Privacy Policy
Last updated: September 12, 2026
This policy explains what data Fireside collects, how we use it, and your rights. Fireside is operated by Fireside Systems Pty Ltd (A.C.N. 695827322).
1. Data We Collect
Account information: When you sign in with Google, we receive your name, email address, and profile picture from Google OAuth. We store this in Supabase (our authentication provider).
Uploaded content: Transcripts (PDF or TXT files) and GitHub repository references you provide for content generation.
Connected source content: Fireside can read from Google Drive, GitHub, GitLab, Notion, Confluence, Grain, and public web pages. It reads nothing from a source until you connect it, and only what it needs to write a story.
Google Drive content: If you connect Google Drive, we read your Google Docs (titles, text, modification dates) through the Google Drive and Google Docs APIs. We use the document to discover and draft stories. On our production deployment, source material may remain inside workspace-scoped discovery records in S3-compatible storage so we can diagnose faults.
Call recordings (Grain): If you connect Grain, we read your recorded calls: the transcript, the title and date, the participant list (names and email addresses), and Grain's own AI summary. Some of those participants are your customers rather than Fireside users, so the responsibility for having the right to share the recording with us sits with you. Our Terms of Service set out what that means.
Video clips: When a story comes from a recorded call, Fireside can cut a short clip out of the source video. A Cloudflare Worker container renders it and we keep it in storage. Section 3 covers where it is held.
Source connection tokens: When you connect a third-party source, we store the OAuth token or personal access token in our database, encrypted with AES-256-GCM.
Generated content: The social media posts and story content Fireside creates from your uploads.
Voice configuration: Your brand voice settings, tone preferences, and audience definitions.
Billing data: Payment processing is handled entirely by Stripe. We store your Stripe customer ID and subscription status, but never your card details.
Usage data: Basic analytics (page views, feature usage) to improve the product. PostHog provides product analytics and session replay. Hall receives the request path and method, timestamp, IP address, host, user agent, and referrer for page views. We use cookie-free analytics where possible.
2. How We Use Your Data
- Content generation: Your uploaded transcripts and documents are sent to Anthropic's Claude API for analysis and content generation. Anthropic processes this data according to their privacy policy. Per Anthropic's commercial terms, your data is not used to train their models.
- Service delivery: To generate content, manage your account, and process payments.
- Connected sources: Content retrieved from a connected source is sent to Anthropic's Claude API the same way an uploaded transcript is. This includes call transcripts from Grain. We do not use data from your connected sources for advertising, and we share it only where providing the Service requires it.
- Product improvement: Aggregated, non-personal usage patterns help us improve Fireside.
3. Data Storage & Security
Account data is stored in Supabase (hosted on AWS). Uploaded content and generated posts may be stored temporarily on our servers, and on our production deployment in S3-compatible storage (Cloudflare R2 or AWS S3). Video clips are stored in Cloudflare R2.
Storage is organised per workspace, so one customer's content is held under its own prefix. The clip bucket is private and is never served publicly: clips reach the browser through links that expire after one hour. All data is transmitted over HTTPS.
4. Third-Party Services
- Anthropic (Claude API) — processes your uploaded content for AI-powered generation.
- Supabase — authentication and database.
- Stripe — payment processing.
- Vercel — application hosting.
- Google OAuth — sign-in provider.
- Google Drive API & Google Docs API — reads your Google Docs content when you connect Google Drive as a source.
- GitHub API — fetches repository data when you use the GitHub source. Private repositories are read only with a token you supply.
- GitLab API — the same, for the GitLab source, on gitlab.com or a self-hosted instance.
- Grain API — reads your call recordings, transcripts and participant lists when you connect Grain.
- Notion API — reads the pages and databases you share with the Fireside integration.
- Confluence API — reads the pages you point Fireside at.
- Cloudflare (R2 and Workers) — stores video clips and runs the container that renders them.
- PostHog — product analytics and session replay.
- Hall — server-side page-view analytics using request and device information.
5. Cookies
Fireside uses a session cookie (firesideSession) to keep you logged in. This is a functional cookie required for the Service to work. Our analytics tool (PostHog) may also set cookies or use similar technologies to understand how visitors use the site.
6. Google API Services Disclosure
Fireside's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Data Retention
Your account data, voice configuration, and generated content are retained while your account is active. Uploaded transcripts are deleted from the application's temporary disk after processing. On our production deployment, the original upload may also be kept in workspace-scoped S3-compatible storage for fault diagnosis. Stored uploads have no fixed expiry. Email us to have them removed.
Video clips are cached. A rendered clip stays in storage so the same moment does not have to be cut twice. Clips have no fixed expiry. Email us to have one removed before you close your account.
Content from connected sources is read at generation time. On our production deployment, some source material may remain inside workspace-scoped discovery records used for fault diagnosis. It may also appear in the stories Fireside writes from it. Disconnecting a source stops further reads; it does not retract stored discovery records or stories already generated. Email us if you want those records removed.
Deleting your login removes your access to Fireside. It does not automatically delete content stored for a workspace, because that workspace may have other members. Email us to have a workspace's stored uploads, discovery records, generated content, and cached clips removed.
8. Your Rights
You can:
- Access your data — view your profile, voice config, and generated content within the app.
- Delete your login — from the Settings page. This removes your Fireside login and access. Email us if you also want stored workspace content removed.
- Export your content — generated posts can be copied from the app interface.
- Revoke third-party access — disconnect sources from the Sources page at any time. For Google Drive, you can also revoke Fireside's access from your Google Account permissions page.
- Request removal of a recording or clip — email us and we will delete the cached clips and stored content for a given call. This applies whether you are a Fireside user or a participant on a call someone recorded.
For any data-related requests, contact sean@fromfireside.com.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice.
10. Contact
Questions about privacy? Email sean@fromfireside.com.