Security & privacy
Protect congregation data with clear access boundaries.
Protect sensitive church data with scoped connectors, encrypted credentials, selected resources, permissions, and action controls.
Scoped access
Nurii uses only authorized apps, files, calendars, channels, properties, sites, and accounts.
Encrypted credentials
Connector credentials are stored in a private credentials store and encrypted before storage using AES-256-GCM.
Reviewed action threads
Review changes or allow selected actions, then continue dependent work.
Access model
Nurii starts from what church leaders intentionally connect.
Usable data depends on the connector, selected resources, permissions, and approved workflow.
Organization and member boundaries
Connection ownership, team membership, and permissions control usable data.
Selected files and resources
Use selected Drive files and limit connectors by resource or permission.
Context-aware AI processing
Each workflow uses needed context, not open-ended access to every connected source.
Action controls
Teams choose which actions need review and which can run automatically.
AI agent governance
AI agent governance controls stay visible before action.
See the proposed action, connector, approval mode, and available stop or undo controls.
AI agent governance controls
Approval cards, action history, connector boundaries, and review settings govern system changes.
Approval modes
Keep sensitive actions under review. Allow routine actions only with a clear owner and scope.
Stop controls
Interrupt active work before its next dependent step.
Undo and action history
Undo supported actions where available; inspect approvals, failures, and follow-up.
Sensitive Google scopes
Request sensitive Google scopes only when needed; use selected Drive files instead of blanket access.
Data handling
What Nurii stores and protects.
Nurii stores what its product, billing, support, and security functions need.
Account, organization, membership, role, billing, and trial information.
Connector metadata, selected resource settings, encrypted credentials, synced records, and provider identifiers.
AI chat, dashboard, automation, Knowledge, file, memory, approval, action history, and audit content.
Operational logs, diagnostics, security events, and support communications needed to run the service.
Security implementation, in plain English.
How Nurii limits access, protects credentials, and reviews changes.
Authentication
Supabase authentication protects app access, with organization membership and route-level checks shaping product access.
Credential storage
Connector credentials are encrypted using AES-256-GCM before being written to the private credentials store.
Transport and storage
Nurii uses TLS in transit and relies on hosting and database providers that support encryption at rest.
Connector boundaries
Supported connectors use selected resources, server-side checks, member ownership, or organization permissions to limit data reach.
Webhook and API safety
Provider webhooks and API surfaces use controls such as signature verification, explicit CORS, rate limits, and server-side validation.
Monitoring
Nurii uses diagnostic monitoring for reliability while avoiding secrets and unnecessary payloads in logs.
Privacy controls should be visible, not buried.
Manage connections, permissions, memory, chats, files, and support requests.
No data sales
Nurii does not sell personal information or use customer content for advertising.
Disconnect paths
Authorized users can disconnect integrations, revoke access, and request data deletion according to the Privacy Policy.
Approval and auditability
Action proposals, delivery history, and audit records help teams understand what happened and why.
Service provider clarity
Nurii lists core service providers and feature-specific providers so teams can review how data moves.
Service providers
Current service providers by role.
Some providers apply only when you configure or use their feature.
Infrastructure and data
- Supabase
- Render
- Vercel
Reliability, communications, and website analytics
- Sentry
- Resend
- Google Analytics
Billing
- Stripe
AI and retrieval
- OpenRouter, including Groq for primary text inference
- Voyage
- Exa when web search is used
Connected services you authorize
- Slack
- QuickBooks
- HubSpot
- Salesforce
- Klaviyo
- Asana
- Notion
- Trello
- Mailchimp
- Meta
- Planning Center
- Subsplash
- WordPress
- Xero
- Stripe
Security FAQ
A few direct answers.
How does Nurii protect connected app data?
Scoped connectors, selected resources, permissions, encrypted credentials, validation, monitoring, and action controls keep work authorized.
Does Nurii sell customer data or use it for ads?
No. Nurii does not sell personal information, rent customer data, or use customer content for advertising.
Can Nurii access every file in Google Drive?
No. Drive files are used when a connected member selects them for AI chat or related product workflows.
Can Nurii AI actions change connected systems automatically?
Yes, when an authorized person allows them. Actions are off by default, and some actions always require review.
Where are connector credentials stored?
Connector credentials are stored in a private credentials store and encrypted before storage using AES-256-GCM.
Which service providers does Nurii use?
The current infrastructure, monitoring, billing, AI, retrieval, and connected-service providers appear here and in the Privacy Policy.
Where can I read the full Nurii Privacy Policy?
It covers data, AI processing, providers, retention, disconnects, deletion, and user rights.
Automate recurring work across your church systems.
Start with one verified report, check, or follow-up workflow.
