1 Introduction

Welcome to Fire Trajectory (“we,” “our,” or “us”). This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you use our web application at firetrajectory.com (the “Service”).

By creating an account or using Fire Trajectory, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.

If you have any questions, please contact us at privacy@firetrajectory.com.

2 Information We Collect

The following table describes the categories of personal information we collect, the sources, the purposes, and how long we retain each category:

Category Examples Source Purpose Retention
Identifiers Email address, account ID, device ID (random token) You provide directly Account creation, authentication, 2FA device trust Until account deletion + 30 days
Credentials Hashed password, MFA enrollment You provide directly Authentication, account security Until account deletion + 30 days
Financial information Income, expenses, debts, investment balances, savings goals, subscriptions, retirement projections You enter voluntarily Providing the Service’s core planning features Until account deletion + 30 days
Commercial information Pro subscription status, billing history (via Stripe) You & Stripe Subscription management, payment processing Until account deletion + 30 days; Stripe retains per its policy
Internet/electronic activity Pages visited, features used, browser type, OS, IP address Collected automatically Security, diagnostics, aggregate analytics 90 days (IP); aggregated/anonymized data retained indefinitely
Geolocation (coarse) Country/region derived from IP address Collected automatically Security, abuse prevention, legal compliance 90 days

Sensitive Personal Information (California CPRA)

Under the California Privacy Rights Act, financial information may be considered sensitive personal information. We use your financial data solely to provide the Service you requested (financial planning calculations). We do not use sensitive personal information for profiling, advertising, or any secondary purpose. You have the right to limit the use of sensitive personal information — see Section 10.

Information We Do NOT Collect

3 How We Use Your Information

We use the information we collect for the following purposes:

We will never sell, rent, or share your personal financial data with third parties for advertising, marketing, or any purpose unrelated to providing the Service.

4 Sharing & Disclosure of Information

We share personal information only in the following limited circumstances:

We Do NOT:

5 Cookies & Local Storage

We use browser storage (localStorage and sessionStorage) to operate the Service. We do not use traditional HTTP tracking cookies, advertising cookies, or third-party analytics cookies.

Storage KeyTypePurposeDuration
ft_access_tokenSession or localStorageAuthentication session tokenSession (cleared on browser close) or up to 30 days if “Remember me” is checked
ft_refresh_tokenSession or localStorageSilent session renewalSame as above
ft_user_emailSession or localStorageDisplay your email in the UISame as above
ft_device_idlocalStorageTrusted device recognition for 2FAPersistent (random ID, no personal info)
ft_* (various)localStorageLocally cached financial data and app preferences (theme, default tab, etc.)Persistent until you clear browser data or delete your account

To clear all stored data, use the “Clear Local Data” option in your account settings or clear your browser’s site data. This will sign you out.

Do Not Track (DNT)

Fire Trajectory honors Do Not Track browser signals. Because we do not engage in cross-site tracking, advertising tracking, or behavioral profiling, all users receive the same privacy protections regardless of DNT settings.

6 Partner Mode & Household Data Sharing

Fire Trajectory offers an optional Partner Mode (Pro feature) that lets two users link their accounts for household financial planning. Here is how it works:

7 Data Storage & Security

Your data is stored securely using Supabase, hosted on Amazon Web Services (AWS) infrastructure in the United States. All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256.

We implement industry-standard security practices including:

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security and encourage you to use a strong, unique password and enable 2FA.

8 Data Retention

We retain your personal data only as long as necessary for the purposes described in this policy:

If you delete your account, we may retain limited data if required by law (e.g., tax records for payment transactions), but all personal financial planning data is permanently deleted.

9 Data Breach Notification

In the event of a data breach that compromises your personal information, we will:

10 California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

How to Exercise Your Rights

Submit a verifiable consumer request by emailing privacy@firetrajectory.com with the subject line “California Privacy Request.” We will verify your identity using the email associated with your account. We will respond within 45 days (extendable by 45 additional days with notice). You may make up to two requests per 12-month period.

Authorized Agents

You may designate an authorized agent to submit a request on your behalf. The agent must provide written proof of authorization (e.g., a signed letter or power of attorney) and we may still verify your identity directly.

California “Shine the Light” (Civil Code § 1798.83)

We do not disclose personal information to third parties for their direct marketing purposes. Therefore, no “Shine the Light” opt-out is necessary.

Do Not Sell or Share My Personal Information

We do not sell or share personal information with third parties for cross-context behavioral advertising. This has been the case since the Service launched and will remain our policy.

CCPA Data Disclosure (Previous 12 Months)

In the preceding 12 months:

11 European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) or equivalent legislation.

Legal Basis for Processing

Processing ActivityLegal Basis (GDPR Art. 6)
Account creation and authenticationPerformance of a contract (Art. 6(1)(b))
Providing financial planning featuresPerformance of a contract (Art. 6(1)(b))
Partner Mode data sharingYour explicit consent (Art. 6(1)(a))
Payment processing via StripePerformance of a contract (Art. 6(1)(b))
Security and abuse preventionLegitimate interests (Art. 6(1)(f))
Aggregate analyticsLegitimate interests (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))

Your GDPR Rights

International Data Transfers

Your data is stored and processed in the United States. Transfers of personal data from the EEA/UK to the US are conducted under appropriate safeguards, including the EU-US Data Privacy Framework (where applicable) and Standard Contractual Clauses (SCCs) maintained by our infrastructure providers (Supabase/AWS, Netlify, Stripe).

To exercise any GDPR rights, contact us at privacy@firetrajectory.com. We will respond within 30 days.

12 Third-Party Services

Fire Trajectory uses the following third-party services to operate:

We do not use Google Analytics, Facebook Pixel, advertising networks, or any third-party service that receives your personal financial data.

13 Children’s Privacy

Fire Trajectory is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have inadvertently collected personal information from a child under 16, we will promptly delete it. If you believe a child has provided us with personal information, please contact us immediately at privacy@firetrajectory.com.

This policy complies with the Children’s Online Privacy Protection Act (COPPA) and GDPR Article 8.

14 Email Communications (CAN-SPAM)

We comply with the CAN-SPAM Act. All emails from Fire Trajectory:

Transactional emails (password resets, security alerts, policy change notices) are exempt from opt-out requirements as they are necessary to provide the Service.

15 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

For non-material changes (e.g., formatting, clarifications), continued use of Fire Trajectory after changes are posted constitutes your acceptance. If you disagree with any changes, you may delete your account at any time.

16 Contact & Data Controller

Fire Trajectory is the data controller for personal information collected through this Service.

We do not currently have a Data Protection Officer (DPO) as we are a small-scale processor. If this changes, we will update this section. For GDPR-related inquiries, please email privacy@firetrajectory.com with “GDPR Request” in the subject line.

For California privacy requests, include “California Privacy Request” in the subject line. We aim to respond to all privacy requests within 30 days (45 days for CCPA requests).