Skip to main content

Security & privacy

Protect congregation data with clear access boundaries.

Protect sensitive church data with scoped connectors, encrypted credentials, selected resources, permissions, and action controls.

Scoped access

Nurii uses only authorized apps, files, calendars, channels, properties, sites, and accounts.

Encrypted credentials

Connector credentials are stored in a private credentials store and encrypted before storage using AES-256-GCM.

Reviewed action threads

Review changes or allow selected actions, then continue dependent work.

Access model

Nurii starts from what church leaders intentionally connect.

Usable data depends on the connector, selected resources, permissions, and approved workflow.

Organization and member boundaries

Connection ownership, team membership, and permissions control usable data.

Selected files and resources

Use selected Drive files and limit connectors by resource or permission.

Context-aware AI processing

Each workflow uses needed context, not open-ended access to every connected source.

Action controls

Teams choose which actions need review and which can run automatically.

AI agent governance

AI agent governance controls stay visible before action.

See the proposed action, connector, approval mode, and available stop or undo controls.

AI agent governance controls

Approval cards, action history, connector boundaries, and review settings govern system changes.

Approval modes

Keep sensitive actions under review. Allow routine actions only with a clear owner and scope.

Stop controls

Interrupt active work before its next dependent step.

Undo and action history

Undo supported actions where available; inspect approvals, failures, and follow-up.

Sensitive Google scopes

Request sensitive Google scopes only when needed; use selected Drive files instead of blanket access.

Data handling

What Nurii stores and protects.

Nurii stores what its product, billing, support, and security functions need.

Account, organization, membership, role, billing, and trial information.

Connector metadata, selected resource settings, encrypted credentials, synced records, and provider identifiers.

AI chat, dashboard, automation, Knowledge, file, memory, approval, action history, and audit content.

Operational logs, diagnostics, security events, and support communications needed to run the service.

Security implementation, in plain English.

How Nurii limits access, protects credentials, and reviews changes.

Authentication

Supabase authentication protects app access, with organization membership and route-level checks shaping product access.

Credential storage

Connector credentials are encrypted using AES-256-GCM before being written to the private credentials store.

Transport and storage

Nurii uses TLS in transit and relies on hosting and database providers that support encryption at rest.

Connector boundaries

Supported connectors use selected resources, server-side checks, member ownership, or organization permissions to limit data reach.

Webhook and API safety

Provider webhooks and API surfaces use controls such as signature verification, explicit CORS, rate limits, and server-side validation.

Monitoring

Nurii uses diagnostic monitoring for reliability while avoiding secrets and unnecessary payloads in logs.

Privacy controls should be visible, not buried.

Manage connections, permissions, memory, chats, files, and support requests.

No data sales

Nurii does not sell personal information or use customer content for advertising.

Disconnect paths

Authorized users can disconnect integrations, revoke access, and request data deletion according to the Privacy Policy.

Approval and auditability

Action proposals, delivery history, and audit records help teams understand what happened and why.

Service provider clarity

Nurii lists core service providers and feature-specific providers so teams can review how data moves.

Service providers

Current service providers by role.

Some providers apply only when you configure or use their feature.

Infrastructure and data

  • Supabase
  • Render
  • Vercel

Reliability, communications, and website analytics

  • Sentry
  • Resend
  • Google Analytics

Billing

  • Stripe

AI and retrieval

  • OpenRouter, including Groq for primary text inference
  • Voyage
  • Exa when web search is used

Connected services you authorize

  • Google
  • Slack
  • QuickBooks
  • HubSpot
  • Salesforce
  • Klaviyo
  • Asana
  • Notion
  • Trello
  • Mailchimp
  • Meta
  • Planning Center
  • Subsplash
  • WordPress
  • Xero
  • Stripe

Security FAQ

A few direct answers.

How does Nurii protect connected app data?

Scoped connectors, selected resources, permissions, encrypted credentials, validation, monitoring, and action controls keep work authorized.

Does Nurii sell customer data or use it for ads?

No. Nurii does not sell personal information, rent customer data, or use customer content for advertising.

Can Nurii access every file in Google Drive?

No. Drive files are used when a connected member selects them for AI chat or related product workflows.

Can Nurii AI actions change connected systems automatically?

Yes, when an authorized person allows them. Actions are off by default, and some actions always require review.

Where are connector credentials stored?

Connector credentials are stored in a private credentials store and encrypted before storage using AES-256-GCM.

Which service providers does Nurii use?

The current infrastructure, monitoring, billing, AI, retrieval, and connected-service providers appear here and in the Privacy Policy.

Where can I read the full Nurii Privacy Policy?

It covers data, AI processing, providers, retention, disconnects, deletion, and user rights.

Automate recurring work across your church systems.

Start with one verified report, check, or follow-up workflow.