens its workspace. Treat the link and the signed-in device as private: a person with access to either may be able to view the account’s projects and organization details. Workspace pages are private application pages and are not search-index pages.
Email delivery and collaboration notices
When email delivery is requested, the configured mail provider processes the recipient address and the message needed to deliver a resume, sign-in, contributor invitation, submission notification, or billing notice. Contributor invitation messages identify the assigned role and may identify the person whose funeral is being planned. A copyable private task link is also available when the organizer prefers to deliver it directly. Delivery failures may be retried from a limited notification queue without storing the raw private link token.
Portraits and uploads
Accepted portraits are decoded and re-encoded to remove embedded metadata such as GPS information. They are stored under randomized names in private storage and streamed only after draft authorization. JPG, PNG, and WebP are accepted; other file types are rejected.
Optional AI writing assistance
AI assistance is opt-in. When you consent and request a draft, only the facts and notes needed for that specific tool are sent to the single AI provider configured for the site, which may be Anthropic, OpenAI, or Google. Requests are not retried through a second provider, and the portrait is never sent. OpenAI requests explicitly disable response storage. The service records a request status and keyed, non-reversible input fingerprint for rate limiting, but is designed not to log the raw prompt or output. Review generated wording carefully and remove any detail you do not want included.
Payments
One-time checkout, recurring Professional Workspace billing, invoices, payment-method updates, and subscription cancellation are handled through Stripe. Stripe receives payment and billing information under its own privacy terms. Catholic Funeral Program receives transaction and subscription identifiers, billing status, amount, currency, period dates, and customer email where supplied; it does not receive or store the full card number.
Cookies and operational data
A strictly necessary short-lived session cookie protects the private planner and CSRF token. A signed-in workspace uses a separate, revocable account cookie for up to 30 days so the verified account can remain signed in. The account cookie is HttpOnly, uses SameSite=Lax, is marked Secure over HTTPS, and contains a random session credential whose verification value is stored in hashed form on the server. Signing out revokes that account session and clears its cookie. The server may process an IP-derived one-way hash, request timing, error type, and limited security events to prevent abuse and operate the service. Public marketing analytics, when enabled, are limited to allowlisted product events and do not contain funeral-program text.
Retention
Contributor invitations, role-specific suggestions, delivery records, and optional memorial share pages follow the retention of their associated draft and may be pruned sooner after expiry or revocation. Unpaid family drafts are scheduled for deletion after 30 days of inactivity. A Single Program purchase includes corrections and downloads for 30 days, and its paid project content is scheduled for deletion after 90 days unless earlier deletion is requested. Professional Workspace projects remain available while subscription access is active and are scheduled for deletion 90 days after that access ends. Minimal transaction, subscription, and support records may be retained longer where reasonably required for accounting, fraud prevention, disputes, or law. Backup copies may persist for a limited rotation period.
Deletion and questions
Use “Delete this draft” inside the builder for immediate application-level deletion, or email support@catholicfuneralprogram.com for help with project or workspace deletion. Canceling a Professional Workspace stops future renewal but does not itself request immediate content deletion; workspace content follows the 90-day retention period unless earlier deletion is requested. We may need a transaction, subscription, workspace, or draft identifier to locate the record without asking for unnecessary family details.
Security and limits
The service uses prepared database queries, hashed access tokens, private upload storage, re-encoded images, CSRF protection, restrictive browser headers, rate limits, and server-side payment verification. No system can promise absolute security; use a private device and treat resume links like passwords.