The steps
- Collect the least you need. A first name and an initial, the ministries, a family name, dates away and a senior tick. No birthdate, age, address, phone number or school.
- Keep the list on one parish computer. Use a tool that stores the list in the browser on that computer and uploads nothing, so the parish is the only place the names exist.
- Print instead of posting. Print the rota for the sacristy and hand or email families their own turns, rather than publishing children's names on a public web page.
- Back up to a file you control. Save a backup file to the parish's own storage, and delete old copies when a server leaves.
- Clear it when you hand over. When a new scheduler takes over, pass on the backup file and clear the browser on the old computer.
Why it matters for a parish
An online scheduler is convenient: families log in and pick their own Masses. It also means a list of children's names, their families and the times they are in church sits on a company's server, under that company's terms, for as long as the account exists. Guidance on children's information, such as the UK regulator's guidance on children and data protection, asks organisations to take particular care with children's personal information and has a whole section on sharing it. The simplest way to share less is not to put it anywhere else.
What PewRota keeps, exactly
Everything lives in the browser's own storage on the computer you use, under the key pewrota.workspace.v1. For each person that is a name or initials (up to 60 characters), the ministries, preferred services, dates away, a monthly limit, a family or pair name, a senior tick and a tick for serving twice on a weekend. There is no field for a birthdate, an age, an address, a phone number or an email address, and a pasted column of birthdates is ignored with a note saying so.
Nothing is sent to PewRota or to anyone else. There are no analytics of what you type and no account. If the billing option is ever switched on, the page checks an anonymous purchase id with the payment company; it never sends the list.
Worked example: a paste with too much in it
A scheduler pastes last year's spreadsheet: Family, Name, Roles, Senior, Birthdate, Max per month, Away. PewRota reads the name, roles, senior tick, family, limit and dates away, drops the birthdate column entirely, and reports: "Birthdates and ages are never kept, so that column was ignored." The saved list has no trace of the birthdates. The same holds for a CSV headed First Name, Last Name, Date of Birth (the two name columns are joined), or Surname, Forename, Age. In a paste with no header row, any date or age outside a dates away column is dropped with the note "A date or age was found and not kept."
Common mistakes
- Collecting birthdates to decide who is senior. A senior tick does the same job.
- Emailing the whole rota with every child's full name to every family.
- Leaving the rota open on a shared computer in the parish office.
- Keeping backup files of old lists for years after the servers have left.
Read the privacy page for the full detail, or start the rota builder.
Sources
Checked on 28 September 2026. PewRota applies your parish's own policy; it ships no liturgical rules. Where your diocese, your parish safeguarding policy or your clergy say something different, follow them.
- Children and the UK GDPR, the UK Information Commissioner's Office guidance (last updated 15 May 2026). Guidance on handling children's personal information, including a section on sharing it; opened 28 September 2026.
- PewRota's rota builder. Every example on this page is built by the same solver the rota builder runs, at build time, and pinned by a test.