Our tools don't replace your system — they read its exports. And your data stays yours: it lives in your own private instance, and every insight is built from a de-identified, coded copy. Every major church database exports a spreadsheet in 3–5 clicks — here's the click-path for each.
Your data, protected
Kept at the church. Built from a coded copy.
Three rules we treat as non-negotiable — the same way we guard person-level data in our own church.
Where it lives
At the church level
Your data lives in your own private instance — one cloneable copy for your organization. We never pool it, mix it with other churches, or centralize it. If you leave, it's a download — not a negotiation.
How it's analyzed
From a coded set
The intelligence runs on a de-identified copy — each person reduced to a few non-identifying traits (gender, marital status, an age band), never the combination of name, phone, email, and birthdate.
Who sees the details
Locked to your admins
Full contact detail appears only where a staff member needs it to do the job — your admin clean-up queue. Every shared view is masked, birthdates become ages, and nothing in our marketing or demos is a real person.
How to export it
Most common · easiest
Planning Center
Event registrations: Signups → pick your signup → Registrations tab → Actions → Export → choose CSV. You can pick which columns to include and filter the list first.
Attendance: Check-Ins → your event → reports → Export CSV.
People: build a List (saved filter) → list actions → Export to CSV.
Anyone with viewer access can do this — no IT needed. Heads-up: "simple" signups (headcount-only) export totals, not names; and canceled attendees drop off the printable Guest List (use the CSV instead). Want it automatic? Planning Center's API supports nightly syncs — ask us about a connector.
Most flexible · one-time setup
Rock RMS
Ask your Rock administrator (once) to build a Data View of the people/registrations you need, and save it as a Report.
After that, any staff member opens the report and clicks Export to Excel on the results grid. That's the whole job.
Rock exports sometimes include extra calculation columns — that's fine, our loader ignores what it doesn't need. Rock also ships with a full API on every install for automated syncs.
Also great
Breeze ChMS
People → filter to the group you want → click the export/download icon → Excel/CSV.
Events → attendance → export.
Breeze is one of the most export-friendly systems out there. Tithely, Subsplash, ChurchTrac and others have similar CSV buttons — if you use something else, send us one sample export and we'll confirm the fit, usually same day.
What the file needs
You keep the names. We only ever get a coded file.
Here's the honest split. The details that identify a person never leave your walls — your own instance uses them once to match people and work out an age, then they're gone. Only the coded set powers the analytics or anything you share.
🔒 Stays at your church · never sent to us
The identifying fields
These may sit in your export, but they never leave your own computer. The coder uses them once — right there on your device — to recognize the same person across events and work out an age band, then drops them. We never receive them, store them, share them, or put them in any analytics.
First & last name
Email
Phone
Birthdate
✅ The coded set · all the analytics ever see
What powers the intelligence
In the coded set
Where it comes from
Anonymous person ID
the match — never a name, email or phone
Age band (e.g. 30–39)
from birthdate — never the date itself
Gender / marital status
kept as-is — non-identifying
Registration date/time
pacing curves & forecasting
Attended / checked in
no-show & walk-up rates
Anonymous couples link
couples modeling — no identities
You run the coder. We never see it.
Here's the part no big platform can offer: the de-identifying doesn't happen on our servers — it happens on yours. You run a small tool that works entirely in your browser (offline, even), and only the coded file ever leaves the building.
The four-step flow
How it actually works
Export your raw sign-ups from Planning Center, Rock or Breeze — the file stays on your computer.
Open your Coder — it runs 100% in your browser, on your machine. Download it once and it even works with no internet at all.
It builds a stable anonymous ID (a one-way code only your private church key can reverse) plus a demographic code — then drops names, email, phone and birthdates entirely.
Load the coded file into your scoreboards. The identifying data never left your laptop.
Because that ID is a one-way code tied to a key only your church holds, no one at Toolz Group can turn a code back into a person — not as a policy we promise, but as something the software physically can't do. Try the Coder yourself →
That's genuinely it. During onboarding we stand up your private instance and load your export into it — the matching happens there, on your data. The identifying details never leave your instance; the analytics run on a coded copy, and you'll see your own scoreboard, usually within a day. Say hello at hello@toolzgroup.com.