OpenChime Hosted Service Privacy Policy
Effective August 1, 2026. OpenChime is a product of Bronze Venture LLC, which trades as OpenChime.
This covers the OpenChime hosted service, the workspace you buy from us and we run for you, together with the OpenChime apps you use to reach it.
We host your workspace, so your messages and files are on machines we operate. We do not read them, sell them, or use them to train anything, and this document says exactly what we do with them, who can reach them, and what happens when someone asks us for them.
If you run your own OpenChime server, this policy does not apply to you and we hold nothing about you. Part B still describes what the app does.
Where we operate
Bronze Venture LLC does business only with United States entities. The hosted service is offered in the United States, to US individuals and US organisations. We do not market it to, or sell it to, anyone outside the country.
Your workspace and its backups are held in the United States.
Part A. The hosted service
Who is responsible for what
For the content of your workspace, meaning messages, files, channels and who is in them, you are the controller and we are the processor. It is your data. We hold and process it to provide the service and on your instructions.
For your account with us, meaning the email address you signed up with, your subscription and your invoices, we are the controller, because that is our own business relationship with you.
What we hold
Because we run your workspace, we hold:
- Your messages, including direct messages, and their metadata: who sent what, when, in which channel.
- Your files and attachments, as uploaded.
- Your workspace structure: channels, membership, display names, and the accounts of everyone you invite.
- Operational data: logs and backups produced by running the machine your workspace is on.
And separately, as controller:
- Your account: email address, name, and a password hash if you set a password rather than signing in with Google.
- Billing. Stripe processes payments. Card numbers go to Stripe and never reach us. We keep a customer identifier and whether the subscription is current.
Who can reach it, and when
Your workspace runs on a machine we provision and administer. That means people at Bronze Venture have the technical ability to reach the data on it. Any privacy policy that hosts your data and implies otherwise is not telling you the truth.
What we commit to is when we do it:
- To operate the service: restoring a backup, diagnosing a fault you have reported, migrating or repairing a machine.
- When you ask us to, on support you have opened.
- When the law compels us, as set out below.
We do not read your messages for any other reason. We do not use your content for advertising, for analytics, or to train machine-learning models, and we do not sell or share it.
Lawful requests
We may receive a subpoena, warrant, or equivalent order for your data. Because we hold it, we can be made to produce it. Where we are legally permitted to, we will notify you before we do, so that you have the opportunity to object.
Backups and deletion
We take backups so that a failure does not lose your workspace. They are retained for a rolling window and are encrypted at rest.
When you cancel, we destroy the machine and its storage. Backups age out of the rolling window after that. Account and billing records survive longer, but only where tax or accounting law requires, generally a few years for transaction records.
Notifications
If you turn on push notifications, your workspace asks our relay to signal Apple or Google so your device knows to check. That signal carries no content. Not the message, not the sender, not the channel. We keep no record of your devices.
Sub-processors
| Who | For what |
|---|---|
| Fly.io | Hosting and storage, including the machine and volume your workspace runs on |
| Stripe | Payment processing |
| Postmark | Transactional email: sign-in confirmations, receipts |
| Apple, Google | Contentless push delivery only |
We will give notice before adding a sub-processor that would process workspace content.
Part B. The apps (rider)
This part applies to the OpenChime applications for Windows, macOS, Linux, iOS, and Android, however you obtained them, including from the Microsoft Store, the Apple App Store, and Google Play.
The apps report nothing to us
There is no analytics, no telemetry, no advertising, and no attribution SDK in any OpenChime app. There is no code in them that phones home. This is what our store listings declare, and it is checkable, because the source is public.
What the app sends, it sends to the server it is configured for. If that is a workspace we host, Part A describes what happens to it there.
Crash reports stay on your device
When the app crashes it writes a report to your own device so that you can attach it to a bug report if you decide to. Nothing uploads it. Nothing asks us. If you never send it, we never see it.
Permissions
The app asks for a permission only when a feature you used needs it: the camera and microphone for a call, files for an attachment, notifications for alerts. Decline any of them and the rest of the app still works.
Children
OpenChime is not directed to children under 13, and we do not knowingly collect personal data from them.
Your rights
Depending on your state, you may have rights to know what personal data we hold, to get a copy of it, to correct it, and to have it deleted, including under the California Consumer Privacy Act as amended by the CPRA, and comparable laws in other US states.
We do not sell or share personal data, and we do not engage in cross-context behavioural advertising, so there is nothing for you to opt out of. We will not discriminate against you for exercising a right.
Write to legal@bronzeventure.com.
One practical note: for content inside a workspace your employer or another organisation bought, they are the controller, so a request to export or erase it goes to them. We will help them act on it.
Changes
If this changes materially we will update the effective date and tell hosted customers by email. We will not apply a materially less protective version retroactively.
Contact
Bronze Venture LLC, trading as OpenChime, is the data controller for your account and the processor for your workspace content.
Bronze Venture LLC7901 4th St N, Ste 300
St. Petersburg, FL 33702
legal@bronzeventure.com