Privacy Policy
Effective / last updated: July 28, 2026
This Privacy Policy describes how Shehryar Kashif, doing business as Firth (“Firth,” “we,” “us,” or “our”), collects, uses, discloses, and retains information in connection with the Firth websites, applications, APIs, and related services (the “Services”). It should be read together with our Terms of Service. Contact: hello@firthhq.com.
1. Roles and scope
Account and Service data. For information about individual users of the Services (for example, account email, billing identifiers, and usage logs), Firth determines the purposes and means of processing and acts as a data controller (or similar role under applicable law).
Customer Content. For content and data that customers submit to the Services or that the Services ingest at the customer’s direction from connected systems (“Customer Content”), the customer generally determines the purposes of processing. Firth processes Customer Content on the customer’s instructions to provide the Services (as a processor / service provider under applicable law), except where we must process it to comply with law, secure the Services, or as otherwise described in these Terms and this Policy.
This Policy does not apply to third-party websites or platforms that we do not control (including Slack, GitHub, and other connectors), which have their own privacy terms.
2. Information we collect
Account and authentication. When you create or use an account, our authentication provider (Clerk) processes sign-in credentials and related authentication data. We store identifiers needed to operate your account (such as email address and plan). We do not receive or store your password.
Billing. Payments are processed by Stripe. Card numbers are submitted directly to Stripe and are not stored on Firth servers. We store Stripe customer/subscription references and plan status.
Customer Content and connectors. Depending on what you enable, Customer Content may include:
- Slack (when connected): message text and related metadata available under the permissions you authorize (for example, channel identifiers, user identifiers as provided by Slack, and timestamps). Bot tokens are stored encrypted at rest.
- GitHub (organizational connector, when connected): content from repositories you enable that our connector is configured to ingest (currently including open issue title/body and related metadata such as author, URLs, and timestamps). Access tokens you provide are stored encrypted at rest.
- Uploads: files you upload (for example CSV/JSON) and the observations derived from them.
- Ingest API: payloads you send using an ingest token you mint, including content and provenance fields you supply.
- Product configuration and workspace inputs: product descriptions, keywords, notes, search queries, drafts, and similar materials you enter into the Services.
Connector scopes and permissions are granted by you through the third-party authorization flow or credentials you supply. You control which sources to connect and may disconnect them as described in Section 8.
Discovery / Act features. If you use Discovery Features, we may store excerpts of publicly available posts obtained via official platform APIs (sources available in the product may include Hacker News, GitHub, Stack Overflow, Bluesky, Discourse, Lemmy, and YouTube; additional sources may appear when enabled), together with public usernames, links, and scoring or enrichment metadata. Optional connections used for identity or user-initiated replies (for example Bluesky or GitHub, where offered) store credentials you provide (encrypted at rest) and related message metadata needed to operate those features.
Tester and access applications. If you apply for limited or campaign access, we process the information you submit (such as name, email, organization, use case, and feedback acknowledgments) to evaluate and administer access.
Waitlist. Email addresses collected during an earlier waitlist period may still be retained. You may request deletion as described in Section 8.
Usage, logs, and telemetry. We collect operational logs and diagnostics reasonably necessary to operate, secure, debug, and bill the Services (for example request metadata, error logs, feature usage counts, and security events). We do not use advertising cookies or third-party advertising SDKs on the Services.
3. Cookies and similar technologies
- Authentication cookies set by Clerk to maintain your signed-in session.
- Anonymous trial cookie (
firth_try): a short-lived HttpOnly cookie (approximately 7 days) so a browser can replay the same trial results. For rate limiting, we may store a salted hash of IP address; we do not store the raw IP for that purpose. - Local preferences: certain UI preferences (for example theme) may be stored in browser local storage rather than cookies.
We do not currently operate a third-party product analytics SDK (such as a marketing analytics pixel) on the Services. Hosting and infrastructure providers may process standard technical logs as part of delivering the Services.
4. How we use information
We use information to:
- Provide, maintain, secure, and support the Services, including evidence extraction, signals, investigations (as made available), Discovery Features, drafts, and account administration;
- Process payments and prevent fraud or abuse;
- Communicate with you about the Services, security, and material policy or Terms changes;
- Comply with law, enforce our Terms, and protect the rights, safety, and property of Firth, customers, and others; and
- Improve reliability and quality of the Services using aggregated or de-identified diagnostics where feasible.
We do not sell personal information. We do not use Customer Content to train Firth models for general public distribution. If we ever change that practice, we will update this Policy and, where required, obtain appropriate consent or offer an opt-out.
5. Artificial intelligence and embeddings
To provide requested features, relevant text from Customer Content and/or public discovery content may be sent to third-party AI providers. Today, large language model processing is performed using Anthropic’s API (model versions as configured in the product).
Separately, certain Discovery Features may generate vector embeddings (currently via our hosting/database provider’s embedding capability) for similarity search and thematic clustering of discovery content. Organizational observation and evidence pipelines do not currently require embeddings for their core operation; if that changes, we will update this Policy.
AI and machine-learning outputs are probabilistic. They may be wrong, incomplete, or misleading. You should review source evidence before relying on them. See also Terms of Service §5 (AI and Analytical Outputs).
We configure AI providers to process Customer Content to provide the Services. We do not authorize providers to use Customer Content to train models for their general public offerings to the extent their applicable commercial API terms prohibit such use. Provider terms and practices can change; we will update this Policy if our configuration or providers change materially.
6. How we share information
We share information with:
- Subprocessors that help us operate the Services, including: Vercel (hosting), Supabase (database and related infrastructure), Clerk (authentication), Stripe (payments), Upstash (caching and rate limiting), Resend (transactional email), and Anthropic (AI inference). Each receives only what is needed for its function.
- Platform providers you connect (for example Slack or GitHub), when you authorize a connection or initiate an action.
- Professional advisors (legal, accounting) under confidentiality obligations, where reasonably necessary.
- Authorities or counterparties when required by law, legal process, or to protect rights and safety.
- Successors in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this Policy will continue to apply to the transferred information until replaced.
We do not share Customer Content with third parties for their independent marketing.
7. International transfers
Firth is operated from the United States. Information may be processed in the United States and in other countries where our subprocessors operate. Those countries may have different data protection laws than your jurisdiction. Where required, we rely on appropriate transfer mechanisms made available by our providers (such as contractual clauses) and will provide additional information on request where legally required.
8. Security
We implement administrative, technical, and organizational measures designed to protect information, including encryption in transit (HTTPS/TLS), access controls, and encryption of connector and connection secrets at rest. No method of transmission or storage is completely secure. You are responsible for safeguarding account credentials and for authorizing only appropriate data sources.
Firth does not currently claim SOC 2, ISO 27001, or similar certifications. We may pursue such programs as the company grows; certification status will be stated only when achieved.
9. Retention, disconnection, and deletion
Retention. Account data and Customer Content are retained while your account remains active and as needed to provide the Services, unless deleted earlier as described below. Trial data associated with the anonymous trial cookie is retained for up to approximately seven (7) days, or until claimed into an account. Operational logs are retained for a period appropriate to security, debugging, and billing, then deleted or aggregated. We may retain limited records as required for law, dispute resolution, fraud prevention, or financial compliance.
Disconnection. You may disconnect or delete connected origins and related stored observations through in-product controls where available (for example, disconnecting Slack or managing Bring-your-data origins). Disconnecting stops new ingest from that source; deletion of stored data follows the control you select or a deletion request.
Requests. To access, correct, export, or delete personal information we control, or to request deletion of an account or Customer Content we process for you, email hello@firthhq.com. We will verify the request and respond within a reasonable period (and within timelines required by applicable law). Enterprise customers may designate an admin contact for deletion and export requests relating to their workspace. For Customer Content that includes other individuals’ data, we generally act on instructions from the customer account that connected the source.
10. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, or export personal information, to object to or restrict certain processing, and to withdraw consent where processing is consent-based. EU/UK individuals may lodge a complaint with a supervisory authority. California residents may have additional rights under the CCPA/CPRA; we do not sell or share personal information as those terms are defined for cross-context behavioral advertising. To exercise rights, contact hello@firthhq.com. We will not discriminate against you for exercising privacy rights.
11. Children
The Services are directed to businesses and are not intended for individuals under 16. We do not knowingly collect personal information from children under 16. If you believe we have, contact us and we will take appropriate steps to delete it.
12. Changes to this Policy
We may update this Policy from time to time. The “last updated” date will change when we do. For material changes, we will provide additional notice to account holders (for example, email or in-product notice) as required by law or as appropriate given the nature of the change.
13. Contact
Privacy requests and questions: hello@firthhq.com. Operator: Shehryar Kashif, doing business as Firth, United States.
Related: Terms of Service · AI and Analytical Outputs.