Legal
Privacy Policy
Last updated August 13, 2026. Early access — we keep this clear and short.
Who we are
Campfire Home (“Campfire”, “we”) is a family hub product powered by the Keystone platform. This policy explains what we collect when you use Campfire on the web or a household display, and how we use it.
What we collect
- Account data — email, name, password hash (or Google profile if you sign in with Google), and household membership.
- Household content — calendar events, lists, meals, chores, rewards, settings, and related metadata you enter.
- Billing — handled by Stripe (customer and subscription identifiers; we do not store full card numbers).
- Usage & security — login sessions, device/app client identifiers, IP and request metadata for security and rate limiting, and cookie consent choices.
- Support — messages you send to campfire@hourglasssystem.com.
How we use data
- Provide and improve Campfire for your household.
- Authenticate you, protect accounts, and prevent abuse.
- Process subscriptions and trials via Stripe.
- Power Assist (AI features) using your household context so answers stay grounded — see AI disclosure below.
- Respond to support requests and send transactional email (e.g. invites).
AI disclosure (Assist)
When Assist is enabled for your household, relevant household context may be sent to our AI provider (currently OpenAI) to generate a response. Do not put secrets (passwords, payment card numbers, government IDs) into Assist prompts.
OpenAI’s API terms: customer content is not used to train foundation models. Providers may retain API inputs briefly (typically up to 30 days) for abuse monitoring and trust & safety. You can turn Assist off anytime in Family settings → AI Assist — Ask is hidden and household content is not sent to AI providers.
Cookies
We use necessary cookies for sign-in and security. Optional analytics cookies are off until you consent. Manage preferences anytime via Cookie preferences in the footer.
Subprocessors
We use trusted vendors to run Campfire:
- MongoDB Atlas (or equivalent) — application and identity data
- Hosting (e.g. Vercel) — web app and API hosting
- OpenAI — Assist / AI features
- Stripe — billing and payments
- Upstash / Vercel KV (optional) — rate limiting
- Resend (optional) — transactional email
- Google (optional) — sign-in if you choose Google OAuth
We update this list when vendors change. Enterprise data-processing agreements (DPAs) are available for business products separately; family early access relies on this Privacy Policy and vendor terms.
Retention
We keep account and household data while your account is active. Security and audit logs are retained for operational and compliance purposes (typically at least one year). You may request deletion of your account by contacting support; some records may be retained where legally required.
Your choices
- Update household data in the product.
- Export your household data anytime (CSV) from Family settings → Your data.
- Manage billing in Family settings (Stripe customer portal).
- Delete your household account in Family settings → Your data (cancels billing and removes data), or contact campfire@hourglasssystem.com.
Children
Campfire is designed for households that may include children under adult accounts. Parents/guardians control household membership and content. We do not knowingly market directly to children under 13.
Contact
Questions about privacy: campfire@hourglasssystem.com. See also our Terms of Service.