Patient Validator
PRICING
Contact
Install
PRICING
Contact
Install
Patient Validator
PRICING
Contact
Install
PRICING
Contact
Install

Privacy Policy

Validator, a product of Bonfire Revenue Inc.

Effective Date: August 2026

Bonfire Revenue Inc. ("Bonfire Revenue," "we," "us," "our") operates Validator (the "Service") — a browser extension and a web application that verify email addresses, phone numbers and mailing addresses.

This policy explains what the Service collects, what we do with it, what we keep, and what we never keep. It applies to the extension and the web application equally, whichever of our storefronts you signed up through.

It is written to meet the Google Chrome Web Store and Microsoft Edge Add-ons User Data Policies.


The short version

We are a pass-through. The contact data you validate reaches our servers, goes to a verification provider, and comes back to you. We do not log it, save it, or store it. What we do keep is your account: a hashed API key, your plan, and a count of how many validations you have used.


Information the Service accesses

Page content, one scan at a time. When you click Scan, the Service reads the text of the browser tab you are already looking at, to find email addresses, phone numbers and mailing addresses. It reads nothing until you ask it to, and it reads nothing in the background.

Bulk upload data. When you use bulk validation, the Service reads the CSV file you choose. The file is parsed for contact fields and processed the same way as a scan.

Authentication data. We store your API key so you do not have to re-enter it. On our servers it is stored only as a SHA-256 hash — the plaintext key is never written to our database.

Account details. The name, email address, phone number and mailing address you give us at signup, plus your subscription status and your usage count for the current period.

Support chat, and optionally audio. If you use the in-app support chat, we receive the text you type. If you choose to use the optional voice-to-text feature, your browser captures microphone audio to transcribe your request. The microphone is never accessed outside of active chat dictation.

What we do with it

Validation. Contact data is transmitted over encrypted HTTPS to our backend, which passes it to third-party verification providers to check deliverability and accuracy. Today those providers are Google Maps Platform (addresses), Telnyx (phone numbers), and Reoon and EmailIt (email addresses). We may add or change providers.

Authentication and metering. Your API key identifies your account, confirms your plan, and increments your usage count.

Support. Chat text and any transcribed voice input are used only to answer your question.

Service email. We send account email — your welcome message with your API key, plan changes, payment problems, and referral notices — through EmailIt.

What we keep, and for how long

Contact data you validate: nothing. The email addresses, phone numbers and addresses you scan or upload are processed in real time and discarded. They are not logged, not written to a database, and not retained after the response is returned to you.

Validation results: nothing on our side. Results are returned to your browser. If you download a CSV of results, that file exists only on your device.

Your account: kept for as long as your account exists, in our customer record — a hashed API key, plan, usage, contact details and billing identifiers.

On your device: your API key and display preferences are saved in your browser's storage so you stay signed in. In the extension this is Chrome sync storage, so it follows your Chrome profile across browsers. You can clear it at any time with "Forget key on this device" in the dashboard.

Support transcripts: may be retained temporarily to improve support. Never put protected health information or sensitive personal details into the support chat.

Who we share it with

We share information with service providers only to the extent needed to do what you asked:

  • Verification providers — Google Maps Platform, Telnyx, Reoon, EmailIt — receive the individual contact values being checked.
  • Stripe handles payments and stores your billing details. We never see or store your full card number.
  • Google Workspace (Apps Script, Sheets, Drive) hosts our backend and customer record.
  • Zipchat.ai powers the support chat widget and processes chat text and voice-to-text.

And to be explicit:

  • We do not sell your data. We will never sell, rent or trade your personal information, or the contact information you validate, to anyone.
  • We do not use your data for advertising. Nothing the Service accesses is used or transferred for personalized, retargeted or interest-based advertising.
  • We do not use your data to assess creditworthiness or for lending purposes.
  • We do not use the contact data you validate for anything other than returning your result.

Permissions, and why each one exists

PermissionWhy
activeTabTo read the text of the tab you are on, only at the moment you click Scan.
scriptingTo inject the short-lived script that does that reading. It stores nothing.
storageTo save your API key and preferences on your own device.
sidePanelTo draw the interface. It is the extension's only UI.
Host accessscript.google.com and script.googleusercontent.com are our own backend. The extension also requests access to the web pages you visit, because it cannot know in advance which EHR, CRM or scheduling app you use. It reads a page only at the moment you click Scan, never in the background, and never on a tab you are not looking at.
MicrophoneNot a browser extension permission. Requested by the support chat widget through the standard browser prompt, only for optional voice dictation.

Your choices

  • Stop storing your key — use "Forget key on this device," or uninstall the extension.
  • Stop the emails — every marketing email has an unsubscribe link. Account and billing email is part of the Service and cannot be turned off while your account is active.
  • Stop the texts — reply STOP to any message.
  • See, correct or delete your account data — email us and we will action it. Deleting your account ends your subscription.

Children

The Service is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.

International users

We operate in the United States, and information is processed there. If you use the Service from elsewhere, you are transferring your information to the United States.

Security

Everything moving between the extension or web app, our backend, and our verification providers is encrypted in transit with TLS. API keys are stored hashed. Access to our customer record is limited to people who need it.

No system is perfectly secure, and we cannot guarantee absolute security — but the strongest protection here is structural: the contact data you validate is never stored, so there is no store of it to breach.

Changes to this policy

We may update this policy. If a change is material, we will update the Effective Date above and place a notice in the Service.


SMS and text messaging

By providing your mobile number and opting in through our website, you consent to receive SMS text messages from Bonfire Revenue Inc. relating to your account, billing, and customer service. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help at any time.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.


Contact

Bonfire Revenue Inc.
8977 S 1300 W PMB #2046, West Jordan, Utah 84088, United States
support@patientvalidator.com

Linkedin
Facebook

© 2026 Bonfire Revenue

All Rights Reserved.

Privacy Policy·Terms & Conditions·HIPAA·Data Protection