Be thou diligent to know the state of thy flocks, and look well to thy herds.Proverbs 27:23, KJV
Every church I have worked with backs up the checkbook. Not because anyone expects the bank to burn down, but because a treasurer, years ago, taught them that the church’s records are the church’s responsibility. The ledger gets reconciled monthly. A copy of the year lives somewhere other than the office. Two people know where it is. Nobody thinks this is paranoid; it is just how a church looks after what it has been given.
Then I ask about the website, and the room goes quiet. The prayer list with the deacon’s diagnosis on it. The directory with the widow’s phone number. The missionary letters. Ten years of Sunday preaching. Nobody has ever made a copy, because nobody ever thought of the website as a set of records. It is one. This entry is the treasurer’s habit, applied to it.
Who this is for.
The person who keeps the website, and the person who keeps the books — because the second one already knows how to do this, and the first one usually does not know it needs doing. If your church rents a hosted site-builder, read on anyway: the routine is the same, and the first step will tell you something about what you can and cannot download. If your church runs FaithKit, or any site that is a plain folder on a host, everything here is a Monday-morning job.
What the website folder is actually made of.
A FaithKit site is one folder on your web host. Almost all of it is the program — the pages, the admin, the radio player — and the program does not change from week to week. You already have a copy of it: the zip you downloaded. Keep that zip and the program is backed up forever.
Four things inside the folder do change, and those four are the church’s records:
Notice the sizes. Three of the four drawers together are smaller than one photograph. Only media/ is big, and it is big because of sermons, which you should be glad to have. This matters for the routine: the part that changes most often is tiny, so there is no excuse to skip a month.
The checkbook rule.
The treasurer does not reconcile because the bank is untrustworthy. She reconciles monthly because a mistake is cheapest to catch when it is one month old. The same three rules move straight across:
Three rules, borrowed from the treasurer
- Monthly, on a fixed day. The first Monday. Not “when there’s time.” A backup that depends on remembering is not a backup.
- Two copies, one of them out of the building. One copy is not a backup; it is the original with extra steps. The second copy lives somewhere the first can’t take it with it — not on the same server, and not in the same room as the church computer.
- Two people know where it is. The person who built the site and one other — a deacon, the clerk, the pastor. If the site was built by a volunteer who might move to Tennessee, this rule is the whole point.
The first-Monday routine.
Twenty minutes, most of it waiting for a download. Tape it beside the checkbook procedure.
First Monday of the month
- Make a folder on the church computer named date-first:
2026-09-website-backup. Date-first means it sorts itself, forever. - Download the four drawers from your host — the File Manager in cPanel, or an FTP program — into that folder:
.env,config/,data/,media/. (Most file managers hide files that start with a dot; turn on “show hidden files.”) - Put the zip beside them — the program download, the same one every month. Now the folder is the whole site.
- Open one file and read it.
data/prayer_data.jsonopens in Notepad or TextEdit and reads as plain words. If you can read it, it is yours. That is the whole test. - Copy the folder to the drive — a plain USB drive kept with the church’s other records. Take the previous month’s copy off only when this month’s is on.
- Write the date in the log. A sheet of paper in the same drawer as the drive: date, who did it, anything odd. The treasurer keeps one for the bank; keep one for this.
After the first month, only media/ takes real time, and only if there were new sermons. Everything else downloads in seconds.
What your host’s backup is for — and what it isn’t.
Most hosts offer a backup of their own: a nightly snapshot, or a “Backup Wizard” in the control panel that downloads the whole account as one file. Use it. It is the fastest way to recover from an ordinary mistake — a deleted folder, a bad update — and it is free.
But it is not the second copy. A host’s backup lives on the host. It goes away when the account lapses, when the card on file expires, when the company is bought, or when the one person whose email the account is under stops answering. It is the bank’s copy of your statement. Useful, and not yours. The drive in the drawer is yours.
The restore drill.
A fire drill is not a fire. A restore drill is not a disaster; it is ten minutes, twice a year, to prove the copy is real. Most backups that fail did not fail on the day they were made. They failed on the day someone needed them and discovered the drive was blank, the folder was half-downloaded, or the only person who knew the password was gone.
Every six months — with the drive, not the live site
- Plug the drive into a different computer than the one that made it, and open last month’s folder.
- Count the four drawers and the zip. Five things. If any is missing, this month’s backup is the first one that counts.
- Open the directory file and find one family you know. Open
media/and find the most recent sermon. If both are there, the copy is current. - Have the second person do it, not the first. If the deacon can open it without calling the webmaster, the rule about two people is true and not just written down.
- Once a year, do a real restore. Put the folder on a spare hosting account or a test domain, open it, and see your site. Moving the site to a new host is the same set of steps — we wrote them down in No. 01. If you would rather not do that part alone, it is the kind of hour MattCreates does at the flat rate.
Treat the copy like the checkbook, because it is one.
The backup contains the directory. That is every family’s phone number and address. It contains the prayer list, which is every private thing the church has been trusted with this year. It contains the scrambled passwords. Treat the drive the way you treat the checkbook and the membership book:
Where the copy does and doesn’t go
- In the safe, or the locked file drawer with the financial records. Not the glovebox, not a desk at home, not a lanyard.
- Never emailed. An emailed backup is a copy in someone’s inbox forever, on a server the church does not own.
- Not in a shared cloud folder the whole church can see. If the second copy must be online, it belongs in a private, password-protected place under the church’s own account — and the treasurer’s rule about two people still applies.
- Old copies get erased, the way old checks get shredded. Keep this year and last; wipe the rest.
The one page to write down.
The backup protects the records. This page protects the backup. It is one sheet, in the same drawer, and it is the difference between a church that owns its website and a church that hopes it does.
The website page — one sheet, in the records drawer
- The domain. Where it is registered, whose name the account is in, when it renews, what email gets the renewal notice.
- The host. Company, account name, whose card is on file, when it renews.
- The two logins. Not the passwords — who holds them, and where they are kept (the safe, the church’s password book).
- The backup. Where the drive is, who does it, the first-Monday date, and the last date on the log.
- The second person. Name and number of the one who can open the drive without calling anyone.
- The zip. Which version of the program is on the drive, and where a fresh copy comes from.
Fill it in once. Update it when a name changes. Read it aloud at one business meeting a year, the way the treasurer reads the report, and the church will never again find out on a Tuesday that its website lived in one person’s inbox.
Everything above is a download, because everything is a file.
FaithKit keeps the church’s records in the four plain drawers in the diagram — no database to export, no “request your data” form, nothing that needs us. That is on purpose; it is most of what owning the site means. It also means there is no automatic backup unless your host provides one: the first-Monday routine is the backup. There is no one-click “download a backup” button in the admin yet. It is on the list, and when it ships it will produce the same folder described here. If MattCreates hosts your site for you, the folder is still yours — ask, and we hand it over.
The sample church at faithkit.org/demo is laid out exactly this way; the sample is not a real congregation.