Skip to content

Draft, not yet live. Pending legal review and technical verification.

Bonfire
For ChurchesFor Businesses
How It WorksPricing
BlogResource HubTrust CenterHelp Center
About
Log In

Privacy Policy

Effective Date: September 1, 2026 · Last updated September 1, 2026

On this page

    At Bonfire AI ("we," "us," or "our"), operated by LIVE Tapestry Technologies LLC, we are committed to protecting your privacy and handling personal data responsibly. This Privacy Policy explains how we collect, use, share, and safeguard information when you interact with our websites and services.

    Controller vs. processor

    For our own websites, marketing, and customer accounts, LIVE Tapestry Technologies LLC is the data controller. For content and conversations inside a customer's workspace, the customer organization is the controller and Bonfire is a processor acting on the organization's instructions. If you are an end user with questions about how an organization uses your data, contact that organization first; we will refer requests we receive to the responsible organization.

    No third-party model training

    We do not use customer content or conversation data to train third-party foundation models. We may use aggregated, de-identified usage patterns to improve the platform and, for partner programs, to provide partners aggregate insights that never expose individual conversations. VERIFY internal practice with Preston.

    1. Purpose and Scope

    1.1 Applicability.

    This policy applies to:

    • Website visitors: individuals who interact with our websites (including heybonfire.com) and social media pages.
    • Customers: organizations and their administrators and team members who use the Bonfire platform.
    • End users: individuals who interact with a customer organization's AI agents (for example a church member, a client, a site visitor, or a conference attendee). See Section 2 for the special rules that apply.
    • Event attendees, marketing prospects, and communication recipients.

    1.2 Data Controller vs. Processor.

    For our own websites, marketing, and customer accounts, LIVE Tapestry Technologies LLC is the data controller. For content and conversations inside a customer's workspace, the customer organization is the controller and Bonfire is a processor acting on the organization's instructions. If you are an end user with questions about how an organization uses your data, contact that organization first; we will refer requests we receive to the responsible organization.

    1.3 Data Processing Addendum.

    Customers who require a DPA (including for GDPR or state-law purposes) can request one at support@heybonfire.com. Prepare standard DPA.

    2. Conversation Data and Customer Content

    This is the heart of the platform, so it gets its own section.

    • What it is. When you chat with a Bonfire-powered agent, we process the messages you send, the AI's responses, and any fields you submit through forms or skills (for example your name, email, or answers to a guided experience). Customer organizations also upload content (documents, media, recordings, integrations) to train their agents.
    • Who sees it. Conversation data belongs to the customer organization whose agent you used. That organization's administrators can review conversations and collected fields in their workspace. Bonfire personnel access conversation data only for support, troubleshooting, safety, and abuse prevention, under access controls.
    • AI processing. Messages are processed by large language model providers (see Section 5) under API agreements that do not permit those providers to train their models on this data.
    • No third-party model training. We do not use customer content or conversation data to train third-party foundation models. We may use aggregated, de-identified usage patterns to improve the platform and, for partner programs, to provide partners aggregate insights that never expose individual conversations. VERIFY internal practice with Preston.
    • Notices in the widget. Organizations are responsible for presenting their own privacy notices to their end users; Bonfire provides a notice link in the chat interface identifying the operator and this policy. Confirm product behavior.

    3. Information We Collect

    3.1 You provide:

    contact information (name, email, phone, company, role), account credentials, payment information (processed by our payment processor; we do not store full card numbers), event registration details, feedback and correspondence, and, as an end user, the messages and form fields described in Section 2.

    3.2 Collected automatically:

    device data (IP address, browser, OS, identifiers), usage data (pages visited, interactions, email engagement), and cookies and similar technologies.

    3.3 From third parties:

    social media platforms, marketing partners, publicly available business information, and integrations customers connect (for example Google Drive content a customer authorizes).

    4. How We Use Information

    To provide and maintain the services (accounts, transactions, support); to process conversations and generate AI responses; to communicate service announcements and respond to inquiries; for marketing to those who have opted in; to improve the services (monitoring usage, developing features); and for security and compliance (fraud detection, legal obligations, enforcing terms).

    5. Sharing and Subprocessors

    We do not sell personal information. We share data with service providers who help us operate, under contracts limiting their use:

    Subprocessors and the role each plays
    ProviderRole
    OpenAIAI model provider - response generation; no training on your data
    AnthropicAI model provider - response generation; no training on your data
    GoogleAI model provider - response generation; no training on your data
    SupabaseHosting and infrastructure — verify list
    AWS/GCPHosting and infrastructure — verify list
    VercelHosting and infrastructure — verify list
    StripePayments
    verifyEmail and communications
    PostHog - verifyAnalytics; analytics never receives raw conversation content, only usage events. VERIFY

    We also may share with affiliates, in business transfers, to meet legal obligations, or with your consent. A current subprocessor list is available on request or at a /subprocessors page.

    6. Data Retention

    We retain personal data only as long as necessary for the purposes above. Conversation data is retained per the controlling organization's settings and plan define defaults, and deleted or de-identified within X days of workspace deletion. Billing and compliance records are kept as required by law.

    7. International Data Transfers

    Data may be processed in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers.

    8. Data Security

    We implement reasonable administrative, technical, and physical safeguards, including encryption in transit, access controls, and vendor vetting (see our Security Overview). No method of transmission or storage is completely secure. We will notify affected parties of breaches as required by law.

    9. Your Rights and Choices

    Access, correction, portability, and deletion requests: email support@heybonfire.com. If your data was collected by a customer organization's agent, we will route your request to that organization. Opt out of marketing via unsubscribe links. Control cookies in your browser settings.

    10. Children's Privacy

    Our services are not directed to individuals under 16, and we do not knowingly collect personal data from children under 13. Customer organizations that serve families are responsible for deploying agents in a manner appropriate to their audiences and applicable law (including COPPA where relevant).

    11. Sensitive Contexts

    Some organizations use Bonfire in ministry and care contexts. Do not submit information you consider confidential pastoral, medical, or crisis information through a public agent; agents are configured to route crisis moments to human help. Organizations are responsible for their own care policies. We treat conversation data in these contexts with heightened care. Consider WA My Health My Data implications.

    12. Changes to This Policy

    We may update this policy and will revise the Effective Date, with more prominent notice for significant changes.

    13. Contact Us

    LIVE Tapestry Technologies LLC (d/b/a Bonfire AI)
    c/o Northwest Registered Agent Service, Inc.
    8 The Green, Suite B
    Dover, DE 19901
    Email: support@heybonfire.com

    14. Additional Information for California Residents

    Categories collected: identifiers, commercial information, internet activity, geolocation (coarse), professional information, inferences, and, for end users, the contents of messages sent to agents (treated as sensitive where applicable). Rights: to know, to delete, to correct, to opt out of sale/sharing (we do not sell or share personal information as defined by the CCPA/CPRA), to limit use of sensitive personal information, and to non-discrimination. We honor Global Privacy Control signals. VERIFY GPC implementation. Exercise rights via support@heybonfire.com with enough information to verify your identity.

    Related documents

    Terms of ServiceLast updated September 1, 2026Security OverviewLast updated September 1, 2026Partner Program AgreementAvailable on request · partners@heybonfire.com

    Questions about this document? Email support@heybonfire.com.

    Bonfire

    Light more fires.

    PRODUCT

    • How It Works
    • Pricing
    • Demo
    • Integrations

    SOLUTIONS

    • For Churches
    • For Businesses
    • Partners
    • Use Cases

    RESOURCES

    • Blog
    • Resource Hub
    • Case Studies
    • Help Center

    COMPANY

    • About
    • Careers
    • Contact

    LEGAL

    • Terms of Service
    • Privacy Policy
    • Security
    • Trust Center

    2026 Bonfire. All rights reserved.