Her Prayer Request Became Training Data
Confidential disclosure, data exposure, and institutional betrayal
“I told the church because I thought it was sacred. Why is part of my story showing up on somebody else’s screen?”
Case at a glance
- Pace
- Acute discovery with long-term consequences
- Harm domains
- Emotional · Relational · Institutional · Reputational · Privacy
- Practice focus
- Caring for a person harmed by institutional technology use while the church investigates, communicates, and accepts responsibility.
- Practice posture
- Receive before correcting. Probe before preaching. Preserve agency while naming risk.
The case
Imani Brooks shared a confidential prayer request through the church website during a difficult custody dispute. She described her child’s anxiety, her former partner’s threats, and a past hospitalization. The form stated that submissions would be seen only by the pastoral-care team. A volunteer later copied several requests into an AI writing tool to produce concise summaries for the weekly care meeting. No names were intentionally included, but the narratives contained distinctive details.
Two months later, another staff member used the same organizational AI account to draft a pastoral-care training example. The generated response included phrases and circumstances strikingly similar to Imani’s request. A screenshot was shared in a staff group chat before someone recognized the details. The church cannot yet determine whether the system retained the original text, whether account history was visible, or whether the resemblance was coincidental. At least nine people have now seen the screenshot.
Imani learns about the incident from a friend rather than from church leadership. She is furious and frightened that details could reach her former partner or affect the custody case. She says the church’s assurances about confidentiality were false and wants to know exactly who read the request, where it was stored, and whether it can be deleted. The senior pastor wants to apologize immediately but has been advised not to speculate before technical and legal review.
Imani agrees to meet but says she does not want a prayer, a lesson about forgiveness, or an explanation of how useful AI can be. She wants accountability and control over her information. Other people who submitted prayer requests may also have been affected, though they have not been notified. Staff members are anxious about blame, and the volunteer who copied the material is distraught and wants to contact Imani personally.
What is known—and what is not
Known so far
The church promised restricted access to prayer requests.
Confidential material was entered into an AI tool without Imani’s knowledge or consent.
A generated example resembling her story circulated among staff.
Imani faces possible personal, legal, and relational consequences.
The institution has pastoral, technical, governance, and communication responsibilities.
Still uncertain
What data the vendor retained, how account history functioned, and whether deletion is possible.
How many requests were entered and who may have accessed outputs or screenshots.
Whether notification, reporting, insurance, legal, or denominational duties apply.
Whether the former partner has obtained any information.
What form of apology, repair, and ongoing care Imani would consider meaningful.
Pastoral response questions
Pause before solving. Imagine that you are the leader receiving this person or community. What do you notice, what do you need to learn, and what is the next faithful step?
Begin with the person
What does Imani need to hear before any explanation of the technology or staff intent?
How can the church apologize without asking her to comfort the people who caused the harm?
Who should offer pastoral care if trust in the senior pastor or institution is compromised?
Assess safety and urgency
Does the exposure create an immediate custody, stalking, domestic-violence, employment, or self-harm risk?
What information must be contained or preserved now?
Who needs prompt notification, and what can be said honestly while facts remain incomplete?
Look beneath—and notice the AI context
What is the presenting technology problem, and what deeper experience of betrayal is occurring?
How do consent, confidentiality, vendor retention, shared accounts, and plausible reconstruction differ from ordinary staff note-taking?
Who is the patient when an institution itself contributed to the harm?
Discern the next faithful step
What belongs to pastoral care, and what requires privacy, legal, cybersecurity, safeguarding, or denominational expertise?
How can Imani have meaningful choices about contact, records, and repair?
What should happen with the volunteer’s desire to apologize directly?
Plan follow-up
How will the church report verified findings and unresolved questions?
What support will be offered without conditioning it on silence, forgiveness, or continued membership?
What policies, training, forms, vendor decisions, and accountability practices must change?
Designing a tool for when you are stuck
Use these final questions to test what a practical pastoral field guide would need to provide.
What should a field guide say when the caregiver’s institution caused the harm?
How can it distinguish pastoral apology from technical investigation and legal response?
What prompts keep consent, power, and repair visible?
Practice note This is a fictional composite for learning, not a diagnostic instrument or substitute for local emergency, safeguarding, legal, clinical, or denominational protocols. Question to hold: What does this person need from a human caregiver right now—and what does the presence of AI require us to notice? |
|---|
Developed from the AI Pastoral Toolkit Design Sprint case corpus and Day One Synthesis and Design Charge (July 2026).
All practice cases are composites written for training and discussion. They do not describe real, identifiable people.