// FireThrust

Privacy Policy

What we collect, why, where it goes, and how to get rid of it.

Last updated 10 August 2026

The short version. FireThrust is local-first and account-optional. Your hosts, snippets, settings and vault credentials live on your device. We do not sell your data, we do not share it with data brokers, and we run no third-party advertising or cross-app tracking SDKs. The material thing that leaves your device is the content you deliberately hand to an AI model — and only after you have agreed to the specific providers named below.

Who we are

FireThrust is operated by Haymakers, Inc. (“we”, “us”). This policy covers the FireThrust web app, desktop app, and the iOS and Android apps. Questions, requests and complaints go to privacy@firethrust.com.

What we collect

Every row below is conditional: it applies only if you use the feature it belongs to. An installed FireThrust that you never sign into and never point at a cloud model transmits none of it.

DataWhenWhyLinked to you
Terminal hosts / snippets / connection settingsOnly if you create themRun the product — operate your agents and hostsNo
Account email (optional)Only if you sign inAuthenticate your accountYes
Sync ciphertextOnly if sync is onMove encrypted state between your own devicesNo — opaque to us
Relay/session metadata (device ids, timestamps)When a remote session runsRoute the session to the right devicePseudonymous
Crash / diagnostic logsOnly if you opt inDiagnose stability problemsNo
Model / AI provider API keysOnly if you add oneLet the model you chose drive the agentNo — never sent to us
Prompt / message content sent to a modelOnly when you use a cloud modelProduce the response you asked forNo — sent to the AI provider you configured
Page-content excerpt / screenshot the agent readsOnly when a task requires reading or seeing a pageGive the model the context the task needsNo — sent to the AI provider you configured
Subscription statusOnly if you subscribeUnlock the features you paid forYes

AI providers that may receive your content

When you ask FireThrust to do something with a cloud model, the content needed to answer — your prompt, an excerpt of the page the agent is reading, and a screenshot if the task requires vision — is sent to the provider you have configured. In this build, that means:

  • Anthropic (Claude)
  • OpenAI (ChatGPT)
  • OpenRouter

This list is generated from the build itself rather than written by hand, so it cannot drift from what the app actually does. It is the same list the first-run consent screen shows you. If a future release adds or removes a provider, your previous agreement does not carry over and you are asked again — consent is recorded against the exact set of recipients it was shown for.

Models you run locally (for example through Ollama, or an on-device model you have downloaded) contact no third party at all, and nothing about those requests leaves your machine.

What never leaves your device

  • Remote-desktop video and input. The stream is peer-to-peer WebRTC between your own phone and your own desktop. Our relay brokers the introduction and never sees decrypted media.
  • Vault credentials. Encrypted on the device; the key never leaves it. We cannot read them.
  • Synced data. Cross-device sync is opt-in and end-to-end encrypted. What passes through our servers is ciphertext we have no key for.
  • Browsing history, keystrokes and screen contents. We collect no telemetry of these.

Consent, and how to withdraw it

Before FireThrust transmits your content to any third-party AI provider, it asks you once, naming the providers. That agreement is enforced at the point of transmission rather than in the interface, so no part of the app can route around it. You can withdraw consent at any time in Settings → Privacy; transmission stops immediately and local models keep working.

Retention and deletion

  • On-device data is deleted when you delete it, or when you uninstall the app. We hold no copy.
  • Account records (email, subscription status) are kept while your account is open and deleted within 30 days of a deletion request.
  • Sync ciphertext is deleted with the account. Because it is end-to-end encrypted, it is unreadable to us before and after.
  • Relay and session metadata (device ids, timestamps needed to route a session) is ephemeral and retained no longer than 30 days.
  • Crash and diagnostic logs, if you have opted in, are retained no longer than 90 days.

Content you send to an AI provider is also subject to that provider’s own retention policy, which we do not control. Their policies are linked from the consent screen.

Your rights

Wherever you live, you can ask us to access, correct, export or delete your account data, and you can object to or restrict processing. If you are in the EEA or UK, the legal bases we rely on are performance of a contract (running the service you asked for), legitimate interests (keeping it secure and working), and consent (AI transmission and optional diagnostics). If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we have not in the preceding twelve months.

Email privacy@firethrust.com and we will respond within 30 days. You may also complain to your local data-protection authority.

Security

Everything in transit is TLS-encrypted. Sync payloads and vault entries are additionally end-to-end encrypted with keys we never hold. Remote sessions are authenticated at both ends and the host’s identity is cryptographically pinned, so a session cannot be silently redirected to a machine that is not yours. No system is perfect, and we will notify affected users and regulators as required if that ever proves true here.

International transfers

Our infrastructure runs in the United States and the European Union. Where personal data moves out of the EEA or UK, it is covered by the European Commission’s Standard Contractual Clauses.

Children

FireThrust is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us data, write to privacy@firethrust.com and we will delete it.

Changes to this policy

We will post any change here and update the date at the top. If a change materially affects how your data is handled — in particular if it changes which AI providers receive your content — you will be asked to agree again in the app before anything is transmitted under the new terms.

Contact

Haymakers, Inc. — privacy@firethrust.com. See also our Terms of Service and Support page.