Legal
Privacy Policy
Last updated: July 11, 2026
This Privacy Policy explains how [FireFight Labs — legal entity name] ("FireFight", "we", "us") collects, uses, shares, and protects information when you use the FireFight hosted service at app.firefight.app and this website (together, the "Service").
FireFight is also available as open-source software you can run yourself. When you self-host FireFight, you are the controller of the data in your deployment and this policy does not apply — your data stays within your own infrastructure and is governed by your own policies. This policy covers only the version of FireFight that we operate for you.
Information we collect
Account and identity information
When you sign in with Slack, we receive information from Slack to create and operate your account, including your name, email address, Slack user ID, workspace (team) ID, and profile image. We store an OAuth access token so FireFight can act inside your Slack workspace on your behalf. Tokens are encrypted at rest.
Incident data
FireFight processes the data you create while managing incidents: incident details, severities and statuses, roles and assignments, timelines, action items and follow-ups, postmortems, and the messages and files shared in incident channels that you choose to capture. This data belongs to you.
AI processing
Some features (postmortem drafts, catch-up summaries, live summaries) use AI models to process the relevant incident content and return a result. We only process what is needed to produce what you asked for. See AI and model providers below.
Usage and technical data
We collect standard technical information such as log data, IP address, browser and device information, and how you interact with the Service, to operate, secure, and improve it.
Payment information
If you subscribe to a paid plan, payment is handled by our payment processor. We do not store your full card details; we receive limited billing information (such as plan, status, and the last four digits of your card) to manage your subscription.
How we use your information
- To provide, operate, and maintain the Service
- To authenticate you and secure your account and workspace
- To generate the AI features you request
- To process payments and manage your subscription
- To provide support and respond to your requests
- To monitor, debug, and improve reliability, security, and performance
- To comply with legal obligations and enforce our Terms
We do not sell your personal information, and neither we nor our AI providers use your data to train AI models.
AI and model providers
FireFight uses AI models to power its generative features and is model-agnostic. We do not use your data to train AI models, and we work only with providers that are contractually bound not to train on or retain the content we submit. Content is processed only to return the result you requested. If you self-host, you can point these features at your own model so this content never leaves your environment.
How we share information
We share information only as described here:
- Subprocessors. We use trusted service providers to run the Service, including cloud compute and hosting, database hosting, object/file storage, AI model providers, and payment processing. They may process data only to provide services to us and under appropriate obligations.
- Slack. The Service integrates with Slack; your use of Slack is governed by Slack's own terms and privacy policy.
- Legal and safety. When required by law, or to protect the rights, safety, and security of users, the public, or FireFight.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy.
See our current list of subprocessors for the third parties that process data on our behalf.
Data retention
We retain your data for as long as your account is active and as needed to provide the Service. If you close your account, we delete or anonymize your data within a reasonable period, except where we must retain it to meet legal, accounting, or security obligations. Backups are cycled out on a rolling basis.
Security
We use industry-standard measures to protect your data, including encryption in transit and at rest for sensitive data such as OAuth tokens, access controls, and monitoring. No system is perfectly secure, but because FireFight is open source, you can review exactly how the Service handles data.
Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. To exercise these rights, contact us at privacy@firefight.app. You can also disconnect FireFight from your Slack workspace at any time from Slack's app settings.
International data transfers
We may process and store information in countries other than where you live. Where required, we use appropriate safeguards for such transfers.
Cookies
We use strictly necessary cookies to keep you signed in and to operate the Service securely. We do not use advertising cookies and we do not sell your data.
Our public website also uses a small number of non-essential cookies and similar storage: privacy friendly analytics to understand which pages are useful, product analytics to diagnose usability problems, and our live chat widget to keep your conversation with us open across pages. These run on our marketing site only, never inside the Service. See our list of subprocessors for who is involved.
Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you.
Contact us
Questions about this policy or your data? Email us at privacy@firefight.app.