Skip to main content

Privacy Policy

Last updated: 1 September 2026

Read alongside our Terms and Conditions and our Financial & AI Disclaimer.

1. Who we are

Fireball is operated by Helios Studio Limited, a company registered in New Zealand (NZBN 9429053665690) ("we", "us", "our"). This policy describes how we handle personal information collected through the Fireball website (fireball.finance) and the Fireball mobile apps.

Fireball is currently offered in New Zealand. We comply with the New Zealand Privacy Act 2020, including the Information Privacy Principles (IPPs).

2. What we collect

We deliberately collect the minimum data needed to run the Service.

  • Account details: username, email address, date of birth, marketing-consent preference, optional signup-attribution answer, optional referral code, and (optionally) two-factor authentication (TOTP) secret stored encrypted in Supabase Auth.
  • Financial data via Akahu: bank account balances, transactions (amounts, dates, descriptions, categories), masked account numbers, account-holder details such as holder name or address where provided, KiwiSaver balances, and other linked-account data retrieved via Akahu (read-only). We never receive your bank login credentials.
  • Manual financial data: any manual transactions, custom categories, manual asset holdings (e.g. private investments, real estate, vehicles), liabilities, and notes you enter.
  • Derived data: calculated net-worth snapshots, savings-rate history, projections, and category summaries.
  • Shared categorisation contributions (optional): if you opt in, category decisions you make for eligible Akahu expenses — including categories you accept or correct in AI categorisation — may be recorded with your user ID, an internal transaction ID, the chosen canonical category, a protected one-way merchant or description fingerprint, and the decision time. The shared-intelligence tables do not store raw merchant names, raw transaction descriptions, amounts, dates, account details, prompts, or notes.
  • AI conversations and summaries: the prompts you send to AI features and the responses returned, stored in your account so you can return to them. For grounded support answers, answer metadata may include source IDs, titles, and public Fireball links, but not copies of the source article bodies. If you enable the AI Weekly Review summary, we also store the latest validated completed-week summary and its source fingerprint.
  • AI-assisted import data: only when you choose an AI-assisted import, a bounded and sanitised profile of file headers, local type statistics, representative values, and unresolved category labels. We exclude filenames, full files, transaction IDs, payees, descriptions, notes, and user-authored account names.
  • AI feedback (optional): your helpful / not-helpful rating, a bounded reason, response and routing classifications, and limited feature metadata. If you separately choose to share an unhelpful exchange for review, authorised reviewers can see only the triggering question and answer while that 30-day conversation text still exists.
  • Subscription and billing analytics data: provider-neutral plan and entitlement status plus the identifiers and lifecycle details needed to reconcile subscriptions purchased through Stripe, the Apple App Store, or Google Play. A private service-only analytics ledger records provider-reported payment and completed-reversal amounts, currency, lifecycle kind and time, provider correlation references, subscription source, and a versioned customer HMAC so we can measure observed collected lifetime value, renewals, retention, churn, and provider-report reconciliation. For Stripe refunds, a separate service-only integrity record can include provider refund, charge, payment and customer references, amount, currency, bounded status and reason fields, timestamps, and a keyed hash of a reusable payment identity. We never see or store your full card details or retain the raw payment identity in that ledger.
  • Legal acceptance records: the Terms version, Privacy version, app platform or web source, and server-recorded time for each version pair you accept. Clients cannot choose the recorded version or timestamp.
  • Known-installation security records: a random installation UUID, broad platform, optional app version, first- and last-seen times, alert state, and whether the installation supports Weekly Review. These records help recognise a returning installation and send a new-installation security alert; they are not advertising identifiers.
  • Collaborator records (if collaborator access becomes available): pending invitation email, delivery status and expiry; the owner and collaborator account IDs for accepted access; the accepted Terms, Privacy and collaborator-disclosure versions; and sanitised invitation, acceptance, decline, removal, leave and access-expiry security events. Invitation codes would be stored only as one-way hashes and never logged. When opening a web invitation, the code would be temporarily held in an encrypted, HttpOnly browser cookie for up to 30 minutes so authentication can return to the invitation.
  • Push notification data: device push tokens (APNs / FCM), ordinary in-app notification records, and bounded delivery metadata. Weekly Review delivery receipts contain only the user, completed week, installation, requested-delivery time, delivery mode, and notification metadata; they do not contain the review's financial facts or generated prose. One-way replay codes can also prevent a transaction alert from being sent twice.
  • Diagnostics: mobile crash reports and non-fatal errors captured by Firebase Crashlytics, and website errors captured by Sentry. Diagnostic records can include app/browser version, device or operating-system details, stack traces, the affected route, your IP address, your account identifier so we can correlate repeat faults, and limited technical context. Sentry is configured to strip emails, cookies, authentication headers, request bodies, and known-sensitive query parameters (auth codes, password-reset tokens). Stripe event and request references may be retained to investigate a specific provider delivery.
  • Mobile usage analytics: during normal live mobile-app use, Firebase Analytics receives an anonymous installation identifier, allowlisted app-outcome events, event time, platform, app version, basic device and operating-system context, and provider-derived coarse or approximate location. Firebase also produces aggregate first-open, session, and engagement signals. We do not set an Analytics user ID or user property and do not send balances, amounts, transactions, account or merchant names, account or provider identifiers, AI prompts or responses, messages, notes, URLs, filenames, free text, or raw errors. Collection is suspended while you use Demo Mode.
  • Address lookup: when you use property search, your typed address query is sent through Fireball's authenticated gateway to the Google Maps Platform Places API with a random per-search session token and New Zealand region and language settings. If you choose a result, we also process its Google place ID.
  • Support data: the name, email address, subject, and message you submit through the support form, plus rate-limit metadata used to prevent abuse. The form does not accept attachments.
  • Marketing signup data: your email address, consent source and confirmation status when you join the newsletter or Australian launch waitlist, plus the date and policy version associated with account-signup consent.
  • Website usage and performance data: Vercel Web Analytics and Speed Insights receive cookieless page/route and referrer information, browser, operating-system and device category, country or region derived from the request, web-performance measurements, and categorical custom-event properties such as the selected billing period, call-to-action surface, sign-in method, or checkout result. We do not put email addresses, support messages, or financial values into those custom events.
  • Reddit ad conversion measurement: when enabled for production Reddit campaigns, Fireball sends only verified account-signup and completed-checkout event types, event time, the relevant Fireball route, your IP address, and browser user-agent to Reddit through a server-to-server connection. Limited Data Use is requested for New Zealand. We do not send Reddit your email address, phone number, Fireball user ID, financial records, payment amount, Stripe identifier, or a browser advertising identifier, and we do not install the Reddit Pixel or persist Reddit click IDs.
  • Technical data: session and essential-gate cookies, IP address, browser / device type, request metadata, and security or rate-limit signals (see Section 9 on cookies).

We do not ask you to provide a full legal name or physical home address as Fireball profile fields. A connected bank may supply account-holder details such as a holder name or address as part of its account record, and property search processes the address fragments you enter. We do not collect your phone number or government ID, and we never receive your full payment card details.

Information collected indirectly (IPP 3A)

Some personal information reaches Fireball from another source rather than directly from you: connected-account information from your connection provider, identity details from Google or Apple sign-in, subscription status and provider identifiers from Stripe, Apple, or Google Play, and diagnostics or usage information from your device, browser, Firebase, Sentry, or Vercel. We collect that information to authenticate you, provide connected features, reconcile billing, secure and diagnose the Service, and measure the limited usage described in this policy. We give notice through sign-up, connection and purchase screens, device permission prompts, and this policy before collection or as soon as reasonably practicable afterwards. Fireball's identity and contact details are in Sections 1 and 15, the recipients are listed in Section 5, and your access and correction rights are in Section 11.

3. How we use your data

  • Provide and maintain the Service, including FIRE projections, budgeting, net-worth tracking, AI features, and an optional qualitative AI Weekly Review summary.
  • If collaborator access becomes available, let an owner invite trusted collaborators, verify and record their acceptance, provide live shared editing plus a sanitised app-sandboxed read-only cache for up to 24 hours after a successful access check, attribute their changes, and end access when the grant or owner entitlement is authoritatively denied.
  • With your explicit opt-in, use accepted or corrected categorisation decisions to create protected, aggregate category suggestions for Fireball users.
  • Process your subscription, reconcile provider lifecycle updates, provide the relevant Stripe, Apple, or Google subscription-management route, and measure provider-neutral collected-payment, renewal, retention, churn, and reconciliation aggregates.
  • Authenticate you and keep your session secure (including optional two-factor authentication and recognition of known app installations).
  • Send transactional emails (sign-up confirmation, subscription receipts, important security notices) and push notifications (transaction, recurring-charge, budget, sync, trial, security, and optional Weekly Review alerts).
  • Send marketing emails only if you opted in. You can withdraw consent at any time by clicking unsubscribe in any marketing email or by updating settings in the app.
  • Enforce our one-trial-per-person rule by retaining a record of email addresses that have started a free trial.
  • Diagnose crashes and improve reliability through Firebase Crashlytics and Sentry error monitoring.
  • Measure aggregate mobile activation, engagement, feature reliability, retention, and subscription conversion. We do not combine mobile Analytics data with your Supabase account or financial records.
  • Measure whether a Reddit advertising campaign led to a verified Fireball signup or completed web checkout, using the limited server conversion data described in this policy.
  • Respond to support enquiries.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Comply with our legal obligations.

We do not use your data for automated decision-making with legal or similarly significant effects.

4. Where your data lives

Your data is hosted on Supabase servers in the Sydney, Australia region (ap-southeast-2). Some features involve cross-border transfers to overseas sub-processors — see Section 5.

Production mobile Analytics events are exported daily to a restricted Google BigQuery dataset in Sydney, Australia. Reporting access exposes only allowlisted event fields and hashed anonymous installation and session keys. It is not joined to your Supabase account or financial data.

The customer-level billing analytics ledger remains in Supabase in Sydney. Only privacy-suppressed aggregate reports may be exported to the Sydney BigQuery project if that separate reporting path is enabled; Supabase user IDs, emails, provider customer/order/transaction IDs, and the customer HMAC are not exported.

All data is encrypted at rest using AES-256, and all connections use TLS 1.2 / 1.3. We enforce Row Level Security (RLS) and server-owned access checks at the database level, so financial data is available only to its owner. If collaborator access becomes available, a separately authenticated person would also need a current owner-authorised collaborator grant.

On your device, the mobile app stores a local cache (SQLite / sqflite) for financial data you own so the app works offline and starts quickly. If collaborator access becomes available, a separate collaborator cache may hold sanitised, previously downloaded shared financial data read-only for up to 24 hours after the last successful access check; it would exclude provider connection details, signed media links and media files, and never queue offline changes. App caches are held inside the app's private sandbox; the underlying SQLite files are not encrypted at the application layer and rely on the operating system's file-level protections (iOS Data Protection / Android app-sandbox isolation). Supabase session data and app-owned session proofs are stored separately in operating-system secure storage (Apple Keychain / Android Keystore). Uninstalling the app removes app-sandbox data from your device.

If you install a Fireball home-screen widget, the app writes a bounded net-worth or FIRE-progress snapshot, update/stale timestamps, display state, and a pseudonymous current-session marker to the operating system's shared widget storage. Snapshot data may remain stored there while the widget is concealed. Financial values and progress are concealed by default and shown only when you choose to reveal them. Fireball removes the widget snapshot and session marker during sign-out, account deletion, session expiry, or other authenticated session cleanup.

5. Sub-processors and cross-border transfers (IPP 12)

We disclose only the data needed for the purpose described below. A provider may process information on our instructions or under its own service terms, depending on the integration. Overseas privacy protections may differ from New Zealand's. We use the transfer routes available under IPP 12 of the NZ Privacy Act; where a transfer relies on informed authorisation, we identify the overseas recipient and the possibility of different legal protections before the relevant feature is used. Provider infrastructure and processing locations can change, so the locations below describe our current configuration or the provider's published service footprint.

ProviderPurposeData sharedLocation
SupabaseDatabase, authentication, file storageAll account and financial dataSydney, AU
StripeSubscription billing, payment processing, refunds, and payment-integrity checksEmail; customer, subscription, invoice, charge, payment and refund references; lifecycle status and dates; refund amount/currency and bounded status/reasons; and a keyed payment-identity hash when available. We never receive full card details, and the refund ledger does not retain the raw payment identity.US / Ireland
AkahuOpen banking — connection to NZ bank accountsBank credentials handled on Akahu's end; we receive balances, transactions, and account info. On reconnect, Fireball may retrieve the current email on your Akahu profile and send it to Akahu as a login hint; for a first connection or unavailable lookup, we use your Fireball account email. Fireball does not retain the hint in its short-lived connection session.New Zealand
OpenAI (Responses API)Primary provider for AI Chat, Weekly Review summaries, categorisation, bounded assumption extraction, support answers, and user-selected AI-assisted import mappingThe current prompt and minimum task-specific context; for support, up to three short excerpts of public Fireball help content; for import mapping, a bounded sanitised profile rather than the full file; and a pseudonymous safety identifier derived from the user ID. No raw user ID, email, login credentials, full account number, government identifier, or filename.United States / OpenAI-controlled processing locations
Google (Gemini API)Fallback provider for the same approved AI tasks, used only if OpenAI fails before producing visible text or a successful model/tool turnThe same bounded task payload OpenAI would receive. Fireball does not send a shadow or duplicate request to both providers. No email, login credentials, full account number, government identifier, or filename.United States / Google-controlled processing locations
Google Maps Platform (Places API)Property / address searchTyped address query, random per-search session token, New Zealand region and language settings, selected Google place ID, and provider-observed gateway request metadataGoogle-controlled locations
Firebase Cloud MessagingPush notification delivery (Android, and on iOS as the relay to Apple Push Notification service)Device push token, notification payload (which may include amounts, merchant names, and account references)United States
Apple Push Notification service (APNs)iOS push notification delivery transport (invoked indirectly via Firebase Cloud Messaging)APNs device token (held by FCM, not by us)United States
Firebase CrashlyticsCrash diagnosticsDevice model, OS version, app version, stack traces, user IDUnited States
Firebase Analytics / Google Analytics 4Live-runtime device-level mobile product analytics and aggregate retention measurementAnonymous installation identifier; allowlisted app-outcome events; event time; platform; app version; basic device and OS context; provider-derived coarse or approximate location. No Analytics user ID or user property, financial records or values, account/provider identifiers, AI content, filenames, free text, or raw errors. Collection is suspended in Demo Mode.Google-controlled processing locations
Google BigQueryDaily production Analytics export and restricted aggregate reportingThe Firebase Analytics data described above, plus reporting views containing only allowlisted fields and hashed anonymous installation/session keys. No Supabase or financial-data join.Sydney, Australia
SentryWebsite error monitoring and debuggingStack traces, error type, app/browser version, IP address, user-agent, the affected route, your account identifier, and Stripe event/request/object references. Emails, cookies, auth headers, request bodies, and known-sensitive query parameters are filtered before sending.European Union / United States and other Sentry provider locations
Firebase Remote ConfigServer-controlled feature flags and stringsAnonymous Firebase installation ID, app version, localeUnited States
Google Cloud Monitoring / Personalized Service HealthProduction uptime probes and provider-incident alertsHealth-check host, path and configuration; masked monitoring credentials; response status and latency; provider-observed request metadata; and sanitised aggregate worker counts/timestamps. No Fireball user ID, financial record, provider account ID, receipt, token, or payment payload.Google-controlled processing locations
Google IdentityOptional Google sign-inGoogle identity token and the email/profile fields returned by GoogleGoogle-controlled locations
Apple — Sign in with AppleOptional Apple sign-in and provider-authorisation revocation during account deletionApple identity credential/token, stable provider subject, and email/name when Apple supplies themApple-controlled locations
ResendSession verification, support-form delivery, subscription-management emails, new-installation and support-abuse alerts, and collaborator invitation or lifecycle messages if collaborator access becomes availableRecipient and sender email, username or display name when needed for the message, subject and message content. A new-installation alert can include broad platform, optional app version, server-recorded sign-in time, and a masked IPv4 or IPv6 network prefix; a support-abuse alert may contain the server-observed IP address. If collaborator access becomes available, invitation codes would be included only in the invitation email and would not be retained in Fireball logs.United States
UpstashDistributed abuse-prevention rate limiting for public website forms and authentication confirmationHMAC-derived, non-reversible rate-limit identifiers and request counters; raw IP addresses and email addresses are not sentSydney / closest available APAC region
LoopsConsent-based lifecycle and marketing email deliveryEmail, first name when available, subscription/confirmation state, consent source, subscription plan and status, and an internal user identifier to deduplicate contactsUnited States
FeaturebaseOptional feature-request and community board sign-inShort-lived token containing account ID, email, display name, issue/expiry times, and administrator status when applicableProvider-controlled locations
PexelsOptional goal-background image search and retrievalSearch query, paging/orientation choices, selected photo ID, and provider-observed request metadataProvider-controlled locations
Yahoo Finance / FrankfurterSecurity search, market quotes, and foreign-exchange rates through Fireball's authenticated gatewaySecurity symbol/search query or currency pair/date plus provider-observed gateway request metadata; no Fireball user ID or financial record is sentProvider-controlled locations
Logo.devTicker-backed investment-logo lookup and shared private image cachingStock, ETF or fund ticker or base cryptocurrency symbol, a server-held provider token, and provider-observed gateway request metadata. No Fireball user ID, holding quantity, balance, price, or other financial value.Provider-controlled locations
SanityBlog content delivery and editorial CMS (Sanity Studio)Public blog page-view request metadata (IP, user-agent, requested asset). Editor identity for staff who sign in to Studio. No customer, account, or financial data.Global CDN / United States
VercelWeb hosting, cookieless Web Analytics and Speed Insights, transactional-email logo hosting, and isolated Apple billing-signature verificationIP/request metadata; page or route, referrer, browser/OS/device category, country/region, web vitals, and categorical custom-event properties; for Apple verification, signed billing payloads and decoded transaction, product, lifecycle, and opaque account-token fieldsGlobal (US headquartered)
RedditServer-side measurement of verified signups and completed web checkouts attributed to Reddit advertisingConversion event type and time, relevant Fireball route, IP address, browser user-agent, and a one-way checkout conversion identifier. Limited Data Use is requested for New Zealand. No email, phone number, Fireball user ID, financial record, payment amount, Stripe identifier, Reddit Pixel, browser advertising identifier, or persisted Reddit click ID.United States / Reddit-controlled processing locations
Apple App Store / StoreKitiOS app distribution, subscription purchase, restore, management, and provider notificationsApp/product/offer IDs, signed transaction data, transaction and original-transaction IDs, price and lifecycle dates/status, and an opaque Fireball account token; no financial records or payment credentialsApple-controlled locations
Google Play BillingAndroid app distribution, subscription purchase, restore, management, and provider notificationsApp/product/base-plan/offer IDs, purchase token, order IDs/state/amount, lifecycle and expiry state, acknowledgement state, and an opaque account ID; no financial records or payment credentialsGoogle-controlled locations

We do notsell or rent your personal information to anyone, ever. We do not use browser advertising trackers and we do not share your data with data brokers. When Reddit conversion measurement is enabled, the limited server event described above is used only to measure signup and checkout outcomes from Fireball's Reddit campaigns.

6. AI features in detail

Before a provider-backed AI request, Fireball presents a prominent disclosure naming its approved OpenAI and Google AI provider pool and requires current explicit consent. Without that consent, the request fails closed and no data is sent to either provider. OpenAI is the primary provider for AI Chat, an optional qualitative Weekly Review summary, manual or overnight categorisation, bounded assumption extraction, support answers, and user-selected AI-assisted import mapping. Google Gemini may receive the same bounded request only if OpenAI fails before producing visible text or a successful model/tool turn. Fireball does not send shadow or duplicate requests to both providers.

  • What we send: only the minimum data needed for the specific task. Financial questions can include selected conversation history and relevant balances, transactions, categories, budgets, goals, debt or net-worth facts. Support-only questions exclude financial context but can include the current question and up to three short excerpts from Fireball's public FAQ or Help content. OpenAI also receives a pseudonymous safety identifier derived from your user ID with a secret keyed hash, not your raw user ID. We never send your email, login credentials, full account numbers, or government identifiers.
  • OpenAI's handling: Fireball uses the OpenAI Responses API with response storage disabled. OpenAI's current API data-controls documentation says API inputs and outputs are not used to train or improve its models unless the customer explicitly opts in. Default abuse-monitoring logs may contain prompts and responses and be retained for up to 30 days, or longer where required by law or reasonably necessary to protect the service or a third party. Fireball has not promised that OpenAI Zero Data Retention or Modified Abuse Monitoring applies.
  • Google's handling: Google's current Gemini API terms distinguish paid and unpaid services. Under paid-service terms, prompts and responses are not used to improve Google's products, but Google may log them for a limited period for abuse monitoring unless Zero Data Retention applies. Unpaid-service terms may permit product improvement and human review. Fireball does not promise that Zero Data Retention is enabled, and does not use your data to train an internal model.
  • AI-assisted imports: PocketSmith parsing stays local unless unresolved categories require enrichment, and an “Other file — AI-assisted” import is sent only after you choose that option. The selected provider receives a bounded sanitised profile, not the full file; filenames, transaction IDs, account names, payees, descriptions, labels, and notes stay local.
  • AI Weekly Review: if you enable this feature and have paid personal access, Fireball may send the selected provider bounded qualitative Budget, Goals, Net worth, FIRE, and Finish up aggregate states for a completed week. It excludes transactions, evidence IDs, account, merchant, category and goal names, notes, other user-authored text, figures, and currencies. Only the latest validated summary is retained, and it is deleted when you turn off the AI Weekly Review summary, withdraw AI permission, or delete your account.
  • Feedback: ratings and bounded feedback metadata are stored for up to 12 months and removed on account deletion. Sharing the triggering question and answer for human review is separately optional, initially off, and available only while the 30-day conversation text remains.
  • Storage: Conversations are stored in your account in Supabase so you can return to them. AI usage is tracked per account to prevent abuse and apply fair-use limits.
  • Deletion: You can delete individual conversations or all chat history at any time from inside the app. Deleting your account permanently removes all conversation and usage records.
  • Disclaimer: AI output is general information only. See our Financial & AI Disclaimer.

Shared categorisation intelligence

Shared categorisation intelligence is separate from OpenAI or Gemini inference. It uses category decisions from participating users to improve merchant-category suggestions without exposing one user's transactions to another.

  • Explicit opt-in: we contribute a category decision only after you choose to participate. Declining does not disable AI categorisation or prevent you from receiving shared suggestions.
  • Eligible decisions only: only categories you accept or correct for eligible Akahu expense transactions may contribute. Ignored suggestions and manual transactions do not contribute.
  • Protected records: on our server, a normalised merchant name or carefully screened description signature is converted into a keyed one-way HMAC-SHA-256 fingerprint. We retain the fingerprint, your user ID, an internal transaction ID, the canonical category, fingerprint type, and decision time so each user counts only once and you can later remove your contribution. Amounts, dates, account details, raw merchant or description text, prompts, and notes are not stored in the shared-intelligence tables.
  • Aggregation: a shared suggestion is available only after at least five different users have contributed for the same protected fingerprint and the category meets a strong consensus threshold. Other users receive only a category hint for their own transaction; they cannot see your identity, transaction, or individual choice.
  • Withdrawal and deletion: you can turn shared categorisation learning off at any time in Settings. This stops future contributions and deletes your contribution records. Aggregate signals are then recalculated from the remaining participating users.

7. Push notifications and marketing communications

  • Push notifications are opt-in at the device level. They are used for transaction, recurring-charge, budget, sync, trial, security, and optional Weekly Review alerts. Weekly Review notifications use generic copy and never include the review's financial facts or generated prose. You can disable notifications in your device settings or in the app at any time. Ordinary notification-delivery attempts are retained for 30 days and in-app notification records for up to 90 days. Weekly Review delivery receipts may remain for up to 400 days, capped at 64 weeks; transaction-alert replay codes remain for up to seven days.
  • Transactional emails (e.g. sign-up confirmation, billing receipts, new-installation and other security alerts) are essential for the Service and you cannot opt out without closing your account. A new-installation alert may contain the broad platform, optional app version, sign-in time, and a masked network prefix derived from the server-observed address.
  • Marketing emails are sent only with your explicit, granular consent collected through a separate checkbox at account sign-up or a confirmed newsletter subscription. Anonymous newsletter signups use double opt-in, so no marketing is sent until the email-address owner confirms. You can withdraw consent at any time by clicking unsubscribe in any marketing email.

8. Diagnostics and mobile usage analytics

During normal live mobile-app use, we use Firebase Crashlytics to receive crash reports and non-fatal errors that help us fix bugs. Crashlytics collects device model, OS version, app version, stack traces, and your user ID. No transactions or balances are sent to Crashlytics. Collection is suspended while you use Demo Mode.

Crash records are retained for 90 days.

We use Sentry on the website to receive errors that would otherwise be visible only in a visitor's browser or a short-lived server process. Sentry is enabled only on production and preview deployments. Performance tracing, session replay, log ingestion, and ad-tech features are disabled. Before an event is sent, we remove emails, cookies, authentication headers, request bodies, and known-sensitive query parameters such as OAuth `code` values and password-reset tokens. We retain your IP address (used only for abuse detection and security investigation), your account identifier (so we can correlate repeat faults to the same account), and Stripe event, request, and object references (so we can investigate a specific provider delivery). Sentry events are used only to diagnose reliability and security faults, are never used for advertising, and are deleted in line with our configured provider retention period when no longer required.

Some diagnostic information is collected automatically from the browser, hosting platform, or software provider rather than typed directly by you. This section gives notice of that indirect collection, its purpose, its recipients, and your access and correction rights.

Firebase Analytics

Firebase Analytics is enabled during normal live mobile-app use. Fireball sends only the allowlisted app outcomes and basic app/device context described in Section 2. We use this device-level information to understand aggregate activation, saved engagement, feature reliability, retention, and subscription conversion. We do not use it for advertising or personalisation, set an Analytics user ID or user property, or join it to your Supabase account or financial records. Automatic screen reporting, advertising-ID collection, and Apple IDFV collection are disabled. Collection is suspended while you use Demo Mode.

Deleting your Fireball account resets the local Firebase Analytics installation identifier, but previously collected or exported anonymous data remains until the 14-month retention period below expires.

9. Cookies

We use a small number of strictly-necessary cookies. We do not use advertising, marketing, or third-party tracking cookies, and there is no cross-site tracking.

CookiePurposeSet byType
sb-*-auth-tokenKeeps you signed in across requests.SupabaseEssential
__stripe_mid, __stripe_sidFraud prevention and payment session integrity in the Stripe Checkout / Billing Portal.StripeEssential (third-party)
__soft_launch_passRemembers that you passed Fireball's temporary pre-release password gate. It is used only while that gate is enabled.FireballEssential (conditional)
__Host-fireball-collaborator-invite*If collaborator access becomes available, temporarily keeps an encrypted invitation code while sign-in, email verification, MFA, or profile completion returns you to the invitation. It would expire after 30 minutes and be cleared after acceptance, decline, inactivity, or expiry.FireballEssential (conditional)

Website measurement: Production pages use Vercel Web Analytics and Speed Insights. They do not set analytics cookies, but they do process the page/route and referrer, browser/OS/device category, country or region derived from the request, performance measurements, and the limited categorical custom events described in Section 2. Vercel also receives the ordinary IP address and request metadata needed to host and deliver the website.

When production Reddit conversion measurement is enabled, Fireball sends the two verified server events described in Section 2 without installing the Reddit Pixel, setting a Reddit cookie, or persisting a Reddit click identifier.

We currently do not set optional analytics or marketing cookies. Consent requirements depend on the visitor's location and the technologies in use; if we add optional cookies or comparable tracking technology, we will request consent where required before enabling it.

You can clear cookies at any time through your browser settings. Removing the Supabase auth cookie will sign you out.

10. How long we keep your data

We retain user-owned service data for as long as your account is active. When you delete your account, we remove your authentication record and user-owned records from Fireball's active systems, including transactions, budgets, categories, net-worth snapshots, AI conversations, shared categorisation contributions, push tokens, and profile details. The narrow operational, legal, security, provider-integrity, and backup exceptions below are not part of the active account and can outlast deletion.

Specific retention rules while your account is active:

  • Transactions, accounts, manual assets, budgets, categories — kept indefinitely while your account is active; removed on account deletion.
  • In-app notifications — automatically purged after 90 days.
  • Akahu webhook event log — diagnostic records purged after 30 days.
  • AI chat conversations — automatically purged 30 days after they were last updated (rolling). AI usage counters are purged after about 13 weeks.
  • AI Weekly Review summary — only the latest validated completed-week summary and its source fingerprint are retained. They are deleted when you turn the feature off, withdraw AI permission, or delete your account.
  • AI response feedback — ratings and bounded metadata are automatically purged after 12 months and removed on account deletion. Any separately authorised review view depends on the related 30-day chat text and does not duplicate that text into analytics.
  • Shared categorisation contributions — kept only while you participate; deleted when you turn shared categorisation learning off or delete your account. Aggregate signals are recalculated without your contribution.
  • Legal acceptance records — version pairs, source, and server timestamps remain while your account is active and are removed when the account is deleted.
  • Collaborator invitations and access (if collaborator access becomes available) — pending invitations would expire after 14 days. Live grants would remain until the owner revokes them, the collaborator leaves, or either account is deleted. Terminal outcomes would be retained as sanitised security events under the 365-day security-event period; lifecycle-email delivery rows would contain account IDs and delivery state only and be removed with the related account.
  • Collaborator website invitation cookie (if collaborator access becomes available) — the encrypted invitation cookie would expire after 30 minutes and be cleared after acceptance, decline, inactivity, or invitation expiry.
  • Subscription-email rate-limit log — purged hourly (kept only for the one-hour rate-limit window).
  • Public website rate-limit counters — HMAC-derived identifiers and counters expire with their endpoint window, no later than 24 hours.
  • Net-worth snapshots, frozen post-disconnect balances, and account-level balance snapshots — kept indefinitely so your historical net-worth charts stay intact. Removed when you choose “also delete net worth history” while disconnecting a bank, or when you delete your account.
  • Device push tokens (FCM / APNs) — cleared when you sign out on a device, when the operating system invalidates the token, or when you delete your account.
  • Known-installation security records — retained across sign-out so later sign-ins on the same random installation UUID can be recognised, capped at 100 rows per user, and removed on account deletion. No scheduled age-based expiry applies while the account remains active.
  • Crash reports (Firebase Crashlytics) — retained for 90 days.
  • Firebase Analytics and production BigQuery export — event data is retained for 14 months. Production raw daily export tables use a 426-day operational expiration to implement that window.
  • Billing purchase diagnostics — bounded provider, operation, app/store code, and correlation metadata is retained for 90 days and removed on account deletion.
  • Operational support diagnostics — bounded service-only events are retained for 90 days and contain no financial data, receipt, provider payload, user text, request body, URL, or raw exception.
  • Billing provider delivery ledger — provider webhook/notification deduplication records are retained for 30 days.
  • Subscription transition, authentication, and security audit events — retained for up to 365 days. Pseudonymous abuse/security fingerprints contain keyed hashes of server-observed IP and user-agent rather than the raw values.
  • Notification delivery attempts — retained for 30 days; in-app notification records remain subject to the 90-day rule above.
  • Weekly Review delivery receipts and transaction-alert replay protection — Weekly Review receipts are retained for up to 400 days and capped at 64 weeks; one-way transaction-alert replay codes are retained for up to seven days. Both are removed on account deletion.
  • Website error reports (Sentry) — retained only for the diagnostic period configured in our Sentry account and deleted when no longer reasonably required.
  • Website analytics and performance measurements — retained under the configured Vercel Web Analytics and Speed Insights retention settings.
  • Reddit conversion events — retained under Reddit's configured advertising measurement retention and deletion controls. Fireball does not keep a separate Reddit conversion ledger.
  • Marketing consent records — retained while consent remains active and afterwards where reasonably necessary to demonstrate consent or honour suppression/unsubscribe requests.
  • Shared investment-logo cache — successful Logo.dev PNGs and permanent-miss markers are keyed by ticker or base cryptocurrency symbol, are not tied to a Fireball account, and currently have no scheduled expiry or provider revalidation.

The following may be retained after account deletion:

  • Trial-abuse marker — a record at Stripe of email addresses that have started a free trial, retained indefinitely to enforce our one-trial-per-person rule.
  • Tax / billing records — invoices and payment records held by Stripe and us as required by tax law (typically 7 years in NZ).
  • Pseudonymous billing analytics grouping — account deletion immediately removes the Fireball owner link from the private provider-neutral payment and completed-reversal ledger. The versioned customer HMAC grouping is retained for up to 36 months and then cryptographically destroyed. Non-identifying provider evidence and completed aggregate reports may remain. This ledger is not an entitlement, accounting, tax, settlement, or predictive-LTV source.
  • Terminal referral audit — rewarded, ineligible, or cancelled referral claims may be anonymised and retained for up to 7 years so both parties' reward history and fraud controls remain auditable.
  • Security and rate-limit records — the bounded records described above expire under their 24-hour, 30-day, 90-day, or 365-day schedules rather than being recreated as an active account.
  • Native-store binding tombstones — an Apple or Google subscription identity already issued to an account may remain permanently with its Fireball owner removed so it cannot be rebound to another account.
  • Stripe refund-integrity evidence — the service-only provider references, refund facts, and keyed payment-identity hash described in Section 2 currently have no automatic expiry. Account deletion removes the Fireball owner link while retaining that provider evidence; the ledger contains no raw payment identity, email, address, or card details.
  • Encrypted backups — residual copies may remain until the applicable provider-managed backup expires or is overwritten. They are not available through the Service or restored to recreate a deleted account; they may be used only for disaster recovery and then remain subject to the deletion record.
  • On-device data — authenticated session cleanup removes Fireball's local cache, secure session material, and widget payloads. Uninstalling the app also removes app-sandbox data controlled by the operating system.

11. Your rights

Under the NZ Privacy Act 2020 (and equivalent overseas laws), you have the right to:

  • Access the personal information we hold about you (IPP 6).
  • Correct anything that's wrong or out of date (IPP 7).
  • Delete your account and user-owned Fireball data through the app or web dashboard, subject to the limited retention exceptions in Section 10.
  • Delete selected data without closing your account, including saved Akahu bank history, AI chats and memories, and shared categorisation contributions.
  • Withdraw marketing consent at any time.
  • Opt out of shared categorisation learning and delete your previous contributions at any time in Settings.
  • Opt out of push notifications in the app or your device settings.
  • Lodge a complaint with the Office of the Privacy Commissioner (privacy.org.nz).

To exercise any of these rights or make a privacy complaint, contact us at support@heliosstudio.app. We will acknowledge the request, investigate it, explain our outcome, and respond within the period required by applicable law (normally within 20 working days for access requests). If you are dissatisfied with our response, you may contact the Office of the Privacy Commissioner above.

12. Notifiable privacy and data breaches

If we suffer a privacy breach that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by the NZ Privacy Act 2020. We maintain incident-response procedures to detect, contain, and report breaches promptly.

13. Children

Fireball is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, notify you by email or an in-app notice.

15. Contact us

Helios Studio Limited
NZBN: 9429053665690
Auckland, New Zealand
Privacy Officer and general enquiries: support@heliosstudio.app
Support form: fireball.finance/support