Privacy
What we hold, and who can see it
Bene exists to keep a careful record of people at a hard moment in their lives. That record deserves more care than most software gives it. This page says plainly what is collected, who can read it, where it lives, and what we will never do with it.
Last updated 8 August 2026
Who is responsible for what
Two organisations are involved, and the distinction matters.
Your church decides. It chooses what questions to ask, who on its team may read a case, how long to keep records, and what to do about any request. In data-protection language, the church is the controller. If you asked a church for help and want to know why they hold something, or want it corrected or removed, they are the ones to ask.
We keep it running. Bene is built and operated by Cotek App FZ-LLC. We store and process information on behalf of each church, under its instructions. We are the processor. We do not decide what a church asks, and we do not use what churches hold for any purpose of our own.
Two kinds of people are recorded here
People who ask for help. If you have submitted a request through a church’s link, this is about you.
People who serve. Deacons, deaconesses, pastors, elders, treasurers, administrators — anyone invited into a church’s account.
If you asked a church for help
What is recorded is whatever that church chose to ask, which may include:
- Your name, and what you prefer to be called.
- How to reach you — email, phone, WhatsApp, when you are free, which language you are easiest in.
- Details about you such as date of birth, nationality, gender or marital status.
- Where you live, and who lives with you.
- Your connection to the church.
- What you need, how much, how soon, and the account you gave of your situation.
- Your work and money situation, if the church asks about it.
- Help you have had before, and what you hope will change.
- Anything you upload — documents supporting the request, and receipts afterwards.
- Anything you write to the church through Bene, and anything they write back.
- What the church decided, when, and any money released to you.
- If you asked for prayer, what you asked prayer for.
A church can switch most of these questions off. What it asks is its own decision, and different churches ask different things.
Your draft stays on your device. While you are filling in a request, what you have typed is saved in your own browser so you do not lose it if the page closes. It is removed once you submit.
Your status link. After submitting you are given a private link that shows where your request has reached, lets you write to the church, and later lets you upload receipts. That link is the key to your case — anyone holding it can see everything on it — so please do not forward it on.
Because it is the key, it is treated as one. The form does not ask you to prove the email address is yours, so if a request is submitted naming an address that has asked this church for help before, the link is sent to that address and is not shown on screen. Nobody can obtain your link by typing your email into a public form. If you lose it, ask for it again on the tracking page and it will arrive in your inbox. The link itself is thirty-two bytes of cryptographic randomness, not a guessable identifier.
If you serve in a church
Your name, email address, a securely hashed password, and optionally a phone number and photograph. Within each church: your role, title, approval limit, the dates of your term, whether you signed the church’s benevolence agreement, and your answers to the questions that church asks of anyone it invites into this work.
Actions that matter are recorded against your name — approving a gift, declining one, releasing money, exporting a report, or opening a restricted case. That record includes the IP address the action came from. This is deliberate: money and confidences are involved, and a record that cannot say who did what is not a record.
Who can read a case
Not everyone with an account. Bene separates two things that most software confuses:
- What you may do — approve, decline, pay, invite, administer. This comes from your role.
- What you may read — this comes from the case itself.
What you confided on a request marked sensitive stays with the caseworker carrying it — not the administrator, not whoever happens to run the account. Running a church’s account is not the same as being entitled to read someone’s medical crisis.
Unless the church has decided otherwise, its pastors and elders can see that the case exists — its reference, who is carrying it, what stage it has reached and the amount — without what you wrote. They bear responsibility for the church, and cannot exercise it over something they cannot see.
Where someone with oversight judges they must read a sensitive case in full, they can. It requires a written reason, it is recorded permanently, and it emails the caseworker at once to tell them it happened. Nobody looks quietly.
A treasurer sees who was paid and how much, and nothing of why. Not the account you gave of your situation, not your documents, not what you asked prayer for.
What we never do
- We do not sell anything held here, to anybody, ever.
- We do not advertise, and we do not let anyone advertise to you through Bene.
- We run no analytics, no tracking pixels and no third-party scripts. There is nothing following you.
- We do not use what churches hold to train artificial intelligence.
- We do not read case narratives. Our access to a church’s data is for keeping the service running.
- We set no cookies for marketing. The only ones are the two that keep you signed in.
Cookies, and what little there are
A session cookie keeps you signed in. A second small cookie remembers which church you are currently working in, for the few people who serve more than one. Both are necessary for the service to function and neither follows you anywhere else. Someone asking a church for help is not asked to accept any cookie at all.
Where it is kept, and who else touches it
We use a small number of established providers, each doing one job:
- Neon — the database holding church records.
- Vercel — hosting, and the storage where uploaded documents and receipts are kept.
- Resend — sending the emails Bene sends on a church’s behalf.
These providers operate internationally, which means information may be stored or processed outside your own country. Each is bound by contract to handle it only as instructed and to protect it appropriately. We add no others without updating this page.
Typefaces are served from our own servers, so viewing Bene makes no request to any font or advertising network.
How long it is kept
A church’s records stay with that church. They persist when a deacon’s term ends — the church keeps its history, and decides what a successor inherits — and they are deleted when the church deletes them or closes its account.
If a church closes its account, we remove its data from our live systems within 30 days, and from routine backups within 90 days.
Your rights
Depending on where you live, you may have the right to ask for a copy of what is held about you, to have it corrected, to have it deleted, to object to how it is used, or to complain to a regulator.
Ask your church first. They decide what is held and are usually able to act immediately. If you cannot reach them, or they cannot help, write to us at support@cotek.live and we will assist the church in responding.
One limit worth stating honestly: a church may need to keep a record of money it gave, even after other details are removed, because it is accountable to its members and sometimes to an auditor for what it did with money entrusted to it.
How it is protected
- Everything travels encrypted, and is encrypted where it is stored.
- Passwords are never stored. They are hashed with bcrypt at twelve rounds and cannot be read back.
- Each church’s data is separated from every other church’s at the level of every query.
- Access follows the confidentiality rules above, enforced on the server and not merely hidden in the page.
- Reports and exports never contain case narratives — only the facts of what was decided and paid.
- Significant actions are written to an audit log that cannot be edited from within the application.
- Every credential that travels in a link — your status link, an invitation, a password reset — is thirty-two bytes from a cryptographic random source. Reset and invitation links are stored only as a SHA-256 hash, so reading the database yields nothing usable.
- Pages are sent with a same-origin referrer policy, so a link that carries a key in its address never leaks that address to another site — not even to the storage host an attachment loads from.
- The pages are not allowed to be framed by another site, which closes the trick of laying an invisible page over a real one to harvest a click.
- Signing in, asking for a reset, submitting a request and opening a status link are rate-limited, so guessing at a password or a link is slow and expensive rather than free.
No system is perfect. If we discover a breach affecting a church’s data, we will tell that church without undue delay and help them meet whatever obligations they have.
Telling us about a security problem
If you believe you have found a way to see something in Bene you should not, please write to support@cotek.live and describe it. We would far rather hear from you than not. Please do not access, download or alter anybody else’s data while demonstrating the problem — tell us what you found and we will reproduce it ourselves. We will acknowledge you within a few days, keep you informed while we fix it, and we will not pursue anyone who reports something in good faith and in that way.
Children
Bene is not intended for use by children. Requests are made by adults. A request will often name children in a household — their ages, their schooling — and that information is held with the same care as everything else and seen by the same small number of people.
Changes to this page
If we change how any of this works, we will update this page and change the date at the top. Where a change is significant, we will tell church administrators by email rather than leaving them to notice.
Who we are, and who to write to
Bene is a product of Cotek App FZ-LLC, a Free Zone Limited Liability Company licensed by the Ras Al Khaimah Economic Zone Authority (RAKEZ), United Arab Emirates.
- Licence number 47031236
- VUNE0564, Compass Building — Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates
- support@cotek.live
Questions about any of this? Write to support@cotek.live.