Firmhold

Privacy Policy

Last updated: July 2026

What we collect

Firmhold collects only what it needs to function:

  • Account data: your email address and hashed password (stored by Supabase Auth).
  • Profile data: your stated goal, estimated monthly cost, baseline frequency, and timezone (everything you enter during onboarding or in settings).
  • Log entries: the type (relapse or urge survived), intensity, stress level, triggers, and timestamp of each entry you submit.
  • Computed patterns: aggregated behavioral patterns derived from your log entries and stored for your insights report.
  • Payment data: managed entirely by Polar, our merchant of record. We do not store card numbers. We store your Polar customer ID and subscription status.

Age requirement

Firmhold is intended for adults 18 and older, consistent with our Terms of Service. We do not knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we will delete it.

How we use your data

  • To provide you with behavioral pattern analysis and insights.
  • To compute your daily risk level and personalize your dashboard.
  • To process subscription payments through Polar.
  • To send transactional emails (account creation, password reset). We do not send marketing emails without your consent.

We do not sell your data. We do not share it with third parties except as described below.

Third parties

  • Supabase: database and authentication hosting. Your data is stored on Supabase infrastructure. Supabase Privacy Policy.
  • Polar: payment processing (merchant of record). We pass your email to Polar when you subscribe. Polar Privacy Policy.
  • Vercel: application hosting. Vercel processes HTTP requests to our servers. Vercel Privacy Policy.
  • Sentry: error monitoring. Sentry receives crash reports and stack traces when something breaks; it never receives your log entries, patterns, or other account content. Sentry Privacy Policy.

Firmhold Companion (browser extension)

The optional Firmhold Companion browser extension checks your open tabs, including ones in the background rather than just the one you're viewing, to notice when a site you've personally chosen to monitor is open. It never reads page content, page titles, or your general browsing history, and matching happens locally in the extension itself. When it detects a session on a monitored site, only the domain, a duration, and a timestamp are sent to Firmhold's servers, never the full URL and never anything from tabs that don't match your list. Nothing is auto-logged: a detected session appears as a card in your dashboard for you to confirm as a relapse, an urge survived, or a false positive. You can edit or clear your monitored-domain list at any time from Settings, and pause or disconnect the extension whenever you want.

Data retention

Your data is retained as long as your account is active. You can delete your account at any time from the Settings page. Account deletion permanently removes all log entries, patterns, and profile data. Payment records are retained by Polar per their legal obligations.

Your rights

  • Access: You can view all your data within the app.
  • Deletion: You can delete your account and all data from Settings → Danger Zone.
  • Portability: Contact us to request a CSV export of your log entries.

Security

All data is transmitted over HTTPS. Row-level security ensures users can only access their own data. Passwords are hashed and never stored in plain text. Pattern analysis runs on our servers. Your data is never sent to a third-party AI service.

Contact

Questions about this policy? Email support@firmhold.app.