Legal

Privacy

Draft. Not yet reviewed by counsel.

Last updated .

This page says exactly what this website stores about you and why. It covers firekeeper.sh and its dashboard. Firekeeper itself runs in your own cluster and sends nothing to us.

Who we are

This draft does not yet name the operator of firekeeper.sh, who is responsible for the data described here. It will before the site launches.

The short version

  • We store the least we need to give you an account and your licenses.
  • We do not share or sell anything.
  • There are no trackers, ads, analytics scripts or third-party scripts on this site.
  • We count requests, but never in a way that identifies you. How we count.

What we store

If you only read the site, we store nothing that identifies you. If you start to sign up, sign in or recover an account, or create an account, we store:

WhatWhy
While you sign up Your name and email address are held with the sign-up request until you create your passkey. The request expires after five minutes. If you do not finish, it is deleted soon after and no account is created.
Your name To show on your account and to put in your license as the licensee.
Your email address To contact you about your account, and to recover your account with a recovery code. We do not verify it and we do not send marketing.
Passkey public keys To sign you in. For each passkey we keep its public key, its id, its name (one we give it or one you choose), a counter, its transports, its backup flags, and when it was created and last used. Each account also has a random user handle that your passkeys store for this site. The private key never leaves your device.
License records To list, renew and retire your licenses: the estate label, the optional hub AWS account id, the plan, the dates, the status, and the signed license file itself, which carries your name as the licensee.
Recovery codes, as hashes To let you back in if you lose your passkeys. We cannot read the codes themselves.
Sessions, as hashes To keep you signed in for up to 14 days. The cookie holds a random token; we store only its hash.
An audit log To protect your account. Sign-ups, sign-ins and sign-outs, failed sign-ins, recoveries, passkey and recovery code changes, and license events, each with the time, the account, details such as which passkey or license it concerns, a keyed hash of your network address (the IP address, or for IPv6 its first 64 bits) and the browser's user agent (first 200 characters). Failed sign-ins and failed recoveries are logged the same way even when they match no account. License downloads are recorded in the audit log like other license events. The latest entries are shown to you on your account's security page. Entries are deleted after one year.
Rate-limit counters To slow down abuse. Counts keyed by a keyed hash of the network address or by account, deleted once their window (at most a day) has passed.

We never store your IP address in the clear. Sessions end after 14 days at most. Account and license records are kept until you delete your account.

Counting

For counting, we count requests by page type, by kind of client (browser, command line, declared robot) and by result; reading pages also by kind of referring site per day. For counting, we never store your address, your browser's name, the page address you asked for, your country or where you came from. Account and license pages are counted per day only. Our code logs nothing about downloads; the hosting platform keeps its standard request records for its stated retention period. There is no analytics script, and nothing on this site asks your browser to report to anyone else.

The audit log described above is separate from counting. It records account actions such as sign-ins, recoveries and license events, and it keeps what the table says.

Cookies

One cookie, __Host-fk_s, set only when you sign in. It keeps you signed in. It is HttpOnly, Secure and SameSite=Lax, and it is deleted when you sign out. There are no other cookies.

The verify page

When you check a license on the verify page, the check runs in your browser. The license you paste is not uploaded.

Sharing

We do not share or sell your data. Our hosting provider runs the site and stores its database, as any host must. We use no other service that receives your data.

Deleting your account

You can delete your account from the dashboard. This deletes your name, email, passkeys, recovery codes and sessions, and the estate labels, hub account ids and files of your licenses. We keep each license id and its status, without your personal data, so that a license that was issued can still be accounted for; active licenses are marked retired. Your audit log entries keep the event, its time, its details and the account's random id, but lose the network hash and the user agent. They are deleted when they reach one year, like every other entry. Failed attempts that matched no account are not linked to you and are not changed.

Contact

Questions about this page: support@firekeeper.sh.