Legal
Privacy Policy
Version 2026-09-24. This policy describes what Midfire processes when you use the Service.
1. Who we are, and what this covers
Midfire ("Midfire", "we", "us") provides the Service described in our Terms of Service: a decision record for your company, where your team frames, decides, and keeps its decisions. This policy covers the Service and the midfire.ai website. Midfire is responsible for the processing it describes, and you can reach us about it at hello@midfire.ai.
The design principles behind everything below: your content is yours and exports as plain files at any time; the documents you check are read once and never stored; every change is attributed to a person and kept in a log; and this page names everything we hold.
2. What we process
Account data. Your email address and, where your sign-in provider shares it, your name. You sign in with a link sent to your email, or with a Google or Microsoft account; the provider tells us who you are and nothing else. We keep an account record (an identifier, your email, your name) and your workspace memberships, so we know which workspaces you belong to and with which role.
Workspace content. The decisions your team frames and commits, the people named on them, the company context your team writes, the publications you share, and the log of who did what. It lives in Midfire's database, in a workspace only its members can reach; folders decide which members may open which decisions. Files you upload for a document check are read once and never stored: the record keeps a quote, the file's name, and a fingerprint of its bytes. Web pages you add to your company context are read at that moment and not kept; what your team writes from them is.
Billing data. Your plan, seats, and payment details are held by Stripe. We store a non-secret billing summary with your workspace, and we record your acceptance of the Terms (your account, the time, the version, your network address and browser) in our database. Card numbers never touch our systems.
Email we send. Invitations to a workspace; requests for your view on a decision, and their reminders; a decision in progress shared with you; notices when a decision is committed or published to you, one at a time or as a daily or weekly digest, as you choose in your settings; a note when you are added to a folder; and reminders when a decision you decided comes due for review. Each carries your address, the decision's title, and a link; nothing else of its content.
Usage and cost data. We meter each workspace's model usage (counts, costs, and timings, not your content) so we can operate and price the Service honestly.
Operational logs. Short-lived server logs that let us run and debug the Service. They are written to carry event metadata and to withhold the content of your documents and decisions by design.
3. How the AI processes your content
When the Service drafts or assesses something for you (a decision's conditions, the hearing, a document check, an analysis of your company context), the relevant workspace content is sent to Anthropic, our model provider, under keys Midfire owns and manages. That work runs under one Midfire provider account shared across customers. Midfire does not train models on your content.
When you add a web page to your company context, the page is fetched through our reader provider rather than directly. One Midfire reader account serves every workspace, so the addresses you ask us to read reach that provider under our credentials rather than yours.
4. Subprocessors
The Service runs on a small, named set of providers. Each links to its own privacy documentation, so you can read their commitments first-hand rather than take ours for them:
- Supabase (the database and sign-in behind the Service)
- Vercel (application hosting and page analytics)
- Anthropic (language models)
- Jina AI, a Elastic company (fetches the web pages you add to your company context)
- Stripe (billing)
- Google Workspace (sends the email the Service sends you)
We add a subprocessor only when the Service needs it, and this page changes when we do. Our subprocessors page gives the longer version: what each provider receives, and why.
5. Cookies
The Service sets only the cookies it needs to work. There is no advertising or cross-site tracking cookie, and our page analytics run without cookies.
- Sign-in session cookies, issued by our authentication provider and readable only by the server. They last as long as you stay signed in and are renewed as you use the Service; signing out ends them.
- A cookie that remembers which of your workspaces you are working in, and a short-lived one that shows an invite link once to the person who created it.
- A cookie that tells our public site you are signed in, so it can offer to open Midfire instead of asking you to sign in. It holds no name, address or identifier, and signing out clears it.
- A short-lived cookie during sign-in that protects the sign-in itself from being forged.
- A short-lived cookie that remembers the address a sign-in code was just sent to, so the sign-in page can accept the code. It lasts an hour at most and is removed once you are signed in.
- Preference cookies that remember small choices, such as the company you picked in the public demo.
6. How we protect it
- Connections to the Service are encrypted in transit.
- Your workspace is stored encrypted at rest, and the rules about who may open what are enforced inside the database itself, for every query, not only in the application.
- The browser-side application never holds a database or provider credential and never calls a provider directly.
- Provider keys and other secrets live only in server-side code.
- Card numbers are handled by Stripe and never touch our systems.
- Every change to a decision is attributed to the person who made it and appended to a log that cannot be edited or erased, so your record is a tamper-evident account of what happened and who decided it.
7. Retention and deletion
Your decisions and company context stay in your workspace for as long as you keep them. A working draft can be deleted by its author; a committed decision is a permanent record, kept so the company can look back at it, and exportable at any time. The documents you check are never stored. What passes through our servers to answer a request is held only for that request and in short-lived caches that the platform reclaims.
Our database is backed up continuously so that we can recover from a failure. Backups are kept for the recovery window (days, not months) and then age out; something you delete leaves the backups on that schedule. If we ever have to restore from a backup, we aim to be back within a few hours, and we tell you what was lost, if anything.
Our providers keep their own records for a limited period, on their own published schedules, which is a normal part of running a service safely. Anthropic sets that out in its API data-retention documentation, and the subprocessors listed above each publish theirs. We tell you this because “never stored” describes our servers, and you deserve the whole picture.
Signing out ends your session. A workspace admin can remove a member at any time, and that person loses access on their next request. If you close your workspace, export your record first, then ask us at hello@midfire.ai: we delete the workspace, its members' access, and your billing customer record, and the backups age out on the schedule above.
8. Your rights
You can ask us what we hold about you, ask for corrections, or ask for deletion at hello@midfire.ai. We answer these requests for everyone, and where a jurisdiction gives you specific data protection rights (such as the GDPR or U.S. state privacy laws), we honor them.
- Portability is built in: from Settings, any member can export the workspace as plain Markdown files at any time, without asking us. The export holds what that member may open.
- We do not sell personal information.
- We run no advertising and no cross-site tracking, so there is nothing to opt out of.
9. Where processing happens
Our subprocessors are United States companies, and your content is stored and processed in the United States. If you use the Service from elsewhere, you are sending your content there.
10. Children
The Service is a business tool for companies. It is not directed to children, and we do not knowingly process children's personal data.
11. Changes to this policy
When this policy changes, the version number above changes with the Terms of Service, the sign-in door presents the new version, and your acceptance is recorded again at your next sign-in.
12. Contact
Questions about this policy, or any request about your data: hello@midfire.ai.