Legal
Privacy Policy
Last updated August 25, 2026
Firebrande ("Firebrande," "we," "us") operates a workspace that connects to Firebase and Google Cloud projects you authorize, so you and your team can manage them from one place. This notice explains what information we collect, why, who we share it with, and the choices you have. It applies to firebrande.com and the Firebrande application.
Information we collect
Directly from you
- Account information: name and email address (via Clerk, our authentication provider).
- Team information: team name, membership, roles, and invitations you send.
- Billing information: Stripe collects and stores your payment details directly — we receive only your Stripe customer ID, subscription status, plan, and billing period. We never see or store your card number.
- Anything you send us directly, such as a support request.
From providers you connect
- Google: when you sign in with Google or connect a Firebase/Google Cloud project, we receive an OAuth token scoped to the permissions you grant, and basic profile info (name, email). Connecting a project lets Firebrande read and act on that project's Firestore, Storage, Authentication, Functions, and Rules on your behalf — only for the operations you initiate.
- GitHub: if you connect a repository for Functions or SQL Connect deployment, we receive an OAuth token scoped to the repository access you grant.
Automatically, as you use the product
We keep operational records tied to your account and team — audit events, deployment and job history, and similar metadata — so actions in the product are attributable and recoverable. These records are scoped to your team and are not shared across tenants.
How we use information
- Operate and maintain the product, including authenticating you and enforcing that your team only ever sees its own projects and data.
- Process subscriptions, trials, and billing through Stripe.
- Send transactional email — invitations, account notices, billing receipts — through Postmark.
- Provide optional AI features (see "AI features" below), only when you use them.
- Respond to support requests and investigate reported problems.
- Maintain security, detect abuse, and keep an audit trail for accountability.
We do not sell your personal information, and we do not use your Firebase/Google Cloud project content to train any model or for advertising.
What we don't do
- We don't browse your connected project's data outside of the specific action you request — Firebrande reads and writes only what a given operation (a query, an edit, a deployment) requires.
- We don't store your Firestore documents, Storage objects, or Authentication users as a separate copy — your Firebase/Google Cloud project remains the source of truth. Firebrande stores references and operational metadata, not a replica of your data.
- Provider access and refresh tokens are encrypted at rest, accessible only from our servers, and are never sent to your browser or included in logs, exports, or support tickets.
AI features
Features like Gemini Intelligence and Change Intelligence send relevant, minimized context from the project you're actively working in to our AI provider to generate a response — not your entire connected project. These features are optional and scoped to your current project; you can choose not to use them.
Data retention
- Account and team data is kept for as long as your account is active.
- AI conversation history defaults to 30 days and can be configured per project between 0 and 365 days.
- Billing records are kept as required for accounting and legal purposes.
- Provider credentials are revoked and deleted when you disconnect a project or close your account.
Disconnecting a project or deleting your Firebrande account removes our connection and operational metadata — it does not delete or modify anything in your actual Firebase or Google Cloud project. That data remains under your control and is managed directly through Google.
Your rights and choices
Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal information. To make a request, contact us using the details below — we'll verify your identity before acting on it. Requests that touch your connected Firebase/Google Cloud project data may require you to also act directly through Google, since that data is not stored by us.
Security
- Provider credentials are encrypted at rest and only ever accessed server-side.
- Every request is checked against your team's actual membership and role before it can touch a project, bucket, or resource — a project ID alone is never treated as proof of access.
- We never store your card details — Stripe handles payment collection directly.
No method of transmission or storage is perfectly secure. If we become aware of an incident affecting your information, we will investigate, contain it, and notify affected users as required by law.
International data
Firebrande and the providers we rely on may process and store information in the United States and other countries where our providers operate. Where required, we rely on appropriate safeguards for any international transfer of personal information.
Children's privacy
Firebrande is a professional tool for developers and teams and is not directed at, or knowingly used to collect information from, children under 16.
Changes to this notice
We may update this notice as the product changes. We'll update the date at the top of this page, and for material changes we'll take reasonable steps to let you know, such as an email or an in-product notice.
Contact us
Questions about this notice, or a request about your information, can be sent to privacy@firebrande.com.