Legal
Privacy Policy & Cookie Notice
Effective August 2026 · Last updated August 2026
This policy explains what personal information Rhema.art collects, how we use it, who we share it with, and the choices and rights you have.
1. Introduction
Welcome to Rhema.art, an AI-powered creative platform designed to help churches, ministries, Christian organisations, faith communities and other users create digital flyers, promotional graphics, captions and related visual content.
Rhema.art is operated by EFZ Solutions and/or its applicable affiliated or operating entities registered in the United Kingdom and Nigeria.
For purposes of this Privacy Policy, "Rhema.art", "Rhema", "we", "us" or "our" means the entity responsible for the relevant Rhema.art service.
This Privacy Policy explains:
- what personal information we collect;
- how and why we use it;
- how we use artificial intelligence and third-party AI providers;
- how we handle photographs and images of individuals;
- when and why information is shared with third parties;
- how long information is retained;
- how cookies and similar technologies are used;
- how international transfers are handled;
- your privacy rights; and
- how you can contact us.
This Privacy Policy applies to the Rhema.art website, application, software, services, APIs and related digital products, together referred to as the "Service".
By using Rhema.art, you acknowledge that you have been provided with this Privacy Policy. Where applicable law requires consent for a particular processing activity, we will obtain that consent separately.
2. Who is responsible for your personal data
The applicable data controller responsible for your personal data is:
- Legal entity: EFZ SOLUTIONS LIMITED
- Trading name: EFZ Solutions / Rhema.art
- Company number: CAC No. 9342965
- Registered office: 10 Alfred Jonah Street, Off Shell Road, Sapele, Delta State, Nigeria
Where different EFZ Solutions entities operate different aspects of Rhema.art, the applicable entity will be identified in the relevant contract, invoice, order confirmation or other documentation.
3. Regulatory framework
Depending on where you live, where you access Rhema.art, and the circumstances in which your information is processed, our processing may be subject to:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Privacy and Electronic Communications Regulations 2003 ("PECR");
- the Nigeria Data Protection Act 2023 ("NDPA");
- applicable United States federal and state privacy laws, including the California Consumer Privacy Act, as amended ("CCPA/CPRA"), where applicable;
- applicable African data-protection legislation, including the Protection of Personal Information Act ("POPIA") where applicable;
- other mandatory privacy and consumer-protection laws applicable to your jurisdiction.
We will apply the legal requirements applicable to the relevant processing activity and user.
4. Information we collect
We collect information necessary to create and operate your Rhema.art account and provide the Service.
4.1 Account information
When you create an account, we may collect:
- full name;
- email address;
- password;
- username, where provided;
- account role;
- email-verification status;
- authentication provider;
- Google account identifier where you use Google sign-in;
- subscription plan;
- Stripe customer and subscription identifiers;
- account creation and last-login information; and
- security and authentication information such as login, password-reset and verification-attempt counters.
We do not ordinarily collect your telephone number, date of birth or residential address merely to create a Rhema.art account.
Passwords are not stored in plain text. Passwords are stored as a one-way bcrypt hash.
5. Google sign-in
If you choose to sign in using Google, we may receive information made available by Google under the permissions associated with the sign-in process, including:
- your name;
- email address; and
- Google account identifier.
We do not intentionally store your Google password, Google access tokens or Google profile photograph.
Your use of Google authentication is also subject to Google's own privacy practices.
6. Content you provide to Rhema.art
You may provide information and content to us when using the Service. This may include:
- church or ministry names;
- event names;
- event dates and times;
- venues;
- themes;
- sermon titles;
- Bible quotations;
- captions;
- promotional text;
- project names;
- project descriptions;
- church websites;
- social-media handles;
- branding preferences;
- colour and style preferences;
- photographs;
- speaker images;
- pastor images;
- other images;
- flyer designs;
- generated content; and
- feedback or screenshots submitted to us.
Some of this information may contain personal data relating to you or other individuals.
7. Photographs and images of other people
Rhema.art allows users to upload photographs of pastors, speakers, ministers, guests and other individuals for the purpose of generating promotional designs.
If you upload a photograph of another person, you are responsible for ensuring that you have all necessary rights, permissions, licences and consents required to upload, process, transform and publish that photograph.
This is particularly important where:
- the person is identifiable;
- the image depicts a child;
- the image contains sensitive information;
- the photograph is used commercially;
- the image is used for AI generation or transformation; or
- the resulting image is published publicly.
Rhema.art does not represent that the mere upload of a photograph establishes that the relevant individual has consented to its use.
You must not upload an image where doing so would breach privacy, publicity, likeness, copyright, data-protection or other applicable rights.
Where required by law, Rhema.art may ask you to demonstrate that you have an appropriate legal basis or permission to process an individual's image.
8. AI processing
Rhema.art uses artificial intelligence and third-party AI service providers to provide features including:
- image generation;
- image transformation;
- text generation;
- captions;
- promotional wording;
- alternative image descriptions; and
- other creative functionality.
Depending on the feature used, information submitted to Rhema.art may be transmitted to third-party AI providers. For example:
- OpenAI: flyer prompts and uploaded speaker photographs may be processed for image generation.
- OpenRouter: event information, quotes, captions and other user-provided text may be processed for AI text functionality. Depending on the image provider we have configured, flyer prompts and uploaded images may also be processed for image generation through models made available by OpenRouter.
- Google Gemini: a YouTube URL submitted for quote extraction may be processed by Google, including retrieval and processing of the relevant video content.
AI providers may process information according to their applicable contracts, privacy policies and data-processing terms.
8.1 AI training
As at the effective date of this Privacy Policy, Rhema.art does not use users' content to train its own AI models.
Rhema.art may review its AI-data practices in the future. If we intend to materially change how user content is used for AI training or model improvement, we will update this Privacy Policy and obtain consent where required by applicable law before commencing such processing.
9. Generated flyers and public URLs
Generated flyer images, thumbnails and certain feedback screenshots are stored using Cloudinary.
Some generated images are served through publicly accessible URLs. This means that a generated image may be accessible to anyone who obtains the relevant URL. Accordingly:
- Rhema.art should not be treated as a confidential image-storage service.
- You should not upload or generate material containing information that you do not want potentially accessible through a public URL.
Public URLs may also be used where you instruct Rhema.art to publish content to Facebook or Instagram.
Deleting content from your Rhema.art account may not remove copies that have already been:
- downloaded;
- shared;
- published;
- reposted;
- cached;
- stored by a social-media platform; or
- retained in limited technical backups.
10. Brand profiles
You may provide brand information such as:
- church or ministry name;
- website;
- social-media accounts;
- visual identity;
- preferred design style;
- colour preferences; and
- other branding information.
We use this information to customise the Service and generated designs.
11. How we use your personal data
We use personal data for purposes including:
| Purpose | Examples | Lawful basis where applicable |
|---|---|---|
| Account creation | Creating and maintaining your account | Contract |
| Authentication | Login, verification and password reset | Contract / legitimate interests |
| Providing the Service | Creating flyers and projects | Contract |
| AI functionality | Generating images and text | Contract / consent where required |
| Payments | Processing subscriptions | Contract / legal obligation |
| Customer support | Responding to enquiries | Contract / legitimate interests |
| Security | Fraud prevention, rate limiting and account protection | Legitimate interests / legal obligation |
| Service improvement | Understanding usage and performance | Consent where required / legitimate interests |
| Analytics | Google Analytics | Consent where required |
| Social publishing | Publishing content to Facebook or Instagram at your request | Contract / your instruction |
| Legal compliance | Tax, accounting and legal obligations | Legal obligation |
| Enforcement | Protecting our rights and preventing misuse | Legitimate interests |
| Communications | Verification, password resets and service messages | Contract / legitimate interests |
Where consent is the lawful basis, you may withdraw consent at any time, although this will not affect processing lawfully undertaken before withdrawal.
12. Google Analytics
Rhema.art uses Google Analytics 4 to understand how visitors and users interact with the Service.
Analytics is not loaded until you accept it. When you first visit, we ask whether you are willing to allow analytics. Until you accept, the Google Analytics script is never requested and no analytics cookie is set.
If you accept, analytics may collect information including:
- pages visited;
- approximate interaction information;
- device and browser information;
- usage patterns; and
- other analytics identifiers.
Google Analytics is not necessary to provide the core account service, and declining it does not limit any part of Rhema.art.
You can change your answer at any time using the Cookie settings link in the site footer. If you withdraw consent, we clear the Google Analytics cookies already stored in your browser and the analytics script is not loaded again.
Essential authentication and security technologies operate without consent, as applicable law permits for storage that is strictly necessary to deliver a service you have requested.
We intend to configure analytics retention to an appropriate limited period, currently proposed to be 14 months, subject to technical implementation and legal requirements.
14. Third-party service providers
Rhema.art uses selected third-party providers to operate the Service. These may include:
| Provider | Purpose | Information potentially processed |
|---|---|---|
| OpenAI | AI image generation | Prompts and uploaded speaker images |
| OpenRouter | AI text and caption generation, and image generation where configured | Event details, quotations, captions, prompts and uploaded images |
| Google Gemini | YouTube quote extraction | Submitted YouTube URLs and content |
| Cloudinary | Image storage and CDN | Generated flyers, thumbnails, uploads and feedback screenshots |
| Resend | Transactional email | Email address and message content |
| Stripe | Payments and subscriptions | Name, email and billing identifiers |
| Google OAuth | Authentication | Google ID, name and email |
| Meta / Facebook | Facebook publishing | Flyer URL, caption and Page access credentials |
| Instagram / Meta | Instagram publishing | Flyer URL, caption and access credentials |
| Google Analytics | Analytics | Website and usage information |
We seek to use reputable providers and appropriate contractual, organisational and technical safeguards.
16. Payment information
Payments and subscriptions are processed through Stripe. Rhema.art does not ordinarily receive or store your full payment-card number.
We may receive and store information such as:
- your name;
- email address;
- Stripe customer ID;
- subscription ID;
- payment status;
- subscription plan;
- transaction identifiers; and
- limited billing information necessary for accounting and customer support.
Stripe processes payment information under its own terms and privacy documentation.
17. Email
We use Resend or another designated transactional-email provider to send necessary service emails, including:
- account verification;
- password reset;
- account notifications;
- security communications; and
- other essential transactional messages.
Rhema.art does not currently operate a general marketing newsletter through this system.
18. Data sharing
We do not sell your personal information in the ordinary sense of selling personal information for monetary consideration.
We may disclose information to:
- technology providers;
- AI providers;
- payment processors;
- cloud-storage providers;
- email providers;
- authentication providers;
- social-media platforms;
- analytics providers;
- professional advisers;
- insurers;
- law-enforcement agencies;
- regulators;
- courts; and
- prospective purchasers or investors in connection with a merger, acquisition, restructuring or sale of the business.
We only share information where reasonably necessary for the relevant purpose and subject to applicable legal requirements.
19. International data transfers
Rhema.art serves users internationally and uses service providers located in countries including the United States. Consequently, personal data may be transferred outside the United Kingdom, Nigeria or your country of residence.
Where applicable law requires safeguards for international transfers, we will use an appropriate mechanism, which may include:
- an adequacy decision;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- appropriate contractual protections;
- an approved Nigerian cross-border transfer mechanism;
- another legally recognised transfer mechanism; or
- a lawful statutory derogation where applicable.
We will take appropriate steps to ensure that international transfers receive the protection required by applicable data-protection law.
20. Data security
We implement technical and organisational measures designed to protect personal information. These measures include, as applicable:
- bcrypt password hashing;
- HTTP-only authentication cookies;
- HTTPS/TLS in transit;
- role-based access control;
- rate limiting;
- temporary lockouts after repeated failed login, verification or password-reset attempts;
- AES-256-GCM encryption of stored social-media tokens;
- CORS restrictions;
- HTTP security headers;
- Stripe webhook-signature verification; and
- controlled access to systems.
No internet-based service can guarantee absolute security. You are responsible for keeping your password and account credentials confidential.
21. Data retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required by law. Our retention periods are:
Account information
While your account remains active. Following account closure or a valid deletion request, information will generally be deleted or anonymised within approximately 30 days, subject to legal and technical exceptions.
Flyers and projects
Active content remains available while your account is active. Deleted flyers and projects are moved to trash, where they can be restored, and are permanently purged by a daily job 30 days after deletion.
Billing and accounting records
Certain financial and transaction records may be retained for approximately six years, or such other period as required by applicable tax, accounting or legal requirements.
Analytics
Analytics data is intended to be retained for approximately 14 months, subject to configuration and applicable law.
Security records
Security and authentication records may generally be retained for approximately 12 months, unless a longer period is reasonably required to investigate security incidents or comply with law.
Social-media tokens
Tokens are retained while necessary to provide the social-publishing functionality or until you disconnect the relevant service.
Backups
Deleted information may remain temporarily in encrypted backups until those backups are overwritten through our normal backup cycle, which may generally be between 30 and 90 days.
22. Your data-protection rights
Depending on your location and applicable law, you may have rights including:
- the right to be informed;
- the right to access your personal information;
- the right to correct inaccurate information;
- the right to request deletion;
- the right to restrict processing;
- the right to object to processing;
- the right to data portability;
- the right to withdraw consent;
- rights concerning automated decision-making;
- rights concerning certain uses of sensitive information; and
- the right to complain to a relevant supervisory authority.
Nigeria's NDPC identifies, among other rights, rights of information, access, rectification, objection, restriction, portability, erasure and rights relating to automated decision-making.
UK privacy law similarly requires transparent information about purposes, lawful bases, recipients, transfers, retention and available rights.
23. How to exercise your rights
Your request should, where possible, include:
- your name;
- account email;
- the nature of your request; and
- sufficient information to verify your identity.
We may request additional information where reasonably necessary to protect against fraudulent or unauthorised requests.
We aim to respond within the period required by applicable law.
24. Account deletion
Subject to applicable law, deletion will result in the removal or anonymisation of account-associated information.
Deletion does not necessarily require immediate deletion of:
- information we are legally required to retain;
- accounting records;
- information necessary to establish or defend legal claims;
- security records;
- information contained in unavoidable backups; or
- content already published to third-party services.
25. Children
Rhema.art is intended for adults and organisational users. We expect account holders to be at least 18, or the age of majority in their jurisdiction if that is higher.
We do not ask for your date of birth and we do not run any age verification. We hold no information about how old a user is, so we cannot tell from an account alone whether it belongs to an adult. We treat not collecting that information as the more privacy-protective choice.
Rhema.art is not directed at children and we do not knowingly collect children's personal data. Section 7 covers your separate responsibilities when you upload a photograph of a child.
26. Automated decision-making
Rhema.art uses AI to assist with creative content generation.
AI-generated content is not intended to determine a user's legal rights, eligibility, employment, creditworthiness, healthcare entitlement, immigration status or other similarly significant matters.
Creative AI outputs are generated algorithmically and may be inaccurate, incomplete, inappropriate or unsuitable for a particular purpose.
27. Your responsibility for third-party information
Where you upload information relating to another individual, you are responsible for ensuring that you have a lawful basis to provide that information to Rhema.art. This includes, where applicable:
- photographs;
- names;
- quotations;
- biographies;
- contact information; and
- other identifying information.
Where required, you should inform the individual that their information will be processed using Rhema.art and relevant third-party service providers.
28. Data breaches
We maintain procedures for identifying, investigating and responding to suspected personal-data breaches.
Where applicable law requires notification to a regulator or affected individuals, we will make the relevant notification within the applicable statutory period.
29. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect:
- changes to the Service;
- changes to our technology;
- new processing activities;
- changes in law;
- changes to third-party providers; or
- improvements to transparency.
Where a change materially affects your rights or how we use your personal data, we will provide an appropriate notice and, where required, obtain consent.
30. Complaints
You may also have the right to complain to the data-protection regulator in your country.
- For UK users, the relevant supervisory authority is the Information Commissioner's Office (ICO).
- For Nigerian users, the relevant supervisory authority is the Nigeria Data Protection Commission (NDPC).
31. Contact us
For privacy questions, requests or complaints:
- Rhema.art / EFZ Solutions
- Legal entity: EFZ Solutions Limited
- Registered office: 10 Alfred Jonah Street, Off Shell Road, Sapele, Delta State, Nigeria
- Website: https://rhema.art