OpenChime Hosted Service Privacy Notice
Effective September 1, 2026. OpenChime is a product of Bronze Venture LLC, which trades as OpenChime.
This covers the OpenChime hosted service — the workspace you buy from us and we run for you — together with the OpenChime apps you reach it with.
We host your workspace, so your messages and your files sit on machines we operate. We do not read them, sell them, or use them to train anything, and the point of this document is to say precisely what we do with them, who is able to reach them, and what happens when somebody asks us for them.
If you run your own OpenChime server, none of Part A applies to you and we hold nothing about you at all. Part B still describes what the app on your own device does.
Where we operate
Bronze Venture LLC does business only with United States entities. The hosted service is offered in the United States, to US individuals and US organisations. We do not market it to, or sell it to, anyone outside the country.
Your workspace and its backups are held in the United States.
Part A. The hosted service
Who is responsible for what
For the contents of your workspace — messages, files, channels, and who is in them — you are the controller and we are the processor. It is your data. We hold it and process it in order to run the service, and on your instructions.
For your account with us — the email address you signed up with, your subscription, your invoices — we are the controller, because that is our own business relationship with you rather than yours with your colleagues.
What we hold
Because we run your workspace, we hold:
- Your messages, direct messages included, and their metadata: who sent what, when, and in which channel.
- Your files and attachments, as uploaded.
- Your workspace structure: channels, membership, display names, and the accounts of everyone you invite.
- Operational data: the logs and backups that come from running the machine your workspace is on.
And separately, as controller:
- Your account: email address, name, and a password hash if you set a password rather than signing in with Google.
- Billing. Stripe processes payments. Card numbers go to Stripe and never reach us. We keep a customer identifier and whether the subscription is current.
Who can reach it, and when
Your workspace runs on a machine we provision and administer. That means people at Bronze Venture have the technical ability to reach what is on it. Any privacy policy that hosts your data and implies otherwise is not telling you the truth, and we would rather say the uncomfortable version.
What we commit to is when we do it:
- To operate the service: restoring a backup, diagnosing a fault you have reported, migrating or repairing a machine.
- When you ask us to, on a support request you opened.
- When the law compels us, as set out below.
There is no fourth reason. We do not read your messages for product research, we do not use your content for advertising or analytics, we do not train machine-learning models on it, and we do not sell or share it.
Lawful requests
We may receive a subpoena, a warrant, or an equivalent order for your data. Because we hold it, we can be made to produce it. Where we are legally permitted to, we will tell you before we do, so that you have the opportunity to object. What we require of a requester, and how we handle notice, is on the legal process page.
Backups and deletion
We take backups so that a failure does not lose your workspace. They are kept for a rolling window and are encrypted at rest.
When you cancel, we destroy the machine and its storage. Backups age out of the rolling window after that. Account and billing records survive longer, but only where tax or accounting law requires it — generally a few years for transaction records.
Notifications
If you turn on push notifications, your workspace asks our relay to signal Apple or Google so that your device knows to check for something. That signal carries no content. Not the message, not the sender, not the channel. We keep no record of your devices.
Sub-processors
| Who | For what |
|---|---|
| Fly.io | Hosting and storage, including the machine and volume your workspace runs on |
| Stripe | Payment processing |
| Postmark | Transactional email: sign-in confirmations, receipts |
| Apple, Google | Contentless push delivery only |
We will give notice before adding a sub-processor that would process workspace content.
Part B. The apps
This part applies to the OpenChime applications for Windows, macOS, Linux, iOS and Android, however you obtained them — including from the Microsoft Store, the Apple App Store and Google Play.
The apps report nothing to us
There is no analytics, no telemetry, no advertising and no attribution SDK in any OpenChime app. There is no code in them that phones home. That is what our store listings declare, and it is checkable rather than merely asserted, because the source is public.
What the app sends, it sends to the server it is configured for. If that server is a workspace we host, Part A describes what becomes of it there. If it is your own, we are not in the conversation.
Crash reports stay on your device
When the app crashes it writes a report to your own device so that you can attach it to a bug report if you decide to. Nothing uploads it. Nothing prompts you. If you never send it, we never see it.
Permissions
The app asks for a permission only when a feature you have used needs one: the camera and microphone for a call, files for an attachment, notifications for alerts. Decline any of them and the rest of the app still works.
Children
OpenChime is not directed to children under 13, and we do not knowingly collect personal data from them.
Your rights
Depending on where you live you may have the right to know what personal data we hold, to receive a copy of it, to correct it, and to have it deleted — including under the California Consumer Privacy Act as amended by the CPRA, and under comparable laws in other US states.
We do not sell or share personal data, and we do not engage in cross-context behavioural advertising, so there is no opt-out for you to exercise. We will not treat you any differently for exercising a right.
Write to legal@bronzeventure.com.
One practical note. For content inside a workspace that your employer or another organisation bought, they are the controller, so a request to export or erase it goes to them rather than to us. We will help them act on it.
Changes
If this changes materially we will update the effective date and tell hosted customers by email. We will not apply a materially less protective version retroactively.
Contact
Bronze Venture LLC, trading as OpenChime, is the data controller for your account and the processor for your workspace content.
Bronze Venture LLC7901 4th St N, Ste 300
St. Petersburg, FL 33702
legal@bronzeventure.com