Scope and operator
This Privacy Policy explains how Fireship.ai (“Fireship,” “we,” “us,” or “our”) handles personal information when you visit our website, create an account, use connected Android phones, operate automations, purchase a subscription or credits, or contact support.
It applies to the Fireship website, dashboard, cloud services, and companion software that communicates with the cloud. It does not replace the privacy terms of Android, PayPal, an AI model provider, or any third-party app or platform you choose to use.
Information you provide
Depending on how you use the service, you may provide:
- Account details such as your name, email address, profile image, and organization name.
- Business profiles, goals, products, audience information, policies, prompts, schedules, and automation settings.
- Content and files, including captions, images, videos, messages, approval decisions, and support requests.
- Contact and lead information that you choose to collect or process through connected apps.
- AI provider credentials when you choose a bring-your-own-key route.
You are responsible for ensuring that you have the authority and any required notices or permissions to provide information about other people.
Connected-phone and automation data
When you connect Android phones, the service receives device and operational information needed to coordinate them. This may include a device name and model, operating-system and app versions, installation identifiers, connection status, capabilities, heartbeats, command queues, command events, worker status, failures, and timestamps.
Automations may create or process prompts, generated content, publication plans, media references, messages, leads, approvals, reports, run history, screenshots or other evidence, and results returned by connected phones. Live-view features process session status, timing, and frames required to display the requested view. Support access is separately requested by a workspace owner, limited in scope, audited, revocable, visibly indicated, and expires within 60 minutes.
AI processing and provider keys
Fireship may send prompts, business context, images, or other selected inputs to model providers to generate content, interpret screens, plan work, or respond to your commands. The specific information depends on the feature and provider route you select.
Managed AI usage is metered through Fireship credits. If you use a bring-your-own-key option, the credential is stored in encrypted form and used to route your requests to the selected provider. The provider may process those requests under its own terms and privacy policy.
Payments and subscriptions
PayPal processes subscription approvals and credit top-ups. We receive and store transaction-related information such as PayPal order or subscription identifiers, status, plan, quantity, amount, currency, payer identifiers, and timestamps. We do not receive or store your full payment-card number through these flows.
PayPal acts as an independent controller for payment data it processes and may use that information for payment services, fraud prevention, legal compliance, and other purposes described in the PayPal Privacy Statement.
How we use information
- Provide, authenticate, secure, maintain, and improve the service.
- Pair devices, dispatch work, show status, and preserve run history.
- Generate content, process approvals, track leads, and prepare reports.
- Meter managed AI usage, administer credits, and reconcile billing.
- Respond to support requests and investigate operational or security incidents.
- Prevent fraud, abuse, unauthorized access, and violations of our Terms.
- Comply with law and enforce agreements.
Service providers and disclosures
We disclose information only as needed to operate the service, including to authentication, hosting, database, storage, monitoring, communications, AI, and payment providers. Their processing is governed by their contracts with us and, where they act independently, by their own terms.
We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or the public, enforce our agreements, investigate abuse, or complete a merger, financing, acquisition, or sale of assets subject to appropriate confidentiality protections. We do not sell personal information for money.
Retention
Our current operational retention schedule is:
- Raw operational evidence is retained for 7 days.
- Closed-lead text is retained for 90 days.
- Unpinned media is retained for 30 days.
- Operational history is retained for 12 months.
- Account deletion is scheduled to complete within 30 days of an owner request.
Billing, fraud-prevention, security, audit, dispute, tax, and other legal records may be retained longer where necessary for a legitimate business purpose or legal obligation. We then delete or pseudonymize those records when the applicable purpose permits.
Training choice and aggregate analytics
Product operation does not automatically enroll your data in model training. Training is a separate owner choice, is off by default, and can be withdrawn from workspace settings. Withdrawing consent does not undo processing already lawfully completed before withdrawal.
Eligible aggregate reporting requires a cohort of at least 10 organizations and 100 completed runs. Smaller cohorts are excluded. We use these thresholds to reduce the risk that an aggregate result identifies a particular organization.
Your controls and privacy rights
Workspace owners can request a private data export, change training consent, and request or cancel account deletion from Settings. Export links expire and are single-use. A deletion request revokes operational credentials as part of the deletion process, subject to limited records we must or are permitted to retain.
Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, or to appeal a decision about a request. Contact us to exercise a right not available in Settings. We may need to verify your identity and authority over the workspace before acting.
Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, scoped credentials, encryption for stored provider keys, audited support activity, and verification of sensitive billing events. No method of storage, transmission, or authentication is completely secure, and we cannot guarantee absolute security.
International processing
Fireship and its service providers may process information in countries other than the one where you live. Those countries may have different data protection rules. Where required, we use appropriate contractual or other safeguards for international transfers.
Children
The service is intended for businesses and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this Privacy Policy as the product, providers, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when required. Your continued use after an update is subject to the revised policy, but a policy update does not convert an off-by-default training choice into consent.
Contact
For privacy questions or requests, email hello@fireship.app. Please identify the workspace connected with your request and do not email passwords, provider keys, or other secrets.