Privacy Policy
Last updated: January 10, 2025
The data you give Boundfire is sensitive. This policy sets out what we collect, why, and how we protect it.
We never sell your personal data.
1. Introduction
This Privacy Policy explains how Boundfire ("we," "us," or "our") collects, uses, stores, and protects your information when you use our services, including Boundfire Bond and PuppyClicker (collectively, "the Services"). By using our Services, you agree to the collection and use of information in accordance with this policy.
Using PuppyClicker? It has its own shorter policy: PuppyClicker privacy policy
2. Information we collect
2.1 Boundfire Bond: information you give us
- Account information: Email address, username, and password (encrypted)
- Profile information: Display name, pronouns, bio, and avatar
- Relationship data: Relationship roles, preferences, and settings
- Content: Messages, photos, videos, journal entries, and task data
- Location data: GPS coordinates (only when you turn it on)
2.2 PuppyClicker: information you give us
- Account information: Email address, username, and password (encrypted)
- Profile information: Display name, pronouns, preferred terms, and avatar
- Friend connections: Friend codes, friend relationships, and connection history
- Click data: Click history, messages attached to clicks, and interaction logs
- OpenShock configuration: API keys (stored encrypted), device IDs (hashed), intensity and duration preferences
- REST API endpoints: Custom endpoint URLs and configurations (stored encrypted)
- Push notification tokens: Device tokens for delivering click notifications
2.3 Information collected automatically
- Device information: Device type, operating system, and app version
- Usage data: Features used, interaction patterns, and performance metrics
- Log data: IP address, access times, and error reports
3. How we use your information
3.1 Both apps
We use collected information to:
- Provide and maintain the Services
- Enable relationship features and task management (Bond)
- Deliver clicks and notifications between friends (PuppyClicker)
- Send notifications (with your consent)
- Improve the Services
- Keep the Services secure and prevent abuse
- Comply with legal obligations
3.2 PuppyClicker
In PuppyClicker we also use it to:
- Execute click commands to your friends' devices
- Send OpenShock commands (shock, vibration, sound) via the OpenShock API
- Trigger your configured REST API endpoints
- Deliver push notifications for received clicks
- Manage friend connections and approvals
- Enforce rate limiting and safety features
AI training: We never use your data or content to train AI or machine learning models.
4. Data security
How we protect your data:
- Encryption: All data is encrypted in transit and at rest
- API key security: OpenShock API keys and REST API configurations are encrypted using AES-256
- Device ID hashing: OpenShock device IDs are stored as hashed values
- Access controls: Every request is authenticated and authorized
- Audits: Regular security reviews and vulnerability testing
- Infrastructure: Hosted with established cloud providers
5. Data sharing
We do not sell, trade, or rent your personal information to third parties.
We do not use your data for AI training or machine learning model development.
We may share information only in these circumstances:
- With your consent: When you explicitly authorize sharing
- Within relationships (Bond): Content shared with your relationship partners
- Between friends (PuppyClicker): Click notifications and messages sent to your approved friends
- Service providers: Companies that help run the Services, under confidentiality agreements
- Legal requirements: When required by law or to protect rights and safety
5.1 Third-party services in PuppyClicker
PuppyClicker integrates with third-party services that have their own privacy policies:
- OpenShock: When you configure OpenShock integration, we send commands to the OpenShock API on your behalf. Your API key is never shared with other users. OpenShock's privacy policy applies to data processed by their service.
- Custom REST API endpoints: When you configure custom endpoints, we send HTTP requests to your specified URLs. We do not control or monitor what these endpoints do with the data. You are responsible for the privacy practices of your configured endpoints.
6. Your rights
You have the right to:
- Access: Request a copy of your personal data
- Correct: Update or correct inaccurate information
- Delete: Request deletion of your account and data
- Export: Download your data in a portable format
- Restrict: Limit how we process your data
- Object: Opt-out of certain data processing
7. Data retention
We keep data only as long as the Services and the law require:
- Active accounts: Kept while the account is active
- Messages (Bond): Deleted from our server within 90 days or once all users have a copy
- Click history (PuppyClicker): Deleted after 30 days
- Deleted accounts: Deleted immediately. Copies may remain in online backups for up to 30 days and offline backups for up to 90 days
- Legal holds: Kept longer if the law requires
8. Location privacy (Boundfire Bond)
Location features are off until you turn them on:
- Location sharing is relationship-specific
- You control when and how location is shared
- Location history can be deleted at any time
- Geofencing data is only visible to authorized partners
9. OpenShock data (PuppyClicker)
For users who connect OpenShock devices:
- API keys: Your OpenShock API key is stored encrypted and is never shared with other users or third parties
- Device IDs: OpenShock device IDs are stored as hashed values and are not shared
- Commands: Shock, vibration and sound commands go straight to OpenShock's API and are not kept
- Intensity and duration: Our servers enforce the safety limits you set
- Revocation: Removing the OpenShock integration deletes your stored API keys and device configuration immediately
10. Children's privacy
The Services are for adults. We do not knowingly collect personal information from anyone under 18.
11. International data transfers
Your data may be stored on servers outside your country. This policy applies wherever it is stored.
12. Third-party services
Third-party services we use:
- Payment processing: Stripe, Apple Pay, Google Play, Patreon (payment data not stored by us)
- Analytics: Anonymous usage analytics, with no media or personal information
- Cloud infrastructure: Server hosting
- Push notifications: Apple Push Notification Service (APNs), Firebase Cloud Messaging (FCM)
13. Moderation and safety
To keep the Services safe:
- Automated scanning: We scan content for policy violations
- Human review: Moderators review reported content
- Safeguards: Technical measures against harmful content
- Zero tolerance: Content involving minors or non-consensual activity ends the account immediately
Safety: If you are unsafe, get help now. Crisis lines and support organizations are listed at /safety.
Emergency data deletion: If your relationship feels unsafe and you need data deleted urgently, contact safety@boundfire.com.
14. Cookies and tracking
We use few cookies:
- Essential cookies: Required for authentication and security
- Preference cookies: Remember your settings
- No third-party tracking: No advertising or tracking cookies
- No cross-app tracking: We do not follow you across other apps or websites
15. Changes to this policy
We may update this policy. We will tell you about material changes in the app or by email.
16. App store privacy requirements
16.1 Apple App Store
For users who downloaded from the Apple App Store:
- Our App Store privacy labels list everything we collect
- iOS permissions require explicit user consent
- Sign in with Apple is supported
- We comply with App Tracking Transparency requirements
16.2 Google Play Store
For users who downloaded from Google Play:
- Google Play's Data Safety section lists everything we collect
- We explain each sensitive permission when we ask for it
- We comply with Google Play's privacy and content policies
17. Contact
Questions about this policy or your data:
- Email: privacy@boundfire.com
- Discord: discord.gg/j9CQJHAheM