Legal
Privacy policy
Version 1.0 · Last updated 15 September 2026
How Firelent collects, uses and protects your data.
1. Who we are and what this policy covers
Firelent is a platform that turns a written description into a working website or native app: you describe what you want, our systems plan and build it, and you refine and publish it — from the browser, or by messaging our Telegram assistant. This policy explains what personal data we handle when you do that, why we handle it, where it goes, and what rights you have.
The controller responsible for the processing described here is Firelent UG (haftungsbeschränkt), Königstraße 38, 70173 Stuttgart, Germany (“Firelent”, “we”). You can reach us about anything in this policy at privacy@firelent.com.
This policy applies to our websites, the Firelent studio, our APIs, the Telegram assistant and our mobile applications. It is written to satisfy the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG), and — for users outside Europe — the privacy laws that apply to them, to the extent they reach us.
2. Two different roles — read this first
Firelent processes data in two clearly separated roles, and your rights run against a different party depending on which side of the line the data sits on.
- Your data — Firelent as controller. Everything connected to your Firelent account: your registration details, billing, the projects you create, the prompts you write, your usage of the platform and your communications with us. This policy governs that data.
- Your project’s data — Firelent as processor. When you publish a website or app, other people interact with it: they visit pages, submit forms, place orders, create accounts, make bookings. That data belongs to your project. You decide why it is collected; we store and process it strictly on your behalf under our Data Processing Agreement. People who use something built with Firelent should direct privacy requests to the person or business that operates it — its own privacy notice says who that is (and for projects in Germany, its Impressum).
3. The data we collect
Data you give us
- Account data. Email address, display name and your sign-in method: a password (stored only as a salted hash) or a one-time code we email you, or Google sign-in, in which case Google sends us your name, email address and profile picture and nothing else.
- Project content. The prompts and instructions you write, files and images you upload, the pages, code, text and configuration our systems generate for you, and the change history of your project. Prompts are free text — please do not put data about your health, beliefs or other special categories (Art. 9 GDPR) into them; the product never asks for it.
- Business data for your project.If you use our compliance features, we ask for the facts a lawful website in your market needs — for German projects, for example, the operator’s name, address, legal form, register entries and VAT ID for the Impressum, plus opening hours and contact details. These facts are published on your site because that is their purpose.
- Billing data. Your plan, credit balance and transaction history. Card and bank details go directly to our payment provider Stripe; we never receive or store full payment card numbers.
- Domain registration data. If you register a domain through Firelent, the registrant contact details required by the registry — name, address, email, phone.
- Communications. Support requests and emails; and, if you link Telegram, your Telegram user ID and the messages you exchange with our assistant there.
Data collected automatically
- Technical and usage data. IP address and the approximate (city-level) location derived from it, browser and device type, sign-in events, the features you use, generation and publishing events, credit consumption per AI model, and error and diagnostic logs. We do not collect precise location.
- Cookies and similar storage — described in section 10.
Data from integrations you connect
When you connect an external account — GitHub to sync your project’s code, Vercel to deploy to your own hosting, Stripe to sell through your shop — we receive and store the tokens and identifiers needed to act on your instruction, and nothing beyond the permissions you granted. Disconnecting an integration ends our access.
Voice input
If you use the microphone button, speech recognition is performed by your browser or operating system under its vendor’s terms; we receive only the resulting text, as part of your prompt.
4. Why we use your data, and the legal basis for each purpose
- Running the platform — operating your account, generating and storing your projects, previews, publishing, support and billing. Basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- AI generation — sending your prompts and the relevant project context to the AI model providers described in section 5. Basis: performance of our contract (Art. 6(1)(b) GDPR).
- Making the product remember your project — we keep a technical memory per project (decisions, structure, preferences you have expressed) so you do not have to repeat yourself. Basis: performance of our contract (Art. 6(1)(b) GDPR).
- Improving Firelent — analysing usage in aggregate, diagnosing failed generations, and deriving content-free editing patterns (rules about how kinds of changes are best applied — stripped of your text, names and data) that make edits faster and cheaper for everyone. Basis: our legitimate interest in improving the service (Art. 6(1)(f) GDPR); you may object at any time (section 14).
- Security and abuse prevention — detecting fraud, misuse of credits, attacks and violations of our platform rules. Basis: legitimate interest in protecting the platform and its users (Art. 6(1)(f) GDPR).
- Payments, accounting and tax — metering credits, invoicing and keeping the records German commercial and tax law requires. Basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c) GDPR).
- Communication — service and security notices (contract); product news and marketing only with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future.
- Legal claims — establishing, exercising or defending legal claims. Basis: legitimate interest (Art. 6(1)(f) GDPR).
We do not make decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you. If an automated safeguard ever restricts your account, a person reviews it on request — write to privacy@firelent.com.
5. How AI generation actually works with your data
When you submit a prompt, our backend assembles what the task needs — your prompt, the relevant files of your project, your project’s technical memory and, for visual checks, screenshots of the pages being built — and sends it to one or more large-language-model providers to produce the result. Depending on the task we use models operated by Anthropic, Google and OpenAI, partly reached through the API gateway OpenRouter (all USA). Which model handled a request is visible in your usage overview.
- What is sent: only what the specific task requires. Our tooling is built so the model reads the parts of your project it needs rather than receiving everything wholesale.
- What providers may do with it: we use these providers under their business API terms, which do not permit them to use API content to train their models, and which limit retention to short-term abuse and operations purposes as described in their terms.
- What we do not do: we do not train foundation or general-purpose AI models on your prompts or your project content, and we do not sell either. Trained members of our team may look at an individual generation where that is necessary to fix a failure you reported, to investigate abuse, or to verify quality — under confidentiality and access controls.
6. Who receives personal data
We share personal data only with recipients that need it to run Firelent, under contracts that bind them to purpose limitation, confidentiality and security (Art. 28 GDPR where they act for us):
- Hosting and databases — Amazon Web Services; our application servers and databases run in the EU (Frankfurt region).
- Content delivery and publishing storage— Cloudflare (USA / global network): published sites, previews and uploaded assets are stored and served through Cloudflare’s network so they load fast worldwide.
- Build and preview infrastructure — Fly.io and Modal (both USA): short-lived machines that compile app builds and run live previews of your project while you edit.
- Web frontend hosting — Vercel (USA), which serves the Firelent web application itself.
- AI model providers — Anthropic, Google, OpenAI and the gateway OpenRouter, as described in section 5.
- Payments — Stripe, for subscriptions and credits.
- Domain registration — Name.com as registrar, plus the registry operating your domain ending and, where ICANN rules require, ICANN and a data-escrow provider. For most endings your contact details are shielded from public lookups by default.
- Messaging — Telegram, if you link it, to deliver the assistant conversation you initiate there.
- Integrations you enable — GitHub, Vercel, Stripe or others you connect: we send them what your instruction requires and no more; their own privacy policies govern their side.
- Image search — if you search stock photography inside the studio, your search terms are sent to Unsplash to return results.
- Authorities and courts — where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims or to protect people from serious harm. Unless we are legally barred from doing so, we tell you first.
- Corporate transactions — if Firelent is ever party to a merger, financing or sale, data may be disclosed to the parties and their advisers under confidentiality, and this policy continues to apply to it.
We do not sell personal data, and we do not share your project content with advertising platforms.
7. Your shop, your money, your code
- Selling through your project.If you enable commerce, you onboard with Stripe under your own Stripe account. Your customers’ payments flow from them to Stripe to you — Firelent never receives or holds your customers’ money or card details. Order records stored in your project are your project’s data (section 2) and we process them only for you.
- GitHub.If you connect GitHub, your project’s code lives in a repository in your GitHub account. Commit messages may include the prompts that produced the change, so consider that when making a repository public.
- Deploying elsewhere. If you deploy to your own Vercel account, the deployed code and its traffic are handled by Vercel under your agreement with Vercel.
8. Analytics on the sites you publish
Projects published with Firelent include our own, first-party analytics so you can see how your site performs: page views, the pages visited, referrer, device type and country/city derived from the IP address. It is built for aggregate measurement — it sets no advertising cookies and builds no cross-site profiles, and raw identifiers are not kept beyond what the aggregation needs. This measurement data is your project’s data: you are its controller, we process it on your behalf, and you are responsible for your own site’s privacy notice.
9. The Telegram assistant
Linking Telegram is optional. If you link it, we store your Telegram user ID against your account and process the messages you send there exactly like prompts in the studio — including forwarding them to the AI providers in section 5 to produce your edits. Telegram itself handles the transport of your messages under its own privacy policy. You can unlink Telegram at any time in your account; unlinking deletes the link between your Telegram ID and your account.
10. Cookies and similar technologies
We keep this layer deliberately small. Firelent uses strictly necessary storage — keeping you signed in, routing your session, remembering consent — which requires no consent under § 25 (2) TDDDG, and functional storage for preferences such as language or layout. We currently set no third-party advertising cookies. If we ever introduce analytics or marketing cookies that require consent, we will ask for it first and you will be able to change your choice at any time at Cookie settings, where the current list of everything we set is maintained.
11. International data transfers
We are a German company and our primary infrastructure runs in the EU. Several of the providers in section 6 are, however, US companies or process data on global networks. Where personal data leaves the EEA, we rely on the safeguards the GDPR provides: an adequacy decision where one exists — including the EU–US Data Privacy Frameworkfor providers certified under it — and otherwise the European Commission’s Standard Contractual Clauses (2021/914), supplemented by a transfer impact assessment and technical measures such as encryption in transit and at rest. You can request a copy of the safeguards applicable to your data (with commercial terms redacted) at privacy@firelent.com.
12. How long we keep data
- Account and project content — for as long as your account exists. After you delete your account, or a verified deletion request, we delete or irreversibly anonymise it within 30 days; copies in encrypted backups are purged within a further 90 days.
- Published sites — taking a site offline removes it from serving; its stored data follows the account rules above.
- Technical and security logs — up to 12 months, longer only while an incident is being investigated.
- Billing and tax records — for the statutory retention periods of German commercial and tax law (§ 257 HGB, § 147 AO): currently up to ten years. These records are kept even after account deletion, in a form limited to what the law requires.
- Consent, opt-out and notice records — for as long as we must be able to demonstrate compliance.
13. Security
We protect personal data with technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption in transit and at rest, role-based access limited to staff who need it, multi-factor authentication, isolation between customer projects, secret management for the tokens of integrations you connect, monitoring and centralised logging, and vetted providers bound by contract. No system is perfectly secure; if a breach occurs that we must report, we will notify the supervisory authority and, where required, affected users within the legally mandated timeframes (Art. 33, 34 GDPR). Help us by using a strong, unique password and keeping sign-in codes to yourself.
14. Your rights
Under the GDPR you can, free of charge:
- Access your data and receive a copy (Art. 15), including in a portable, machine-readable format (Art. 20);
- Correct inaccurate data (Art. 16) and delete your data and account (Art. 17);
- Restrict processing in the situations Art. 18 describes;
- Withdraw any consent at any time, with effect for the future (Art. 7(3)).
Right to object (Art. 21 GDPR): where we process your data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation, and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. If data is ever used for direct marketing, you may object at any time without giving any reason, and we will stop immediately.
To exercise any right, use your account settings or write to privacy@firelent.com. We answer within one month; if a request is complex we may extend by up to two further months and will tell you why within the first month. Where we genuinely doubt who is asking, we verify identity through the email address on the account, requesting further proof only where necessary.
You also have the right to complain to a data protection supervisory authority — in any EU member state where you live or work, or where you believe an infringement occurred. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
If your data sits inside someone else’s Firelent project — you used a website or app built by one of our customers — address your request to its operator (section 2). Where we can, we will help route your request to them.
15. Age
Firelent is for adults: you must be at least 18 years old to create an account. If we learn that someone younger holds an account, we will close it and delete the associated personal data. Parents and guardians can reach us at privacy@firelent.com.
16. Changes to this policy
When we change this policy in a way that reduces your rights or meaningfully expands our use of your data, we will notify you at least 30 days before the change takes effect — by email or a prominent notice in the product — and, where the law requires consent for a change, we will ask for it. Earlier versions are available on request.
17. Contact
Firelent UG (haftungsbeschränkt)
Königstraße 38
70173 Stuttgart, Germany
privacy@firelent.com