Church social media policy: the full text, the photo rules, and who holds the login
A complete policy a board can adopt, a decision tree for whether you may post a photo, the minor consent statutes quoted, the offboarding rule, and the procedure for 11pm on a Saturday.
At 11:04 on a Saturday night there is a photograph of the children’s program on the church Facebook page. Forty-one people have seen it. One of them is a mother whose custody order says her daughter’s image is not to appear anywhere public, and she is typing. The photograph was posted by a volunteer who holds the password, who is asleep, and who moved out of state in March.
Nobody did anything malicious. What that church did not have was one page saying who may post, whose picture may appear, who else can get into the account at 11pm, and what the first five minutes look like. This page is that document, the legal grounding under the parts that have any, and the arithmetic on the two things it will cost you.
Take the policy with you. The full policy text is a markdown file with fifteen numbered sections and every church-specific value in square brackets. Blank the brackets, read it in a meeting, vote, file the signed copy with your bylaws. Three companion files sit beside it: the photograph and recording permission forms, the incident log as a CSV, and the six recurring review jobs as a calendar file you can subscribe to.
The short version
A church social media policy answers six questions and nothing else matters until it does.
Who may speak as the church. A named list, maintained by one role, reviewed quarterly. Being on staff does not put you on it. Being a volunteer does not keep you off it.
Whose picture may appear. Three consent levels. No recognizable image of anyone under 18 without a signed parent release dated inside twelve months. A No-Photo list anyone may join by asking, with no reasons recorded.
Who holds the credentials. The church, on the church’s own domain, in a shared vault, with two-factor on and the recovery phone number going to the office rather than to a volunteer’s cell.
What is never posted. Anything from a pastoral conversation, any screenshot of a private message, any personnel matter, and any minor’s location at a stated future time.
How comments are handled. Checked every 24 hours by a named person. Disagreement stays up. Sexual content, threats, doxxing, and named accusations come down and the author is blocked.
What happens when it goes wrong. Take it down first, and never discipline anyone for taking something down too fast.
The rest of this page is those six answers written out far enough to adopt.
What separates a policy from good advice
Search this and you mostly get conduct essays. Be gracious online. Remember whom you represent. Think before you post. All true, and none of it is a policy, because a policy is a document that answers a question at 11pm with the author asleep.
Five properties make the difference. It names roles rather than people, so it survives a resignation. It states a standard that can be failed, so a violation is identifiable. It assigns each decision to exactly one role. It hands out authority as well as restriction, which is the part almost every draft misses. And it carries a review date, because a policy assuming a platform control the platform has since removed is worse than none.
Can we post this photo?
Seven tests, in order, before anything with a person in it goes up. Fail one and you are somewhere other than publish.
Print it and tape it inside the door of the room where the camera lives. The order matters: test one is free, test two costs a phone call, and test seven costs a license, so running them in order means the cheapest disqualification comes first. The four pre-post checks in the weekly checklist are the shorter version for a volunteer who runs this every Thursday and has the tree memorized.
When does the law actually reach a church photograph?
Almost never for the Sunday recap, and squarely for the capital campaign. The distinction is the word every relevant statute turns on: commercial, advertising, or trade purpose.
New York makes it a misdemeanor. Civil Rights Law section 50 reads: “A person, firm or corporation that uses for advertising purposes, or for the purposes of trade, the name, portrait, picture, likeness, or voice of any living person without having first obtained the written consent of such person, or if a minor of such minor’s parent or guardian, is guilty of a misdemeanor.” Section 51 adds the civil side, for a likeness “used within this state for advertising purposes or for the purposes of trade without the written consent first obtained,” and gives the subject an action to restrain the use and recover damages.
California attaches a floor to the damages. Civil Code section 3344 covers anyone who “knowingly uses another’s name, voice, signature, photograph, or likeness, in any manner, on or in products, merchandise, or goods, or for purposes of advertising or selling, or soliciting purchases of, products, merchandise, goods, or services, without that person’s prior consent,” and the subject recovers “the greater of seven hundred fifty dollars ($750) or the actual damages suffered,” plus any profits. For a person under the age of majority the statute requires “the prior consent of their parent or legal guardian.”
Florida writes the exemption out loud, which is the useful part. Statute 540.08 bars publishing a likeness “for purposes of trade or for any commercial or advertising purpose” without “the express written or oral consent,” with a minor’s consent given “by the guardian of her or his person or by either parent.” Then subsection (4) exempts use “as part of any bona fide news report or presentation having a current and legitimate public interest and where such name or likeness is not used for advertising purposes.”
Three states, checked on 29 July 2026, and the same shape in each. Your state is probably similar and might not be, and this is the point in the document where a lawyer in your own state earns an hour of billing. Nobody here holds a legal credential, which is why the statutes are quoted rather than summarized.
What follows from it, practically:
- A photograph of the potluck on the church page is not advertising or trade. The statutes above do not reach it.
- The same photograph in a boosted post asking for building fund pledges is advertising, and every recognizable adult in it now needs written consent that names that use.
- A general release signed at registration does not cover the campaign. Consent for advertising is specific to one use, and it does not roll forward.
- Every one of those statutes puts a minor’s consent in a parent’s hand, without exception and without a maturity test.
That is why the policy has three consent levels rather than one, and why level three is a separate signature on a separate form. The permission forms in the download split accordingly: Form A for adults, Form B for a minor, Form C for anything that asks for money or runs as promotion, and Form D for a withdrawal.
Does COPPA apply to a church?
Probably not, and church policy templates that promise COPPA compliance are borrowing a statute that does not govern them. 15 U.S. Code section 6501 defines a child as “an individual under the age of 13” and defines the covered service as “a commercial website or online service that is targeted to children.” 16 CFR 312.2 repeats it: “A commercial website or online service, or portion thereof, that is targeted to children.” A church’s Facebook page is not a commercial online service targeted to children, and the rule’s parental consent obligation under 15 U.S. Code section 6502 attaches to the operator of one.
Borrow the definition anyway, because it is the sharpest one in federal law and it settles an argument churches have every August. 16 CFR 312.2 lists among the items that count as personal information: “A photograph, video, or audio file where such file contains a child’s image or voice.” A picture of a child is that child’s personal information. The Federal Trade Commission says so about commercial operators, and there is no version of church practice where the same picture stops being personal because the publisher is a nonprofit.
One narrow case where the rule may actually bind: a church that runs its own kids app or its own site section built for children and collects anything from them through it. That is closer to an operator than a Facebook page is, and it is worth an hour with counsel rather than a paragraph here. The FTC’s own COPPA compliance FAQ refused an automated request on 29 July 2026, returning 403, so nothing on this page is attributed to it.
The practical rule is the one the media-team-of-one guide already states plainly: the child photograph rule at your church is your policy, not federal law, which means nobody is coming to enforce it and you have to.
The minors rules, written out
These are the provisions that do the work. They live in section 6 of the download and they are stricter than the statutes require, on purpose.
A signed parent or guardian release, naming that child, dated inside twelve months. Not a blanket registration checkbox from four years ago. Twelve months because families change, custody changes, and a signature from 2022 is not evidence of a decision in 2026. Re-collect at the start of the program year rather than chasing them one at a time in October.
First name only, or no name. A first and last name together, attached to a face and a weekly location, is the assembly a stranger needs.
Nothing legible in the frame. No school, team, bus route, house number, street sign, license plate, name badge, check-in tag, or class roster. This is the test that fails most often in practice, and it fails because a phone shoots at a resolution where the volunteer cannot read the tag but a viewer who zooms can.
No location tag on any post containing a minor. The photograph and the pin together answer where and when.
No image of a minor in a swimsuit, in athletic clothing a stranger would read as revealing, or in any state of undress, at any age, for any reason. Camp is not an exception. Baptism is not an exception: photograph it from behind, or after, robed.
No direct message from an adult worker to a minor on any platform, ever. Communication with minors runs through a parent or through a group thread a second adult reads. This belongs to your child protection policy and the social media policy should say the same thing rather than a slightly different thing.
No minor’s location at a stated future time. Announce that youth group meets. Do not announce that eleven named students will be at a named park on Friday at seven. If you are already writing that post, the youth calendar problem is the better place to solve it.
A parent’s no is final and needs no reason. Recorded on the No-Photo list within one business day, effective until the parent changes it in writing.
The kids-ministry side of this has its own set of moving parts. Registration, allergies, ratios, and release collection all happen at the same table on the same morning, which is exactly why the VBS planning order puts paperwork before program.
The No-Photo list has no reasons column
One written list. Every person, adult or minor, whose image is not posted. Stored where every authorized poster can read it before they post. Names only.
There is no reasons column, and that is a design decision rather than an oversight. The moment the list records why, three things follow. Someone reads a reason they were not meant to read. Someone else weighs a reason and decides it is not good enough. And the person asking to be left out learns that asking costs them an explanation, so they stop asking and start being upset instead.
A person joins the list by asking, in any way, through anyone. A parent joins their child by asking. No form is required, though Form D in the download exists for people who prefer paper.
Anyone who cannot check the list before posting does not post. That sentence is what makes the list real, and it is the reason the list has to live somewhere a volunteer can open on a phone in a hallway.
Withdrawal outranks every signature on file, including one signed the same morning. A release is permission, not a transfer of ownership, and a church that answers a takedown request by producing the form the person signed has misunderstood what it was given.
Who may do what
Restriction alone produces a page nobody uses. The matrix below hands out authority as well, and the row that matters most is the one where four roles may delete a church post without asking anyone.
Three deliberate asymmetries in that grid.
Direct messages sit with one person. A church inbox holds crisis messages, abuse disclosures, and pastoral requests, and the volunteer who is good at captions did not sign up to receive them. One named person reads the inbox and one escalation path exists. Moving that conversation to text is a different legal regime with its own consent standard and opt-out clock, worked out in the texting rules.
Posting an image of a minor sits with the kids ministry lead, not the communications lead. The releases live where the children are. A communications lead who wants to post a kids photograph gets a second signature from the person who can actually look up whether the release is current.
Approving a fundraising use sits with the board. That is the use the statutes above reach, it is the one with a damages floor attached in California, and it should require a meeting rather than a Thursday afternoon.
Who holds the login, and what happens when a volunteer leaves
The volunteer in the opening paragraph is the most common failure in this whole subject, and it has nothing to do with photographs. She was helpful for four years, she registered the page under her own Gmail address because that was the fastest way to get it working, and the church has no way to remove her, no way to reset the password, and no way to prove ownership if she stops answering.
Fix ownership first. Everything else is downstream of it.
The account belongs to an address on the church’s domain. Not a personal Gmail. Not a shared address whose password is on a card in the office. Google Workspace for Nonprofits is published at “0 USD / user / month” with 100 TB shared across all users and a ceiling of 2,000 users, checked 29 July 2026, so the cost of doing this correctly is an application rather than a line item.
The recovery phone number is the office line. When the platform sends a code to reclaim the account, it should ring in the building.
Access is granted person by person, through the platform’s own controls, never by sharing a password. Meta’s help center describes three types of Facebook Page access: “Page access, task access and Community Manager access,” and states that “If you have Facebook access with full control of a Page, you can add, edit or remove someone’s Page access at any time,” checked 29 July 2026. Full control is the thing the church needs to hold, and it is the thing a church almost never checks it holds until the week it needs it.
Two-factor is on, and the printed recovery codes sit with an officer rather than with the person who posts. That is why the matrix splits the password and the recovery codes across two roles. One person cannot be locked out by their own departure, and one person cannot lock the church out either.
Offboarding happens within 24 hours of a departure, friendly or not. Remove their access on every platform. Remove them from the vault. Rotate any password they could have read. Open the account’s active sessions and end any the church does not recognize, because removing a person’s access does not end a session already running. Confirm the recovery email and phone are still the church’s. Do it the same way every time, so that doing it says nothing about the person.
That last point is the reason to write it down. An offboarding checklist that only comes out when somebody leaves badly is an accusation. One that runs every time, including for the volunteer who moved for a job and cried at her last Sunday, is administration.
Membership records deserve the same treatment for the same reasons, and the four-tier sort of what a church database holds is the companion piece to this section.
What a shared password vault costs
The policy says passwords live in a shared vault. Here is what that sentence costs, worked out at the number of people who actually need the church’s logins rather than at a seat count somebody guessed.
- Bitwarden Teams
- Bitwarden Enterprise
- 1Password Teams Starter up to 10 members
- 1Password Business
Read off the vendors' own pricing pages on 29 July 2026, at the annual billing rate, rounded to the dollar. Bitwarden publishes Teams at $4 per user per month and Enterprise at $6, both billed annually. 1Password publishes the Teams Starter Pack at $24.95 a month paid annually with 10 members included, and Business at $8.99 per user per month paid annually. 1Password states that it discounts for nonprofits without publishing a rate, so the two 1Password lines are list prices and your invoice may be lower.
See the numbers
| Vendor | 2 people | 4 people | 8 people | 16 people |
|---|---|---|---|---|
| Bitwarden Teams | $96 | $192 | $384 | $768 |
| Bitwarden Enterprise | $144 | $288 | $576 | $1,152 |
| 1Password Teams Starter | $299 | $299 | $299 | not offered |
| 1Password Business | $216 | $432 | $863 | $1,726 |
Read the crossover. Below about four people, the flat Teams Starter Pack is the most expensive option on the board. Between four and eight it wins outright, because a flat $299 beats eight seats at any per-user rate quoted here. Above ten members it stops being available and you are back on a per-user plan, where the cheapest line is $48 per person per year.
Two things the chart does not show. Bitwarden’s free plan lets you “share items with one other existing Bitwarden user by creating a Free organization,” checked 29 July 2026, and two people is one short of a policy: the moment a third person needs the Instagram password, the free organization stops being a mechanism and becomes the reason somebody texts a password.
The other is that the number of people who need the logins is smaller than you think, and shrinking it is free. If access is granted through each platform’s own controls, as the policy requires, almost nobody needs the password itself. The vault holds credentials for the two or three accounts with no delegated access model, plus the recovery codes. A church with six people posting might genuinely need two vault seats, which is $96 a year on the cheapest line, and that is the whole difference between an account the church owns and an account it borrows.
What may staff post about a pastoral conversation?
Nothing. Not the content, not a paraphrase, not an anonymized version, not a sermon illustration with the details changed, and not the fact that the conversation happened. The rule is absolute in the download because every softer version fails in practice: a church that permits “general” reference to pastoral conversations produces a post four people recognize, and the person in it learns that what they said in an office is material.
Three specifics that catch people out.
A screenshot of a private message is a private message. Including one sent to the church’s own account. Including one that is complimentary. Including one where the sender was rude and the screenshot would prove it.
A prayer request does not become public because it was read out. Read aloud in a room is not published to a feed, and the two audiences are not the same size or the same permanence. Getting a yes in writing before a named need goes online takes one text message.
Recording a conversation can be a crime. California Penal Code section 632 reaches “A person who, intentionally and without the consent of all parties to a confidential communication, uses an electronic amplifying or recording device to eavesdrop upon or record the confidential communication,” with a first offense carrying a fine up to $2,500 or up to a year in county jail, and repeat offenses up to $10,000. Subdivision (c) defines a confidential communication as one “carried on in circumstances as may reasonably indicate that any party to the communication desires it to be confined to the parties thereto,” excluding public gatherings. California is one of several states that require the consent of everyone in the conversation rather than just one party, and a church that runs a livestream with a room microphone should know which kind of state it is in before somebody has a hallway conversation eight feet from the lectern. Checked 29 July 2026.
The related rule about counseling notes and where they may never be stored is worked out in detail in the member data piece, and the two documents should agree word for word where they overlap.
The comment moderation rule
Four dispositions, one clock, one named person. Section 10 of the download.
Checked at least once every 24 hours, and within two hours of publishing anything about a contested subject.
Left alone. Disagreement. Criticism of the church, its leadership, a sermon, or this policy. Hard theological questions. A complaint about a real thing. Deleting these teaches the congregation that the page is a stage, and it moves the conversation to a place the church cannot see, which is the outcome moderation was supposed to prevent.
Hidden, with no announcement, so it stays visible to its author and to nobody else: promotion and spam, off-topic argument, a comment naming a private person’s situation, and the same comment posted a fourth time.
Deleted and the author blocked, immediately: sexual content, a sexual approach to any person, content involving a minor that would fail the rules above, threats, slurs, doxxing, a named accusation against an individual, and anything a reasonable person would call harassment. Screenshot the comment and the profile before deleting. This is the one category where the church keeps a copy of what it removes.
Reported first and preserved rather than deleted: any credible threat of harm, and any content involving the sexual exploitation of a minor. Deleting it destroys the evidence. Call law enforcement before investigating internally, and put the number in the policy so nobody has to look it up at 11pm.
One more provision, and it is the one that gets left out. Mandatory reporting is not suspended by a platform. A disclosure of abuse arriving in a comment or a message is handled exactly as it would be if it had been said in a hallway. Reporting duties for clergy and church workers are state law and they vary in whether clergy are named, and whether the clergy-penitent privilege limits the duty. We attempted the federal Child Welfare Information Gateway publication on clergy as mandated reporters twice on 29 July 2026 and both URLs returned 404, so no count of states appears on this page. Get your own state’s rule from your own state, in writing, and name it in the policy.
Where the volume gets high enough that comments and messages need a rota rather than a person, the same argument applies to the whole workload, and the strategy piece works through what one volunteer can actually carry.
The 11pm Saturday procedure
The rule is take it down first. Every authorized poster has standing authority to delete any church post, hide any comment, and take any church account offline without asking permission and without waiting for a decision. Nobody is ever disciplined here for taking something down too fast.
That sentence is the most important one in the document, because the alternative is a volunteer who sees the problem at 11:04, does not have permission, texts three people, and watches the post sit there for two hours while the church looks like it does not care.
Two notes on the stops.
The 30 minute call is made by the lead, not by the person who posted. The volunteer who made the mistake should not be the person telephoning a parent at midnight. That call is a leadership job and offering it to the volunteer as penance is how a church loses a volunteer over a cropping error.
The 24 hour correction is narrower than it looks. A correction is published when the original made a factual claim other people repeated. It is not published to apologize in public to a person who would rather have a phone call, and a church that confuses the two produces a second post the family has to read.
Every entry lands in the incident log CSV, which ships with a worked example row so the shape is obvious: what happened, who was pictured, whether a minor was involved, how long it was visible, when it came down, who was called and when, which policy section it touched, and what changed as a result. Those last two columns are what makes the log worth keeping. An entry that closes without a change will recur.
The song in the recording is not yours
Posting a clip of the service means publishing somebody else’s song, and the license that covers projecting lyrics in the room does not cover posting the recording. CCLI lists them as separate products: the Church Copyright License to “Project song lyrics from a computer or digital device. Print lyrics in bulletins or song sheets,” and the Streaming License to “Live-stream or upload services including the worship music.” A Church Video License is a third product again, for showing movie scenes.
The Streaming License page states the catalog as “450,000 worship songs and hymns performed live during online worship,” and says the coverage extends to uploading “to your church website, your social media pages, or other streaming platforms,” and that a church may “leave your service recordings online indefinitely” while the license is maintained. On price it publishes two reference points rather than a table: “Prices start from just $84 per year for churches already licensed with CCLI, or $108 for an average church (100 - 199 people).” Checked 29 July 2026. The full band table is behind a quote request, so ask for your own attendance band rather than trusting a number from a blog.
Two consequences for the policy. A song outside the covered catalog gets cut from the clip or the clip does not go up, which means somebody has to check song by song rather than license once and forget. And a commercial recording used as background music on a church post is not covered by any of this, which is the most common copyright mistake a church volunteer makes and the easiest one to stop.
The livestream side of the same question, including whether the license is required at all for what your church actually does, is worked through in the live stream setup piece.
Adopt it this month
A policy nobody voted on is a draft, and a draft in a shared drive is how the church in the opening paragraph got where it is. Three steps, and they fit inside one board cycle.
This week. Download the policy and fill in the brackets. They are all names of roles, numbers of hours, and places where a thing is stored. Do not rewrite the prose. Then do the part that takes real work: log into every account the church has and write down who can get in. Most churches find at least one account nobody controls and at least one person who left three years ago.
At the next meeting. Read sections 2, 3, 5, 6, and 13 aloud. Those five carry the authority grants and the minors rules, and reading them aloud is how you find the sentence your board will not accept. Vote. Print the review date at the top. Get the acknowledgment in section 14 signed that night, in the room, by everyone who posts.
Within thirty days. Move every account onto the church’s own domain, put the passwords in a vault, turn on two-factor, print the recovery codes, and hand them to an officer. Start the No-Photo list with one name if that is all you have. Load the calendar file so the quarterly access audit and the annual release refresh arrive without anyone remembering them.
Then have counsel in your own state read sections 5 through 9 against your statutes on likeness, recording consent, and mandatory reporting. That is the one part a publisher cannot do for you, and it is the cheapest hour of legal work a church will ever buy.
Sources
Every statute, price, and quotation above was read off these pages on 29 July 2026.
- New York Civil Rights Law section 50, New York State Senate, checked 29 July 2026
- New York Civil Rights Law section 51, New York State Senate, checked 29 July 2026
- California Civil Code section 3344, California Legislative Information, checked 29 July 2026
- California Penal Code section 632, California Legislative Information, checked 29 July 2026
- Florida Statute 540.08, Florida Legislature, checked 29 July 2026
- 15 U.S. Code section 6501, definitions, Legal Information Institute, checked 29 July 2026
- 15 U.S. Code section 6502, regulation of unfair and deceptive acts in connection with children, Legal Information Institute, checked 29 July 2026
- 16 CFR 312.2, COPPA definitions, Legal Information Institute, checked 29 July 2026
- About Facebook Page access, Meta, checked 29 July 2026
- Google Workspace for Nonprofits, Google, checked 29 July 2026
- Bitwarden pricing and Bitwarden business pricing, checked 29 July 2026
- 1Password business pricing, checked 29 July 2026
- CCLI copyright licenses, checked 29 July 2026
- CCLI Streaming License, checked 29 July 2026
Four sources were attempted and refused, so nothing above is attributed to them. The Federal Trade Commission’s COPPA compliance FAQ returned 403. Brotherhood Mutual’s article on privacy in photographs returned 403. The Child Welfare Information Gateway publication on clergy as mandated reporters returned 404 at two addresses, which is why no count of states appears in the moderation section. The Illinois General Assembly’s page for the Biometric Information Privacy Act returned 404 and 500 at three addresses, so this page makes no claim about whether photo tagging by facial geometry is covered there, and a church in Illinois should ask.
CCLI publishes only two reference prices on its Streaming License page and holds the full attendance band table behind a quote request, so no price curve for music licensing appears here. 1Password confirms a nonprofit discount exists without publishing the rate, so its two lines in the chart are list prices.
This is not legal advice and nobody who wrote it holds a legal credential. The statutes are quoted rather than summarized precisely so that a reader can check every claim against the primary source without trusting the writer. Our review method covers what gets verified, what gets refused, and when it is rechecked.


