Privacy Policy
Last updated 1 August 2026
The short version. We cannot read your messages. They travel between your team and your server and are stored on your disk; no OpenChime service sits in that path. What we hold is the small set of account and workspace metadata listed in section 2, and we do not sell it, rent it, or train models on it.
1. Who this covers
This policy describes how [LEGAL ENTITY NAME] ("OpenChime", "we") handles personal data in the services we operate: the account console, billing, hosted provisioning, and the optional federated services (single sign-on relay, mobile push relay, the app directory, and SCIM).
It does not cover the data inside your workspace. Messages, channels, files, and user profiles live on the OpenChime server you or we operate on your behalf, and you are the controller of that data. Where we operate the machine for you, we act as your processor for it and do not access its contents.
2. What we collect
This is the complete list of what our systems store about you.
- Account
- Your email address and a hashed password. If you sign in through an external identity provider, we store the identifier that provider gives us instead of a password.
- Workspace registry
- An opaque workspace identifier, your server's public key, its network address, and its binding state. The identifier names a workspace without describing it.
- Billing
- Subscription status and a customer reference held by our payment processor. We never receive or store card numbers — payment fields are rendered by the processor and tokenized in your browser.
- Hosted machines
- For workspaces we operate: the machine's status and lifecycle state with our infrastructure provider.
- Operational logs
- Request metadata such as IP address, timestamp, and endpoint, kept for security and debugging. Logs are scrubbed of credentials and never contain message content.
3. What we do not collect, and cannot
The following are not absent by policy. There is no path by which they reach us:
- Message content of any kind, including drafts and edits
- Channel names, topics, or membership
- Your workspace's users, their names, or their profiles
- File attachments or their filenames
- Search queries or read state
- Voice or screen-share media
- Mobile device tokens — your server holds those, not us
4. Mobile push notifications
When your server decides someone should be woken, it sends us a notification request containing only metadata — which device to wake, which channel it concerns, and a badge count. Our gateway rejects any field capable of carrying message text.
We relay that request to Apple or Google and retain nothing. We do not keep a device registry; your server owns that list and supplies what is needed per notification. Apple and Google receive a wake signal with no message content in it.
5. Single sign-on
If you enable the sign-on relay, we act as a relying party against your identity provider and re-issue a short-lived token scoped to your workspace alone. We process the identity claims needed to do that — a subject identifier and email address — and do not build a profile from them or retain them beyond the exchange.
6. Cookies
We set cookies strictly necessary to operate the console: a session cookie once you sign in, and an anti-forgery token that protects forms from cross-site request forgery.
We run no third-party analytics, advertising, or tracking on this site. There is nothing to consent to and no preference centre to configure, which is why you were not shown a cookie banner.
7. Who else processes your data
We use a small number of subprocessors, each for a single purpose. None receives message content, because we do not have any to give them.
- Payment processing
- Card handling and subscription billing.
- Infrastructure hosting
- Runs our control plane, and the per-workspace machines for hosted customers.
- Push notification delivery
- Apple Push Notification service and Firebase Cloud Messaging, for contentless wake signals only.
- Identity providers
- Only those you choose to connect, and only when you enable sign-on.
8. How long we keep things
Account and workspace records are kept while your account is open. Close it and we delete them within 30 days, except where we must retain billing records to meet tax and accounting obligations. Operational logs are retained for a limited period and then discarded.
Push relay requests are not stored at all — they are forwarded and discarded in the same operation.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold, to object to or restrict processing, and to complain to a supervisory authority. Because the list in section 2 is short, so is our answer to most of these requests.
Write to [privacy@openchime.io] and we will respond within the period the applicable law requires. Note that we cannot action requests about data inside your workspace — we have no access to it. Direct those to whoever administers your OpenChime server.
10. We do not train AI on your data
No model is trained, fine-tuned, or evaluated on your messages, and none indexes your workspace. This is not a setting or an undertaking we could later revise: message content never reaches our infrastructure, so there is nothing on our side to train on.
11. Security
Connections to our services use TLS. Passwords are stored hashed. Enrollment trust rests on a key your server generates and never discloses. Card data is tokenized in your browser and never reaches our systems. Full architectural detail is on our security page.
12. International transfers
Our control plane and subprocessors may process data outside your country. Where required, transfers rely on an approved safeguard such as the Standard Contractual Clauses.
Hosted workspaces run in a region you pick when the workspace is created, so your messages and files stay on a server in that region. The account metadata in section 2 is still held by our control plane, which is not region-specific. If you need everything under your own jurisdiction, self-host — then no part of it leaves the machine you choose.
13. Children
OpenChime is a business product and is not directed at children under 16. We do not knowingly collect their personal data.
14. Changes
We will post any change here and update the date above. For changes that materially reduce your protections, we will notify account holders by email before they take effect.
15. Contact
[LEGAL ENTITY NAME] — [privacy@openchime.io]