Privacy Policy
Latest update: July 16, 2026
The protection of your personal data is important to Firepanel, and we carry out our processing activities in accordance with your rights as provided for under Regulation (EU) 2016/679 of April 27th, 2016 (the "GDPR") and other applicable data protection law (together, the "Legal framework"). This document (our "Privacy Policy") explains, in detail, the types of personal information we collect and what may happen to that personal information when you use our websites and related applications and resources (collectively, the "Services").
Data Controller and Contact
The data controller is: Hypnotic Digital Agency Lda, a Portuguese company whose registered office is located at Av. Prof Dr Egas Moniz 13 C 1 Esq, 2625-147, Portugal, registered on the commercial and company register of Portugal under the number 509 136 818, represented by Luis Freire and Gonçalo Pinheiro ("Firepanel", "we" or the "Data controller").
The Data is processed at the Data Controller's operating offices and in any other places where the parties involved with the processing are located.
To exercise your rights, as described under this Privacy Policy, or for any question you might have, you can contact us at the following address:
Hypnotic Digital Agency LdaAv Prof Dr Egas Moniz 13 Edif C 1 Esq
2625-147 Portugal
Email: support@firepanel.io
Legal Basis of Processing
The legal bases on which Firepanel processes your Data are:
- performance of a contract — where processing is necessary to provide the Services you have signed up for (e.g. creating and operating your account, billing);
- our legitimate interests — for example, keeping the Services secure, monitoring and diagnosing errors, and understanding how the Services are used so we can improve them, where these interests are not overridden by your rights;
- your consent — for example, for non-essential analytics cookies and for commercial communications; and
- compliance with a legal obligation — for example, retaining accounting and tax records.
This Privacy Policy is incorporated into the Firepanel Terms of Service. Your use of the Services and any information you provide through the Services is subject to this Privacy Policy and our Terms of Service.
This Privacy Policy applies to the following websites and apps:
- The main Firepanel Website — https://firepanel.io
- The Firepanel Console — https://console.firepanel.io
- The Firepanel Mobile App (Android & iOS)
The mobile apps collect the same categories of data as the Console, described below, except where a platform feature (such as device push notifications) requires additional data, in which case you will be asked for the relevant permission on your device.
The Data may be freely provided by the User or collected automatically when using the Services. Where the legal basis is consent, Users can withdraw their consent at any time. An unsubscribe link is present in newsletters sent by Firepanel.
Data We Collect
Creating and using a Firepanel account
Accounts are created through federated sign-in with a third-party identity provider (Google, GitHub, Apple, or Microsoft). We do not ask you to create or store a password with us. When you sign in, we collect your name, email address, profile photo (if provided by your identity provider), the identity provider used, and the date and time of your logins. You can later edit your display name and profile photo in your account settings.
We also store your notification preferences (which email, push, and desktop notifications you wish to receive).
Feedback and support
We sometimes ask for your feedback on the Services. If you choose to respond, you may provide comments together with details such as your first name, last name, job title, or telephone number. Providing these is entirely optional.
Billing and payments
Payments for paid plans are processed by Stripe through Stripe-hosted checkout and billing pages. Your card details are entered directly with Stripe and are never received or stored by Firepanel. From Stripe we receive and store only non-sensitive billing information needed to manage your subscription: your Stripe customer identifier, your card brand and its last four digits (for display), your invoice history, and your plan, amount, currency, status, and renewal date.
Content and uploads
When you upload a profile photo, it is stored in our file storage. If you use the Console to manage your own project(s), you may upload project content (documents, images, and other files) and provide Firebase service-account credentials to connect your project. See "Data We Process on Your Behalf" below for how this data is handled.
Technical and usage data
To operate the Services, we and our providers process technical data such as authentication tokens (stored in your browser's local storage), device and browser information, IP address, and usage data, including analytics identifiers where you have consented to analytics cookies.
You are responsible for any Data of third parties you obtain, publish, or share through the Services, and you confirm that you have the third party's consent to provide such Data to Firepanel.
Data We Process on Your Behalf
The Firepanel Console lets you manage the content and end-users of your own applications and Firebase projects. This may include personal data about your users (for example, names, email addresses, phone numbers, geolocation, dates of birth, tax identifiers, and push-notification tokens or audience segments).
With respect to this data, you are the data controller and Firepanel acts as your processor. We process it only on your documented instructions and to provide the Services, and not for our own purposes. Our processing of this data is governed by a Data Processing Agreement (DPA), which is available on request at support@firepanel.io. You are responsible for having a valid legal basis to collect and process the personal data you upload to or manage through the Services.
Purposes of the Processing
We process the Data in order to:
- create and administer your User account;
- deliver, maintain, and improve our Services;
- provide you with technical support;
- process payments and generate and send invoices;
- keep the Services secure and diagnose, monitor, and fix errors;
- analyze usage of the Services to improve them (subject to your consent for analytics cookies);
- communicate with you about the Services, including changes to our business or new features;
- comply with our legal obligations; and
- ask for your feedback on the Services.
Recipients
The Data we collect can be accessible to:
- authorized employees of Firepanel who need it to provide the Services — for example, our support, engineering, commercial, and accounting teams; and
- the sub-processors listed below, strictly for the purposes described in this Policy.
These recipients are subject to confidentiality and data protection obligations consistent with this Privacy Policy. The User acknowledges that the Data Controller may be required to disclose Data at the request of public authorities.
Sub-processors
Firepanel relies on the following third-party providers to deliver the Services. Each provides appropriate technical and organizational safeguards, and personal data is shared with them only to the extent needed for their function:
- Google / Firebase (Google LLC) — authentication, database (Firestore), file storage, cloud messaging, and hosting infrastructure. Place of processing: USA and EU.
- Stripe (Stripe, Inc.) — payment processing and subscription billing. Card data is collected and stored directly by Stripe. Place of processing: USA and EU.
- Sentry (Functional Software, Inc.)— error monitoring and session replay (see "Analytics and Cookies" below). Place of processing: USA.
- Google Analytics (Google LLC) — website and product usage analytics. Place of processing: USA.
- Google Fonts (Google LLC) — delivery of icon and typeface assets, which involves your IP address being sent to Google. Place of processing: USA.
- Sanity (Sanity AS) — content management for our website. Place of processing: EU/USA.
- Mailgun (Sinch / Mailgun Technologies, Inc.) — sending transactional and newsletter emails. Personal data collected: email address. Place of processing: USA.
- Identity providers (Google, GitHub, Apple, Microsoft) — federated sign-in. We receive your name, email, and profile photo from the provider you choose to sign in with.
An updated list of sub-processors may be requested from the Data Controller at any time.
International Transfers
The User has been informed that the Data may be shared with third parties located, or which use servers located, outside of the European Union in countries whose data protection laws differ from those of the European Union.
In these cases, Firepanel ensures that this transfer is performed in compliance with the applicable regulations and guarantees a sufficient level of protection for the privacy and fundamental rights of individuals (in particular via the European Commission's standard contractual clauses). You can contact us for any questions or requests for additional information related to these transfers.
Security Measures
The Data Controller processes the Data in a proper manner and takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of the Data. Data processing is carried out using computers and/or IT-enabled tools, following organizational procedures and modes strictly related to the purposes indicated.
We have security measures in place to help protect against unauthorized access to personal information under our control, including encryption in transit, access controls, and restricted physical access to the places where information is stored. Payment card data is isolated within Stripe's PCI-DSS-compliant environment and never stored on Firepanel's systems. Our staff is trained to comply with our security procedures, which are regularly reviewed and revised as we deem necessary.
Retention Time
The Data is kept for:
- the time necessary to provide the Services to the User;
- a period of 3 years after:
- the last period of inactivity on the User account; or
- the last contact made by the User with the Data Controller;
- or any other duration required by applicable law (for example, accounting and tax records, which must be retained for the periods set by applicable accounting and tax legislation).
The User's Data may also be used for legal purposes by the Data Controller, for the duration of any dispute, in court or in the stages leading to possible legal action arising from improper use of the Services by the User.
Collection of Information from Minors
The Services are intended for a general audience and are not directed at children under the age of 16. Use of the Services is prohibited for anyone under the age of 16. If you are under 16, you must obtain authorization from your parent or legal guardian before using the Services. We do not knowingly collect or solicit personal information from children under the age of 16.
Analytics and Cookies
Google Analytics 4 (Google LLC)
We use Google Analytics 4 to understand how our websites and Console are used so we can improve them. Analytics cookies are loaded with Google Consent Modeand are set to "denied" by default; they are only activated after you accept them via our cookie banner. When you are signed in to the Console, we send Google only your Firepanel user identifier and plan — we do not send your name, email, or other directly identifying information to Google Analytics.
Personal Data collected: cookie and usage data, analytics identifiers. Place of processing: USA.
Sentry (Functional Software, Inc.)
We use Sentry to detect, diagnose, and fix errors in the Services. When you are signed in, Sentry receives your user identifier and email address so we can correlate and resolve issues affecting your account. Sentry also records a sample of session replays — reconstructions of interactions with the interface — to help us reproduce and fix errors. Sensitive fields are masked in these recordings. Place of processing: USA.
Google Fonts (Google LLC)
Google Fonts is a typeface and icon visualization service provided by Google that allows the Services to display these assets on their pages. Loading these assets involves your IP address being sent to Google.
Personal Data collected: usage data and other data as specified in the provider's privacy policy. Place of processing: USA.
Mailgun
Mailgun is an email address management and message-sending service. Personal Data collected: email address. Place of processing: USA.
Cookies and local storage
A cookie is a small information file saved by a website on your device. We use strictly necessary cookies and local storage to operate the Services — for example, to keep you signed in (authentication tokens are stored in your browser's local storage) and to remember your preferences. These are required for the Services to function and are not subject to consent.
Non-essential analytics cookies are only set after you accept them via our cookie banner, and you can change your choice at any time. Most browsers accept cookies automatically; you can configure your browser to notify you when a cookie is created or to prevent cookies from being saved. Note that disabling some cookies may make certain features of the Services unavailable.
Your Rights
Users have the right, at any time, to know whether their data is being processed and to access its content and origin, to verify its accuracy or ask for it to be supplemented, corrected, updated, or erased, to object to or restrict its processing, to withdraw consent, to set instructions for the preservation, erasure, and communication of their Data after their death, and to the portability of their Data.
Requests should be sent to the Data Controller at the contact information set out above. You also have the right to lodge a complaint with the competent data protection supervisory authority in your EU member state, or to seek remedies from the competent courts, if you believe we have not respected your rights.
Changes to this Privacy Policy
The Data Controller reserves the right to make changes to this Privacy Policy at any time by giving notice to Users on this page. We strongly recommend checking this page regularly, referring to the date of the last modification listed at the top. If a User objects to any of the changes, the User must cease using the Services and may request that the Data Controller remove their Data. Unless stated otherwise, the then-current Privacy Policy applies to all Data the Data Controller holds about Users.
Definitions
- Data / Personal information
- Shall have the same meaning as set forth under article 4 of the GDPR: "any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person".
- User
- The individual using the Services (paid subscription or free subscription) or visiting the Websites, which must coincide with or be authorized by the data subject to whom the Data refers.
- Data Controller
- The natural person, legal person, public administration, or any other body, association, or organization with the right, also jointly with another Data Controller, to make decisions regarding the purposes and methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of the Services. The Data Controller, unless otherwise specified, is the Owner of the Services.
- Data Processor
- The natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Data Controller, as described under article 4 of the GDPR.